Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

491–500 of 666 posts

Re: NordVPN confirms it was hacked

#491
This sounds suspiciously like the Supermicro BMC bug reported here a while back[1], and while it actually can be hard to make sure the IPMI stuff doesn't take over a NIC you don't want it to[2], there are things you can do to prevent that, such as explicitly setting IPMI interface and address information so it won't use "smart" behavior to negate all your security.

As to whether "no-one could know", well, I knew after I read that HN submission, and at work we made sure to double check all our configs. This ended up being mostly a known problem, but the extra context helped us find another edge case I believe.

It's not great that you have to be aware of the latest security problems and how they may interact in obscure ways with system configs, but that's the nature of security and state of the industry right. Not much to do except buckle down and pay attention. To everything.

1: https://news.ycombinator.com/item?id=20870686

2: https://news.ycombinator.com/item?id=20872084

Re: NordVPN confirms it was hacked

#492

Earlier quoted context omitted.

I am guessing #1 is mot wanting your internet provider (eg. AT&T) knowing what you are doing, then Netflix, Torrents, getting better deals on tickets and such, maybe activities of questionable legality? Personally, I don't like the idea of my mobile provider profiting off knowing which applications I am using and what sites I visit.

I don't understand being unhappy with your ISP knowing these things, but being fine with your VPN provider knowing them.

Well then youre an idiot

Re: NordVPN confirms it was hacked

#493

Earlier quoted context omitted.

I'm torn for this reason: I want to avoid ads, but I don't want to give Google any more money. It's unfortunate that YouTube is really the only one of it's kind. For the moment, I get around this conundrum using a combination of uBlock Origin[0] (Firefox) and NewPipe[1] on Android. Not 100% sure what I'll do about the latter when I switch to iOS. [0] https://github.com/gorhill/uBlock [1] https://newpipe.schabi.org/

You don't have ad-blockers on all devices or for their app. I'm on iOS and I like using the app since Premium allows for playing stuff in the background, plus downloading stuff for offline viewing. You can't get that in Firefox with uBlock. I find some of the anti-Google arguments to be really, really weird and I've been speaking against Google on this website countless of times. If you don't want to be tracked, you'…

> I like using the app since Premium allows for playing stuff in the background

I remember vividly the day (sometime in 2013?) when they removed that feature from the base app. I had been streaming music or casts from YouTube in the background since day 1 of my iPhone 4, and suddenly it became a paid feature.

"Bastards", I thought with a smile, "but hey, fair enough! Ok, now where do I pay?..."

Except that outside of the US, premium wasn't available. So they had removed background play but offered no alternative. It lasted until 2017!! Took them 4 years to bring the premium offer to Europe... what a shame. That fueled some resentment, as a wannabe customer. Any gave more than enough time to find better alternatives (Spotify, youtube-dl...) and never look back.

When they finally introduced premium in my country, I took the free 3 months offer and cancelled immediately thereafter. They don't want my money, 4 years made that emphatically clear.

I may reconsider after 2021, on the condition that management has changed at YouTube and Google. Right now, I'm just not feeling it.

Google is just awful at marketing stuff and customer service. They plain and simple don't care. That's monopoly for us: customers lose, always. So I find it both logical and "the right thing to do" to spend my money to directly support creators and alternative platforms whenever I can.

Re: NordVPN confirms it was hacked

#494
post #490

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

The fact that NordVPN advertise so heavily, and get so many youtubers to sell it, is exactly why I will never use the service. It is way too on the nose. They heavily sponsor PayMoneyWubby who also does a great job at de-anonymising a group of youtubers. The last VPN you ever want to use is the one that is heavily on the market.

while I don't disagree with you, I am wondering why you would think that? I don't understand what "way too on the nose" means. Are you saying that because they are big makes them a bigger target?

If anything, I would think the larger the provider the more resources they would have to provide a stable and secure service.

Re: NordVPN confirms it was hacked

#495
post #429

Earlier quoted context omitted.

Why would you think he was a troll? I've had my google account suspended without explanation.

Read the comments. The claimed suspension message was extremely unlikely to be real.

I speak Finnish, and if I'm 'google cancelled my main account'-level pissed, I just might pick a username very much like that for a site I don't really want to be on in the first place. Maybe a cultural thing. So that argument is moot.

Agree with ryanlol's comment here next to mine on the rest. I'd really want more clarifications before I touch third party Youtube clients while logged in (which I want to be, for recommendations etc).

Re: NordVPN confirms it was hacked

#496

Earlier quoted context omitted.

I’m on iOS and I just deal with the ads. There’s a lot and I guess it would be more annoying if you were used to no ads, but it’s manageable. I’d pay for a video service if the company didn’t track me, but I’m resistant to paying for services and also being tracked.

Do you think they would get more money by monetizing you with a credit card than they do by monetizing with ads? I hear this argument that people don't want to pay with money as opposed to attention, and I always feel the opposite.

I feel like I would love to pay for a video service that didn’t support surveillance and mass data collection. Or that provided user transparency on what they did track (obviously some level of user tracking can improve a service meaningfully). That said, I don’t for example pay for Vimeo so I suppose there are network effects. I’m on YouTube because everyone else is. That said I regularly publish YouTube videos but have not enabled monetization. Not all youtubers can afford to do that but it’s a small thing I can to do help.

Re: NordVPN confirms it was hacked

#498
post #230

Earlier quoted context omitted.

I find NordVPN's marketing reprehensible. Too many claims and broad strokes about the "anonymity" their service can provide. While I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data, I think NordVPN really overplays the role of changing IP addresses in the age of browser fingerprinting.

> I find NordVPN's marketing reprehensible. A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.

> No one was ever going to be able to read your emails

As long as no one practiced a trivial mitm attack on your network and that you have a browser that does not try http first when you type in your webmail.com or that no one rubber duckied a custom CA certificate in your browser ...

Re: NordVPN confirms it was hacked

#499

Earlier quoted context omitted.

Maybe they only disclosed it publicly but notified customers out of the public eye ?

I was a NordVPN customer 4 months ago and got no notification. I’m hearing about this now via this post on HN. Dropped them around July.

Aight then i'm sorry for their lack of accountability.

Re: NordVPN confirms it was hacked

#500
post #348

Earlier quoted context omitted.

> I find NordVPN's marketing reprehensible. A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.

I normally don’t mind YouTube ads all that much, and I don’t see them on desktop browsers anyway. However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. Hard to relax with some totally not weird ASMR when my blood pressure is through the roof because some chirpy ad agency dude wants to show me how much a VPN is like an umbrella or whatever.

NewPipe is free.
Post reply on HN