Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

401–410 of 666 posts

Re: NordVPN confirms it was hacked

#401
post #141
post #125

Earlier quoted context omitted.

Truth is - if hackers did a MIM attack and collected a bunch user traffic (for how long?) they could have everything.. banking info, emails, logins... at this point if i was a user of that VPN service - i'd be replacing all of my sensitive passwords, secret questions/answers to key accounts.

MitM-ing a VPN does not break HTTPS. Hence, any passwords send over HTTPS are still safe. You could speculate that a VPN MitM is a nice way to get an MitM position for a further attack on TLS. But that requires a lot more speculation. What isn't safe is your browsing history. True, any HTTP data isn't safe, but trusting that to be safe is baaaaad anyway. In short. This leaked browser behavior, and could be a single s…

NordVPN's advertising has deliberately downplayed the significance of HTTPS, as part of their fear mongering campaign about public wifi and residential ISP connections, so it's not really surprising to see such misconceptions raise their heads when NordVPN screws the pooch like this.

Re: NordVPN confirms it was hacked

#402
post #393

Earlier quoted context omitted.

Use hooktube & adblock

Looks cool, but feeling slightly twitchy about going anywhere near that with my Google account after last week's news https://news.ycombinator.com/item?id=21247759

That guy was a troll. Many of us have been using youtube-dl extensively every day for years without any trouble.

Re: NordVPN confirms it was hacked

#403

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

If someone hacks a VPN, what are the implications for the users? As long as you're using HTTPS, you don't have to worry about your passwords or session tokens being stolen, right? Is it just your DNS records and unencrypted HTTP traffic?

It depends on what you mean by 'hacking' a VPN. One assertion in this breach is that the NordVPN certificate private key was leaked, allowing anybody to spin up a NordVPN server that would pass HTTPS certificate validation (the cert is expired, it's currently unknown if the cert was valid for a period of time after it was compromised). This kind of an attack would let an attacker convince most users to download viruses, input credentials, etc.

Nord says that the above issue was caused by a data center breach. Depending on the company this may mean a leak of user info (account details, emails, etc) and password data (generally secure hashes, but often insecure/near-plaintext passwords).

There's a lot that can go wrong here even before considering the MITM vector. As far as that goes, you can generally trust that well-secured sites (Google, Facebook, etc) won't allow someone to steal your session tokens/passwords. There is a high likelihood that a malicious VPN would achieve script execution on your machine in a short period of time.

Re: NordVPN confirms it was hacked

#404
post #322

Earlier quoted context omitted.

This worse web is literally Google bullying you unless you tell them everything about who you are.

No, that's a different web. I live in the "google bullying" web between my combination of using Firefox + uMatrix on desktop, Brave on Android, and DuckDuckGo as my search engine. Google gets very little of my desktop info and fragmentary mobile use only. I do a few extra CAPTCHAs but it's not too bad. The "I think you're a bad actor" web is much worse. Ask Tor users.

Sorry, I confused the two. I'm out here using Tor for my privacy (good kid; didn't do nuffin').

Re: NordVPN confirms it was hacked

#405

Earlier quoted context omitted.

If your privacy concerns include your DNS requests then a commerical VPN isn't a realistic choice. And unlike some rando pseudo-bespoke brand-less coffee shop wifi, commerical VPNs are a big target. > I always assume that hostile public networks like free WiFi have agents actively trying to man in the middle any connections they can. And VPNs just move that problem. If you're not demanding and forcing SSL, you're not…

Try running a traffic or packet monitor on a WiFi network. Now tell me how much of that traffic is going over SSL And even if I don’t run my own VPN, I’d prefer to “move the problem”. It’s so much easier to attack machines on public WiFi than compromise a VPN provider... and much more anonymous, and less likely to incite law enforcement activity. Public airports, libraries, etc are hotbeds of nefarious activity.

I use plugins to force SSL to all connections. I block outbound non-SSL http traffic.

So, 0%? But personally I don't go to many sites that dont have full SSL coverage. Do you?

I highly recommend you do this.

> It’s so much easier to attack machines on public WiFi than compromise a VPN provider... and much more anonymous, and less likely to incite law enforcement activity.

Do you think there will be a successful law enforcement follow up to this breach? I doubt it.

> Public airports, libraries, etc are hotbeds of nefarious activity.

As are VPN data centers, as evidenced here.

If you really want to just shift your egress point, lots of self-hosted VPN options exist. These are much better able to do the things you want to do, without being as vulnerable to corporate VPN attacks.

Re: NordVPN confirms it was hacked

#406
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

I've been using Private Internet Access (PIA) since 2016 and can also recommend it from a usability point of view. I'm not a security expert so I defer to others on PIA's security.

In 2015ish PIA got hacked via https://old-support.privateinternetaccess.com because of https://classichelp.kayako.com/hc/en-us/articles/36000646089... and never told anyone.

This bug loudly announces itself on every pageload, it speaks of tremendous incompetence that they ever let this go into production.

The site used to set a cookie that looked like this:

  Set-Cookie: SWIFT_client=a%3A1%3A%7Bs%3A15%3A%22templategroupid%22%3Bs%3A1%3A%221%22%3B%7D; expires=Wed, 28-Dec-2016 23:24:13 GMT; path=/; httponly
Obvious PHP object injection vulnerability that should've been caught by any automated auditing tool.

Re: NordVPN confirms it was hacked

#407

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

Honestly, I don't think it's exclusive to NordVPN, I've found that all VPN advertising has increased significantly in the last year or two. Noticeably, ExpressVPN is also everywhere. Almost every podcast or youtube video has some VPN ads in it. It seems like with the recent focus on privacy, they are really these two companies and others are really trying to make a run for it.

Re: NordVPN confirms it was hacked

#409

From the amazing service providing “Double VPN” (yes, really) for extra privacy and “Onion VPN” (with the Tor bit being behind NordVPN, not the other way around) for ultra extra privacy!

> with the Tor bit being behind NordVPN, not the other way around This is so dumb that I'm not sure if it's an inside joke or not. (Looking at you, ProtonVPN.)

We are pretty clear though that Tor over VPN is for convenience and not necessarily more security or privacy, depending on your threat model.

Re: NordVPN confirms it was hacked

#410

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

Honestly, I don't think it's exclusive to NordVPN, I've found that all VPN advertising has increased significantly in the last year or two. Noticeably, ExpressVPN is also everywhere. Almost every podcast or youtube video has some VPN ads in it. It seems like with the recent focus on privacy, they are really these two companies and others are really trying to make a run for it.

Is VPN advertising increasing due to content restrictions from online streaming services?

If you travel overseas, you can't access Netflix, AmazonPrime Video, etc. so a VPN service allows you to still use your service while you're away from home.

And then sports streaming. You can sign up for a yearly subscription to watch sports, but not the teams closest to your physical location due to local blackouts.

Utah is in a terrible place too. No NFL, MLB, or NHL team. But the closest teams are all blacked out from streaming services.

Post reply on HN