Earlier quoted context omitted.
It's not like you're running a website on there - all you have to keep secure is SSH and your VPN. Keeping up to date with security updates and using a strong password (or better yet, private key) is essentially all you need to do. I wouldn't necessarily recommend it to random non-technical people, but I figure most HN users could figure it out.
I've seen "infosec professionals" say they don't trust themselves to secure their own VPN server. It blows my mind...if you can't do that, why are you even in this business? How do you even use a personal computer?
NordVPN confirms it was hacked
351–360 of 666 posts
Re: NordVPN confirms it was hacked
#352@dang or mods - I'm surprised that this isn't merged with https://news.ycombinator.com/item?id=21311475 ; is there some special value in keeping them separate?
If you want to let us know about something, it's best to email hn@ycombinator.com. We don't see all the comments—I only saw this one by accident—but we do see all the emails. (Well, except possibly a few that go into spam. We comb through the spam folder and rescue most, but a few with unfortunate subject lines probably get missed.)
Re: NordVPN confirms it was hacked
#353I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…
"no one could know" is ridiculous. A proper security team vets all of its vendors and ultimately writes security issues like this into contracts.
Re: NordVPN confirms it was hacked
#354Re: NordVPN confirms it was hacked
#355Earlier quoted context omitted.
> I find NordVPN's marketing reprehensible. A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.
I normally don’t mind YouTube ads all that much, and I don’t see them on desktop browsers anyway. However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. Hard to relax with some totally not weird ASMR when my blood pressure is through the roof because some chirpy ad agency dude wants to show me how much a VPN is like an umbrella or whatever.
Re: NordVPN confirms it was hacked
#356Re: NordVPN confirms it was hacked
#357Earlier quoted context omitted.
> I find NordVPN's marketing reprehensible. A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.
> No one was ever going to be able to read your emails. Except for Google, Yahoo, Microsoft, and Apple of course, and whoever they have to answer to depending on where you live.
Re: NordVPN confirms it was hacked
#358@dang or mods - I'm surprised that this isn't merged with https://news.ycombinator.com/item?id=21311475 ; is there some special value in keeping them separate?
No, we just hadn't seen it yet. They're merged now. If you want to let us know about something, it's best to email hn@ycombinator.com. We don't see all the comments—I only saw this one by accident—but we do see all the emails. (Well, except possibly a few that go into spam. We comb through the spam folder and rescue most, but a few with unfortunate subject lines probably get missed.)
Re: NordVPN confirms it was hacked
#359Earlier quoted context omitted.
> On one hand, there's anonymous websites, competing VPN companies, and hundreds of Twitter bots pushing a story that is demonstratively false (just check public records). I agree, the VPN industry is rife with shady business practices. But the story being pushed isn't 'demonstratively false'. * TesoNet offers data mining services * You did contract TesoNet employees * Due to an error and unyielding policies by Googl…
Definitely appreciate your concern here, but there's still a lot which is being confused. Proton does not today, and has never, used contracted (outsourced) employees. As is common with startups, in the past we did not always do all our HR in house (it's all in house today), but employees were always working on Proton and for Proton. There are no board members, directors, shareholders, or employees, related to Tesone…
I realized another way that would work for you guys (but is out of your hands) is fighting a court case about this. You'd be legally compelled to tell the truth and very screwed if you deny but then it comes out there is logging or mining going on. It's not ironclad but it is how most VPNs end up being considered 'solid'.
Re: NordVPN confirms it was hacked
#360Earlier quoted context omitted.
I've seen "infosec professionals" say they don't trust themselves to secure their own VPN server. It blows my mind...if you can't do that, why are you even in this business? How do you even use a personal computer?
I've heard the same thing from cryptography authorities in regard to rolling your own encryption and it makes sense to me. Having specialized knowledge opens your eyes to all the gotchas and gottahaves that most people wouldn't think about. While you certainly can take the time to set everything up exactly the way it should be and keep it updated, I'd rather spend my time doing/thinking about other stuff and am happy…
When you use a VPN service, though, you really don’t have any real insight into what’s going on on their servers. Run your own and you can be sure you’re running the most recent, audited version of OpenVPN on an updated operating system.