Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

321–330 of 666 posts

Re: NordVPN confirms it was hacked

#322
post #269

Earlier quoted context omitted.

I've pondered this before, but I don't see much advantage in having my traffic which currently comes from many IP addresses as I roam about the world, many of them shared and constantly changing, all come from one IP address that is absolutely only me. Plus browsing the web from a hosting provider is a worse web; you'll get more sites rejecting you or putting you through bad CAPTCHAs all the time because the same ser…

This worse web is literally Google bullying you unless you tell them everything about who you are.

No, that's a different web. I live in the "google bullying" web between my combination of using Firefox + uMatrix on desktop, Brave on Android, and DuckDuckGo as my search engine. Google gets very little of my desktop info and fragmentary mobile use only. I do a few extra CAPTCHAs but it's not too bad.

The "I think you're a bad actor" web is much worse. Ask Tor users.

Re: NordVPN confirms it was hacked

#323

Earlier quoted context omitted.

> Your IP address is a largely irrelevant metric in modern tracking systems. I don't believe this for one second. Your IP address on its own is not sufficient to identify you. That doesn't mean your IP address is not helpful in identifying you. If you have Javascript disabled, it is a heck of a lot easier to identify you with a combination of an IP address, user agent, and OS than it is to identify you without the IP…

If you have Javascript disabled, it is a heck of a lot easier to identify you because you're one of the very few who disabled Javascript.

Yes and no.

Disabling javascript is like wearing a ski mask in a crowded mall.

It makes you much more obvious and easier to track, but harder to identify on the outset.

Re: NordVPN confirms it was hacked

#324

This is always topical: Don't use VPN Services https://gist.github.com/joepie91/5a9909939e6ce7d09e29

"Dont use VPN services" then at the bottom: So then, what? THIS TYPE OF VPN

Analogy: "Don't eat at restaurants if you want to control your food."

"If you for some reason cannot do that, here is a way to set up a food truck"

Re: NordVPN confirms it was hacked

#325

Earlier quoted context omitted.

From the article: "“One of the data centers in Finland we are renting our servers from was accessed with no authorization,” said NordVPN spokesperson Laura Tyrell." I believe that would be the section they're referencing.

How does this quote demonstrate that the service provider was not at fault?

“We failed by contracting an unreliable server provider...”

They are casting blame on the provider. Providing remote access tools is not a fault. Failure by NordVPN to disable said access is the issue, yet they passed the blame on.

Re: NordVPN confirms it was hacked

#326
What about the data-mining and selling infrastructure of NordVPN, known as Tesonet? Are those intact? Also interesting to know how their legal departments are doing, such as the Panamanian shell and the Lithuanian headquarters.

http://vpnscam.com/wp-content/uploads/2018/08/2018-08-24-09_...

http://vpnscam.com/hola-vpn-and-nordvpn-partners-in-data-min...

http://vpnscam.com/nordvpn-protonvpn-proton-mail-owned-by-te...

Re: NordVPN confirms it was hacked

#327

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa... RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

[deleted]

Re: NordVPN confirms it was hacked

#328
post #230

Earlier quoted context omitted.

I find NordVPN's marketing reprehensible. Too many claims and broad strokes about the "anonymity" their service can provide. While I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data, I think NordVPN really overplays the role of changing IP addresses in the age of browser fingerprinting.

> I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data I wouldn't. Much of the web is moving over to https, VPNs are hit-or-miss on whether they route DNS requests, and having to deal with blocked websites because of abuse isn't worth it. That, and you're trusting the VPN to not sell your data. > browser fingerprinting I mean...your IP address changes on cell networks…

>either do whatever Torbrowser does or use the most popular iPhone.

Using a iPhone does not preclude you from being blindsided, as illustrated by a NordVPN bug, which was exposed a couple of weeks ago.

Here's how it works:

The user first connects to 1.1.1.1 with Warp, then disables the app without turning off Warp. Then, when connecting to a NordVPN server with ikev2 protocol, the iOS device will report as being connected to NordVPN and secured, without actually being connected. In other words, you're connected and protected, but you're not.

https://www.theregister.co.uk/2019/10/05/security_roundup_oc...

Re: NordVPN confirms it was hacked

#329
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

I have a slightly dissenting answer to these questions, in the form of an interactive Q&A website: https://faq.dhol.es/@Soatok/cryptography/which-vpn-service-w...

How is this not the top comment?

Nobody should be using a VPN provider, full-stop. It is structurally impossible for anyone to verify their claims, they have more incentive to lie than your ISP does, and they're cheap and easy to set up, so the industry is a cesspool.

You should assume that all of them are behaving badly.

Re: NordVPN confirms it was hacked

#330

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

The tinfoil hat would argue maybe this was a leak that happened, but it was shared by design. It’s an HK company with questionable relationships and owners.

> It’s an HK company with questionable relationships and owners.

That seems to be ExpressVPN[1], the main competitor of NordVPN.

[1] https://vpnscam.com/expressvpn-really-based-in-hong-kong/

Post reply on HN