4 ms·
Lots of talk here from highly technical folks but not one person brings up the fact that these are expired keys - as in not usable? I understand that the fact
by arshbot 7y ago
Lots of talk here from highly technical folks but not one person brings up the fact that these are expired keys - as in not usable?
I understand that the fact that these keys were obtained is concerning but the security of nord and etc prevailed at the end of the day.
The question is: were they leaked before they expired or long after?
- esnard 7y agoThey were leaked on March 2018 [0][1], and they expired on October 2018 [2]. [0] https://web.archive.org/web/20180504001844/https://8ch.net/b/res/7948898.html https://web.archive.org/web/20180504001844/https://8ch.net/b... [1] https://nordvpn.com/fr/blog/official-response-datacenter-breach/ https://nordvpn.com/fr/blog/official-response-datacenter-bre... [2] https://crt.sh/?id=10031443 https://crt.sh/?id=10031443
- arshbot 7y ago> However, the key couldn’t possibly have been used to decrypt the VPN traffic of any other server. On the same note, the only possible way to abuse website traffic was by performing a personalized and complicated MiTM attack to intercept a single connection that tried to access nordvpn.com. However crt.sh shows > Validity > Not Before: Oct 6 12:53:38 2015 GMT > Not After : Oct 6 12:53:38 2018 GMT What exactly were these keys for if they were only usable in such a manner according to nord?
- wswope 7y agoNord has a couple thousand severs, and each has their own key. In order to decrypt traffic, you'd have to intercept some traffic to decrypt, which would require a MitM attack unless you're an ISP/state actor.
- thenewnewguy 7y agoDepending on the web server configuration they could be used to decrypt past traffic.