Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

661–666 of 666 posts

Re: NordVPN confirms it was hacked

#661

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

On Supermicro hardware and maybe others, IPMI has a very dangerous default setting: if you're not connecting the dedicated IPMI port to a network (typically some closed network dedicated to management), it will use the first ethernet NIC on the motherboard (sharing it with the host), possibly making it accessible through the internet (with default, insecure credentials adding insult to injury) or at least neighbouring machines.

Re: NordVPN confirms it was hacked

#662

Earlier quoted context omitted.

IPMI does not have to be open to the internet to be open to a wide audience. Many of these out of band management interfaces are hosted on an internal network, but not isolated by customer. Cheap datacenters are favored by VPN providers for their unlimited bandwidth and lax abuse policies. Many of them allow access to IPMI only over a VPN, but do not isolate each customer’s IPMI to a customer VLAN. I personally know…

Which cheap data centers are you referring to? Curious as someone unfamiliar w/ the space.

I have decided to contact them directly rather than publicize.

Re: NordVPN confirms it was hacked

#663
post #581

What this article is missing is that the hackers had root access and had NordVPNs private key for their HTTPS cert for several months in 2018. This went undetected for months and they're only now publically admitting what happened due to press attention. Their public response seems to be "it's not a big deal guys, mitm is hard". > The key wasn't set to expire until October 2018, some seven months after the March 2018…

Why isn't anybody in journalism publishing this? Really, they're scammers!

Re: NordVPN confirms it was hacked

#664
post #481

Earlier quoted context omitted.

> ...it's not super clear to me when tracks are clean encodes sourced from the proper music distribution ecosystem... Isn't that kind of the point? If you can't tell which is which without a visual cue (aka bias-generator) then they sound the same.

Yes! Which is why you won't hear me waste a whole lot of breath yammering about lossy compression. I'd sure pay Spotify extra for lossless, because I'm weird in ways I'll reveal below, but I agree that people should give lossy compression a break. Well-encoded AAC and Vorbis averaging over 256 kbps are very transparent-sounding, in ways that never was possible with mp3. If I put in time, I get 5/6 right in this famou…

What codec do they use:

https://support.google.com/youtubemusic/thread/338369?msgid=...

Stats for nerds: https://support.google.com/youtubemusic/thread/340313?msgid=...

Post reply on HN