3 ms·
Linked article says: > “The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so
by uniformlyrandom 7y ago
Linked article says:
> “The server itself did not contain any user activity logs; none of our applications send user-created credentials for authentication, so usernames and passwords couldn’t have been intercepted either,” said the spokesperson. “On the same note, the only possible way to abuse the website traffic was by performing a personalized and complicated man-in-the-middle attack to intercept a single connection that tried to access NordVPN.”
> According to the spokesperson, the expired private key could not have been used to decrypt the VPN traffic on any other server.
> NordVPN said it found out about the breach a “few months ago,” but the spokesperson said the breach was not disclosed until today because the company wanted to be “100% sure that each component within our infrastructure is secure.”
- SimeVidas 7y agoIf I were a NordVPN customer, these quotes would not give me confidence that my traffic wasn’t exposed.
- Snawoot 7y ago> According to the spokesperson, the expired private key could not have been used to decrypt the VPN traffic on any other server. It's simply not true. Their CA private key which is used to issue certificates for ALL servers also leaked along with RADIUS key which is used to secure EAP session [1]. They DO hide facts. [1] https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa36f16059a629eea/raw/e4e4af26e4c411d32bbc6bd3ba26301c2ae074bd/nordvpn.txt https://gist.githubusercontent.com/Snawoot/85f77356e229d77aa...