Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

471–480 of 666 posts

Re: NordVPN confirms it was hacked

#471

Earlier quoted context omitted.

I've been using Mullvad for a while now and I have nothing but praise for them. Only complaint is they're more expensive than some of their competitors.

What aspects of a VPN provider would you praise? Customer service, consistency of connection speed? Seems almost like a utility where it's hard to differentiate.

I would say transparency/security, quality of the client(s) and customer service, in that order. It's one thing to offer a VPN service, but to make sure you have a nice app on both iOS, Android, MacOS, Windows and Linux seems like quite an investment.

Re: NordVPN confirms it was hacked

#473

Earlier quoted context omitted.

Hahahaha, this bug was perfectly exploitable via TLS wrapped HTTP (so HTTPS, which is still HTTP as far as the PHP application is concerned). The SWIFT_client cookie gets passed directly into unserialize(), TLS has literally nothing to do with this. FWIW rasengan is one of the PIA founders, he should know much better. This response is so utterly silly I must wonder if this is all just an incredible display of incompe…

Sorry, I glanced at the link you pasted and wrote the response as I knew this was a non issue from the past. So, I spoke with our internal team and was able to find more details: - We haven't used that machine since that exploit was made public. - We were never exploited. - There was no sign of intrusion of any kind. - The specific machine was a backup helpdesk test server without any real user data. Thanks again for…

>- We haven't used that machine since that exploit was made public.

So what? You were exploited before kayako patched this bug, it was glaringly obvious to anyone who ever looked at the cookies set by your site.

>- We were never exploited.

This simply isn't true, either you're misinformed or lying.

>- The specific machine was a backup helpdesk test server without any real user data.

The specific machine (Which you took down really fast after I pointed it out! :P) I linked probably did not even exist in 2015, I was talking about your prod env.

I don't have a horse in this race, there's no incentive for me to lie about this. I know what you are saying isn't true.

Re: NordVPN confirms it was hacked

#474
post #387
post #363

Earlier quoted context omitted.

> However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. For me it was those incessant Grammarly ads. A service, by the way, that has its own serious security and privacy concerns[0]. (I feel like YouTube Premium ($18/mo for up to 6 people) is a better deal than Spotify Premium ($15/mo for up to 6 people) for a household like mine where we liste…

Yeah, Grammarly is creepy as hell. I've explicitly banned it (and similar services) at work. As for Youtube music, yup, that's undeniably a good deal. The music services should watch out, especially in younger demographics (I'm already 30+, Spotify premium user since 2009). Apple will probably push Music even harder and bundle that with their new video streaming. Spotify's really trying to become the defacto podcast…

> Spotify's audio didn't use to be all that great, except with the normalization turned off. Now with their 'quiet' normalization option, that doesn't compress quiet tracks (a clear edge over Apple Music), it's starting to sound transparent to me, as -q 9 encoded (~320 kbps) Vorbis should.

What annoys me is they're mixing together two features (namely normalization and dynamic range compression) and putting them behind one toggle.

I want normalization, it's hugely annoying playing music on my PS4 because the Spotify client doesn't have it there and I constantly have tot tweak the volume.

I do not want compression.

But on my phone and computer I have to use their 'normal' normalization level and take the compression because 'quiet' means I am constantly turning up my sound level when listening to Spotify and turning it back down when I do anything else so my ears don't get blasted.

Re: NordVPN confirms it was hacked

#476
post #380

Earlier quoted context omitted.

AWS has external auditors verify their policies, procedures, and actual methods meet a wide variety of compliance requirements from many different agencies. The level of access those auditors and other verification methods have to AWS is not none but very significant. https://aws.amazon.com/compliance/programs/

That page looks impressive but there is no way to casually verify that what they are talking about actually happens (on a quick check). There is simply so much info there you'd have to spend considerable time trying to track down what is needed to make sure it's actually legit. [1] Of course with 'assume' with AWS it is and it's meaningful but my point is if someone else were doing that people might simply 'check the…

Rereading your comment, here is one easy verification method for one of the programs: literally a marketplace of compliant services by the group which does the verification.

https://marketplace.fedramp.gov/#/products?sort=productName

Re: NordVPN confirms it was hacked

#477

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

I work for a web hosting company in the US and at least in our case, it's quite common for remote management to be enabled on pretty much all of our dedicated hardware. However, because of the inherent dangers in opening this up to the public internet, unless explicitly requested by the customer (or Managed Colocation), the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter.…

Maybe it wasn't open to the public Internet, but the VPN exit is inside the datacenter and connects out to the public Internet. Is it feasible that NordVPN provided their customers with a secure tunnel into their own datacenter's management software?

Re: NordVPN confirms it was hacked

#478

Earlier quoted context omitted.

I'm torn for this reason: I want to avoid ads, but I don't want to give Google any more money. It's unfortunate that YouTube is really the only one of it's kind. For the moment, I get around this conundrum using a combination of uBlock Origin[0] (Firefox) and NewPipe[1] on Android. Not 100% sure what I'll do about the latter when I switch to iOS. [0] https://github.com/gorhill/uBlock [1] https://newpipe.schabi.org/

You don't have ad-blockers on all devices or for their app. I'm on iOS and I like using the app since Premium allows for playing stuff in the background, plus downloading stuff for offline viewing. You can't get that in Firefox with uBlock. I find some of the anti-Google arguments to be really, really weird and I've been speaking against Google on this website countless of times. If you don't want to be tracked, you'…

> I like using the app since Premium allows for playing stuff in the background, plus downloading stuff for offline viewing. You can't get that in Firefox with uBlock.

But on firefox you can get play in background with this:

https://addons.mozilla.org/en-US/firefox/addon/video-backgro...

Edit: Firefox on Android. I do not know about iOS

Re: NordVPN confirms it was hacked

#479

Earlier quoted context omitted.

Torguard for me, relatively happy with it. Also hideMe was very good too.

Per OP article Torguard was hacked to

Torguard is contesting the extent of their breach: https://torguard.net/blog/why-torguards-network-is-secure-af...

Re: NordVPN confirms it was hacked

#480

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

Honestly, I don't think it's exclusive to NordVPN, I've found that all VPN advertising has increased significantly in the last year or two. Noticeably, ExpressVPN is also everywhere. Almost every podcast or youtube video has some VPN ads in it. It seems like with the recent focus on privacy, they are really these two companies and others are really trying to make a run for it.

Maybe it's one of things where there's hundreds of "dedicated server providers" but really it's all the same thing just rebranded/resold, sometimes under one entity[0]. I've seen this rebrand/resell behavior with proxy services, people search engines, etc. I don't know much about VPN providers but I'm guessing they share or pipe into each other since there's so many of them.

https://en.m.wikipedia.org/wiki/Endurance_International_Grou...

Post reply on HN