Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

601–610 of 666 posts

Re: NordVPN confirms it was hacked

#601
post #12

If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo

Another option is Outline VPN, Jigsaw/Google's open source implementation of Shadowsocks: https://getoutline.org https://github.com/Jigsaw-Code/outline-client https://github.com/Jigsaw-Code/outline-server Shadowsocks is more resistant to censorship from adverse actors (such as the Great Firewall) than OpenVPN. Outline's user experience is the best I've seen among self-hosted VPN solutions, as it includes apps for bot…

It's an alternative for sure and has specific use cases, but calling Outline a VPN is disingenuous. It's just a Socks proxy with some obfuscation built in.

Re: NordVPN confirms it was hacked

#602

Earlier quoted context omitted.

They mean IPMI. All servers have IPMI and there’s remote root exploits against many versions of them.

> All servers have IPMI Most (not all) servers have out-of-band management; of which IPMI is just one of many such solutions. It's also worth noting that the hack could have been against in-band management if the Nord used an OS image provided by the DC hosts. However OOB feels more likely given their description (as vague as it was).

I'm confused why a factually accurate post was down voted. anyone care to enlighten me?

Re: NordVPN confirms it was hacked

#603

Earlier quoted context omitted.

Also allowing historical sessions to be decrypted.

Also looks like NordVPN has been misleading customers about the number of servers they have (or didn't make clear they were VM/containers).

I don't think they ever wrote anywhere that they have 6,000+ physical servers. Calling a VM (like an EC2 instance) a server is not unusual. For the customers it was important that the resources, bandwidth and different IPs were available. For that it doesn't matter if it's a physical server.

Re: NordVPN confirms it was hacked

#604

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Within 72 hours According to GDPR I thought? “ The GDPR introduces a duty on all organisations to report certain types of personal data breach to the relevant supervisory authority. You must do this within 72 hours of becoming aware of the breach, where feasible.” https://ico.org.uk/for-organisations/guide-to-data-protectio...

I don't think they care about GDPR much. They were set up in a way to avoid legal scrutiny (not a bad idea for a VPN provider).

Re: NordVPN confirms it was hacked

#605
post #314

Earlier quoted context omitted.

Maybe NordVPN would argue personal data wasn't breached? It's a bad look in any case.

Theis Keys were stolen. All data is exposed now.

Only if someone used it successfully for MITM attacks. We don't know that, they can still argue that in fact no user data got breached.

Re: NordVPN confirms it was hacked

#606
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

Any provider that offers that many IP addresses? I found NordVPN to be the only reliable service if you need to run requests from many IPs from different countries (web scraping).

Re: NordVPN confirms it was hacked

#607

Earlier quoted context omitted.

Both Mozilla and the European Commission have looked into the accusations being made on anonymous websites, and determined that they are false. The EU in particular, has access to records which allow independent verification. There is also an abundance of public record which demonstrates this is false. The bad faith of those spreading this information is also apparent from the hundreds of fake Twitter accounts used t…

Can you confirm the certificate for Proton never had Tesonet in it? The number of overlapping coincidences is just unreal.

There's actually a point by point write-up about this on Reddit: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn...

There's a historical, almost accidental connection dating back to the infamous November 2015 DDoS against Proton, but zero connection today, and certainly not in the way it has been portrayed by people seeking to attack Proton.

Re: NordVPN confirms it was hacked

#608
post #37
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

I am surprised why isn’t anyone suggesting Cloudflare’s Warp VPN? Genuinely curious what is the difference. I guess Clodflare one is only for mobile?

- Doesn't work for Georestriction - Shows your IP address (some pages) - You cannot choose your data center - Only for mobile

Re: NordVPN confirms it was hacked

#609
post #329

Earlier quoted context omitted.

I have a slightly dissenting answer to these questions, in the form of an interactive Q&A website: https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w...

How is this not the top comment? Nobody should be using a VPN provider, full-stop. It is structurally impossible for anyone to verify their claims, they have more incentive to lie than your ISP does, and they're cheap and easy to set up, so the industry is a cesspool. You should assume that all of them are behaving badly.

Shouldn't matter to your average torrent user or someone who wants to watch US YouTube. And I guess that's most people who actually use it.

Re: NordVPN confirms it was hacked

#610

Earlier quoted context omitted.

> Your IP address is a largely irrelevant metric in modern tracking systems. I don't believe this for one second. Your IP address on its own is not sufficient to identify you. That doesn't mean your IP address is not helpful in identifying you. If you have Javascript disabled, it is a heck of a lot easier to identify you with a combination of an IP address, user agent, and OS than it is to identify you without the IP…

If you have Javascript disabled, it is a heck of a lot easier to identify you because you're one of the very few who disabled Javascript.

But who wants to put in the effort to develop tracking for non-JS users? In reality, most will just ignore the few users that don't want to be tracked. Even ublock origin should be enough for most.

However, IP is certainly used. I know of a few cases where IP is at least used as a filter. Most websites won't see that many users from one IP address.

Post reply on HN