Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

621–630 of 666 posts

Re: NordVPN confirms it was hacked

#621
post #12

If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo

Nothing on this page or on the trailofbits blog article tells me why I should actually use this. Why should I trust DigitalOcean more than ? Especially when it says "Does not claim to provide anonymity or censorship avoidance" - why would I use a VPN if it can't even attempt to provide some measure of anonymity?

Re: NordVPN confirms it was hacked

#622

Earlier quoted context omitted.

Their Google cert literally is "Tesonet" - how is this claim debunked - you can check it yourself.

There's actually a point by point write-up about this on Reddit: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn... There's a historical, almost accidental connection dating back to the infamous November 2015 DDoS against Proton, but zero connection today, and certainly not in the way it has been portrayed by people seeking to attack Proton. Android certs are permanent and can never be changed so that is…

For a company based in Switzerland to be "accidentally" connected to a company in another country they claim to have no connection to such that their permanent google cert lists the name of the company they are supposedly not connected with - that doesn't seem odd to you?

That fact that this had to be slowly pried out with changing explanations along the way?

When you say the claim that has been debunked - I expect the claim not to be confirmed.

Re: NordVPN confirms it was hacked

#623

Earlier quoted context omitted.

If you have Javascript disabled, it is a heck of a lot easier to identify you because you're one of the very few who disabled Javascript.

Are there really so few of us? It feels like there should be millions of us: https://addons.mozilla.org/en-GB/firefox/addon/noscript/

modern "web apps" written purely in tens of MB of javascript complicate it a bit

Re: NordVPN confirms it was hacked

#624

Earlier quoted context omitted.

Amazon has security critical functionality on an unauthenticated http endpoint on a link local address. That's pretty damn dumb in my book.

Yes, software that runs on the instance can learn instance metadata. No, that is not a problem. Running e.g. user-supplied scripts on the instance would be "pretty damn dumb", but no one is that dumb. Any widely distributed software that did something shady with instance metadata would get busted PDQ. Just like any widely distributed software that did something shady with e.g. root credentials, which is about the sam…

It's crappy design which bypasses important security mechanisms of the OS (lower privileged users) by allowing every application with network access to access such critical functionality. One sane approach would be passing this information to the OS through the hypervisor which then exposes it as a properly ACLed file system.

This is like an author of a website vulnerable to CSRF (because it relies on IP for auth) blaming browsers for allowing cross site requests instead of require proper authentication. Except that Amazon is powerful enough to get away with pushing all the effort onto developers and admins.

Re: NordVPN confirms it was hacked

#625

Earlier quoted context omitted.

As a ProtonMail client I’d like to see that myth busted too.

There's a couple ways to look at this. On one hand, there's an anonymous website and hundreds of Twitter bots pushing a story that is demonstratively false (just check public records). Then, on the other hand, you have Mozilla and the EU (which has access to all European corporate records) vouching for Proton (since they partially fund Proton). We also operate in a highly transparent way, so all information debunking…

Can you explain how Mozilla entering into a partnership is the same as vouching? Did they do any particular vetting or analysis, or was this just a marketing partnership?

Re: NordVPN confirms it was hacked

#626

Earlier quoted context omitted.

There's actually a point by point write-up about this on Reddit: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn... There's a historical, almost accidental connection dating back to the infamous November 2015 DDoS against Proton, but zero connection today, and certainly not in the way it has been portrayed by people seeking to attack Proton. Android certs are permanent and can never be changed so that is…

For a company based in Switzerland to be "accidentally" connected to a company in another country they claim to have no connection to such that their permanent google cert lists the name of the company they are supposedly not connected with - that doesn't seem odd to you? That fact that this had to be slowly pried out with changing explanations along the way? When you say the claim that has been debunked - I expect t…

Given all that is going on with VPNs, your caution is warranted, but one should also critically examine the claims that are being made.

Proton definitely has an office and subsidiary in Vilnius, it's not a secret because it's on our Instagram: https://www.instagram.com/p/BxMz62oHb6K/ The office is inside a 30 storey building, so it is not surprising the address is shared with quite a few other companies. That doesn't mean Proton as a whole is headquartered there, or that the subsidiary somehow controls the parent company in Switzerland, or that there is somehow data mining going on.

Those are the claims that have been clearly debunked. The fact that Proton has a subsidiary in Vilnius, or the fact that we outsourced our HR back in 2016, are not secrets, and is on our Instagram and the Reddit thread linked above. This is the truth, and this is not some wild EU-funded data mining conspiracy as some would have you believe.

Re: NordVPN confirms it was hacked

#627

Earlier quoted context omitted.

There's a couple ways to look at this. On one hand, there's an anonymous website and hundreds of Twitter bots pushing a story that is demonstratively false (just check public records). Then, on the other hand, you have Mozilla and the EU (which has access to all European corporate records) vouching for Proton (since they partially fund Proton). We also operate in a highly transparent way, so all information debunking…

Can you explain how Mozilla entering into a partnership is the same as vouching? Did they do any particular vetting or analysis, or was this just a marketing partnership?

You can read about what Mozilla did on their blog post about this: https://blog.mozilla.org/futurereleases/2018/10/22/testing-n...

Quoting from the blog post: "We therefore set out to conduct a thorough evaluation of a long list of market-leading VPN services. Our team looked closely at a wide variety of factors, ranging from the design and implementation of each VPN service and its accompanying software, to the security of the vendor’s own network and internal systems. We examined each vendors’ privacy and data retention policies to ensure they logged as little user data as possible. And we considered numerous other factors, including local privacy laws, company track record, transparency, and quality of support."

It was quite intensive, with on site visits to our office in Geneva and discussions with Mozilla technical leadership.

Re: NordVPN confirms it was hacked

#628
post #542

Earlier quoted context omitted.

The thing that scares me here is that these keys were leaked May 2018, and it's becoming public knowledge now. Someone found certificates for those three VPN providers and posted them to 8chan with a message like "I don't recommend these VPN providers lol" The good news is that they're only certificates, and they have now expired, but theoretically they could have been used for the past year without anyone noticing.

During the spate of health care information leakage, someone invented a MTBCA, meaning "Meantime to CEO Apology" for the time between the breach and the CEO apology. At that time, it was running on the order of 8 months.

haha this is fantastic.

Re: NordVPN confirms it was hacked

#629

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa... RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

Read up on "Perfect forward secrecy": https://en.wikipedia.org/wiki/Forward_secrecy

Assuming their IPsec was enabled with it (and OpenVPN should be enabled by default), them leaking their keys does not matter. The sessions can not be decrypted even if the master key is leaked.

TLS also has perfect forward secrecy by default.

Impersonation is an issue, but the article stated the CA keys have already been rotated and are out of date.

EDIT: I meant to reply to the post below me, but this is fine. Sorry about that!

Re: NordVPN confirms it was hacked

#630
post #617

Earlier quoted context omitted.

Which cheap data centers are you referring to? Curious as someone unfamiliar w/ the space.

Sorry hacker, not today!

Haha! If I was up to no good I wouldn't be using my real name in my handle to ask such questions :)
Post reply on HN