NordVPN confirms it was hacked


NordVPN, a virtual private network provider that promises to “protect your privacy online,” has confirmed it was hacked.

The admission comes following rumors that the company had been breached. It first emerged that NordVPN had an expired internal private key exposed, potentially allowing anyone to spin out their own servers imitating NordVPN.

VPN providers are increasingly popular as they ostensibly provide privacy from your internet provider and visiting sites about your internet browsing traffic. That’s why journalists and activists often use these services, particularly when they’re working in hostile states. These providers channel all of your internet traffic through one encrypted pipe, making it more difficult for anyone on the internet to see which sites you are visiting or which apps you are using. But often that means displacing your browsing history from your internet provider to your VPN provider. That’s left many providers open to scrutiny, as often it’s not clear if each provider is logging every site a user visits.

For its part, NordVPN has claimed a “zero logs” policy. “We don’t track, collect, or share your private data,” the company says.

But the breach is likely to cause alarm that hackers may have been in a position to access some user data.

NordVPN told TechCrunch that one of its data centers was accessed in March 2018. “One of the data centers in Finland we are renting our servers from was accessed with no authorization,” said NordVPN spokesperson Laura Tyrell.

The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the data center provider; NordVPN said it was unaware that such a system existed.

NordVPN did not name the data center provider.

“The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so usernames and passwords couldn’t have been intercepted either,” said the spokesperson. “On the same note, the only possible way to abuse the website traffic was by performing a personalized and complicated man-in-the-middle attack to intercept a single connection that tried to access NordVPN.”

According to the spokesperson, the expired private key could not have been used to decrypt the VPN traffic on any other server.

NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.”

A senior security researcher we spoke to who reviewed the statement and other evidence of the breach, but asked not to be named as they work for a company that requires authorization to speak to the press, called these findings “troubling.”

“While this is unconfirmed and we await further forensic evidence, this is an indication of a full remote compromise of this provider’s systems,” the security researcher said. “That should be deeply concerning to anyone who uses or promotes these particular services.”

NordVPN said “no other server on our network has been affected.”

But the security researcher warned that NordVPN was ignoring the larger issue of the attacker’s possible access across the network. “Your car was just stolen and taken on a joy ride and you’re quibbling about which buttons were pushed on the radio?” the researcher said.

The company confirmed it had installed intrusion detection systems, a popular technology that companies use to detect early breaches, but “no-one could know about an undisclosed remote management system left by the [data center] provider,” said the spokesperson.

“They spent millions on ads, but apparently nothing on effective defensive security,” the researcher said.

NordVPN was recently recommended by TechRadar and PCMag. CNET described it as its “favorite” VPN provider.

It’s also believed several other VPN providers may have been breached around the same time. Similar records posted online — and seen by TechCrunch — suggest that TorGuard and VikingVPN may have also been compromised.

A spokesperson for TorGuard told TechCrunch that a “single server” was compromised in 2017 but denied that any VPN traffic was accessed. TorGuard also put out an extensive statement following a May blog post, which first revealed the breach.

- End of Article -​

Summary:

- A data center was breached in March 2018.

- They kept quiet about it until completing an infrastructure audit.

- NordVPN is being criticized for investing in advertising over security.
 

Ver archivo adjunto 980252
Okay yeah that shit is really funny.
 
I mean if you're using a VPN to do terrorist shit you're fucked eventually. If you're just changing your location and hiding from a website or torrenting HD porn then it's good enough.

If the spooks want you they'll get you.

We all know that people use VPN's and Tor so that they won't get caught watching child stag reels. You guys all know it to be true, you're just too scared to say the truth of the matter.
 
"So let's put literally everything online, including our fucking refrigerators and lightbulbs, since that will make everything more convenient!"

We as a species are too stupid to live :heart-empty:
I’ll never allow a WiFi camera in my home or get remote controlled locks, but I do have an Alexa, so I’m not helping.
 
Lol at whatever dumb nigger thought NordVPN would actually work.

NordVPN and even ProtonVPN for that matter were literally created by the private data maining company Tesonet. Only retards use that shit. If you want good shit Proxy.sh, IVPN, Perfect Privacy, Cryptostorm, and maybe Mullvad are worth using. If you want a good browser, probably Opera or Waterfox, a friend of mine even chances it with Brave but haven't really tried it. Maybe even Yandex if you wanna go the extra mile. I really don't give a fuck if the Russians know what I search since they won't definitely won't be extraditing me for gay shit.
 
Última edición:
That goes to show: it's advertised on YouTube, it's probably shit.
I'm still waiting on a Ridge wallet expose.
"So let's put literally everything online, including our fucking refrigerators and lightbulbs, since that will make everything more convenient!"

We as a species are too stupid to live :heart-empty:
In our goddamn cars!
 
It will be interesting to see what comes out of this. They seem to have non-technical people explaining the problem. C.f. this.
“The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so usernames and passwords couldn’t have been intercepted either,” said the spokesperson. “On the same note, the only possible way to abuse the website traffic was by performing a personalized and complicated man-in-the-middle attack to intercept a single connection that tried to access NordVPN.”
This is either stupidity or misleading.

I am not aware of any option for using NordVPN with a standard built in operating system client that uses anything but a user's username and password. Certainly their regular OpenVPN configs do. My understanding is that NordVPN's branded client uses OpenVPN internally. So, unless they're doing something odd and authenticating with the username and password to some other NordVPN server to get a token to authenticate to the actual servers, the VPN server gets your username at least. Even if the password is sent as a hash, which I would imagine is probably the case without bothering to look into the OpenVPN protocol deeply, a modified OpenVPN server version installed by an attacker on this one server could still easily correlate outgoing traffic with usernames and source IPs.

And that's why you should use both a VPN and Tor for more sensitive stuff, and shouldn't make a habit of connecting to one single VPN server (don't 'favourite' a single server, connect to a random one in a place that's relatively safe from the traditional enemies of the truth like Russia, Serbia, Hong Kong, etc).

In hindsight, I'm glad I use Opera instead of NordVPN. Something always did seem kind of sus about NordVPN, considering how highly advertised it is on alot of youtube channels that I follow.

This post was brought to you by Opera Web Browser, Faster, Safer, Smarter......and completely Free!
No offence, but 'a paid privacy-focused VPN had a problem' is not a good argument for using a 'free VPN', which are problematic by definition.

If your only reason to use a VPN is to lightly mask your geographic location, or to bypass web filtering on your work wifi, these things might be fine, but they're basically all just honeypots. Either to insert their own ads or collect ad profiling data, or to collect blackmail information

That is not to say that if you have dissident political views, or have information that you want protected, you're not better off using the very limited free Chinese 'protection' of Opera than a Israeli paid honeypot like CyberGhost. But Chinamen are fundamentally untrustworthy and would happily sell out their users even at the risk of reputational damage. To the extent that they haven't, it's probably because noone's made the offer.

If you're too cheap to use a paid VPN at least use the free service from an otherwise paid VPN like WindScribe or ProtonVPN that has some interest in preserving their reputation and money supply by not diming out their users. If that's too hard just find a dodgy random free PPTP VPN and use that with your OS's built in software, at least you won't be installing untrustworthy software on there that can snoop on everything else you do on your computer as well as everything you browse.

Nord VPN rents their servers infrastructure and hosting from an unknown third party, who knows what they are logging? If your VPN provider doesn’t control their own fucking hardware they aren’t providing you a vpn.
If you manage to find a VPN provider that only uses dedicated servers that solely they control, mounted in racks where they have 360 degree surveillance cameras monitoring watching for anyone interfering with them, which is monitored 24/7/365 and replaced if the camera feed drops for more than a few tends of seconds.. let us know.
 
Atrás
Top Abajo