Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

371–380 of 666 posts

Re: NordVPN confirms it was hacked

#371
post #125

Earlier quoted context omitted.

Truth is - if hackers did a MIM attack and collected a bunch user traffic (for how long?) they could have everything.. banking info, emails, logins... at this point if i was a user of that VPN service - i'd be replacing all of my sensitive passwords, secret questions/answers to key accounts.

A MITM attack of a VPN allows attackers to collect unencrypted traffic. Most people access email over a webmail interface, like gmail, that uses modern TLS encryption. All that's sent unencrypted is the SNI header, e.g. "mail.google.com", and roughly how much traffic total is transferred, e.g. "20 MB of browsing on mail.google.com". A VPN can't easily defeat TLS. It would require the user to ignore many scary warning…

The sky is not falling!

Everyone is discounting one thing - State actor possibility behind this attack.

With state actor comes completely different ball game - totally different budget and capabilities to crack things. NOBODY knows what their unpublicized capabilities could be! So it is good practice to stay vigilant!

Re: NordVPN confirms it was hacked

#372

I don't understand the obsession with VPN providers. Funneling all your Internet access through a single entity no matter where you connect from just seems like a fundamentally bad idea to me, especially if that entity's business is getting people to funnel all their traffic through, making them a juicy target for governments or hackers.

Regardless of anonymity or privacy, my ISP almost certainly deprioritizes some traffic (video), so a VPN at least ensures I can use my full bandwidth for whatever I want to access on the Internet.

Re: NordVPN confirms it was hacked

#374

Earlier quoted context omitted.

Google can track you fairly effectively even if you’re behind a VPN. I’m not sure if they choose to at this time, but if a significant population switches to hiding behind VPNs, they will turn on the finer fingerprinting means.

>Google can track you fairly effectively even if you’re behind a VPN. You don't know anything about my setup, so you have no basis for claiming this. On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and look at basic HTTP logs.

> You don't know anything about my setup, so you have no basis for claiming this.

Sure, but the discussion isn't specifically about your setup, it's about the advertising claims that a VPN will help prevent tracking. Which is totally bunk.

> On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and look at basic HTTP logs.

Tracking with IP is honestly hardly tracking at all. With local network NAT and CGN your device IP will not be unique at all. With modern tracking, your IP will be just another couple bits of entropy, and most certainly not enough to pinpoint traffic to individuals in a robust and scaleable way.

The only tracking protection that a VPN offers is preventing your ISP from seeing your traffic, and making it harder to pinpoint web traffic to you as an individual (assumging you VPN provider doesn't have logs)

Re: NordVPN confirms it was hacked

#376

Earlier quoted context omitted.

AWS has external auditors verify their policies, procedures, and actual methods meet a wide variety of compliance requirements from many different agencies. The level of access those auditors and other verification methods have to AWS is not none but very significant. https://aws.amazon.com/compliance/programs/

Yea, but my example wasn't access that auditors have, it's you, as a client. Now on topic... You could argue that Nord perhaps was a bigger client than you or I am to AWS, and maybe they should have had better access, but the fact of the matter here is that it's absolutely possible that Nord is being accurate when they say "[we] could not have known". Contract violation or not, you should never have full 100% confide…

As a client I can ask for policies, records, 4th party audit reports, etc and choose your vendor based on their ability to answer and the quality of answers.

It's not about contract violations if something like that happens you don't know about, it would have to be willful deception and incompetence of several organizations.

"we could not have known" is an answer you get when what you really mean is "we didn't think to look". If something like this happened and you had done the right things the message would be "vendor X violated their policy, our contracts, and auditors A, B, and C failed due diligence requirements here and here"

"We could not have known" as a response means no one should trust NordVPN because clearly they think they're helpless which means they aren't clever enough to trust my data with.

> you should never have full 100% confidence in someone else's system

Of course.

Re: NordVPN confirms it was hacked

#377

Earlier quoted context omitted.

Regular people who are NordVPN’s customers can’t possibly understand that. A highly technical explanation is not good enough. They need to put out a statement that explains clearly and concisely what this means for their users, something that all people can understand.

"To recap, in early 2018, one isolated datacenter in Finland was accessed without authorization. That was done by exploiting a vulnerability of one of our server providers that hadn’t been disclosed to us. No user credentials have been intercepted. No other server on our network has been affected. The affected server does not exist anymore and the contract with the server provider has been terminated." Not sure what…

Ok, I’m going to pretend that I’m a NordVPN customer who is 50, works as a plumber, and has installed a VPN on their phone because they were convinced that it’s very good for privacy. Here goes…

“What is a datacenter? How was it accessed? Like in that Mission Impossible movie? What are server providers? What role do they play in all this? Credentials? That’s like my passwords? What about my browsing activity? All I want to know is if my traffic was spied on.”

How was I?

Re: NordVPN confirms it was hacked

#378

Earlier quoted context omitted.

This has been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence. ProtonVPN is 100% owned by the company behind ProtonMail, which in turn is funded by the European Union, so this has been verified by the European Commission. Details here: https://bit.ly/35RDKzB

Over the course of the disclosure of the connection between NordVPN, Tesonet, and possibly ProtonVPN, Proton's story kept changing. They said contradicting things multiple times. They locked the Reddit thread. Why did Proton keep changing their story if they had nothing to hide? I will keep reminding this every time the issue gets raised. There is a compilation [0] of changing Proton's responses and them successively…

Both Mozilla and the European Commission have looked into the accusations being made on anonymous websites, and determined that they are false. The EU in particular, has access to records which allow independent verification.

There is also an abundance of public record which demonstrates this is false. The bad faith of those spreading this information is also apparent from the hundreds of fake Twitter accounts used to spread the rumors.

If you are acting in good faith, then we ask that you also take a moment to verify your facts and discover the truth, much of which can be found here: https://protonvpn.com/blog/is-protonvpn-trustworthy/

Re: NordVPN confirms it was hacked

#379

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

If someone hacks a VPN, what are the implications for the users?

As long as you're using HTTPS, you don't have to worry about your passwords or session tokens being stolen, right? Is it just your DNS records and unencrypted HTTP traffic?

Re: NordVPN confirms it was hacked

#380

Earlier quoted context omitted.

That supplier may be in violation of their contract. If Nord put in that there are to be no undisclosed methods to access the supplier system they're renting, and there are, this doesn't change any facts about the incident here. If I was a Nord user, I wouldn't care that the supplier will refund Nord their service charges. I don't think "no one could know" is ridiculous on it's own. Think about the level of access yo…

AWS has external auditors verify their policies, procedures, and actual methods meet a wide variety of compliance requirements from many different agencies. The level of access those auditors and other verification methods have to AWS is not none but very significant. https://aws.amazon.com/compliance/programs/

That page looks impressive but there is no way to casually verify that what they are talking about actually happens (on a quick check). There is simply so much info there you'd have to spend considerable time trying to track down what is needed to make sure it's actually legit. [1] Of course with 'assume' with AWS it is and it's meaningful but my point is if someone else were doing that people might simply 'check the box' and say 'ok they have this handled'. Might not be the case.

[1] Edit: Story today about Amazon and expired baby formula:

https://news.ycombinator.com/item?id=21310697

Post reply on HN