3 ms·
It depends on what you mean by 'hacking' a VPN. One assertion in this breach is that the NordVPN certificate private key was leaked, allowing anybody to spin up
by badger_bravo 7y ago
It depends on what you mean by 'hacking' a VPN. One assertion in this breach is that the NordVPN certificate private key was leaked, allowing anybody to spin up a NordVPN server that would pass HTTPS certificate validation (the cert is expired, it's currently unknown if the cert was valid for a period of time after it was compromised). This kind of an attack would let an attacker convince most users to download viruses, input credentials, etc.
Nord says that the above issue was caused by a data center breach. Depending on the company this may mean a leak of user info (account details, emails, etc) and password data (generally secure hashes, but often insecure/near-plaintext passwords).
There's a lot that can go wrong here even before considering the MITM vector. As far as that goes, you can generally trust that well-secured sites (Google, Facebook, etc) won't allow someone to steal your session tokens/passwords. There is a high likelihood that a malicious VPN would achieve script execution on your machine in a short period of time.
- Bnshsysjab 7y agoLet’s not forget that if they’ve got to a point where they can breach a private key they’re at a point where they’ve probably dumped hashed user creds and contact details, and probably gained persistence on breached hosts, too.
- Dylan16807 7y ago> probably dumped hashed user creds and contact details Not if the hacker only got access to relay servers.