If you care less about the pseudo-anonymous-but-not-really shared-IP aspect of using a VPN, and care more about the this-lan-is-sketchy use case, I have had good experiences with Algo [0]. You can just paste in an API key and spin up your own VPN on something like DigitalOcean. And it uses WireGuard! [0] https://github.com/trailofbits/algo
NordVPN confirms it was hacked
591–600 of 666 posts
Re: NordVPN confirms it was hacked
#592Earlier quoted context omitted.
The claims about ProtonVPN have been disproven.
I would like to hear more about this. Could you share some information?
Besides, the argumentation from that vpnscam website and its followers reminds you of the typical conspiracy retards that follow Trump.
Re: NordVPN confirms it was hacked
#593So what does this mean for an every day consumer? I had been debating using the 30-day money back guarantee as I realised I didn't use it as much as I thought I would. I want to stay protected on public Wifi. Added anonymity occasionally would be good too, as well as accessing US Netflix from here in the UK. Now my 30 days is up. What would be the best course of action? Should I email and say that I'm not comfortable…
My gut tells me that the level of advertising and incredibly low prices is too good to be true...
Now with this hack it's the same problem, how bad is it, does it affect me and should i be concerned?
Re: NordVPN confirms it was hacked
#594Earlier quoted context omitted.
Yes, network KVMs are expected of any co-location center. You want to be able to access the console and the power switches of any real physical server without having to send someone out to the center, and is a common feature of most high end data centers. Even a lot of VM/cloud systems have some kind of virtual management console (Linode has their LISH system that lets you SSH in to console and Vultr/Digital Ocean ha…
.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.
Re: NordVPN confirms it was hacked
#595> The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the datacenter provider, which NordVPN said it was unaware that such a system existed. This screams for clarification and I'd love for someone more knowledgeable in the area to elaborate on it. Is this common practice for data-center providers? Do I now not only have to wor…
Sounds like an iDRAC exploit (assuming Dell servers). But, yes, remote management is pretty common in datacenters. The fact that NordVPN wasn't aware of them just shows incompetence.
Re: NordVPN confirms it was hacked
#596Earlier quoted context omitted.
User root, password calvin. That's the default. And, if I had a dime for every time I've seen one of these in a data center, I'd be a rich man. I have literally begged sys admins to change the default password, but they say, "Why... we're behind a firewall using RFC 1918 addresses. No one can get to these." The rest, as they say, is history.
> we're behind a firewall This is the dumbest thing I've ever seen... unless your firewall is between your host versus every other host and there's no multi-tenancy, this will suck.
Re: NordVPN confirms it was hacked
#597Earlier quoted context omitted.
I would like to hear more about this. Could you share some information?
Just search for proton in this thread. They've explained what happened themselves. Besides, the argumentation from that vpnscam website and its followers reminds you of the typical conspiracy retards that follow Trump.
Re: NordVPN confirms it was hacked
#598Earlier quoted context omitted.
It's the same shit. https://news.ycombinator.com/item?id=17258203
The claims there have been thoroughly debunked, most recently by Mozilla and the European Commission as part of their due diligence, details here: https://bit.ly/35RDKzB
Re: NordVPN confirms it was hacked
#599Earlier quoted context omitted.
Over the course of the disclosure of the connection between NordVPN, Tesonet, and possibly ProtonVPN, Proton's story kept changing. They said contradicting things multiple times. They locked the Reddit thread. Why did Proton keep changing their story if they had nothing to hide? I will keep reminding this every time the issue gets raised. There is a compilation [0] of changing Proton's responses and them successively…
Both Mozilla and the European Commission have looked into the accusations being made on anonymous websites, and determined that they are false. The EU in particular, has access to records which allow independent verification. There is also an abundance of public record which demonstrates this is false. The bad faith of those spreading this information is also apparent from the hundreds of fake Twitter accounts used t…
Re: NordVPN confirms it was hacked
#600Earlier quoted context omitted.
.. AWS surprisingly doesn't. Why is this surprising? AWS seem to know what they're doing in general, and this is obviously the right policy in this particular area.
Amazon has security critical functionality on an unauthenticated http endpoint on a link local address. That's pretty damn dumb in my book.