NordVPN confirms it was hacked


NordVPN, a virtual private network provider that promises to “protect your privacy online,” has confirmed it was hacked.

The admission comes following rumors that the company had been breached. It first emerged that NordVPN had an expired internal private key exposed, potentially allowing anyone to spin out their own servers imitating NordVPN.

VPN providers are increasingly popular as they ostensibly provide privacy from your internet provider and visiting sites about your internet browsing traffic. That’s why journalists and activists often use these services, particularly when they’re working in hostile states. These providers channel all of your internet traffic through one encrypted pipe, making it more difficult for anyone on the internet to see which sites you are visiting or which apps you are using. But often that means displacing your browsing history from your internet provider to your VPN provider. That’s left many providers open to scrutiny, as often it’s not clear if each provider is logging every site a user visits.

For its part, NordVPN has claimed a “zero logs” policy. “We don’t track, collect, or share your private data,” the company says.

But the breach is likely to cause alarm that hackers may have been in a position to access some user data.

NordVPN told TechCrunch that one of its data centers was accessed in March 2018. “One of the data centers in Finland we are renting our servers from was accessed with no authorization,” said NordVPN spokesperson Laura Tyrell.

The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the data center provider; NordVPN said it was unaware that such a system existed.

NordVPN did not name the data center provider.

“The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so usernames and passwords couldn’t have been intercepted either,” said the spokesperson. “On the same note, the only possible way to abuse the website traffic was by performing a personalized and complicated man-in-the-middle attack to intercept a single connection that tried to access NordVPN.”

According to the spokesperson, the expired private key could not have been used to decrypt the VPN traffic on any other server.

NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.”

A senior security researcher we spoke to who reviewed the statement and other evidence of the breach, but asked not to be named as they work for a company that requires authorization to speak to the press, called these findings “troubling.”

“While this is unconfirmed and we await further forensic evidence, this is an indication of a full remote compromise of this provider’s systems,” the security researcher said. “That should be deeply concerning to anyone who uses or promotes these particular services.”

NordVPN said “no other server on our network has been affected.”

But the security researcher warned that NordVPN was ignoring the larger issue of the attacker’s possible access across the network. “Your car was just stolen and taken on a joy ride and you’re quibbling about which buttons were pushed on the radio?” the researcher said.

The company confirmed it had installed intrusion detection systems, a popular technology that companies use to detect early breaches, but “no-one could know about an undisclosed remote management system left by the [data center] provider,” said the spokesperson.

“They spent millions on ads, but apparently nothing on effective defensive security,” the researcher said.

NordVPN was recently recommended by TechRadar and PCMag. CNET described it as its “favorite” VPN provider.

It’s also believed several other VPN providers may have been breached around the same time. Similar records posted online — and seen by TechCrunch — suggest that TorGuard and VikingVPN may have also been compromised.

A spokesperson for TorGuard told TechCrunch that a “single server” was compromised in 2017 but denied that any VPN traffic was accessed. TorGuard also put out an extensive statement following a May blog post, which first revealed the breach.

- End of Article -​

Summary:

- A data center was breached in March 2018.

- They kept quiet about it until completing an infrastructure audit.

- NordVPN is being criticized for investing in advertising over security.
 
Let me know if the formatting is messy, I separated the three sources with quotes.

Virtual private network provider NordVPN has confirmed an attacker breached one of its servers, though the tangible impact of the breach seems to be pretty limited. There were no user activity logs on the server -- the company says it doesn't track, collect or share people's private data. There was also no way for the hacker to access usernames and passwords and nor could the attacker have decrypted VPN traffic to other servers.

"The only possible way to abuse website traffic was by performing a personalized and complicated MiTM attack to intercept a single connection that tried to access nordvpn.com," the company wrote in a blog post.

The incident took place in March 2018, when an unauthorized person accessed a server NordVPN rented from a third-party data center in Finland. They exploited an "insecure remote management system" that the data center provider left in place. NordVPN wasn't aware that such a system existed.

The affected server was added to NordVPN's server list on January 31st that year. The provider detected the vulnerability and removed the remote management account on March 20th without informing NordVPN.

The company learned of the incident a few months ago and right away ended its contract with the data center provider and scrubbed all the data it had on the rented servers. It didn't disclose the breach immediately because it had to audit the rest of its infrastructure to ensure similar issues wouldn't occur elsewhere. It also "accelerated the encryption of all of our servers." That took some time because of its complex infrastructure and the more than 3,000 servers it uses.

The issue didn't affect any of NordVPN's other servers or data centers. It says it will require providers it works with to meet higher security standards. It's also moving all of its servers to RAM, a process that should be completed next year.

While the breach doesn't seem to have had a significant impact on user privacy, it's not a great look for a company that touts itself as offering "secure and private access to the internet." As such, NordVPN is doubling down on security. "We have undergone an application security audit, are working on a second no-logs audit right now, and are preparing a bug bounty program," it wrote in the post. "[Next] year we will launch an independent external audit all of our infrastructure to make sure we did not miss anything else."

Engadget: https://www.engadget.com/2019/10/21/nordvpn-server-breach-data-center-finland/



NordVPN, a virtual private network provider that promises to “protect your privacy online,” has confirmed it was hacked.

The admission comes following rumors that the company had been breached. It first emerged that NordVPN had an expired internal private key exposed, potentially allowing anyone to spin out their own servers imitating NordVPN.

VPN providers are increasingly popular as they ostensibly provide privacy from your internet provider and visiting sites about your internet browsing traffic. That’s why journalists and activists often use these services, particularly when they’re working in hostile states. These providers channel all of your internet traffic through one encrypted pipe, making it more difficult for anyone on the internet to see which sites you are visiting or which apps you are using. But often that means displacing your browsing history from your internet provider to your VPN provider. That’s left many providers open to scrutiny, as often it’s not clear if each provider is logging every site a user visits.

For its part, NordVPN has claimed a “zero logs” policy. “We don’t track, collect, or share your private data,” the company says.

But the breach is likely to cause alarm that hackers may have been in a position to access some user data.

NordVPN told TechCrunch that one of its data centers was accessed in March 2018. “One of the data centers in Finland we are renting our servers from was accessed with no authorization,” said NordVPN spokesperson Laura Tyrell.

The attacker gained access to the server — which had been active for about a month — by exploiting an insecure remote management system left by the data center provider; NordVPN said it was unaware that such a system existed.

NordVPN did not name the data center provider.

“The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so usernames and passwords couldn’t have been intercepted either,” said the spokesperson. “On the same note, the only possible way to abuse the website traffic was by performing a personalized and complicated man-in-the-middle attack to intercept a single connection that tried to access NordVPN.”

According to the spokesperson, the expired private key could not have been used to decrypt the VPN traffic on any other server.

NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.”

A senior security researcher we spoke to who reviewed the statement and other evidence of the breach, but asked not to be named as they work for a company that requires authorization to speak to the press, called these findings “troubling.”

“While this is unconfirmed and we await further forensic evidence, this is an indication of a full remote compromise of this provider’s systems,” the security researcher said. “That should be deeply concerning to anyone who uses or promotes these particular services.”

NordVPN said “no other server on our network has been affected.”

But the security researcher warned that NordVPN was ignoring the larger issue of the attacker’s possible access across the network. “Your car was just stolen and taken on a joy ride and you’re quibbling about which buttons were pushed on the radio?” the researcher said.

The company confirmed it had installed intrusion detection systems, a popular technology that companies use to detect early breaches, but “no-one could know about an undisclosed remote management system left by the [data center] provider,” said the spokesperson.

NordVPN said it disputes this. “We treat VPN servers as untrusted in the rest of our infrastructure. It is not possible to get access to other VPN servers, users database or any other server from a compromised VPN server,” said the spokesperson.

“They spent millions on ads, but apparently nothing on effective defensive security,” the researcher said.

NordVPN was recently recommended by TechRadar and PCMag. CNET described it as its “favorite” VPN provider.

It’s also believed several other VPN providers may have been breached around the same time. Similar records posted online — and seen by TechCrunch — suggest that TorGuard and VikingVPN may have also been compromised.

A spokesperson for TorGuard told TechCrunch that a “single server” was compromised in 2017 but denied that any VPN traffic was accessed. TorGuard also put out an extensive statement following a May blog post, which first revealed the breach.

Updated with comment from TorGuard, and again with additional comment from NordVPN.

TechCrunch: https://techcrunch.com/2019/10/21/nordvpn-confirms-it-was-hacked/


There was a successful attack against NordVPN:

Based on the command log, another of the leaked secret keys appeared to secure a private certificate authority that NordVPN used to issue digital certificates. Those certificates might be issued for other servers in NordVPN's network or for a variety of other sensitive purposes. The name of the third certificate suggested it could also have been used for many different sensitive purposes, including securing the server that was compromised in the breach.
The revelations came as evidence surfaced suggesting that two rival VPN services, TorGuard and VikingVPN, also experienced breaches that leaked encryption keys. In a statement, TorGuard said a secret key for a transport layer security certificate for *.torguardvpnaccess.com was stolen. The theft happened in a 2017 server breach. The stolen data related to a squid proxy certificate.
TorGuard officials said on Twitter that the private key was not on the affected server and that attackers "could do nothing with those keys." Monday's statement went on to say TorGuard didn't remove the compromised server until early 2018. TorGuard also said it learned of VPN breaches last May, "and in a related development we filed a legal complaint against NordVPN."
The breach happened nineteen months ago, but the company is only just disclosing it to the public. We don't know exactly what was stolen and how it affects VPN security. More details are needed.

VPNs are a shadowy world. We use them to protect our Internet traffic when we're on a network we don't trust, but we're forced to trust the VPN instead. Recommendations are hard. NordVPN's website says that the company is based in Panama. Do we have any reason to trust it at all?

I'm curious what VPNs others use, and why they should be believed to be trustworthy.

Schneider on Security: https://www.schneier.com/blog/archives/2019/10/nordvpn_breache.html

NordVPN's official response:

A video detailing VPN ranking, TorGuard comes out as top.
I did use TorGuard when I was in China, it just did not work, and I got a refund for it. So anecdotally the list is alright? I discovered the farms isn't blocked anyway which is why I wanted the VPN to begin with, so it all worked out.

tl;dr: NordVPN was hacked, some genius left management tools in some server in Finland. NordVPN instead of disclosing the hack immediately and subsequently taking action to fix the flaws, they decided to sweep it under a rug for a fucking year till someone tips information off. NordVPN as many undoubtedly knows spends millions on "influencer advertising", making them the most popular VPN service. The company's reputation is pretty much tarnished.

Here's some videos made by YouTube people.
Non-shills, both of these guys did a great job:
My favourite Aussie.

Louis Rossman, repairs expert of Apple products.
He responded to NordVPN's shill emails a while ago, telling them to fuck themselves.

Here's some videos by the shills:
JayzTwoCents, Ex-shill:
Tom Scott, Ex-shill:
Another Ex-shill:

Most of the shills I personally watch are silent.
 
I knew about Tom Scott and Mutahar (SomeOrdinaryGamers) telling Nord to go fuck off, but it'd be interesting to see who else told NordVPN to go screw themselves.

Opportunity to possibly become the new BetterHelp, who knows? I started using Mullvad due to them needing very minimal info and the fact they offer WireGuard support, anyway.
 
I knew about Tom Scott and Mutahar (SomeOrdinaryGamers) telling Nord to go fuck off, but it'd be interesting to see who else told NordVPN to go screw themselves.

Opportunity to possibly become the new BetterHelp, who knows? I started using Mullvad due to them needing very minimal info and the fact they offer WireGuard support, anyway.
Calling it the new better help is a bit of a stretch, don't you think?
 
Well shit... I don't think the hack impacts me as I started using it this year, but I do find it quite the coincidence that they release this information after one of their bigger deals has ended (I know my 30 day free trial expired a week or two ago).

Guess I'll just take a few days to find a new one before canceling NordVPN for good.
Calling it the new better help is a bit of a stretch, don't you think?
I think its because of how they pushed content creator advertisement. Better Help was using every Youtuber possible, and NordVPN has kind of done the same thing. Definitely not the same level of scummy, as they weren't preying on people's mental health, but nonetheless kind of a dick thing to do.

Pewdiepie was pushing it for a while. I wonder if he's going to say anything.


------------------------------------------
Just remembered. Will a new hero emerge?
will a new challenger approach.png
 
Funny because I started seeing commercials for them on telly today 🤔
 
If you're just trying to pirate movies and 4k porn does it matter if you had PIA or Nord or Mullvad?

The spooks will get you no matter what.
 
Why do people just assume if they pay a company money, their personal information will be kept privet ?
It's no secret that hackers have been going after VPNs for a long time ... using onion or garlic networks *is not* 100% risk free ether .

Using Tor in combination with a VPN is a very good thing as well. Exit node owners can't see your real IP, and if the Snowden leaks are to be believed, the US government couldn't accurately track Tor traffic either.
 
I don't trust anything that gets shilled by Youtubers, especially security related products like Nord or Dashlane. On a side note, is anyone else annoyed by how everyone tries to "seamlessly" blend these ads into their content now?
One youtuber claimed nordvpn to be "the only vpn trusted by both apple and google" and that's when I knew it was shit. If you're dumb enough to have trust in those scumbag companies you deserve what happens.
 
lol finns r re.tarded
At least they brought us spurdo.

Oh... my..God... I cant believe a fat man who reviews video games on youtube would shill me a bunk product...
Oh yeah! Boogie1488 and (((Philip D))) shills it, so it must be good amirite??/?

I don't trust anything that gets shilled by Youtubers, especially security related products like Nord or Dashlane. On a side note, is anyone else annoyed by how everyone tries to "seamlessly" blend these ads into their content now?
I am very annoyed. Even some very good channels I watch do it from time to time without mentioning explicitly that it's a sponsorship. Piece together in the description... pretty deceptive imo. Sometimes it's sponsorship crap masquerading as a proper video.

Nice syntax error in the subtitle, OP. Is everything in life a race for you A&H dweebs?

Remember, lube first, then jack it.
Fixed, what's A&H? I often fuck up subtitles.
Austria-Hungary? Adolf Hitler? Art History? The name should indicate that I'm poking fun at how autistic the alt-right type are.

I think its because of how they pushed content creator advertisement. Better Help was using every Youtuber possible, and NordVPN has kind of done the same thing. Definitely not the same level of scummy, as they weren't preying on people's mental health, but nonetheless kind of a dick thing to do.
Pewdiepie was pushing it for a while. I wonder if he's going to say anything.
------------------------------------------
Just remembered. Will a new hero emerge?
Ver archivo adjunto 992786
Not the same level of scummy because much of information is sweeped under the rug by Nord, who knows what scummy shit they've engaged in? That's why one should never trust viral marketing. Speaking of metal health, they gave people false information, false promises, and a false sense of safety. That's pretty fucking bad too.
 
Why do people just assume if they pay a company money, their personal information will be kept privet ?
It's no secret that hackers have been going after VPNs for a long time ... using onion or garlic networks *is not* 100% risk free ether .

This is why only use a VPN that takes crypto.

A lot of the 'nodes' are compromised. If I can find the news articles ... international police have tracked down many folks who where hiding behind an onion or garlic network.

Not by compromising tor, though. People do dumb shit and tor isn't magic. Unless you configure a webserver very carefully it will leak its real IP address, since shit like Apache isn't designed for use with tor. Among other major mistakes, Silk Road's captcha service was leaking IP address information.
 
Atrás
Top Abajo