NordVPN confirms it was hacked


NordVPN, a virtual private network provider that promises to “protect your privacy online,” has confirmed it was hacked.

The admission comes following rumors that the company had been breached. It first emerged that NordVPN had an expired internal private key exposed, potentially allowing anyone to spin out their own servers imitating NordVPN.

VPN providers are increasingly popular as they ostensibly provide privacy from your internet provider and visiting sites about your internet browsing traffic. That’s why journalists and activists often use these services, particularly when they’re working in hostile states. These providers channel all of your internet traffic through one encrypted pipe, making it more difficult for anyone on the internet to see which sites you are visiting or which apps you are using. But often that means displacing your browsing history from your internet provider to your VPN provider. That’s left many providers open to scrutiny, as often it’s not clear if each provider is logging every site a user visits.

For its part, NordVPN has claimed a “zero logs” policy. “We don’t track, collect, or share your private data,” the company says.

But the breach is likely to cause alarm that hackers may have been in a position to access some user data.

NordVPN told TechCrunch that one of its data centers was accessed in March 2018. “One of the data centers in Finland we are renting our servers from was accessed with no authorization,” said NordVPN spokesperson Laura Tyrell.

The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the data center provider; NordVPN said it was unaware that such a system existed.

NordVPN did not name the data center provider.

“The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so usernames and passwords couldn’t have been intercepted either,” said the spokesperson. “On the same note, the only possible way to abuse the website traffic was by performing a personalized and complicated man-in-the-middle attack to intercept a single connection that tried to access NordVPN.”

According to the spokesperson, the expired private key could not have been used to decrypt the VPN traffic on any other server.

NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.”

A senior security researcher we spoke to who reviewed the statement and other evidence of the breach, but asked not to be named as they work for a company that requires authorization to speak to the press, called these findings “troubling.”

“While this is unconfirmed and we await further forensic evidence, this is an indication of a full remote compromise of this provider’s systems,” the security researcher said. “That should be deeply concerning to anyone who uses or promotes these particular services.”

NordVPN said “no other server on our network has been affected.”

But the security researcher warned that NordVPN was ignoring the larger issue of the attacker’s possible access across the network. “Your car was just stolen and taken on a joy ride and you’re quibbling about which buttons were pushed on the radio?” the researcher said.

The company confirmed it had installed intrusion detection systems, a popular technology that companies use to detect early breaches, but “no-one could know about an undisclosed remote management system left by the [data center] provider,” said the spokesperson.

“They spent millions on ads, but apparently nothing on effective defensive security,” the researcher said.

NordVPN was recently recommended by TechRadar and PCMag. CNET described it as its “favorite” VPN provider.

It’s also believed several other VPN providers may have been breached around the same time. Similar records posted online — and seen by TechCrunch — suggest that TorGuard and VikingVPN may have also been compromised.

A spokesperson for TorGuard told TechCrunch that a “single server” was compromised in 2017 but denied that any VPN traffic was accessed. TorGuard also put out an extensive statement following a May blog post, which first revealed the breach.

- End of Article -​

Summary:

- A data center was breached in March 2018.

- They kept quiet about it until completing an infrastructure audit.

- NordVPN is being criticized for investing in advertising over security.
 
You use a VPN like normal, make sure DNS requests/traffic is not leaking, and then use the Tor browser like normal.

It gives you the protection of Tor (mostly, the VPN can't see what sites you go to, but there are more advanced attacks), and your ISP can't tell that you use Tor.
At that point you only need the VPN.
 
Any VPN is better than no VPN but I'll never trust large, commercialised VPNs. Their business interests are just too large and ambitious to be inconvenienced by having to stop to defend themselves in court every time the alphabet soup knocks on their door. Investors are skittish about companies that have to deal with government interference (legal weed, for example) and will demand that NordVPN roll over to avoid rocking the boat.
 
In hindsight, I'm glad I use Opera instead of NordVPN. Something always did seem kind of sus about NordVPN, considering how highly advertised it is on alot of youtube channels that I follow.

This post was brought to you by Opera Web Browser, Faster, Safer, Smarter......and completely Free!

You might want to be careful with Opera.

Wikipedia dijo:
Opera is a freeware web browser ... developed by Opera Software, a Norwegian software company, publicly listed on the NASDAQ stock exchange, with the majority of ownership and control belonging to Chinese businessman Zhou Yahui, founder of Beijing Kunlun Tech which specialises in mobile games and Chinese cybersecurity company Qihoo 360.
 
Wasn't there some story not too long ago where someone found out the NordVPN client was sending weird data to some unregistered IP, bought it to see what was being sent, and figured out it could be used to identify the actual region a user was in?

I legit don't know why people don't use PIA, sure, bulk payments tend to be higher, but it's been tested in a court of law not to keep logs and you don't hear about this shit with an air of "oh, yeah, it happened, what can you do about it?"
 
Sam Riegal can't keep getting away with this!

images
 
The "anonymous senior security researcher" sounds like a competitor. Their commentary is such over-the-top smugness they can only be a competitor cheering as they get their kicks in.
 
Summary:

- A data center was breached in March 2018.

- They kept quiet about it until completing an infrastructure audit.

- NordVPN is being criticized for investing in advertising over security.

That goes to show: it's advertised on YouTube, it's probably shit.
 
Advertising is like saying you got a big dick. The more you feel like you have to do it the more likely you're trying to hide some shortcoming.
It also just makes you a target for hacking. Like the dude from LifeLock who put his social security number in their ads and was like, "Just you try to steal my identity! LifeLock will protect me!" and then ended up having his identity stolen like a dozen times.
 
It also just makes you a target for hacking. Like the dude from LifeLock who put his social security number in their ads and was like, "Just you try to steal my identity! LifeLock will protect me!" and then ended up having his identity stolen like a dozen times.
Source? I believe you, but that sounds really funny and I’d like to know more.
 
No wonder NordVPN was only $3 a month when I last saw an ad telling me to sign on. Turns out I was right to be suspicious.

Military level security, my ass.
 
Atrás
Top Abajo