Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

391–400 of 666 posts

Re: NordVPN confirms it was hacked

#391
post #360

Earlier quoted context omitted.

Rolling your own encryption is an entirely different animal. I agree with that sentiment for encryption. When you use a VPN service, though, you really don’t have any real insight into what’s going on on their servers. Run your own and you can be sure you’re running the most recent, audited version of OpenVPN on an updated operating system.

You're right and I don't disagree with your core thinking, except to say that everyone draws a line beyond which they'll be happy to trade some risk for some time. I understand why someone would run their own VPN, but I also understand why someone wouldn't.

Yeah, I totally agree -- and there are a lot of very valid reasons someone might choose a service over a DIY solution.

My main point up there was just that I'm always kind of surprised and honestly have trouble believing it when I hear someone whose career is in network security say they don't trust themselves to secure a VPN server. If a person can tout creds securing an entire organization, a little ephemeral Linux instance that you can blow away and rebuild at will should be cake.

Re: NordVPN confirms it was hacked

#393
post #348

Earlier quoted context omitted.

I normally don’t mind YouTube ads all that much, and I don’t see them on desktop browsers anyway. However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. Hard to relax with some totally not weird ASMR when my blood pressure is through the roof because some chirpy ad agency dude wants to show me how much a VPN is like an umbrella or whatever.

Use hooktube & adblock

Looks cool, but feeling slightly twitchy about going anywhere near that with my Google account after last week's news https://news.ycombinator.com/item?id=21247759

Re: NordVPN confirms it was hacked

#394

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Maybe they only disclosed it publicly but notified customers out of the public eye ?

Re: NordVPN confirms it was hacked

#395

This is always topical: Don't use VPN Services https://gist.github.com/joepie91/5a9909939e6ce7d09e29

This article tries to enumerate the use cases for use of commercial VPN services, but misses out my only use case of these services: evading geoblocks. It seems fallacious to me.

Re: NordVPN confirms it was hacked

#396

Earlier quoted context omitted.

"To recap, in early 2018, one isolated datacenter in Finland was accessed without authorization. That was done by exploiting a vulnerability of one of our server providers that hadn’t been disclosed to us. No user credentials have been intercepted. No other server on our network has been affected. The affected server does not exist anymore and the contract with the server provider has been terminated." Not sure what…

Ok, I’m going to pretend that I’m a NordVPN customer who is 50, works as a plumber, and has installed a VPN on their phone because they were convinced that it’s very good for privacy. Here goes… “What is a datacenter? How was it accessed? Like in that Mission Impossible movie? What are server providers? What role do they play in all this? Credentials? That’s like my passwords? What about my browsing activity? All I w…

Have you used Nord VPN? These aren't questions users would have. I could be wrong, but I'm confident that a plumber that has used Nord would know what a datacenter is, just from using the app. My tech illiterate Dad (70s) sure does.

Re: NordVPN confirms it was hacked

#397

Earlier quoted context omitted.

Sorry for posting under top comment, but I think it is very important. Official response hides fact OpenVPN CA keys also leaked, so attacker could impersonate any other NordVPN server: https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa... RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan.

> RADIUS secret key also leaked, so propably it is possible to break into EAP session which infers session secret key for StrongSwan. Could you elaborate on this? I am familiar with PKI so the first part makes sense, but I am not familiar with the intricacies of VPNs so I am not sure what this means.

When StrongSwan EAP-RADIUS plugin is in use, authentication delegated to RADIUS server. Actual EAP handshake occurs between VPN client and RADIUS server. [1]

Some EAP authentication methods (namely, EAP-MSCHAPv2 and EAP-TLS) export Master Session Key, which is exported to StrongSwan via MS-MPPE-Send-Key/MS-MPPE-Recv-Key EAP attributes. [2] So, MSK derived on RADIUS side and sent to StrongSwan. Eavesdropper with knowledge of RADIUS secret key capable to intercept and decrypt such EAP payload.

[1] - https://wiki.strongswan.org/projects/strongswan/wiki/EAPRadi...

[2] - https://tools.ietf.org/html/rfc5216#section-2.3

Re: NordVPN confirms it was hacked

#398
post #343

People have been talking about using VPN's because of "dangerous" public wifi, but I have to admit, I don't understand the risks. Let's say you go to a coffee house and sign-in to their wifi with their password and use it browse https websites, like gmail or you favorite social media... what's the main risk? What can happen? What does happen?

The primary concern is MITM attacks I'd presume.

OP specified HTTPS, so MITM is a non-issue.

DNS leakage maybe?

Re: NordVPN confirms it was hacked

#399

Earlier quoted context omitted.

You start to wonder where their money is coming from - their retail prices are already cheap, the discounts the influencers offer make it basically free. How's that sustainable?

But do they even have to pay much to youtubers for those ads? If you get 50k to 100k views per video then you'll likely make around the range of $50-$150 for the video. Paying the youtuber $50-$100 per video would already have a significant impact on their income, so they'd probably consider it. That would be 50k-100k people who will see the ad, because adblock can't block it.

If somebody is getting $50-$150 per video, they're probably doing it for the passion of making videos, not for the income, and they probably have another source of income that dwarfs what they're getting from youtube.

Re: NordVPN confirms it was hacked

#400

From the amazing service providing “Double VPN” (yes, really) for extra privacy and “Onion VPN” (with the Tor bit being behind NordVPN, not the other way around) for ultra extra privacy!

> with the Tor bit being behind NordVPN, not the other way around

This is so dumb that I'm not sure if it's an inside joke or not.

(Looking at you, ProtonVPN.)

Post reply on HN