FYI NordVPN may have been compromised 10/20/19 * w/ response

Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking
Author Message
tinkeruntilitworks
Guest





PostPosted: Mon Oct 21, 2019 13:00    Post subject: FYI NordVPN may have been compromised 10/20/19 * w/ response Reply with quote
https://twitter.com/hexdefined/status/1185864801261477891?s=20

Last edited by tinkeruntilitworks on Mon Oct 21, 2019 16:34; edited 1 time in total
Sponsor
SurprisedItWorks
DD-WRT Guru


Joined: 04 Aug 2018
Posts: 1447
Location: Appalachian mountains, USA

PostPosted: Mon Oct 21, 2019 16:25    Post subject: Reply with quote
NordVPN response: https://nordvpn.com/blog/official-response-datacenter-breach/
_________________
2x Netgear XR500 and 3x Linksys WRT1900ACSv2 on 53544: VLANs, VAPs, NAS, station mode, OpenVPN client (AirVPN), wireguard server (AirVPN port forward) and clients (AzireVPN, AirVPN, private), 3 DNSCrypt providers via VPN.
tinkeruntilitworks
Guest





PostPosted: Mon Oct 21, 2019 21:42    Post subject: Reply with quote
https://techcrunch.com/2019/10/21/nordvpn-confirms-it-was-hacked/

*
another article

https://arstechnica.com/information-technology/2019/10/hackers-steal-secret-crypto-keys-for-nordvpn-heres-what-we-know-so-far/?utm_brand=arstechnica&utm_source=twitter&utm_social-type=owned&utm_medium=social


Last edited by tinkeruntilitworks on Mon Oct 21, 2019 23:35; edited 1 time in total
SurprisedItWorks
DD-WRT Guru


Joined: 04 Aug 2018
Posts: 1447
Location: Appalachian mountains, USA

PostPosted: Mon Oct 21, 2019 22:11    Post subject: Reply with quote
This afternoon I verified with a shell script that the openvpn config files posted at https://downloads.nordcdn.com/configs/files/ovpn_udp/servers/SERVERNAME.nordvpn.com.udp.ovpn for the several dozen SERVERNAMEs that I use are still showing the .ca and .tls keys that I have had in place in dd-wrt for over a year, identical keys across all those servers. I'm not sure what that talk about expiring keys was about if they are not actually forcing us to update our configurations.
_________________
2x Netgear XR500 and 3x Linksys WRT1900ACSv2 on 53544: VLANs, VAPs, NAS, station mode, OpenVPN client (AirVPN), wireguard server (AirVPN port forward) and clients (AzireVPN, AirVPN, private), 3 DNSCrypt providers via VPN.
SurprisedItWorks
DD-WRT Guru


Joined: 04 Aug 2018
Posts: 1447
Location: Appalachian mountains, USA

PostPosted: Tue Oct 22, 2019 15:03    Post subject: Reply with quote
This Ars Technica piece is the most thorough writeup I've seen so far. It's clear that I needn't have been concerned about our .ca and .tls files. It appears that the vulnerability was strictly regarding access of the main nordvpn.com website itself. There was some possibility of a MITM attack substituting a fake site. Perhaps the bigger issue is just that NordVPN was so quiet about this for so long. What else are they not telling us, if that's their philosophy?

Hackers steal secret crypto keys for NordVPN. Here’s what we know so far
https://arstechnica.com/information-technology/2019/10/hackers-steal-secret-crypto-keys-for-nordvpn-heres-what-we-know-so-far/

_________________
2x Netgear XR500 and 3x Linksys WRT1900ACSv2 on 53544: VLANs, VAPs, NAS, station mode, OpenVPN client (AirVPN), wireguard server (AirVPN port forward) and clients (AzireVPN, AirVPN, private), 3 DNSCrypt providers via VPN.
tinkeruntilitworks
Guest





PostPosted: Fri Nov 01, 2019 18:48    Post subject: Reply with quote
another breach
https://arstechnica.com/information-technology/2019/11/nordvpn-users-passwords-exposed-in-mass-credential-stuffing-attacks/
SurprisedItWorks
DD-WRT Guru


Joined: 04 Aug 2018
Posts: 1447
Location: Appalachian mountains, USA

PostPosted: Fri Nov 01, 2019 20:52    Post subject: Reply with quote
I gave up on these guys and moved my router to AirVPN. See the last link in my sig below.
_________________
2x Netgear XR500 and 3x Linksys WRT1900ACSv2 on 53544: VLANs, VAPs, NAS, station mode, OpenVPN client (AirVPN), wireguard server (AirVPN port forward) and clients (AzireVPN, AirVPN, private), 3 DNSCrypt providers via VPN.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Advanced Networking All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You cannot download files in this forum