Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

341–350 of 666 posts

Re: NordVPN confirms it was hacked

#342
post #60

Earlier quoted context omitted.

ProtonVPN has a large history of being connected to TesoNet, a company providing among other things data mining(!). An extra cherry on top of that is the CEO of TesoNet also being the CEO of CloudVPN, which more or less controls NordVPN. Now that doesn't mean ProtonVPN is automatically compromised but I feel with stuff like no-log VPNs one should always err on the side of caution.

This has been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence. ProtonVPN is 100% owned by the company behind ProtonMail, which in turn is funded by the European Union, so this has been verified by the European Commission. Details here: https://bit.ly/35RDKzB

Over the course of the disclosure of the connection between NordVPN, Tesonet, and possibly ProtonVPN, Proton's story kept changing. They said contradicting things multiple times. They locked the Reddit thread. Why did Proton keep changing their story if they had nothing to hide? I will keep reminding this every time the issue gets raised. There is a compilation [0] of changing Proton's responses and them successively admitting more and more things not in their favor. The compilation starts at the part called "Online accusations fly".

[0] https://restoreprivacy.com/lawsuit-names-nordvpn-tesonet/

Re: NordVPN confirms it was hacked

#343

People have been talking about using VPN's because of "dangerous" public wifi, but I have to admit, I don't understand the risks. Let's say you go to a coffee house and sign-in to their wifi with their password and use it browse https websites, like gmail or you favorite social media... what's the main risk? What can happen? What does happen?

The primary concern is MITM attacks I'd presume.

Re: NordVPN confirms it was hacked

#344

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

"no one could know" is ridiculous. A proper security team vets all of its vendors and ultimately writes security issues like this into contracts.

That supplier may be in violation of their contract. If Nord put in that there are to be no undisclosed methods to access the supplier system they're renting, and there are, this doesn't change any facts about the incident here.

If I was a Nord user, I wouldn't care that the supplier will refund Nord their service charges.

I don't think "no one could know" is ridiculous on it's own. Think about the level of access you have to ensure AWS or Azure is truly secure... none.

Re: NordVPN confirms it was hacked

#345

People have been talking about using VPN's because of "dangerous" public wifi, but I have to admit, I don't understand the risks. Let's say you go to a coffee house and sign-in to their wifi with their password and use it browse https websites, like gmail or you favorite social media... what's the main risk? What can happen? What does happen?

DNS spoofing is one I think. You request mybankwebsite.com and end up entering you login info on mybankwebslte.com

Re: NordVPN confirms it was hacked

#346

Why would their website's SSL certificate be on one of their VPN servers? Do all of their current 3000 servers have the private key for their website right now?

OpenVPN CA key also leaked: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa...

oof

Re: NordVPN confirms it was hacked

#347
post #188

Earlier quoted context omitted.

I doubt serious VPN provider are using LXC/OpenVZ containers. They don't even work with OpenVPN without special setup from provider, I don't know how about other protocols.

Both LXC and OpenVZ can run VPN services with just setting a couple of flags, I've done it on both.

I know, but these flags have to be set by provider of container, not user (provider of VPN). And they might require changes in kernel.

Re: NordVPN confirms it was hacked

#348
post #230

Earlier quoted context omitted.

I find NordVPN's marketing reprehensible. Too many claims and broad strokes about the "anonymity" their service can provide. While I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data, I think NordVPN really overplays the role of changing IP addresses in the age of browser fingerprinting.

> I find NordVPN's marketing reprehensible. A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.

I normally don’t mind YouTube ads all that much, and I don’t see them on desktop browsers anyway.

However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership.

Hard to relax with some totally not weird ASMR when my blood pressure is through the roof because some chirpy ad agency dude wants to show me how much a VPN is like an umbrella or whatever.

Re: NordVPN confirms it was hacked

#349

Earlier quoted context omitted.

Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa... RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

What is the source of the gist you linked?

It is copy of snippet linked from 8ch.net: https://web.archive.org/web/20180504001844/https://8ch.net/b...

Re: NordVPN confirms it was hacked

#350

Earlier quoted context omitted.

"no one could know" is ridiculous. A proper security team vets all of its vendors and ultimately writes security issues like this into contracts.

That supplier may be in violation of their contract. If Nord put in that there are to be no undisclosed methods to access the supplier system they're renting, and there are, this doesn't change any facts about the incident here. If I was a Nord user, I wouldn't care that the supplier will refund Nord their service charges. I don't think "no one could know" is ridiculous on it's own. Think about the level of access yo…

AWS has external auditors verify their policies, procedures, and actual methods meet a wide variety of compliance requirements from many different agencies. The level of access those auditors and other verification methods have to AWS is not none but very significant.

https://aws.amazon.com/compliance/programs/

Post reply on HN