Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

551–560 of 666 posts

Re: NordVPN confirms it was hacked

#551
post #544

Earlier quoted context omitted.

.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.

How is it “obviously” the right policy? If implemented, console input would presumably be part of the AWS API, guarded with IAM permissions like everything else. If you have full IAM permissions, you can already take over any instance by temporarily attaching its disk to a different instance and modifying the data from there. (That requires rebooting, but so would takeover via console input.) Indeed, I’ve had to do e…

This "personal instance" model doesn't really fit AWS: if the instance is borked then fail over to another one that isn't. No need for console input.

Re: NordVPN confirms it was hacked

#552
post #422

Earlier quoted context omitted.

But the problem remain the same. Whoever manages the network that hosts your instance will see your traffic...

There are places that rent boxes for XMR if you want a hosting provider who doesn't have your information.

Any examples?

Re: NordVPN confirms it was hacked

#553
post #329

Earlier quoted context omitted.

I have a slightly dissenting answer to these questions, in the form of an interactive Q&A website: https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w...

How is this not the top comment? Nobody should be using a VPN provider, full-stop. It is structurally impossible for anyone to verify their claims, they have more incentive to lie than your ISP does, and they're cheap and easy to set up, so the industry is a cesspool. You should assume that all of them are behaving badly.

> they have more incentive to lie than your ISP does

A lot of ISPs openly collect user data, so I don't know how much that factor matters. And while I can go get a VPN, I can't just get another ISP.

Re: NordVPN confirms it was hacked

#554

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Typically data centers have compliance requirements like SSAE 16 specifies controls around physical access. Most any major retail data center would have that certification and others.

One presumes that because of NordVPN's business, they're colocating a server or two in many very many "POPs", presumably not all of them have tight controls on physical access. Its likely that there are none available in many areas where they seek to maintain a point of presence.

Re: NordVPN confirms it was hacked

#555
post #136

Earlier quoted context omitted.

It doesn't make much sense to me, even with iDRAC/some other console access you don't really have access to OS unless you reboot & go to single user mode etc at which point they should be noticing their servers rebooting etc. would love more info

Why would they notice their server rebooting? And why would they not just assume it was a glitch or power failure?

When someone gets notified by their monitoring system that a server was unavailable (because it rebooted) they might investigate and see that the IPMI logs don't mention power loss

Power failure would require both of the power feeds in the DC failing simultaneously and would be easily verified by contacting the DC and asking if they had any power outages reported at the time. Of course there are cheapskates who don't go for redundant power supplies so it's possible but would be indicated in the IPMI logs

Re: NordVPN confirms it was hacked

#556
post #239
post #200

Earlier quoted context omitted.

They can do active attacks on you, as most people don't actively attempt to ban and absolutely block unencrypted connections (and there are also sometimes attacks on SSL stacks anyway); and like... SSL isn't really designed to protect the content of your connection anyway: due to size and timing attacks, people have deployed practical implementations of stuff like "figure out where I am looking at on Google Maps" and…

> SSL isn't really designed to protect the content of your connection anyway: due to size and timing attacks, people have deployed practical implementations of stuff like "figure out where I am looking at on Google Maps" and "figure out what movie I am watching on Netflix", and while I haven't seen a practical implementation of it yet, "learn too much about my search queries due to find-as-you-type". A VPN won't prot…

Not by default, but it could. Send a monolithic stream of 1500 byte packets with some padding to obfuscate transfer rates and you can really disrupt that kind of thing.

Re: NordVPN confirms it was hacked

#557

Earlier quoted context omitted.

Yes, network KVMs are expected of any co-location center. You want to be able to access the console and the power switches of any real physical server without having to send someone out to the center, and is a common feature of most high end data centers. Even a lot of VM/cloud systems have some kind of virtual management console (Linode has their LISH system that lets you SSH in to console and Vultr/Digital Ocean ha…

.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.

FreeBSD has an interactive kernel debugger that you can use with a serial console. Super useful to track down some things, not usable on AWS -- you'd need to (somehow) do a core dump and hope you can figure it out from there.

Re: NordVPN confirms it was hacked

#558
post #387

Earlier quoted context omitted.

Yeah, Grammarly is creepy as hell. I've explicitly banned it (and similar services) at work. As for Youtube music, yup, that's undeniably a good deal. The music services should watch out, especially in younger demographics (I'm already 30+, Spotify premium user since 2009). Apple will probably push Music even harder and bundle that with their new video streaming. Spotify's really trying to become the defacto podcast…

> ...it's not super clear to me when tracks are clean encodes sourced from the proper music distribution ecosystem... Isn't that kind of the point? If you can't tell which is which without a visual cue (aka bias-generator) then they sound the same.

> If you can't tell which is which

This isn't a comparison test. There's only one version uploaded. With only one version, it's hard to tell if many flaws you hear were introduced by sloppy uploading or if they were present in the master.

Re: NordVPN confirms it was hacked

#559
post #374

Earlier quoted context omitted.

>Google can track you fairly effectively even if you’re behind a VPN. You don't know anything about my setup, so you have no basis for claiming this. On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and look at basic HTTP logs.

> You don't know anything about my setup, so you have no basis for claiming this. Sure, but the discussion isn't specifically about your setup, it's about the advertising claims that a VPN will help prevent tracking. Which is totally bunk. > On the other hand, if you have an exclusive sticky IP, you will be tracked all the time. And even if they don't do extensive fingerprinting right now, they can always go back and…

Local NAT does barely anything for an average household, and I'm not behind CGN. My IP is extremely pinpointing, way more than a "couple" bits.

Re: NordVPN confirms it was hacked

#560

Earlier quoted context omitted.

It depends on what you mean by 'hacking' a VPN. One assertion in this breach is that the NordVPN certificate private key was leaked, allowing anybody to spin up a NordVPN server that would pass HTTPS certificate validation (the cert is expired, it's currently unknown if the cert was valid for a period of time after it was compromised). This kind of an attack would let an attacker convince most users to download virus…

Let’s not forget that if they’ve got to a point where they can breach a private key they’re at a point where they’ve probably dumped hashed user creds and contact details, and probably gained persistence on breached hosts, too.

> probably dumped hashed user creds and contact details

Not if the hacker only got access to relay servers.

Post reply on HN