Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

451–460 of 666 posts

Re: NordVPN confirms it was hacked

#451

Earlier quoted context omitted.

I've been using Private Internet Access (PIA) since 2016 and can also recommend it from a usability point of view. I'm not a security expert so I defer to others on PIA's security.

In 2015ish PIA got hacked via https://old-support.privateinternetaccess.com because of https://classichelp.kayako.com/hc/en-us/articles/36000646089... and never told anyone. This bug loudly announces itself on every pageload, it speaks of tremendous incompetence that they ever let this go into production. The site used to set a cookie that looked like this: Set-Cookie: SWIFT_client=a%3A1%3A%7Bs%3A15%3A%22templategrou…

While the helpdesk software PIA used to use years ago did have that potential vulnerability, fortunately, Private Internet Access never exposed the support desk via plain http, and therefore, PIA itself did not have the vulnerability in its helpdesk.

Re: NordVPN confirms it was hacked

#452
post #363

Earlier quoted context omitted.

> However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. For me it was those incessant Grammarly ads. A service, by the way, that has its own serious security and privacy concerns[0]. (I feel like YouTube Premium ($18/mo for up to 6 people) is a better deal than Spotify Premium ($15/mo for up to 6 people) for a household like mine where we liste…

I'm torn for this reason: I want to avoid ads, but I don't want to give Google any more money. It's unfortunate that YouTube is really the only one of it's kind. For the moment, I get around this conundrum using a combination of uBlock Origin[0] (Firefox) and NewPipe[1] on Android. Not 100% sure what I'll do about the latter when I switch to iOS. [0] https://github.com/gorhill/uBlock [1] https://newpipe.schabi.org/

You don't have ad-blockers on all devices or for their app. I'm on iOS and I like using the app since Premium allows for playing stuff in the background, plus downloading stuff for offline viewing. You can't get that in Firefox with uBlock.

I find some of the anti-Google arguments to be really, really weird and I've been speaking against Google on this website countless of times.

If you don't want to be tracked, you're going to be tracked for as long as you're a free user. uBlock Origin will not save you, since you're on their website and you can't block "youtube.com".

Also Google is a big target and subject to laws such as GDPR. I actually trust Google more than I trust any startup advertised on HN, because Google is a big target with a lot of eyes watching. When you go to your profile and turn off the data collection, you can probably trust Google more than you can trust DuckDuckGo.

This isn't to say that you should trust Google. Not what I'm saying.

But paying a membership is voting with your wallet against ads. By not paying you're simply encouraging them to serve more ads. And the break you're getting via uBlock Origin is only temporary. If the audience using ad-blockers on Android grows, I expect them to simply block browser access, problem solved. And because you used YouTube anyway, it means you haven't payed for their competition either, which means you directly contributed to YouTube's monopoly, without encouraging them to give up on ads in favor of Premium memberships.

It's basically how software piracy used to work. Piracy was never a problem for the big companies like Microsoft, piracy being responsible in part for Microsoft's monopoly. And when piracy became a problem, software companies simply moved to online subscriptions. There's always a solution for milking free loaders later.

Re: NordVPN confirms it was hacked

#453
post #363
post #348

Earlier quoted context omitted.

I normally don’t mind YouTube ads all that much, and I don’t see them on desktop browsers anyway. However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. Hard to relax with some totally not weird ASMR when my blood pressure is through the roof because some chirpy ad agency dude wants to show me how much a VPN is like an umbrella or whatever.

> However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. For me it was those incessant Grammarly ads. A service, by the way, that has its own serious security and privacy concerns[0]. (I feel like YouTube Premium ($18/mo for up to 6 people) is a better deal than Spotify Premium ($15/mo for up to 6 people) for a household like mine where we liste…

I realize this is probably not the point of the preceding two comments, but does nobody here use an ad blocker? uBlock Origin is great, or NewPipe for YouTube specifically.

Re: NordVPN confirms it was hacked

#454
post #56
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

Apparently The Wirecutter now recommends TunnelBear and Mullvad because they post regular transparency reports and do third-party audits. https://thewirecutter.com/reviews/best-vpn-service/

Mullvad is a great choice, but I'm mildly surprised about TunnelBear as a choice. They log bandwidth and they incentivize social media spam.

Citation: https://thatoneprivacysite.net/#detailed-vpn-comparison

Re: NordVPN confirms it was hacked

#455
post #413

Earlier quoted context omitted.

I've found that using a VPN reduces my streaming ability. Using Private Internet Access in the past I was forbidden from watching anything on Netflix. Also I was forbidden from editing Wikipedia even on an old account with positive editing history.

Netflix (et al) are blacklisting some common VPN's IP ranges. If that fails, they use some DNS tricks to route the requests to your nearest geographical API and if there is a discrepancy between your IP's location and endpoint's location, they block the requests too. It is possible to overcome, but with some work.

Yeah tried to fool Disney+ and most things failed. Even routing through my own private VPS didn't work. They're definitely getting much better at it.

Re: NordVPN confirms it was hacked

#457

Earlier quoted context omitted.

In 2015ish PIA got hacked via https://old-support.privateinternetaccess.com because of https://classichelp.kayako.com/hc/en-us/articles/36000646089... and never told anyone. This bug loudly announces itself on every pageload, it speaks of tremendous incompetence that they ever let this go into production. The site used to set a cookie that looked like this: Set-Cookie: SWIFT_client=a%3A1%3A%7Bs%3A15%3A%22templategrou…

While the helpdesk software PIA used to use years ago did have that potential vulnerability, fortunately, Private Internet Access never exposed the support desk via plain http, and therefore, PIA itself did not have the vulnerability in its helpdesk.

Hahahaha, this bug was perfectly exploitable via TLS wrapped HTTP (so HTTPS, which is still HTTP as far as the PHP application is concerned).

The SWIFT_client cookie gets passed directly into unserialize(), TLS has literally nothing to do with this.

FWIW rasengan is one of the PIA founders, he should know much better.

This response is so utterly silly I must wonder if this is all just an incredible display of incompetence instead of malice.

Re: NordVPN confirms it was hacked

#458

Earlier quoted context omitted.

Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa... RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

Also allowing historical sessions to be decrypted.

Who has logs of full historical sessions, and the tools to decrypt them? NSA?

Re: NordVPN confirms it was hacked

#459
post #363

Earlier quoted context omitted.

> However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. For me it was those incessant Grammarly ads. A service, by the way, that has its own serious security and privacy concerns[0]. (I feel like YouTube Premium ($18/mo for up to 6 people) is a better deal than Spotify Premium ($15/mo for up to 6 people) for a household like mine where we liste…

I'm torn for this reason: I want to avoid ads, but I don't want to give Google any more money. It's unfortunate that YouTube is really the only one of it's kind. For the moment, I get around this conundrum using a combination of uBlock Origin[0] (Firefox) and NewPipe[1] on Android. Not 100% sure what I'll do about the latter when I switch to iOS. [0] https://github.com/gorhill/uBlock [1] https://newpipe.schabi.org/

I haven't bothered with music lately but last time I did I just went to my pc grabbed an updated version of Youtube-dl and went to my playlist and downloaded all the songs. Then I put those into itunes and synced them to my phone. It was pretty straight forward and youtube-dl is great it works on other video services as well.

Re: NordVPN confirms it was hacked

#460
post #329

Earlier quoted context omitted.

I have a slightly dissenting answer to these questions, in the form of an interactive Q&A website: https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w...

How is this not the top comment? Nobody should be using a VPN provider, full-stop. It is structurally impossible for anyone to verify their claims, they have more incentive to lie than your ISP does, and they're cheap and easy to set up, so the industry is a cesspool. You should assume that all of them are behaving badly.

Pretty much a textbook "Lemon Market"

https://en.wikipedia.org/wiki/The_Market_for_Lemons

Post reply on HN