Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

571–580 of 666 posts

Re: NordVPN confirms it was hacked

#571
post #533
post #40

Earlier quoted context omitted.

If you already have a DigitalOcean droplet up and running and you have ssh access, you can use sshuttle [0]. e.g. run this from the command line: sshuttle -r example.com 0/0 -x example.com --dns [0] https://github.com/sshuttle/sshuttle

OpenSSH also includes a SOCKS proxy which you can use with no additional software: https://ma.ttias.be/socks-proxy-linux-ssh-bypass-content-fil... Whether it grants you any significant anonymity is debatable, but it works well for evading content filters and tunneling your traffic onto a more trustworthy network.

Speaking from experience, sshuttle is way easier and more robust than using OpenSSH's built-in SOCKS proxy.

Re: NordVPN confirms it was hacked

#572
post #12

If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo

Another option is Outline VPN, Jigsaw/Google's open source implementation of Shadowsocks:

https://getoutline.org

https://github.com/Jigsaw-Code/outline-client

https://github.com/Jigsaw-Code/outline-server

Shadowsocks is more resistant to censorship from adverse actors (such as the Great Firewall) than OpenVPN.

Outline's user experience is the best I've seen among self-hosted VPN solutions, as it includes apps for both the server and the client. The server app is suitable for use in organizations, and can manage VPN profiles for multiple individuals.

Re: NordVPN confirms it was hacked

#575
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

IPv6 VPN is available for free from https://ungleich.ch/ipv6/vpn/ if you buy a VM from them.

Haven't tested it, just rembered datacenterlight from a HN thread about buying a mainframe.

Re: NordVPN confirms it was hacked

#576
post #40
post #12

If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo

If you already have a DigitalOcean droplet up and running and you have ssh access, you can use sshuttle [0]. e.g. run this from the command line: sshuttle -r example.com 0/0 -x example.com --dns [0] https://github.com/sshuttle/sshuttle

I use sshuttle all the time when working from "restricted" networks (car dealerships, airports, etc.) For some reason, my local Honda dealer has a guest WiFi that restricts outgoing traffic to a small number of ports, and apparently SSH isn't on that list, so I can't push/pull to GitHub. Firing up sshuttle on port 80 punches right through the filter and allows me to do real work while I wait for my oil change.

Re: NordVPN confirms it was hacked

#577
post #99

Earlier quoted context omitted.

This has been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence. ProtonVPN is 100% owned by the company behind ProtonMail, which in turn is funded by the European Union, so this has been verified by the European Commission. Details here: https://bit.ly/35RDKzB

I mean this[1] is pretty convincing and not directly from the accused company's blog. The only thing it gets wrong is framing ProtonVPN Lithuania as the main ProtonVPN company instead of as a subsidiary. Regardless of that, there is so much mud being slung I recommend anyone to just search for 'protonvpn nordvpn tesonet', read a few articles on the topic and form your own opinion. Like I said, you can decide if you w…

Anyone can set up an anonymous website and make spurious accusations and/or take money to post glowing reviews. The VPN segment is full of shady tactics like this. Never trust any VPN review site.

Trust serious organizations such as Mozilla and the EFF.

Mozilla trusts ProtonVPN enough to officially partner with them. That means a lot more than some random anonymous reviews.

Re: NordVPN confirms it was hacked

#578
post #542

Earlier quoted context omitted.

The thing that scares me here is that these keys were leaked May 2018, and it's becoming public knowledge now. Someone found certificates for those three VPN providers and posted them to 8chan with a message like "I don't recommend these VPN providers lol" The good news is that they're only certificates, and they have now expired, but theoretically they could have been used for the past year without anyone noticing.

During the spate of health care information leakage, someone invented a MTBCA, meaning "Meantime to CEO Apology" for the time between the breach and the CEO apology. At that time, it was running on the order of 8 months.

Now that's a metric

Re: NordVPN confirms it was hacked

#580
Could this be another marketing trick to lure more customers? Last time I checked, companies are actually favourable when they "get slightly hacked". They get front page from top tech websites, magazines, forums...
Post reply on HN