Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

161–170 of 666 posts

Re: NordVPN confirms it was hacked

#161

This is so well timed, I just bought a 3-year subscription to NordVPN and they have a 30 day refund policy.

You should probably ask for a refund, then set up your own VPN. Commerical VPNs are, for the vast majority of cases, simply not a good bet for your privacy. You're changing your network traffic path from a diffuse and byzantine series of paths to once centralized collection point. The payoff for an attack on a VPN rises very quickly. Meanwhile, you're also conditioning yourself to say, "My traffic is secure while my…

It works for when you need to use untrusted WiFi, because the alternative is worse. Beyond that, it forms a nice defense against unsophisticated attackers. (e.g. it breaks a single datapoint (ip address) used by Google and FaceBook).

Re: NordVPN confirms it was hacked

#162

This is troublesome. I was planning to eke out $85/ annum and go for NordVPN, but now even this is unreliable

I would look at one of the cryptoanarchist aligned providers like Cryptostorm, Mullvad, or AirVPN. Of course, no one is immune to a hack but they don't have any shady connections or financial incentive to deprioritize security.

Re: NordVPN confirms it was hacked

#163
post #125

The best thing NordVPN can do right now is make a statement that clearly and honestly describes how its users are affected. No bullshit marketing language, no trying to hide facts, just a short and simple explanation of what this means for users and what they should do next.

Truth is - if hackers did a MIM attack and collected a bunch user traffic (for how long?) they could have everything.. banking info, emails, logins... at this point if i was a user of that VPN service - i'd be replacing all of my sensitive passwords, secret questions/answers to key accounts.

A MITM attack of a VPN allows attackers to collect unencrypted traffic.

Most people access email over a webmail interface, like gmail, that uses modern TLS encryption. All that's sent unencrypted is the SNI header, e.g. "mail.google.com", and roughly how much traffic total is transferred, e.g. "20 MB of browsing on mail.google.com".

A VPN can't easily defeat TLS. It would require the user to ignore many scary warnings from the browser.

You're still right that a user should change their passwords for any websites that do not use TLS (very few these days), or for any that use old versions of TLS if their threat model includes someone with close to nation-state resources attacking their connections individually.

It also probably doesn't hurt to be paranoid and rotate anyway, but it should be with a proper understanding of the threats, not because of some ridiculous "the sky is falling" incorrect information like this.

Re: NordVPN confirms it was hacked

#164

Earlier quoted context omitted.

You should probably ask for a refund, then set up your own VPN. Commerical VPNs are, for the vast majority of cases, simply not a good bet for your privacy. You're changing your network traffic path from a diffuse and byzantine series of paths to once centralized collection point. The payoff for an attack on a VPN rises very quickly. Meanwhile, you're also conditioning yourself to say, "My traffic is secure while my…

I thinking about spinning up a Digital Ocean droplet and rolling my own right now

Absolutely. Look for project Streisand.

Re: NordVPN confirms it was hacked

#165

Earlier quoted context omitted.

I can use a VPN provider outside the jurisdiction of my own country.

If you're doing something illegal in your own country, that seems like a good idea. If you're not, that would seem to achieve nothing other than making it much more difficult to enforce any action against the VPN provider for selling your private data.

In the US at least, there still remain a few tatters of laws that control how law enforcement and intelligence agencies can surveil you.

But there are zero controls on US agencies hoovering up data indiscriminately outside US borders.

Re: NordVPN confirms it was hacked

#166
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

PIA is also compromised. They installed the known criminal Mark Karpelès as CTO.

Re: NordVPN confirms it was hacked

#167
post #113

This is troublesome. I was planning to eke out $85/ annum and go for NordVPN, but now even this is unreliable

Except this isn't their fault because their infrastructure provider messed up and didn't even disclose this possible backdoor. If anyone the provider should be named and shamed, not NVPN.

If you're making a living selling a secure channel, where the whole point is to be more secure then other channels, you better fucking secure that channel. You can't outsource the underlying hardware and then wash your hands of what happens.

Re: NordVPN confirms it was hacked

#168
post #99

Earlier quoted context omitted.

This has been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence. ProtonVPN is 100% owned by the company behind ProtonMail, which in turn is funded by the European Union, so this has been verified by the European Commission. Details here: https://bit.ly/35RDKzB

I mean this[1] is pretty convincing and not directly from the accused company's blog. The only thing it gets wrong is framing ProtonVPN Lithuania as the main ProtonVPN company instead of as a subsidiary. Regardless of that, there is so much mud being slung I recommend anyone to just search for 'protonvpn nordvpn tesonet', read a few articles on the topic and form your own opinion. Like I said, you can decide if you w…

There's a couple ways to look at this.

On one hand, there's anonymous websites, competing VPN companies, and hundreds of Twitter bots pushing a story that is demonstratively false (just check public records).

Then, on the other hand, you have Mozilla and the EU (which has access to all European corporate records) vouching for Proton, which also operates in a highly transparent way, examples here: https://protonvpn.com/blog/is-protonvpn-trustworthy/

Proton definitely has an office and subsidiary in Vilnius, it's not a secret because it's on Instagram: https://www.instagram.com/p/BxMz62oHb6K/ The office is inside a 30 storey building, so it is not surprising the address is shared with quite a few other companies. And that doesn't mean Proton on a whole is based in Vilnius.

Re: NordVPN confirms it was hacked

#169

Earlier quoted context omitted.

Sounds like an iDRAC exploit (assuming Dell servers). But, yes, remote management is pretty common in datacenters. The fact that NordVPN wasn't aware of them just shows incompetence.

How the hell do you pwn a server with iDRAC?

In certain configurations, iDRAC gives you an rdp connection. If idrac is left at default, windows admin login not being changed isn't too much of a stretch.
Post reply on HN