Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

411–420 of 666 posts

Re: NordVPN confirms it was hacked

#411

Earlier quoted context omitted.

Try running a traffic or packet monitor on a WiFi network. Now tell me how much of that traffic is going over SSL And even if I don’t run my own VPN, I’d prefer to “move the problem”. It’s so much easier to attack machines on public WiFi than compromise a VPN provider... and much more anonymous, and less likely to incite law enforcement activity. Public airports, libraries, etc are hotbeds of nefarious activity.

I use plugins to force SSL to all connections. I block outbound non-SSL http traffic. So, 0%? But personally I don't go to many sites that dont have full SSL coverage. Do you? I highly recommend you do this. > It’s so much easier to attack machines on public WiFi than compromise a VPN provider... and much more anonymous, and less likely to incite law enforcement activity. Do you think there will be a successful law e…

Well I agree with you on the self hosted VPN option being the best. I’m just saying there’s not zero benefit to hosted VPN in some cases.

And it sounds like your just looking at http traffic and web browser traffic. Your computer is communicating over lots of other ports and protocols that are often not encrypted. Are you blocking all outbound traffic?

Let’s take the recent iTerm vulnerability. ( https://www.kb.cert.org/vuls/id/763073/ ) I’m guessing you don’t have a plug-in to force curl to use https? What if you execute a script that curls http and you don’t realize?

Now you could say well “I just make sure all my curls are https.” The problem with that approach is it requires unrealistic levels of vigilance, about every outgoing service you may use, and that all your software on your machine is patched or bug free.

The easiest and quickest place for a hacker to learn their tools and skills is simply public WiFi. Want to try that iTerm exploit out... you go to the coffee shop and wait for a programmer to accidentally curl something over http.

VPN is not perfect, but it does provide some protection in certain circumstances that can’t be ruled out.

Best course, force https for web browser, and use your own hosted VPN anytime you are on a public network.

Re: NordVPN confirms it was hacked

#412

Earlier quoted context omitted.

Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa... RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

Also allowing historical sessions to be decrypted.

Also looks like NordVPN has been misleading customers about the number of servers they have (or didn't make clear they were VM/containers).

Re: NordVPN confirms it was hacked

#413

Earlier quoted context omitted.

Honestly, I don't think it's exclusive to NordVPN, I've found that all VPN advertising has increased significantly in the last year or two. Noticeably, ExpressVPN is also everywhere. Almost every podcast or youtube video has some VPN ads in it. It seems like with the recent focus on privacy, they are really these two companies and others are really trying to make a run for it.

Is VPN advertising increasing due to content restrictions from online streaming services? If you travel overseas, you can't access Netflix, AmazonPrime Video, etc. so a VPN service allows you to still use your service while you're away from home. And then sports streaming. You can sign up for a yearly subscription to watch sports, but not the teams closest to your physical location due to local blackouts. Utah is in…

I've found that using a VPN reduces my streaming ability. Using Private Internet Access in the past I was forbidden from watching anything on Netflix. Also I was forbidden from editing Wikipedia even on an old account with positive editing history.

Re: NordVPN confirms it was hacked

#414
post #387
post #363

Earlier quoted context omitted.

> However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. For me it was those incessant Grammarly ads. A service, by the way, that has its own serious security and privacy concerns[0]. (I feel like YouTube Premium ($18/mo for up to 6 people) is a better deal than Spotify Premium ($15/mo for up to 6 people) for a household like mine where we liste…

Yeah, Grammarly is creepy as hell. I've explicitly banned it (and similar services) at work. As for Youtube music, yup, that's undeniably a good deal. The music services should watch out, especially in younger demographics (I'm already 30+, Spotify premium user since 2009). Apple will probably push Music even harder and bundle that with their new video streaming. Spotify's really trying to become the defacto podcast…

Really helpful guidance on the audio quality considerations, thank you!

Re: NordVPN confirms it was hacked

#415
"no-one could know about an undisclosed remote management system left by the [data center] provider"

Why not? I'm generally familiar with the services offered by dedicated-server/co-lo/vps providers, and remote management systems are very common. This includes out-of-band (OOB) access when using dedicated systems. Seems like the sort of thing that solid due diligence would pick up. Even if it's completely undocumented, designing a robust security checklist to be completed by the vendor should find this sort of thing.

This excuse also makes NordVPN look extremely bad for future use: If you say "nobody could have known" then you're also saying "it could happen again" because if you can't know about it, you can't know if other vendors do the same. If you can stop it from happening in the future by implementing additional measures, that means those additional measures could have been used to prevent it the first time. So either you're inherently unsecure, or the issue was preventable.

Re: NordVPN confirms it was hacked

#416
post #251

Earlier quoted context omitted.

I’m not a network expert, but doesn’t TLS just cover your connection with a specific website? Since your IPS is often also your DNS, can’t they still see which specific websites you’re trying to connect to? Wouldn’t TLS just obfuscate what you’re specifically sending to and receiving from that site? I’m under the impression that my ISP can (and probably does) see every website I visit, which is in the least browsing…

That’s what the parent said: they can still see “hostnames and IP addresses.” But, for most people, that means that the ISP will just see: • google.com • facebook.com • reddit.com • somebignewspaper.example.com Etc. And there’s really nothing much too valuable about that. They won’t even be able to figure out if you’re shopping for something (unlike every other nosy channel provider), because most shopping traffic to…

Please don't underestimate the value of metadata.

While it's true that the big platforms dominate web use today, don't forget that the concept of metadata includes when you actively surf on the information superhighway. That's valuable information for advertisers.

So is every DNS lookup related to the API backends of specific apps you use. And every random website outside the massive platforms.

These might reveal tons of information about you. Like:

Are you doing research on politics (and which flavor)? Do you worry about health? When do you access online banking? Which banks? Any tax filing software? Invoicing apps? Do you use shitty payday loans? Are you looking for dates? Are you gay? Which games do you play? Which car dealerships do you consider? Do you gamble? And of course, any particularly.. specific porn sites? Do you access banking, travel/flight booking, investment, shitcoin trading, adult or gambling sites in a specific pattern that might indicate mania or other mental health issues?

With metadata alone, your ISP has a thick dossier on your habits, with stuff therapists don't know about their clients.

Re: NordVPN confirms it was hacked

#417

Earlier quoted context omitted.

To be fair, they can't actually see more than hostnames & IP addresses (assuming the use of TLS, which is becoming ubiquitous), so implying that they sell your "Internet history" makes it sound worse than it is. I've always assumed VPN providers sell whatever data they can too.

... and request sizes, relative times, and time of day. It would be foolish to not assume that the complete history of your sessions can be inferred from how this data clusters, everything but the actual text of your messages. Of course the people that find this problem worthwhile to solve then go on to work for or found surveillance companies, rather than publishing proof of concepts to security lists. We also alrea…

TLS has optional padding. In TLS 1.3 clever design means the padding is "free" (each byte of padding adds exactly one byte of data transmitted) so if you would like the sizes transmitted to be misleading you can choose how much.

We can't solve for you the question of how much to use. If you want a snooper to not know if you retrieved file A of 14583 bytes or file B of 14621 bytes maybe a very small amount of padding will get the job done. If file B was 800 Mb that's a lot more padding you're asking for.

Re: NordVPN confirms it was hacked

#418
post #393

Earlier quoted context omitted.

Looks cool, but feeling slightly twitchy about going anywhere near that with my Google account after last week's news https://news.ycombinator.com/item?id=21247759

That guy was a troll. Many of us have been using youtube-dl extensively every day for years without any trouble.

Why would you think he was a troll? I've had my google account suspended without explanation.

Re: NordVPN confirms it was hacked

#419
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

PIA is also compromised. They installed the known criminal Mark Karpelès as CTO.

[deleted]

Re: NordVPN confirms it was hacked

#420

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

If someone hacks a VPN, what are the implications for the users? As long as you're using HTTPS, you don't have to worry about your passwords or session tokens being stolen, right? Is it just your DNS records and unencrypted HTTP traffic?

If you're a user of a VPN service, if you're not worried because you were using HTTPS then why would you be bothering to use a VPN in the first place?
Post reply on HN