Apparently the hacker was able to find out - so while it may be unknown, it's not an impossibility to detect it. Beyond whether or not sensitive information was accessed, what will NordVPN do in the future to eliminate or mitigate the possibility that this will occur again?
NordVPN confirms it was hacked
201–210 of 666 posts
Re: NordVPN confirms it was hacked
#202> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…
Absolutely. We had similar situation with one of the DC vendors.
Re: NordVPN confirms it was hacked
#203Earlier quoted context omitted.
Except this isn't their fault because their infrastructure provider messed up and didn't even disclose this possible backdoor. If anyone the provider should be named and shamed, not NVPN.
> NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” Not acceptable.
Re: NordVPN confirms it was hacked
#204>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…
Re: NordVPN confirms it was hacked
#205Earlier quoted context omitted.
Is the alternative actually worse than SSL? Why? And no, it doesn't break analytical by Facebook or Google in any substantial way. I know some people use them to evade Netflix region exceptions, and that's about all they're good for.
You can’t always ensure that all traffic goes over SSL. DNS traffic is an example. I always assume that hostile public networks like free WiFi have agents actively trying to man in the middle any connections they can. If your device has a known exploit and a single connection not going over SSL you drastically increase your exposure on a public WiFi, hence the one use case for VPN.
> I always assume that hostile public networks like free WiFi have agents actively trying to man in the middle any connections they can.
And VPNs just move that problem. If you're not demanding and forcing SSL, you're not actually addressing this problem.
> If your device has a known exploit and a single connection not going over SSL you drastically increase your exposure on a public WiFi, hence the one use case for VPN.
I regret to inform you that none of these things you've described stop thise sort those attacks. Forcing SSL on your browser is a realistic option for most threat models. If you're at a level where you're actually being surveilled by a nation-state-level actor, a commercial VPN won't help you. Short of that scenario, forcing SSL will cover most cases.
Re: NordVPN confirms it was hacked
#206Earlier quoted context omitted.
Any (large?) ISP will report your torrenting and/or terminate your internet usage if you torrent anything they deem copyrightable. Both Comcast and Spectrum do this, at least. Edit, to add: No VPNs do this.
They don't. What you're describing would take them out of common carrier status and make their business unworkable. What they do is respond to notices from copyright holders. https://arstechnica.com/tech-policy/2011/07/major-isps-agree...
Re: NordVPN confirms it was hacked
#207Earlier quoted context omitted.
What exactly can they be doing with your data other than selling a list of which DNS queries you make and which IP addresses you connect to? (Which the VPN provider can also do.)
On the cellphone side, most carriers will sell your identity and real time location to websites that your visit. https://news.ycombinator.com/item?id=15477286
Re: NordVPN confirms it was hacked
#208Earlier quoted context omitted.
Any (large?) ISP will report your torrenting and/or terminate your internet usage if you torrent anything they deem copyrightable. Both Comcast and Spectrum do this, at least. Edit, to add: No VPNs do this.
They don't. What you're describing would take them out of common carrier status and make their business unworkable. What they do is respond to notices from copyright holders. https://arstechnica.com/tech-policy/2011/07/major-isps-agree...
Edit: spelling
Re: NordVPN confirms it was hacked
#209>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…
If they have EU customers then article 33 of GDPR should see to that.
"In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after having become aware of it, notify the personal data breach to the supervisory authority competent in accordance with Article 55, unless the personal data breach is unlikely to result in a risk to the rights and freedoms of natural persons. Where the notification to the supervisory authority is not made within 72 hours, it shall be accompanied by reasons for the delay."
Unless the authorities in EU accept the explanation they are in trouble, but I think you shall report even if you think there has been a breach.
Re: NordVPN confirms it was hacked
#210This is always topical: Don't use VPN Services https://gist.github.com/joepie91/5a9909939e6ce7d09e29
So can my ISP and they have been confirmed to sell customer data and work directly with NSA.
https://en.wikipedia.org/wiki/Room_641A
https://www.theguardian.com/business/2016/oct/25/att-secretl...