Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

431–440 of 666 posts

Re: NordVPN confirms it was hacked

#431
post #359

Earlier quoted context omitted.

Slightly off-topic but I am delighted by the generally non-abrasive way this thread is going. Dialogue is good! I realized another way that would work for you guys (but is out of your hands) is fighting a court case about this. You'd be legally compelled to tell the truth and very screwed if you deny but then it comes out there is logging or mining going on. It's not ironclad but it is how most VPNs end up being cons…

We have indeed retained lawyers to look into our options to fight the online defamation, but its hard to take anonymous accusers to court. However, as we have discussed here ( https://protonvpn.com/blog/is-protonvpn-trustworthy/ ) there is already a lot of ironclad legal evidence. First, were we to lie in our privacy policy, we would be subject to GDPR fines of up to 20 million Euros, since we have both European cust…

'January 2019 – A data request from a foreign country was approved by the Swiss court system. However, as we do not have any customer IP information, we could not provide the requested information and this was explained to the requesting party.'

I'm not terribly well-versed in the international (or Swiss) legal system but are portions of that request public record, or would it be possible to put portions of it online, verbatim?

It would really strengthen the case to your customers because whilst claiming you had a request when you didn't isn't illegal, falsifying court documents definitely is.

Re: NordVPN confirms it was hacked

#432
post #421

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

i find it surprising that none of the threads in this topic mention the very serious threat this breach might have for users in countries like china. the fact that nordvpn neglected to tell its users for months after the breach quite possibly endangered people's lives. unforgivable.

Dystopian and true.

Re: NordVPN confirms it was hacked

#433

Earlier quoted context omitted.

I am guessing #1 is mot wanting your internet provider (eg. AT&T) knowing what you are doing, then Netflix, Torrents, getting better deals on tickets and such, maybe activities of questionable legality? Personally, I don't like the idea of my mobile provider profiting off knowing which applications I am using and what sites I visit.

I don't understand being unhappy with your ISP knowing these things, but being fine with your VPN provider knowing them.

Because they're required to reply to subpoenas?

Re: NordVPN confirms it was hacked

#434

Earlier quoted context omitted.

Ok, I’m going to pretend that I’m a NordVPN customer who is 50, works as a plumber, and has installed a VPN on their phone because they were convinced that it’s very good for privacy. Here goes… “What is a datacenter? How was it accessed? Like in that Mission Impossible movie? What are server providers? What role do they play in all this? Credentials? That’s like my passwords? What about my browsing activity? All I w…

Have you used Nord VPN? These aren't questions users would have. I could be wrong, but I'm confident that a plumber that has used Nord would know what a datacenter is, just from using the app. My tech illiterate Dad (70s) sure does.

VPNs are advertised a lot on all kinds of YouTube channels. It is reasonable to believe that they have a bunch of customers who know almost nothing about VPNs or the Internet in general.

Re: NordVPN confirms it was hacked

#435
post #86

NordVPN just posted this a few minutes ago: https://nordvpn.com/blog/official-response-datacenter-breach...

I'm curious about who this cloud provider might be.

The local IP for the OpenVPN endpoint (185.212.149.9 listed in the gist) belongs to creanova.org since 2017.

Re: NordVPN confirms it was hacked

#436
post #366
post #355

Earlier quoted context omitted.

No adblock?

Yes, on desktop. Harder to achieve with the mobile app. And as it happens, I don't use a desktop OS to play stuff that helps me fall asleep.

Just use firefox on mobile it has extension support

Re: NordVPN confirms it was hacked

#437
post #209

Earlier quoted context omitted.

> I wonder when that sort of thing will become a criminal offence. If they have EU customers then article 33 of GDPR should see to that. "In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal da…

They could argue that they don't have proof that the exposed private key led to a personal data breach.

They would have to be sure that no private data leaked though, right?

Re: NordVPN confirms it was hacked

#438
post #374

Earlier quoted context omitted.

>Google can track you fairly effectively even if you’re behind a VPN. You don't know anything about my setup, so you have no basis for claiming this. On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and look at basic HTTP logs.

> You don't know anything about my setup, so you have no basis for claiming this. Sure, but the discussion isn't specifically about your setup, it's about the advertising claims that a VPN will help prevent tracking. Which is totally bunk. > On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and…

>Tracking with IP is honestly hardly tracking at all.

There are many, many cases where this is patently false.

For example, correlating different devices by IP is a very common technique advertisers use for establishing cross-device tracking profiles.

Re: NordVPN confirms it was hacked

#440
post #387
post #363

Earlier quoted context omitted.

> However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. For me it was those incessant Grammarly ads. A service, by the way, that has its own serious security and privacy concerns[0]. (I feel like YouTube Premium ($18/mo for up to 6 people) is a better deal than Spotify Premium ($15/mo for up to 6 people) for a household like mine where we liste…

Yeah, Grammarly is creepy as hell. I've explicitly banned it (and similar services) at work. As for Youtube music, yup, that's undeniably a good deal. The music services should watch out, especially in younger demographics (I'm already 30+, Spotify premium user since 2009). Apple will probably push Music even harder and bundle that with their new video streaming. Spotify's really trying to become the defacto podcast…

> ...it's not super clear to me when tracks are clean encodes sourced from the proper music distribution ecosystem...

Isn't that kind of the point? If you can't tell which is which without a visual cue (aka bias-generator) then they sound the same.

Post reply on HN