Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

261–270 of 666 posts

Re: NordVPN confirms it was hacked

#261

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

I think that is pretty criminal already. Basically: 1- Nord falsely blames its server provider. 2- Nord hides it from their users. 3- Nord claims all will be well with an “audit” (again, since they were already “audited”) This is either criminal negligence, “security theater”, or both.

> Nord falsely blames its server provider.

I don't see anything in the article about those claims being false. Where did you get that?

Re: NordVPN confirms it was hacked

#262

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

I work for a web hosting company in the US and at least in our case, it's quite common for remote management to be enabled on pretty much all of our dedicated hardware. However, because of the inherent dangers in opening this up to the public internet, unless explicitly requested by the customer (or Managed Colocation), the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter.…

IPMI does not have to be open to the internet to be open to a wide audience. Many of these out of band management interfaces are hosted on an internal network, but not isolated by customer.

Cheap datacenters are favored by VPN providers for their unlimited bandwidth and lax abuse policies.

Many of them allow access to IPMI only over a VPN, but do not isolate each customer’s IPMI to a customer VLAN. I personally know at least three large budget datacenters which allow all customers access to each others’ “private” IPMI IP addresses.

Re: NordVPN confirms it was hacked

#263
post #243
post #230

Earlier quoted context omitted.

I find NordVPN's marketing reprehensible. Too many claims and broad strokes about the "anonymity" their service can provide. While I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data, I think NordVPN really overplays the role of changing IP addresses in the age of browser fingerprinting.

They’re also not based in a Nordic country, which I find misleading.

For awhile, my brain conflated it with [OpenVPN-NL](https://openvpn.fox-it.com/about.html), a publicly-available, hardened version of OpenVPN used by the Dutch government.

You can't really blame NordVPN for that (I mean, the Netherlands aren't even a Nordic country, my brain is just broken), but it's a data point.

Re: NordVPN confirms it was hacked

#264
post #250

Earlier quoted context omitted.

Pick a cloud provider you trust. I was thinking of moving from Digital Ocean (US) to Hetzner (German) and setting my own VPN up through a normal server.

Why are public cloud providers more trustworthy than VPN providers? Some VPN providers are sketchy but not all of them.

It's not that they're more trustworthy it's that you have more control. They could be feeding traffic to the NSA as well but you can encrypt it yourself -- with VPN services like Nord you're relying on other people to do that for you but often VPN services can offer convenience services like country switching etc but if security is what you're after then cloud providers and setting up your own VPN seems like a more reliable alternative.

To the people looking to setup a simple http proxy in three steps:

1. Set up a server instance who's IP you know and have configured ssh.

2. In Browser: Manual SOCKS Proxy: 127.0.0.1: your_chosen_port

3. In terminal: ssh -i ssh_key -D your_chosen_port user@ip_address

Re: NordVPN confirms it was hacked

#265

This is always topical: Don't use VPN Services https://gist.github.com/joepie91/5a9909939e6ce7d09e29

> Your IP address is a largely irrelevant metric in modern tracking systems. I don't believe this for one second. Your IP address on its own is not sufficient to identify you. That doesn't mean your IP address is not helpful in identifying you. If you have Javascript disabled, it is a heck of a lot easier to identify you with a combination of an IP address, user agent, and OS than it is to identify you without the IP…

If you have Javascript disabled, it is a heck of a lot easier to identify you because you're one of the very few who disabled Javascript.

Re: NordVPN confirms it was hacked

#266

This is so well timed, I just bought a 3-year subscription to NordVPN and they have a 30 day refund policy.

You should probably ask for a refund, then set up your own VPN. Commerical VPNs are, for the vast majority of cases, simply not a good bet for your privacy. You're changing your network traffic path from a diffuse and byzantine series of paths to once centralized collection point. The payoff for an attack on a VPN rises very quickly. Meanwhile, you're also conditioning yourself to say, "My traffic is secure while my…

Good way to deploy your own personal vpn on DigitalOcean, google cloud, or any cloud server of your choice really. Took me 5 minutes. https://news.ycombinator.com/item?id=21313902

Re: NordVPN confirms it was hacked

#267

Earlier quoted context omitted.

One very explicit reason to not trust your ISP with your internet traffic is that since 2017 [1], they are allowed by Congress to sell your internet history. As a cherry on top, they were also the ones that successfully lobbied the government to allow that in the first place [2]. [1] https://www.privateinternetaccess.com/blog/2017/03/house-rep... [2] https://www.privateinternetaccess.com/blog/2017/02/internet-...

To be fair, they can't actually see more than hostnames & IP addresses (assuming the use of TLS, which is becoming ubiquitous), so implying that they sell your "Internet history" makes it sound worse than it is. I've always assumed VPN providers sell whatever data they can too.

... and request sizes, relative times, and time of day. It would be foolish to not assume that the complete history of your sessions can be inferred from how this data clusters, everything but the actual text of your messages.

Of course the people that find this problem worthwhile to solve then go on to work for or found surveillance companies, rather than publishing proof of concepts to security lists.

We also already know the type of molds the surveillance companies are trying to fit us in, from their own marketing materials (eg https://www.experianintact.com/content/uk/documents/productS...). Do you really think there isn't enough metadata being leaked to bucket people into these categories?

And yeah, IP proxying is a hack. But it's seemingly the best we can do to mitigate the utterly broken HTTPS/JS protocol stack.

There are other straightforward advantages too, like having location targeting miss the mark which breaks up the coherency of their manipulation. I've got zero intrinsic interest in local/news events for elsewhere.

Re: NordVPN confirms it was hacked

#268

This is troublesome. I was planning to eke out $85/ annum and go for NordVPN, but now even this is unreliable

Buy a $5/month VPS and run your own VPN on that (popular setup script: https://github.com/StreisandEffect/streisand ). It'll cost you a little bit of time in setup and maintenance (mostly just upgrading packages), but it has many benefits: - Cheaper than most VPN providers - You won't be using a known VPN IP - VPN providers are more likely to snoop on your traffic or be targeted by snoopers (such as the government),…

Good way to deploy your own personal vpn on DigitalOcean, google cloud, or any cloud server of your choice really. Took me 5 minutes. https://news.ycombinator.com/item?id=21313902

Re: NordVPN confirms it was hacked

#269
post #250

Earlier quoted context omitted.

> Because a VPN in this sense is just a glorified proxy. The VPN provider can see all your traffic, and do with it what they want - including logging. So can my ISP and they have been confirmed to sell customer data and work directly with NSA. https://en.wikipedia.org/wiki/Room_641A https://www.theguardian.com/business/2016/oct/25/att-secretl...

Pick a cloud provider you trust. I was thinking of moving from Digital Ocean (US) to Hetzner (German) and setting my own VPN up through a normal server.

I've pondered this before, but I don't see much advantage in having my traffic which currently comes from many IP addresses as I roam about the world, many of them shared and constantly changing, all come from one IP address that is absolutely only me.

Plus browsing the web from a hosting provider is a worse web; you'll get more sites rejecting you or putting you through bad CAPTCHAs all the time because the same service you can rent a server from, so can all the spammers and scrapers and other bad actors, so you're pretty likely to end up in an IP space with bad reputation.

If anyone can argue me out of this position, go nuts. I want this to work and do something useful, I just can't convince myself it does even with that bias.

Re: NordVPN confirms it was hacked

#270
post #136

> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…

It doesn't make much sense to me, even with iDRAC/some other console access you don't really have access to OS unless you reboot & go to single user mode etc at which point they should be noticing their servers rebooting etc. would love more info

It opens an exploit chain, in a normal circumstance you are correct. In a malicious circumstance, it is always feasible irrespective of the likelihood.
Post reply on HN