Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

511–520 of 666 posts

Re: NordVPN confirms it was hacked

#511
post #431

Earlier quoted context omitted.

We have indeed retained lawyers to look into our options to fight the online defamation, but its hard to take anonymous accusers to court. However, as we have discussed here ( https://protonvpn.com/blog/is-protonvpn-trustworthy/ ) there is already a lot of ironclad legal evidence. First, were we to lie in our privacy policy, we would be subject to GDPR fines of up to 20 million Euros, since we have both European cust…

'January 2019 – A data request from a foreign country was approved by the Swiss court system. However, as we do not have any customer IP information, we could not provide the requested information and this was explained to the requesting party.' I'm not terribly well-versed in the international (or Swiss) legal system but are portions of that request public record, or would it be possible to put portions of it online…

No public indictment was issued because in this case the accused could not be charged since they couldn't be identified. Generally there are only documents if police decide to move forward with a prosecution, which is unlikely since we do not have logs that can identify users.

Re: NordVPN confirms it was hacked

#512
post #495

Earlier quoted context omitted.

I speak Finnish, and if I'm 'google cancelled my main account'-level pissed, I just might pick a username very much like that for a site I don't really want to be on in the first place. Maybe a cultural thing. So that argument is moot. Agree with ryanlol's comment here next to mine on the rest. I'd really want more clarifications before I touch third party Youtube clients while logged in (which I want to be, for reco…

FWIW I don't think there's necessarily any link between his account getting suspended and the youtube client. Google suspends accounts for all kinds of weird reasons. It seems really weird to me to assume that this is a troll, the other issues created by the user over a couple of weeks seem legit. I think this is just some slightly confused person trying to figure out why their account was suspended. I get lots of le…

I don't think "confusion" can explain his claim to have received emails attributing his ban to his use of a youtube video downloading software. He's not provided any evidence of such emails and numerous people who've been banned by google seem to think it unlikely that google would deign to explain why they banned somebody in such detail.

I don't think the emailed explanation exists, and I don't think confusion can explain why he'd say it exists, which leads me to conclude he's lying.

(And really, if such bans were genuinely a threat, more than one person would be complaining about it happening. Tons of people use youtube-dl and newpipe (including many youtube creators who do commentary on other youtube videos) and there's this single guy claiming to have been banned for it. It doesn't pass my sniff test.)

Re: NordVPN confirms it was hacked

#513

Earlier quoted context omitted.

If someone hacks a VPN, what are the implications for the users? As long as you're using HTTPS, you don't have to worry about your passwords or session tokens being stolen, right? Is it just your DNS records and unencrypted HTTP traffic?

It depends on what you mean by 'hacking' a VPN. One assertion in this breach is that the NordVPN certificate private key was leaked, allowing anybody to spin up a NordVPN server that would pass HTTPS certificate validation (the cert is expired, it's currently unknown if the cert was valid for a period of time after it was compromised). This kind of an attack would let an attacker convince most users to download virus…

Let’s not forget that if they’ve got to a point where they can breach a private key they’re at a point where they’ve probably dumped hashed user creds and contact details, and probably gained persistence on breached hosts, too.

Re: NordVPN confirms it was hacked

#514
Wasn't NordVPN the one that was created by a marketeer? I wouldn't be suprised if this was just cover for them to sell their customer's data indirectly. If anybody finds a dump of the data they sold they could just claim it was from the breach.

Re: NordVPN confirms it was hacked

#515

Earlier quoted context omitted.

How the hell do you pwn a server with iDRAC?

Oh, IPMI and friends are a total mess. Some implementations allow one to take control of a running server remotely especially if they use a shared ethernet for management ( popular in supermicros ). I once had our security geek demonstrate it by taking over the running server, rebooting it using network emulated USB stick, adding a file into /etc and rebooting the server again. In secure environments one pulls IPMI m…

The first time I booted a server using a virtual CD-ROM (iso on my laptop shows up as a hardware CD-ROM on the server) over IPMI I was simultaneously relieved (because I could fix the machine remotely) and absolutely totally horrified.

Re: NordVPN confirms it was hacked

#516
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

Freedome VPN has been similarly been shown to do the same.

Re: NordVPN confirms it was hacked

#517
post #505

NordVPN just posted this a few minutes ago: https://nordvpn.com/blog/official-response-datacenter-breach...

NordVPN is down, also looks like VikingVPN and TorGuard were affected as well: https://twitter.com/cryptostorm_is/status/118609795032747622...

The thing that scares me here is that these keys were leaked May 2018, and it's becoming public knowledge now.

Someone found certificates for those three VPN providers and posted them to 8chan with a message like "I don't recommend these VPN providers lol"

The good news is that they're only certificates, and they have now expired, but theoretically they could have been used for the past year without anyone noticing.

Re: NordVPN confirms it was hacked

#518

Earlier quoted context omitted.

FWIW I don't think there's necessarily any link between his account getting suspended and the youtube client. Google suspends accounts for all kinds of weird reasons. It seems really weird to me to assume that this is a troll, the other issues created by the user over a couple of weeks seem legit. I think this is just some slightly confused person trying to figure out why their account was suspended. I get lots of le…

I don't think "confusion" can explain his claim to have received emails attributing his ban to his use of a youtube video downloading software. He's not provided any evidence of such emails and numerous people who've been banned by google seem to think it unlikely that google would deign to explain why they banned somebody in such detail. I don't think the emailed explanation exists, and I don't think confusion can e…

IDK, I see weird claims like that from customers all the time! They see non-existent error messages with ridiculous texts. There's constantly weird inconsistencies like this in descriptions of real bugs.

I just assume that these people are very confused and not good at english.

Re: NordVPN confirms it was hacked

#519

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Leaving default creds on IPMI/iLO is not uncommon,some providers don't allow internet access,you have to login on the web console and use a java applet to access it iirc. I can't imagine a well reputed provider exposing ipmi to the internet but the nature of their business means they have to diversify server and network providers.
Post reply on HN