Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

581–590 of 666 posts

Re: NordVPN confirms it was hacked

#581
What this article is missing is that the hackers had root access and had NordVPNs private key for their HTTPS cert for several months in 2018. This went undetected for months and they're only now publically admitting what happened due to press attention. Their public response seems to be "it's not a big deal guys, mitm is hard".

> The key wasn't set to expire until October 2018, some seven months after the March 2018 breach

https://crt.sh/?id=10031443

And here's a dump of their logs: https://share.dmca.gripe/hZYMaB8oF96FvArZ.txt

Re: NordVPN confirms it was hacked

#582
post #260

Earlier quoted context omitted.

>For dedicated servers this would work, especially for VPN where data-loss is "acceptable". FWIW there's no need for data loss when you ditch the server, just download the encrypted data and decrypt using a clean environment elsewhere. >But if it where based on containers like LXC or OpenVZ, then the host can force root access via a command without even changing the root password of the container. You should never do…

I mean that encryption puts the entire data-store at risk, I've seen it happen more than twice due to RAM being faulty (In one incident it was using ECC RAM) and a power-failure. Even the backups where corrupt due to being backed up in encrypted images. When encrypted volumes and images are corrupted by RAM or power-failure, they are locked forever. Of course one should never force root access, I'm saying that you ca…

Yeah this sounds so weird. Data loss due to bad RAM will be extremely similar with or without encryption, it's not going to corrupt the header of the disk.

The catastrophic data loss you describe almost certainly resulted from you doing something horribly wrong, and not encryption.

Re: NordVPN confirms it was hacked

#583

Earlier quoted context omitted.

Full Disk Encryption is an option, but that’ll entail needing the use the IPMI console to enter the password at every reboot, essentially turning it into a manual operation.

If you have physical access twice, full disk encryption usually doesn't help really at all. IPMI seems about as powerful as physical access.

If you just ignore random reboots, sure. But why would you?

Re: NordVPN confirms it was hacked

#584
post #340
post #136

Earlier quoted context omitted.

It doesn't make much sense to me, even with iDRAC/some other console access you don't really have access to OS unless you reboot & go to single user mode etc at which point they should be noticing their servers rebooting etc. would love more info

Just set up your code as a boot-once config and wait for the owner to reboot their machine. Make your code end by booting the installed OS (or even by just rebooting again, most people will just curse about the damn slow server boot process).

You can't do that as you don't have any access until it's being rebooted. It's basically like you're standing in front of the machine so there's not really much you can do when you're just looking at a login prompt, you have to be able to stop grub from just booting with the default options and instead boot up using init=/bin/bash or maybe if the server supports iPXE you can just chain load some payload off the internet.

Re: NordVPN confirms it was hacked

#585
post #51

Earlier quoted context omitted.

It's the same shit. https://news.ycombinator.com/item?id=17258203

The claims there have been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence, details here: https://bit.ly/35RDKzB

Do you have a non-shortened link?

Re: NordVPN confirms it was hacked

#586
post #550

Earlier quoted context omitted.

Thanks for sharing these. I was familiar with the Protonmail business but did not know this all connected to a bigger picture. I never trusted NordVPN... they spent way too much money on advertising and snake oil advertising at that, focusing on meaningless numbers and distractions. Hopefully you don't have similar news to share about Mullvad...

The claims about ProtonVPN have been disproven.

I would like to hear more about this. Could you share some information?

Re: NordVPN confirms it was hacked

#587

Earlier quoted context omitted.

Source ?

As a ProtonMail client I’d like to see that myth busted too.

There's a couple ways to look at this. On one hand, there's an anonymous website and hundreds of Twitter bots pushing a story that is demonstratively false (just check public records).

Then, on the other hand, you have Mozilla and the EU (which has access to all European corporate records) vouching for Proton (since they partially fund Proton). We also operate in a highly transparent way, so all information debunking this is actually in public record, details here: https://protonvpn.com/blog/is-protonvpn-trustworthy/

Proton definitely has an office and subsidiary in Vilnius, it's not a secret because it's on Instagram: https://www.instagram.com/p/BxMz62oHb6K/ The office is inside a 30 storey building, so it is not surprising the address is shared with quite a few other companies. But that doesn't mean Proton on a whole is based in Vilnius.

The people spreading the false information are also falsely implying that Proton's subsidiary controls the Swiss parent company, which is never the case as it's always the other way around (parent controls the subsidiary). And its super easy to disprove because unlike most companies in the VPN space, the directors of Proton's Swiss parent company are in public record, and are all well known people who have been in the public eye for years (e.g. at TED: https://www.ted.com/talks/andy_yen_think_your_email_s_privat...)

Re: NordVPN confirms it was hacked

#588
post #586
post #550

Earlier quoted context omitted.

The claims about ProtonVPN have been disproven.

I would like to hear more about this. Could you share some information?

Check a few comments down, its discussed here: https://news.ycombinator.com/item?id=21321598

Re: NordVPN confirms it was hacked

#589
So what does this mean for an every day consumer? I had been debating using the 30-day money back guarantee as I realised I didn't use it as much as I thought I would. I want to stay protected on public Wifi. Added anonymity occasionally would be good too, as well as accessing US Netflix from here in the UK.

Now my 30 days is up. What would be the best course of action? Should I email and say that I'm not comfortable being their customer any more, and asked to be reimbursed? Carry on, for my use case? I'd never connected to a Finnish server.

Re: NordVPN confirms it was hacked

#590

Earlier quoted context omitted.

The claims there have been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence, details here: https://bit.ly/35RDKzB

Do you have a non-shortened link?

https://news.ycombinator.com/item?id=21321598
Post reply on HN