https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

MSSP Insider


Shutterstock

VPN Security

NordVPN Hacked, Making MSSPs’ Jobs Harder

  • Written by Pam Baker
  • October 21, 2019
MSSPs see big trouble ahead when even a top-ranked VPN is breached.

While virtual private networks (VPNs) are regularly under attack by the likes of China and Russia, it’s disconcerting to see a powerhouse like NordVPN actually breached. Incredibly, the often top-ranked VPN followed a week’s worth of rumors with confirmation today that it was breached.

“We became aware that on March 2018, one of the data centers in Finland we had been renting our servers from was accessed with no authorization. The attacker gained access to the server by exploiting an insecure remote management system left by the data-center provider while we were unaware that such a system existed,” said the company in its official blog on the matter.

A hacker and web developer known as @hexdefined on Twitter tweeted, “Whoever compromised NordVPN had root access to a container server, allowing full control of everything in it (presumably including the ability to view and tamper with all network traffic going through it).” The same source also tweeted that TorGuard was also compromised and there was also an OpenVPN server key in that hack.

I should probably make it clear that whoever compromised NordVPN had root access to a container server, allowing full control of everything in it (presumably including the ability to view and tamper with all network traffic going through it).

Why was this never detected?

— undefined (@hexdefined) October 21, 2019

Venafi's Kevin Bocek

Venafi’s Kevin Bocek

“VPN providers have grown rapidly because of the growing need for privacy. VPN cloud providers require TLS certificates that act as machine identities to authorize connection, encryption and establish trust between machines,” explained Kevin Bocek, vice president of security strategy and threat intelligence at machine identity protection provider Venafi.

The exposed expired internal private key “potentially allowed anyone to spin out their own servers imitating NordVPN,” according to a TechCrunch report.

MSSPs are likely to find it harder to advise clients on how to protect their mobile and remote workforces using unsecured internet connections now that VPNs have been breached too. However, NordVPN assures its customers that no other servers were affected, nor were any user activity logs or user-created credentials for authentication – such as usernames and passwords – taken.

Still, it strikes some as strange that internal and external audits didn’t catch this server vulnerability.

The company regularly seeks third-party audits. A recent one was an application security audit. Independent auditor VerSprite conducted the three-phased application penetration test.

NordVPN's Laura Tyrell

NordVPN’s Laura Tyrell

“This audit made our apps even stronger. After the initial Application Penetration Test, our developer team followed the auditor’s recommendations and implemented a few changes,” said Laura Tyrell, head of public relations at NordVPN. “We’re keeping our pledge and intend to regularly audit our service in the future to help verify our systems match the highest standard.”

And last year, NordVPN retained PricewaterhouseCoopers (pwc), a Big 4 auditing firm, to audit its no-logs policy.

But security professionals are wary of assurances of any kind, even from outside auditors. After all, NordVPN, by its own admission, did not know about this server vulnerability until it was breached. What else does it not know about its own operations? But remember that this is true of almost every company in every industry. In any case, this type of attack will continue against a wide variety of companies using the cloud.

“Machine identities are extremely valuable targets for cybercriminals and large enterprises often have tens of thousands of machine identities they need to protect. These breaches will become more common in the future. It is imperative organizations have the agility to automatically replace every key and certificate that may have been exposed in breaches,” said Bocek.

Tags: MSPs Cloud and Edge MSSP Insider Network Security

Most Recent


  • IronNet Layoffs
    Rackspace Layoffs Impact 275 People — What About Channel Leader?
    The cloud managed service provider’s CEO blames the “uncertain macro environment.”
  • boxing gloves
    Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart
    There's always something to buzz about in the channel.
  • XDR
    Netsurion Rolls Out Enhanced Partner Program for Managed XDR
    Netsurion now offers reseller partnerships.
  • Cisco African American Partner Community Eyes Hiring, HBCU Opportunities
    Cisco is working with 14 Black-owned partner firms in a "high-touch" manner to invest in their growth.

One comment

  1. Avatar Renald February 18, 2020 @ 2:30 am
    Reply

    The TLS keys were expired…so you can’t really call it a hack, it was more of an attempt at best. I have been using Nords business solution (https://nordvpnteams.com/) and do trust them as a service to keep my data safe. Throughout this time period a number of VPNs and other security software ran into similar situations, but from these event you can only learn and grow.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Security Vulnerability
    Older Fortinet Vulnerabilities Lead to Attack on Local Government Office
  • Threats
    Cybersecurity and Threat Protection: MSSPs, Get Your Advice Here
  • DevSecOps
    ServiceNow, Microsoft Set to Deliver Broad SecOps Integration
  • Dunce Cap Businessman
    Tired of MSSPs ‘Failing,’ Nuspire Debuts Platform to Combat Cyberattacks

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart

March 28, 2023

Cisco African American Partner Community Eyes Hiring, HBCU Opportunities

March 28, 2023

National Women’s History Month: Channel Women Recall ‘the Best Thing’

March 28, 2023

Industry Perspectives

View all

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Does Your Company Have a Virtual Water Cooler?

March 13, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

The latest @ATTPartners awards give a nice glimpse of how M&A is shaping partner hierarchies.… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

.@Netsurion announces partner program enhancements. #XDR dlvr.it/Sld2wM https://t.co/KuanLOeTMB

March 28, 2023
ChannelFutures

.@ATTBusiness retains top spot in latest carrier-managed #SDWAN leaderboard. dlvr.it/SlcvcN https://t.co/QehfYFbOrN

March 28, 2023
ChannelFutures

#Layoffs now happening at #Rackspace. Who’s affected? dlvr.it/SlcscW https://t.co/udMGRSUX3r

March 28, 2023
ChannelFutures

📺 New on CFTV: Adolfo Morales, MBA, Alliances Manager at @eatoncorp speaks with Craig Galbraith Editorial, Director… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

Learn about what @ciscopartners is doing with partners like @molaprise. dlvr.it/SlcTc3 https://t.co/Cf1IN55r1Z

March 28, 2023
ChannelFutures

.@Genesys is offering the solution as a free, automated self-service trial. dlvr.it/SlcSck https://t.co/mooYGE3KCH

March 28, 2023
ChannelFutures

.@allisonbergamo of @BergamoMktg will share insights on harnessing the power of AI in marketing at @channel_expo.… twitter.com/i/web/status/1…

March 28, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X