Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

591–600 of 666 posts

Re: NordVPN confirms it was hacked

#591
post #12

If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo

If you are looking to spin up your own vpn server with wireguard and pihole there is an excellent guide here https://drexl.me/guides/wireguard-pihole-vpn-setup.html

Re: NordVPN confirms it was hacked

#592
post #586
post #550

Earlier quoted context omitted.

The claims about ProtonVPN have been disproven.

I would like to hear more about this. Could you share some information?

Just search for proton in this thread. They've explained what happened themselves.

Besides, the argumentation from that vpnscam website and its followers reminds you of the typical conspiracy retards that follow Trump.

Re: NordVPN confirms it was hacked

#593

So what does this mean for an every day consumer? I had been debating using the 30-day money back guarantee as I realised I didn't use it as much as I thought I would. I want to stay protected on public Wifi. Added anonymity occasionally would be good too, as well as accessing US Netflix from here in the UK. Now my 30 days is up. What would be the best course of action? Should I email and say that I'm not comfortable…

It's so hard to understand what is correct (I'm aware this is a problem with every news story) between the people telling me that they're almost certainly evil, keeping logs and selling data and those that are telling me that it's a smear campaign by the competing VPN providers.

My gut tells me that the level of advertising and incredibly low prices is too good to be true...

Now with this hack it's the same problem, how bad is it, does it affect me and should i be concerned?

Re: NordVPN confirms it was hacked

#594

Earlier quoted context omitted.

Yes, network KVMs are expected of any co-location center. You want to be able to access the console and the power switches of any real physical server without having to send someone out to the center, and is a common feature of most high end data centers. Even a lot of VM/cloud systems have some kind of virtual management console (Linode has their LISH system that lets you SSH in to console and Vultr/Digital Ocean ha…

.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.

Amazon has security critical functionality on an unauthenticated http endpoint on a link local address. That's pretty damn dumb in my book.

Re: NordVPN confirms it was hacked

#595

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Sounds like an iDRAC exploit (assuming Dell servers). But, yes, remote management is pretty common in datacenters. The fact that NordVPN wasn't aware of them just shows incompetence.

Pointing fingers without having the details at hand is not competent either.

Re: NordVPN confirms it was hacked

#596
post #221

Earlier quoted context omitted.

User root, password calvin. That's the default. And, if I had a dime for every time I've seen one of these in a data center, I'd be a rich man. I have literally begged sys admins to change the default password, but they say, "Why... we're behind a firewall using RFC 1918 addresses. No one can get to these." The rest, as they say, is history.

> we're behind a firewall This is the dumbest thing I've ever seen... unless your firewall is between your host versus every other host and there's no multi-tenancy, this will suck.

Yes, this kind of firewall is always supposed to be between the management hosts and everything else. Only the sysadmins at the data center a very limited set of applications is supposed to be able to access it. The very real risk is misconfiguration.

Re: NordVPN confirms it was hacked

#597
post #586

Earlier quoted context omitted.

I would like to hear more about this. Could you share some information?

Just search for proton in this thread. They've explained what happened themselves. Besides, the argumentation from that vpnscam website and its followers reminds you of the typical conspiracy retards that follow Trump.

In no world is it excusable to have your ostensible competitor sign your binaries or certificates. They can make all the excuses they want, but it doesn't dissolve their incompetence, and shows they are unfit for running such a user-critical business.

Re: NordVPN confirms it was hacked

#598
post #51

Earlier quoted context omitted.

It's the same shit. https://news.ycombinator.com/item?id=17258203

The claims there have been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence, details here: https://bit.ly/35RDKzB

Their Google cert literally is "Tesonet" - how is this claim debunked - you can check it yourself.

Re: NordVPN confirms it was hacked

#599

Earlier quoted context omitted.

Over the course of the disclosure of the connection between NordVPN, Tesonet, and possibly ProtonVPN, Proton's story kept changing. They said contradicting things multiple times. They locked the Reddit thread. Why did Proton keep changing their story if they had nothing to hide? I will keep reminding this every time the issue gets raised. There is a compilation [0] of changing Proton's responses and them successively…

Both Mozilla and the European Commission have looked into the accusations being made on anonymous websites, and determined that they are false. The EU in particular, has access to records which allow independent verification. There is also an abundance of public record which demonstrates this is false. The bad faith of those spreading this information is also apparent from the hundreds of fake Twitter accounts used t…

Can you confirm the certificate for Proton never had Tesonet in it? The number of overlapping coincidences is just unreal.

Re: NordVPN confirms it was hacked

#600

Earlier quoted context omitted.

.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.

Amazon has security critical functionality on an unauthenticated http endpoint on a link local address. That's pretty damn dumb in my book.

Support for your assertion: https://rhinosecuritylabs.com/cloud-security/aws-security-vu...
Post reply on HN