Jump to content

Recommended Posts

Posted

One datacenter in Finland and not even NordVPN it's fault, but the datacenter.

 

Quote

The breach was the result of hackers exploiting an insecure remote-management system that administrators of a Finland-based datacenter installed on a server NordVPN leased. The unnamed datacenter, the statement said, installed the vulnerable management system without ever disclosing it to its NordVPN. NordVPN terminated its contract with the datacenter after the remote management system came to light a few months later.

 

  • Thanks 1
Posted
10 hours ago, Jan Dietz said:

That would be the teamviewer virus then

That would surprise me; I would think something like the VMWare console or IPMI based on information I have read. 

Posted

They were always one of the solid go-to companies— considered well run.  Depending on what you are using them for... it can be hard to trust anyone though.  I’m much happier having my own VPN connection to my place in the US (or even work).   Most of my need is just geo-blocking issues, and often to make sure I can reasonably obfuscate online banking.

Posted

Who needs logs. According to this recent article OpenVPN has been exploited and if compression is used on the transmission it can be decoded. The companies mentioned below including NordVPN use compression.
According to an article by Paul Wagensell which he presented at DEF CON 26 and was published August 13th in Tom's guide many well known VPN service providers (NordVPN, PureVPN, Hotspot Shield, ExpressVPN, PIA) can be hacked. The recommendation it to use another protocol.

https://www.tomsguide.com/us/vpn-voracle-attack-defcon26,news-27784.html

Posted
On 10/22/2019 at 9:35 AM, Stocky said:

I can't imagine many NordVPN users in Thailand would be using a server in Finland. I certainly don't.

 

I'm not concerned.

Well I sometimes have my VPN set on a Danish address when I want to watch some Danish TV programs. Some programs from one particular TV channel can only be seen in DK.

I could imagine the same applies for Finish nationals regarding above? 

 

I uses NordVPN by the way and are happy with it.

  • Like 1
Posted (edited)
15 hours ago, tjo o tjim said:

Isn’t NordVPN IKEv2?

Yes, you do have the option to define an IKEv2 connection for NordVPN.

See https://nordvpn.com/tutorials/ for tutorials on how to do it for various devices.

Just tried it on Win 10 and works fine.

So far NordVPN works fine for me (OpenVPN & IKEv2).

Edited by Mutt Daeng
typo
Posted (edited)
20 hours ago, Shengen said:

Who needs logs. According to this recent article OpenVPN has been exploited and if compression is used on the transmission it can be decoded. The companies mentioned below including NordVPN use compression.
According to an article by Paul Wagensell which he presented at DEF CON 26 and was published August 13th in Tom's guide many well known VPN service providers (NordVPN, PureVPN, Hotspot Shield, ExpressVPN, PIA) can be hacked. The recommendation it to use another protocol.

https://www.tomsguide.com/us/vpn-voracle-attack-defcon26,news-27784.html

But you should be enforcing a https connection. Extensions like HTTPS Everywhere help ensure https encryption, I think Chrome forces this by default.

 

.

Edited by Stocky
  • Like 1
Posted (edited)
On 10/31/2019 at 12:14 PM, Shengen said:

Who needs logs. According to this recent article OpenVPN has been exploited and if compression is used on the transmission it can be decoded. The companies mentioned below including NordVPN use compression.
According to an article by Paul Wagensell which he presented at DEF CON 26 and was published August 13th in Tom's guide many well known VPN service providers (NordVPN, PureVPN, Hotspot Shield, ExpressVPN, PIA) can be hacked. The recommendation it to use another protocol.

https://www.tomsguide.com/us/vpn-voracle-attack-defcon26,news-27784.html

This vulnerability was fixed by Nord in Aug 2018. I woudn't describe Aug 2018 as recent. Not sure how other VPN providers have responded to the threat.

Edited by Mutt Daeng
  • Like 1
Posted (edited)

<Rant>

NB I'm not affiliated in any way to any VPN provider. Just a retired sysprog, who hates to see scaremongering posts by people who post things after reading some article somewhere without any kind of veracity checks.

</Rant>

Edited by Mutt Daeng
  • Like 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.



×
×
  • Create New...