Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

611–620 of 666 posts

Re: NordVPN confirms it was hacked

#611

Earlier quoted context omitted.

The claims there have been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence, details here: https://bit.ly/35RDKzB

Their Google cert literally is "Tesonet" - how is this claim debunked - you can check it yourself.

There's actually a point by point write-up about this on Reddit: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn...

There's a historical, almost accidental connection dating back to the infamous November 2015 DDoS against Proton, but zero connection today, and certainly not in the way it has been portrayed by people seeking to attack Proton. Android certs are permanent and can never be changed so that is why there is still one mistakenly issued Android cert out there today.

Re: NordVPN confirms it was hacked

#612

It's odd that NordVPN, VikingVPN and Torguard all got their private keys leaked here. - Did the hackers use an SSH or a VPN service vulnerability? - Or maybe even a previously unknown vulnerability? - Was SSH access firewalled? If not, why? - Do they still have root access?

Answer: Compromised datacenter that had insecure remote management system running.

And only few data centers that want to have VPNs on their hardware (and offer cheap bandwidth).

Re: NordVPN confirms it was hacked

#613

Earlier quoted context omitted.

Amazon has security critical functionality on an unauthenticated http endpoint on a link local address. That's pretty damn dumb in my book.

Support for your assertion: https://rhinosecuritylabs.com/cloud-security/aws-security-vu...

That's a great link, but they're looking at "misconfigurations". How is that relevant here?

Re: NordVPN confirms it was hacked

#614

Earlier quoted context omitted.

> All servers have IPMI Most (not all) servers have out-of-band management; of which IPMI is just one of many such solutions. It's also worth noting that the hack could have been against in-band management if the Nord used an OS image provided by the DC hosts. However OOB feels more likely given their description (as vague as it was).

I'm confused why a factually accurate post was down voted. anyone care to enlighten me?

Don't worry about it. It could have been a mistake or a bot randomly voting. Either way complaining about down votes is against community guidelines.

Re: NordVPN confirms it was hacked

#615

Earlier quoted context omitted.

.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.

Amazon has security critical functionality on an unauthenticated http endpoint on a link local address. That's pretty damn dumb in my book.

Yes, software that runs on the instance can learn instance metadata. No, that is not a problem. Running e.g. user-supplied scripts on the instance would be "pretty damn dumb", but no one is that dumb. Any widely distributed software that did something shady with instance metadata would get busted PDQ. Just like any widely distributed software that did something shady with e.g. root credentials, which is about the same threat scenario.

Re: NordVPN confirms it was hacked

#616

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Yes. Dedicated servers generally have IPMI / ILO / IDRAC / whatever. It's the only way to scale out management of hosts and provisioning.

To the person / people down voting, can you share your ideas for how you can go about providing at-scale management of large estates of physical machines? I've never seen anything else that's both as practical and as affordable as IPMI / IDRAC / ILO systems that ship with servers, that doesn't introduce weird new failure conditions that can impact significantly more than a single host.

Re: NordVPN confirms it was hacked

#617

Earlier quoted context omitted.

IPMI does not have to be open to the internet to be open to a wide audience. Many of these out of band management interfaces are hosted on an internal network, but not isolated by customer. Cheap datacenters are favored by VPN providers for their unlimited bandwidth and lax abuse policies. Many of them allow access to IPMI only over a VPN, but do not isolate each customer’s IPMI to a customer VLAN. I personally know…

Which cheap data centers are you referring to? Curious as someone unfamiliar w/ the space.

Sorry hacker, not today!

Re: NordVPN confirms it was hacked

#618

Earlier quoted context omitted.

IPMI does not have to be open to the internet to be open to a wide audience. Many of these out of band management interfaces are hosted on an internal network, but not isolated by customer. Cheap datacenters are favored by VPN providers for their unlimited bandwidth and lax abuse policies. Many of them allow access to IPMI only over a VPN, but do not isolate each customer’s IPMI to a customer VLAN. I personally know…

Which cheap data centers are you referring to? Curious as someone unfamiliar w/ the space.

Generally speaking, there are four (4) tiers of "public" data centers are on the market, ranging from essentially a big room with some alright AC and a line out, to huge, highly secure (cameras, fingerprint readers, SSAE certifications, etc.) buildings with redundant power and HVAC systems.

The higher end ones are usually newer-ish, but there are lot of older "computer rooms" that offer acceptable-level benefits for a reasonable price. Lots of legacy customers and ISPs in these rooms, for the record. You get what you pay for but a lot of older DC spaces are just fine for most users; everyone thinks they need 99.999 but most don't.

There are also re-sellers and managed services companies who take out a footprint in data centers and then lease space in their cabs, sell bandwidth, IPs, etc. Using a series of resellers you can often get around restrictions as to what you're doing -- small fry MSPs don't ask a lot of questions -- but still get a data center footprint. These are sometimes one-man shows, and their quality and professionalism are often sub-par, which is how you end up with default iDRAC creds and the like.

Check out Data Center Maps or WebHostingTalk for some examples.

Source: data center ops manager for several different companies.

Re: NordVPN confirms it was hacked

#619

Earlier quoted context omitted.

Support for your assertion: https://rhinosecuritylabs.com/cloud-security/aws-security-vu...

That's a great link, but they're looking at "misconfigurations". How is that relevant here?

> Since the metadata service doesn’t require any particular parameters, fetching the URL http://169.254.169.254/latest/meta-data/iam/security-credent... will return the AccessKeyID, SecretAccessKey, and Token you need to authenticate into the account.

They talk about the AWS “Metadata Service” Attack Surface and how juicy a target it is. I was just providing support for that opinion.

Re: NordVPN confirms it was hacked

#620
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

I have a slightly dissenting answer to these questions, in the form of an interactive Q&A website: https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w...

... this site is awful. It doesn't address the actual reason why people use VPN's. They don't want all their activities to be recorded/tracked by their ISP's (which depending on jurisdiction log everything for at least 6 months if not more) or other actors. And if somebody wants to deanonymize your traffic, they have to go to extra effort, whether it's by exploiting or establishing a relationship with your VPN host or whatever else. Or there are other use cases, like wanting to torrent in a country that is very liberal with serving fines (Germany).

And frankly, his alternatives are just absurd. Tor? Really? Has he ever tried to use Tor for usual daily browsing? Does he expect people to try to use Facebook, Instagram, Youtube over Tor? Really?

Post reply on HN