Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

521–530 of 666 posts

Re: NordVPN confirms it was hacked

#521

Earlier quoted context omitted.

I don't think "confusion" can explain his claim to have received emails attributing his ban to his use of a youtube video downloading software. He's not provided any evidence of such emails and numerous people who've been banned by google seem to think it unlikely that google would deign to explain why they banned somebody in such detail. I don't think the emailed explanation exists, and I don't think confusion can e…

IDK, I see weird claims like that from customers all the time! They see non-existent error messages with ridiculous texts. There's constantly weird inconsistencies like this in descriptions of real bugs. I just assume that these people are very confused and not good at english.

Well, maybe he's a troll or maybe he's just confused or delusional, but either way I don't think the claim that google is banning people for using youtube-dl or newpipe should be taken seriously at this moment. I'm certainly not going to stop using youtube-dl.

Re: NordVPN confirms it was hacked

#522
post #12

If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo

There's also Streisand[0], that gives a lot more options. [0] https://github.com/StreisandEffect/streisand

Came here to post this. I’ve been using streisand for a long time with no problems. I’ve given out logins to a few trusted friends / colleagues and all have had good experiences as far as I know.

Plus I really enjoyed learning about the in’s and outs of setting it up. I poke around in the VM just for giggles.

Re: NordVPN confirms it was hacked

#523
post #12

If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo

There's also Streisand[0], that gives a lot more options. [0] https://github.com/StreisandEffect/streisand

Ive done this but have found that most services (Netflix, etc) recognize DO as a VPN. Does anyone know of a hosting provider that isn't blacklisted but I can still setup wireguard on?

Re: NordVPN confirms it was hacked

#524

This is always topical: Don't use VPN Services https://gist.github.com/joepie91/5a9909939e6ce7d09e29

> Your IP address is a largely irrelevant metric in modern tracking systems. I don't believe this for one second. Your IP address on its own is not sufficient to identify you. That doesn't mean your IP address is not helpful in identifying you. If you have Javascript disabled, it is a heck of a lot easier to identify you with a combination of an IP address, user agent, and OS than it is to identify you without the IP…

> Your IP address on its own is not sufficient to identify you.

Wasnt there a story yesterday that FBI tracked some a guy who had logged into Jihadi forums with the IP, knocked on the door with a copy of a passport of the guy's dad.

Re: NordVPN confirms it was hacked

#525
post #506

Earlier quoted context omitted.

You're being downvoted because people believe in propaganda being pushed by competitors, but ProtonVPN / ProtonMail are very good options. Plenty of links and reports by Mozilla in this thread will lend credence to that.

Aka the conspiracy theory that was ultimately found to be pushed by PIA, one of their direct competitors. I've got enough HN internet points that a few downvotes will be fine. Thanks!

> Aka the conspiracy theory that was ultimately found to be pushed by PIA, one of their direct competitors.

Source?

I've heard this several times but nobody has ever been able to provide a source.

Re: NordVPN confirms it was hacked

#526
There are quite a lot of anti NordVPN and VPN in general experts pontificating here. A quick scroll down through all comments and I note a distinct lack of green handles.

This is a 500+ comment article with hardly any near null comment commentards. My analysis is not very rigorous.

Re: NordVPN confirms it was hacked

#527
post #217

Earlier quoted context omitted.

>> Is this common practice for data-center providers? Absolutely. We had similar situation with one of the DC vendors.

So what can you do about it?

Full Disk Encryption is an option, but that’ll entail needing the use the IPMI console to enter the password at every reboot, essentially turning it into a manual operation.

Re: NordVPN confirms it was hacked

#528
post #523

Earlier quoted context omitted.

There's also Streisand[0], that gives a lot more options. [0] https://github.com/StreisandEffect/streisand

Ive done this but have found that most services (Netflix, etc) recognize DO as a VPN. Does anyone know of a hosting provider that isn't blacklisted but I can still setup wireguard on?

Run it on https://1984hosting.com. I've heard it's good although I can't attest personally.

Re: NordVPN confirms it was hacked

#529
post #12

If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo

The problem with this is that jumping out onto the net from a VPS-allocated IP causes all sorts of trouble for "normal" internet use. For example you won't be able to use Netflix doing something like this.

Re: NordVPN confirms it was hacked

#530
post #329

Earlier quoted context omitted.

I have a slightly dissenting answer to these questions, in the form of an interactive Q&A website: https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w...

How is this not the top comment? Nobody should be using a VPN provider, full-stop. It is structurally impossible for anyone to verify their claims, they have more incentive to lie than your ISP does, and they're cheap and easy to set up, so the industry is a cesspool. You should assume that all of them are behaving badly.

You can always setup Algo on your own personal VPS running on Azure, GCE, DigitalOcean, Vultr, etc.

https://github.com/trailofbits/algo

Also, hasn't CloudFlare been audited to verify their no log claims? I know while Mullvad hasn't been audited to verify their no log claims, they have at least been audited to verify the security of their app.

https://blog.cloudflare.com/1111-warp-better-vpn/

"1. We don't write user-identifiable log data to disk;

2. We will never sell your browsing data or use it in any way to target you with advertising data;

3. Don’t need to provide any personal information — not your name, phone number, or email address — in order to use the 1.1.1.1 App with Warp; and

4. We will regularly hire outside auditors to ensure we're living up to these promises."

https://mullvad.net/en/blog/2018/9/24/read-results-security-...

Post reply on HN