Live data from Hacker News

NordVPN confirms it was hacked

techcrunch.com

481–490 of 666 posts

Re: NordVPN confirms it was hacked

#481
post #387

Earlier quoted context omitted.

Yeah, Grammarly is creepy as hell. I've explicitly banned it (and similar services) at work. As for Youtube music, yup, that's undeniably a good deal. The music services should watch out, especially in younger demographics (I'm already 30+, Spotify premium user since 2009). Apple will probably push Music even harder and bundle that with their new video streaming. Spotify's really trying to become the defacto podcast…

> ...it's not super clear to me when tracks are clean encodes sourced from the proper music distribution ecosystem... Isn't that kind of the point? If you can't tell which is which without a visual cue (aka bias-generator) then they sound the same.

Yes! Which is why you won't hear me waste a whole lot of breath yammering about lossy compression.

I'd sure pay Spotify extra for lossless, because I'm weird in ways I'll reveal below, but I agree that people should give lossy compression a break. Well-encoded AAC and Vorbis averaging over 256 kbps are very transparent-sounding, in ways that never was possible with mp3. If I put in time, I get 5/6 right in this famous test from NPR's website[1], just because mp3 is awful and ancient.

But I double dare anyone to blind test Opus as low as ~128 and ~160 kbps and working upwards, with decent gear. Having grown up with shitty mp3s, it feels like magically good. And it's free software.

Even lossy-lossy transcoded AAC and Opus, which Youtube uses for a lot of stuff, sounds shockingly fine, most of the time, on most equipment, if the original copy was ok to begin with. All this is mostly passable, especially as background music.

That is, until you run into special circumstances, like listening attentively with halfway-decent equipment. Spotify's default normalization mode sometimes can adds dynamic compression, which sounds bad in itself. But this can make artifacts stand out in ways shouldn't (thank god for the 'quiet' setting, added sometime in 2018). This is especially true with poor source material, for example the stupidly bright 90s Led Zeppelin remasters, which still float around on tons of curated Spotify playlists, despite being superseded by really good releases.

So what I'm trying to say is that I want to maintain a music library I can pull up on any device and expect consistently good quality during playback. Take my little hobby I discussed here as an example (that is, me and my friends independently inventing the Japanese audiophile parlor/café concept) https://news.ycombinator.com/item?id=20583900

Just because I can't hear a guitar riff getting slightly distorted or hi-hats smeared when I listen at work, doesn't mean I won't hear it with in an acoustically outstanding room with 5k worth of audio gear. This problem is very pronounced with Youtube material when there's a poor supply chain, so I won't add a bunch of random garbage from Youtube in a playlist on the tram and expect to actually enjoy it later as I'm leaning back in a proper listening room.

Spotify, on the other hand is relatively close to providing a universally sane way to access music on any device.

1 - https://www.npr.org/sections/therecord/2015/06/02/411473508/...

Re: NordVPN confirms it was hacked

#483
post #474
post #387

Earlier quoted context omitted.

Yeah, Grammarly is creepy as hell. I've explicitly banned it (and similar services) at work. As for Youtube music, yup, that's undeniably a good deal. The music services should watch out, especially in younger demographics (I'm already 30+, Spotify premium user since 2009). Apple will probably push Music even harder and bundle that with their new video streaming. Spotify's really trying to become the defacto podcast…

> Spotify's audio didn't use to be all that great, except with the normalization turned off. Now with their 'quiet' normalization option, that doesn't compress quiet tracks (a clear edge over Apple Music), it's starting to sound transparent to me, as -q 9 encoded (~320 kbps) Vorbis should. What annoys me is they're mixing together two features (namely normalization and dynamic range compression) and putting them behi…

Sigh, yeah, that's actually a great point. Wonder how many great pairs of ears have been ruined by opening a random youtube tab while Spotify is playing with the quiet normalization mode enabled.

And just like the PS4 example, it's just insane to me that Spotify Connect doesn't mandate normalization.

Re: NordVPN confirms it was hacked

#484

>NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.” So instead of allowing their customers to do their own damage limitation, they left their customers in the dark and continued to expose them to a breach they weren't sure they had fully c…

Maybe they only disclosed it publicly but notified customers out of the public eye ?

I was a NordVPN customer 4 months ago and got no notification. I’m hearing about this now via this post on HN. Dropped them around July.

Re: NordVPN confirms it was hacked

#485
post #348

Earlier quoted context omitted.

> I find NordVPN's marketing reprehensible. A claim that really, really bothered me was something along the lines of "use us and no one will be able to read your email!" Every mainstream email provider (Google, Yahoo, Microsoft, Apple) now require HTTPS for emails. No one was ever going to be able to read your emails.

I normally don’t mind YouTube ads all that much, and I don’t see them on desktop browsers anyway. However, I was bombarded with ads for NordVPN and their crap made me so angry it pretty much sold me a paid YouTube membership. Hard to relax with some totally not weird ASMR when my blood pressure is through the roof because some chirpy ad agency dude wants to show me how much a VPN is like an umbrella or whatever.

[deleted]

Re: NordVPN confirms it was hacked

#486
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

ExpressVPN - gets the job done, a bit expensive but rock solid reliable, breaches great firewall of china.

Re: NordVPN confirms it was hacked

#487

Earlier quoted context omitted.

I'm torn for this reason: I want to avoid ads, but I don't want to give Google any more money. It's unfortunate that YouTube is really the only one of it's kind. For the moment, I get around this conundrum using a combination of uBlock Origin[0] (Firefox) and NewPipe[1] on Android. Not 100% sure what I'll do about the latter when I switch to iOS. [0] https://github.com/gorhill/uBlock [1] https://newpipe.schabi.org/

> I don't want to give Google any more money. I guess I'm on the opposite side of the spectrum. I want to opt-out of being the product and instead be a customer by paying for "Google Premium" or whatever. It would be an "all things Google" subscription, not just YouTube. Any place there would normally be a Google-curated ad... there wouldn't be one. No more ads at the top of my Google searches. No ads embedded in web…

I'm game. What should the monthly price be though?

Considering that it needs to make actual money (and the streaming royalties for music are kinda expensive).

Re: NordVPN confirms it was hacked

#488
post #5

Someone is probably going to ask what other HN users recommend as an alternative. Personally, I use Private Internet Access because they're the only provider I've found with a track record of demonstrably not being able to turn your records over to someone asking for them [1]. [1] https://torrentfreak.com/private-internet-access-no-logging-...

I've had fantastic experience with airvpn. They're cheap, fast, reliable, and support all the configuration types you could want. I'm not affiliated with them but I'm surprised nobody here has mentioned them yet. By far the best VPN provider IMO.

Another vote for AirVPN. Good track record, happy customer for 6+ years.

Re: NordVPN confirms it was hacked

#489

Earlier quoted context omitted.

I am guessing #1 is mot wanting your internet provider (eg. AT&T) knowing what you are doing, then Netflix, Torrents, getting better deals on tickets and such, maybe activities of questionable legality? Personally, I don't like the idea of my mobile provider profiting off knowing which applications I am using and what sites I visit.

I don't understand being unhappy with your ISP knowing these things, but being fine with your VPN provider knowing them.

I feel like the only good reasons to use a VPN are if you're torrenting or if you want access to sites from different countries (foreign Netflix libraries, streams from state-run media channels, etc). Most VPNs worth a damn aren't going to sell you out just for torrenting movies/music/games while your ISP will.

Re: NordVPN confirms it was hacked

#490

I can't help but notice that NordVPN is one of the most heavily advertised VPNs from what I've seen (which raises the question, as one researcher pointed out in the article - are they not spending enough money on their security and infrastructure to protect their users?). They are claiming that: "no-one could know about an undisclosed remote management system left by the [data center] provider". Apparently the hacker…

The fact that NordVPN advertise so heavily, and get so many youtubers to sell it, is exactly why I will never use the service. It is way too on the nose. They heavily sponsor PayMoneyWubby who also does a great job at de-anonymising a group of youtubers.

The last VPN you ever want to use is the one that is heavily on the market.

Post reply on HN