Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

381–390 of 666 posts

Re: NordVPN confirms it was hacked

#381
post #360

Earlier quoted context omitted.

I've heard the same thing from cryptography authorities in regard to rolling your own encryption and it makes sense to me. Having specialized knowledge opens your eyes to all the gotchas and gottahaves that most people wouldn't think about. While you certainly can take the time to set everything up exactly the way it should be and keep it updated, I'd rather spend my time doing/thinking about other stuff and am happy…

Rolling your own encryption is an entirely different animal. I agree with that sentiment for encryption. When you use a VPN service, though, you really don’t have any real insight into what’s going on on their servers. Run your own and you can be sure you’re running the most recent, audited version of OpenVPN on an updated operating system.

You're right and I don't disagree with your core thinking, except to say that everyone draws a line beyond which they'll be happy to trade some risk for some time. I understand why someone would run their own VPN, but I also understand why someone wouldn't.

Re: NordVPN confirms it was hacked

#382
post #188

Earlier quoted context omitted.

For dedicated servers this would work, especially for VPN where data-loss is "acceptable". But if it where based on containers like LXC or OpenVZ, then the host can force root access via a command without even changing the root password of the container.

I doubt serious VPN provider are using LXC/OpenVZ containers. They don't even work with OpenVPN without special setup from provider, I don't know how about other protocols.

NordVPN _was_ (and certainly still is) using LXC containers. Look at the document linked in the Techcrunch article.

Re: NordVPN confirms it was hacked

#383
post #251

Earlier quoted context omitted.

I’m not a network expert, but doesn’t TLS just cover your connection with a specific website? Since your IPS is often also your DNS, can’t they still see which specific websites you’re trying to connect to? Wouldn’t TLS just obfuscate what you’re specifically sending to and receiving from that site? I’m under the impression that my ISP can (and probably does) see every website I visit, which is in the least browsing…

That’s what the parent said: they can still see “hostnames and IP addresses.” But, for most people, that means that the ISP will just see: • google.com • facebook.com • reddit.com • somebignewspaper.example.com Etc. And there’s really nothing much too valuable about that. They won’t even be able to figure out if you’re shopping for something (unlike every other nosy channel provider), because most shopping traffic to…

I see. As someone who has practically zero knowledge of networking, I had misconstrued hostnames for something else, which I’m now too embarrassed to mention.

Very educational response though. Thank you.

Re: NordVPN confirms it was hacked

#384
post #359

Earlier quoted context omitted.

Definitely appreciate your concern here, but there's still a lot which is being confused. Proton does not today, and has never, used contracted (outsourced) employees. As is common with startups, in the past we did not always do all our HR in house (it's all in house today), but employees were always working on Proton and for Proton. There are no board members, directors, shareholders, or employees, related to Tesone…

Slightly off-topic but I am delighted by the generally non-abrasive way this thread is going. Dialogue is good! I realized another way that would work for you guys (but is out of your hands) is fighting a court case about this. You'd be legally compelled to tell the truth and very screwed if you deny but then it comes out there is logging or mining going on. It's not ironclad but it is how most VPNs end up being cons…

We have indeed retained lawyers to look into our options to fight the online defamation, but its hard to take anonymous accusers to court. However, as we have discussed here (https://protonvpn.com/blog/is-protonvpn-trustworthy/) there is already a lot of ironclad legal evidence.

First, were we to lie in our privacy policy, we would be subject to GDPR fines of up to 20 million Euros, since we have both European customers, and a presence in the EU.

Second, there has already been a court case. We were ordered by a Swiss court to hand over logs, and we stated truthfully (under penalty of perjury) that we did not have the logs requested. This case was previously disclosed here: https://protonvpn.com/blog/transparency-report/

Re: NordVPN confirms it was hacked

#385
post #83
post #61

Earlier quoted context omitted.

Any (large?) ISP will report your torrenting and/or terminate your internet usage if you torrent anything they deem copyrightable. Both Comcast and Spectrum do this, at least. Edit, to add: No VPNs do this.

>Edit, to add: No VPNs do this. counter-example: https://forum.goldenfrog.com/t/no-longer-feeling-private-aft...

If you read the last message in the thread, they no longer log IP. At the time the user originally posted his complaint, they did.

Re: NordVPN confirms it was hacked

#386

Earlier quoted context omitted.

I am guessing #1 is mot wanting your internet provider (eg. AT&T) knowing what you are doing, then Netflix, Torrents, getting better deals on tickets and such, maybe activities of questionable legality? Personally, I don't like the idea of my mobile provider profiting off knowing which applications I am using and what sites I visit.

I don't understand being unhappy with your ISP knowing these things, but being fine with your VPN provider knowing them.

Well your ISP knows more about you than your VPN necessarily does. Your ISP probably has your credit card on file, with your real name, and they have your precise street address too. The VPN may have none of that, except your IP address. If somebody were to purchase your history from your VPN, they would have to also purchase the IP->name/address/etc mapping from your ISP and JOIN the two. That seems marginally better than a one stop shop.

(Of course, some people give their VPN their credit card info, so the above rationale doesn't apply for them.)

Re: NordVPN confirms it was hacked

#387
post #363
post #348

Earlier quoted context omitted.

I normally don’t mind YouTube ads all that much, and I don’t see them on desktop browsers anyway. However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. Hard to relax with some totally not weird ASMR when my blood pressure is through the roof because some chirpy ad agency dude wants to show me how much a VPN is like an umbrella or whatever.

> However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. For me it was those incessant Grammarly ads. A service, by the way, that has its own serious security and privacy concerns[0]. (I feel like YouTube Premium ($18/mo for up to 6 people) is a better deal than Spotify Premium ($15/mo for up to 6 people) for a household like mine where we liste…

Yeah, Grammarly is creepy as hell. I've explicitly banned it (and similar services) at work.

As for Youtube music, yup, that's undeniably a good deal. The music services should watch out, especially in younger demographics (I'm already 30+, Spotify premium user since 2009). Apple will probably push Music even harder and bundle that with their new video streaming. Spotify's really trying to become the defacto podcast service, which sucks in its own right (unlike Apple Podcasts, no user facing RSS support for indie premium content etc. Podcasting is the last free rich medium on the internet, largely thanks to Apple).

As for music, I'm too deep in the Spotify ecosystem myself, with stuff like proper Last.fm integration, recommendations and consistent audio quality.

I can't really enjoy music with that mushy sound typical for content that has been lossy-lossy transcoded tons of times. Of course, I have to deal with that for all the awesome live takes[1] available on Youtube, and there I'm of course just grateful they exist.

Spotify's audio didn't use to be all that great, except with the normalization turned off. Now with their 'quiet' normalization option, that doesn't compress quiet tracks (a clear edge over Apple Music), it's starting to sound transparent to me, as -q 9 encoded (~320 kbps) Vorbis should.

Youtube doesn't allow disabling of normalization at all, and it's not super clear to me when tracks are clean encodes sourced from the proper music distribution ecosystem that stocks Spotify, Apple Music, Tidal et al.

1 - https://www.youtube.com/watch?v=E4V66UP4aDs

Re: NordVPN confirms it was hacked

#388
post #33

Earlier quoted context omitted.

Yeah it's diffidently not being recommended, it is being advertised. I wonder how many money they have spend. Every freaking channel mention them at some point.

You start to wonder where their money is coming from - their retail prices are already cheap, the discounts the influencers offer make it basically free. How's that sustainable?

But do they even have to pay much to youtubers for those ads? If you get 50k to 100k views per video then you'll likely make around the range of $50-$150 for the video. Paying the youtuber $50-$100 per video would already have a significant impact on their income, so they'd probably consider it. That would be 50k-100k people who will see the ad, because adblock can't block it.

Re: NordVPN confirms it was hacked

#390
post #380

Earlier quoted context omitted.

AWS has external auditors verify their policies, procedures, and actual methods meet a wide variety of compliance requirements from many different agencies. The level of access those auditors and other verification methods have to AWS is not none but very significant. https://aws.amazon.com/compliance/programs/

That page looks impressive but there is no way to casually verify that what they are talking about actually happens (on a quick check). There is simply so much info there you'd have to spend considerable time trying to track down what is needed to make sure it's actually legit. [1] Of course with 'assume' with AWS it is and it's meaningful but my point is if someone else were doing that people might simply 'check the…

As for [1], the FTC etc. do a bad job of regulation, especially of Amazon. I actively do not trust Amazon to sell me things I ingest.

>there is no way to casually verify that what they are talking about actually happens

I have first hand experience working in more than one organization with security departments which did this sort of verification of vendors. Usually as required by law.

And the opposite was true as well, working in organizations which were beholden to those kinds of compliance requirements and to customers (and investors) verifying them.

It is indeed a long process with a lot of work. That kind of "box checking" tends to happen sometimes but not in an inventing reality way but a cargo cult way. There is enough surface area of these regulations though that you can't just get away with a song and dance, you end up actually having to do the right things.

Post reply on HN