Earlier quoted context omitted.
> I certainly would recommend that US consumers use a VPN router to prevent their ISP from selling data I wouldn't. Much of the web is moving over to https, VPNs are hit-or-miss on whether they route DNS requests, and having to deal with blocked websites because of abuse isn't worth it. That, and you're trusting the VPN to not sell your data. > browser fingerprinting I mean...your IP address changes on cell networks…
>either do whatever Torbrowser does or use the most popular iPhone. Using a iPhone does not preclude you from being blindsided, as illustrated by a NordVPN bug, which was exposed a couple of weeks ago. Here's how it works: The user first connects to 1.1.1.1 with Warp, then disables the app without turning off Warp. Then, when connecting to a NordVPN server with ikev2 protocol, the iOS device will report as being conn…
NordVPN confirms it was hacked
561–570 of 666 posts
Re: NordVPN confirms it was hacked
#562If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo
Re: NordVPN confirms it was hacked
#563Re: NordVPN confirms it was hacked
#564If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo
I use Algo for the exact reason you mention ("this lan is sketchy") and have been pleased, but I always assumed even if my traffic was mingling, one (possibly secret) court order would out me since I paid with a CC tied to my real name.
Re: NordVPN confirms it was hacked
#565Earlier quoted context omitted.
Is the alternative actually worse than SSL? Why? And no, it doesn't break analytical by Facebook or Google in any substantial way. I know some people use them to evade Netflix region exceptions, and that's about all they're good for.
You can’t always ensure that all traffic goes over SSL. DNS traffic is an example. I always assume that hostile public networks like free WiFi have agents actively trying to man in the middle any connections they can. If your device has a known exploit and a single connection not going over SSL you drastically increase your exposure on a public WiFi, hence the one use case for VPN.
But wouldn't you get a cert error if someone messed with the DNS to send you to a different IP than you would normally?
(Especially if they're using pinned certs, which many sites do now)
Re: NordVPN confirms it was hacked
#566Earlier quoted context omitted.
I work for a web hosting company in the US and at least in our case, it's quite common for remote management to be enabled on pretty much all of our dedicated hardware. However, because of the inherent dangers in opening this up to the public internet, unless explicitly requested by the customer (or Managed Colocation), the NIC used for Dell iDRAC or HP iLO is on an isolated network unique to the physical datacenter.…
IPMI does not have to be open to the internet to be open to a wide audience. Many of these out of band management interfaces are hosted on an internal network, but not isolated by customer. Cheap datacenters are favored by VPN providers for their unlimited bandwidth and lax abuse policies. Many of them allow access to IPMI only over a VPN, but do not isolate each customer’s IPMI to a customer VLAN. I personally know…
Re: NordVPN confirms it was hacked
#567> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…
Typically data centers have compliance requirements like SSAE 16 specifies controls around physical access. Most any major retail data center would have that certification and others. One presumes that because of NordVPN's business, they're colocating a server or two in many very many "POPs", presumably not all of them have tight controls on physical access. Its likely that there are none available in many areas wher…
Re: NordVPN confirms it was hacked
#568Earlier quoted context omitted.
> we're behind a firewall This is the dumbest thing I've ever seen... unless your firewall is between your host versus every other host and there's no multi-tenancy, this will suck.
In well maintained networks the management interface (IDRAC, etc.) for each server is placed on a separate VLAN which the servers cannot access. This isn't to say that cheap providers actually do this, or that the VLAN can't be accessed by a compromised technician's workstation/laptop.
Never trust the network.
Re: NordVPN confirms it was hacked
#569Re: NordVPN confirms it was hacked
#570Earlier quoted context omitted.
Thanks for sharing these. I was familiar with the Protonmail business but did not know this all connected to a bigger picture. I never trusted NordVPN... they spent way too much money on advertising and snake oil advertising at that, focusing on meaningless numbers and distractions. Hopefully you don't have similar news to share about Mullvad...
The claims about ProtonVPN have been disproven.