Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

101–110 of 666 posts

Re: NordVPN confirms it was hacked

#101

I don't understand the obsession with VPN providers. Funneling all your Internet access through a single entity no matter where you connect from just seems like a fundamentally bad idea to me, especially if that entity's business is getting people to funnel all their traffic through, making them a juicy target for governments or hackers.

Well, you're funneling your traffic through a single entity in almost all cases, right? So I view it more as, who do I distrust more? My ISP or a VPN?

I don't use a VPN provider, but it's tempting as I don't trust my ISP at all.

Re: NordVPN confirms it was hacked

#102
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

If we're offering recommendations, then I'll go ahead and recommend Mullvad. They've got great clients for most common operating systems, good customer support, good performance, lots of servers to choose from, the ability to open ports, etc.

Something I find pretty neat about them from a technical standpoint is their account creation, user authentication, and payment processes. Sign-up literally takes less than a second, so even if you don't plan on using their service, I recommend you try creating an account.

Re: NordVPN confirms it was hacked

#104
The best thing NordVPN can do right now is make a statement that clearly and honestly describes how its users are affected. No bullshit marketing language, no trying to hide facts, just a short and simple explanation of what this means for users and what they should do next.

Re: NordVPN confirms it was hacked

#106
post #78
post #55

Lots of talk here from highly technical folks but not one person brings up the fact that these are expired keys - as in not usable? I understand that the fact that these keys were obtained is concerning but the security of nord and etc prevailed at the end of the day. The question is: were they leaked before they expired or long after?

They were leaked on March 2018 [0][1], and they expired on October 2018 [2]. [0] https://web.archive.org/web/20180504001844/https://8ch.net/b... [1] https://nordvpn.com/fr/blog/official-response-datacenter-bre... [2] https://crt.sh/?id=10031443

> However, the key couldn’t possibly have been used to decrypt the VPN traffic of any other server. On the same note, the only possible way to abuse website traffic was by performing a personalized and complicated MiTM attack to intercept a single connection that tried to access nordvpn.com.

However crt.sh shows

> Validity > Not Before: Oct 6 12:53:38 2015 GMT > Not After : Oct 6 12:53:38 2018 GMT

What exactly were these keys for if they were only usable in such a manner according to nord?

Re: NordVPN confirms it was hacked

#108
> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed.

This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to worry about my own infrastructure security but also worry that my IaaS provider hasn't installed some backdoor to my servers?

Re: NordVPN confirms it was hacked

#110

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

Sounds like an iDRAC exploit (assuming Dell servers).

But, yes, remote management is pretty common in datacenters. The fact that NordVPN wasn't aware of them just shows incompetence.

Post reply on HN