Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

541–550 of 666 posts

Re: NordVPN confirms it was hacked

#541
post #217

Earlier quoted context omitted.

So what can you do about it?

Full Disk Encryption is an option, but that’ll entail needing the use the IPMI console to enter the password at every reboot, essentially turning it into a manual operation.

If you have physical access twice, full disk encryption usually doesn't help really at all. IPMI seems about as powerful as physical access.

Re: NordVPN confirms it was hacked

#542
post #505

Earlier quoted context omitted.

NordVPN is down, also looks like VikingVPN and TorGuard were affected as well: https://twitter.com/cryptostorm_is/status/118609795032747622...

The thing that scares me here is that these keys were leaked May 2018, and it's becoming public knowledge now. Someone found certificates for those three VPN providers and posted them to 8chan with a message like "I don't recommend these VPN providers lol" The good news is that they're only certificates, and they have now expired, but theoretically they could have been used for the past year without anyone noticing.

During the spate of health care information leakage, someone invented a MTBCA, meaning "Meantime to CEO Apology" for the time between the breach and the CEO apology. At that time, it was running on the order of 8 months.

Re: NordVPN confirms it was hacked

#543
post #506

Earlier quoted context omitted.

Aka the conspiracy theory that was ultimately found to be pushed by PIA, one of their direct competitors. I've got enough HN internet points that a few downvotes will be fine. Thanks!

> Aka the conspiracy theory that was ultimately found to be pushed by PIA, one of their direct competitors. Source? I've heard this several times but nobody has ever been able to provide a source.

It came from a protonvpn founder, an obviously biased source: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn...

but was conveniently never denied by PIA that I could ever find. If it was a lie, it would be easy for them (PIA) to prove under libel laws in the discovery phase of a trial. I'd argue if it was a lie from ProtonVPN, it would have been in PIA's best interests to clear their name. After all, PIA and ProtonVPN are a few of the only providers who've proven in courts they don't have logs of users. We know they're legit because they said so in court under penalty of perjury. Also, the European Commission has investigated these exact claims, and would have privileged access to a lot of the business documents, and found the claims without merit.

Me? Just a happy protonvpn user who finds the oft repeated shilling for PIA dull. If you really want to hate protonvpn, use PIA, or use someone else. Better, don't trust any of them! Setup algo on a digital ocean droplet of your own: https://github.com/trailofbits/algo

However, this is meant for running over an untrusted network, not for maintaining internet anonymity. Use Tor for that.

Re: NordVPN confirms it was hacked

#544

Earlier quoted context omitted.

Yes, network KVMs are expected of any co-location center. You want to be able to access the console and the power switches of any real physical server without having to send someone out to the center, and is a common feature of most high end data centers. Even a lot of VM/cloud systems have some kind of virtual management console (Linode has their LISH system that lets you SSH in to console and Vultr/Digital Ocean ha…

.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.

How is it “obviously” the right policy? If implemented, console input would presumably be part of the AWS API, guarded with IAM permissions like everything else. If you have full IAM permissions, you can already take over any instance by temporarily attaching its disk to a different instance and modifying the data from there. (That requires rebooting, but so would takeover via console input.) Indeed, I’ve had to do exactly that on multiple occasions to fix broken config files on my personal instance; it would have been much more convenient to have console input.

Re: NordVPN confirms it was hacked

#546
post #531

Earlier quoted context omitted.

The problem with this is that jumping out onto the net from a VPS-allocated IP causes all sorts of trouble for "normal" internet use. For example you won't be able to use Netflix doing something like this.

I can see why Netflix would try to block it, but I haven't run into any issues with it myself (OpenIKEd on OpenBSD on a $3.50/mo Vultr server as detailed here: https://www.snazz.xyz/how-to/2019/09/13/vpn.html ). A lot of websites seem aggressive towards Tor users, but my VPS IP address was treated the same as my home, work, and LTE addresses. Are there any other documented cases I should be aware of?

Vultr is a lesser-known VPS, ymmv. I had issues with several websites using Linode. I don't have a list, but iirc it was some gaming related service that took issue with the IP.

Re: NordVPN confirms it was hacked

#547

What about the data-mining and selling infrastructure of NordVPN, known as Tesonet? Are those intact? Also interesting to know how their legal departments are doing, such as the Panamanian shell and the Lithuanian headquarters. http://vpnscam.com/wp-content/uploads/2018/08/2018-08-24-09_... http://vpnscam.com/hola-vpn-and-nordvpn-partners-in-data-min... http://vpnscam.com/nordvpn-protonvpn-proton-mail-owned-by-te...

Thanks for sharing these. I was familiar with the Protonmail business but did not know this all connected to a bigger picture. I never trusted NordVPN... they spent way too much money on advertising and snake oil advertising at that, focusing on meaningless numbers and distractions.

Hopefully you don't have similar news to share about Mullvad...

Re: NordVPN confirms it was hacked

#548
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

Don't use Tunnelbear, they're known compromised. Honestly it's hard to beat Mullvad right now but that does make them a hot target, so keep your eyes peeled and know when to jump ship.

Re: NordVPN confirms it was hacked

#549
post #221

Earlier quoted context omitted.

User root, password calvin. That's the default. And, if I had a dime for every time I've seen one of these in a data center, I'd be a rich man. I have literally begged sys admins to change the default password, but they say, "Why... we're behind a firewall using RFC 1918 addresses. No one can get to these." The rest, as they say, is history.

> we're behind a firewall This is the dumbest thing I've ever seen... unless your firewall is between your host versus every other host and there's no multi-tenancy, this will suck.

In well maintained networks the management interface (IDRAC, etc.) for each server is placed on a separate VLAN which the servers cannot access. This isn't to say that cheap providers actually do this, or that the VLAN can't be accessed by a compromised technician's workstation/laptop.

Re: NordVPN confirms it was hacked

#550

What about the data-mining and selling infrastructure of NordVPN, known as Tesonet? Are those intact? Also interesting to know how their legal departments are doing, such as the Panamanian shell and the Lithuanian headquarters. http://vpnscam.com/wp-content/uploads/2018/08/2018-08-24-09_... http://vpnscam.com/hola-vpn-and-nordvpn-partners-in-data-min... http://vpnscam.com/nordvpn-protonvpn-proton-mail-owned-by-te...

Thanks for sharing these. I was familiar with the Protonmail business but did not know this all connected to a bigger picture. I never trusted NordVPN... they spent way too much money on advertising and snake oil advertising at that, focusing on meaningless numbers and distractions. Hopefully you don't have similar news to share about Mullvad...

The claims about ProtonVPN have been disproven.
Post reply on HN