Live data from Hacker News

PIA VPN to be acquired by malware company founded by former Israeli spy

telegra.ph

221–230 of 381 posts

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#221

Earlier quoted context omitted.

How can we verify that?

You can't generally prove someone isn't beating their wife. https://en.wikipedia.org/wiki/Loaded_question

When the concern is our privacy and secrecy, isn’t it better to err on the side of caution than trust naively?

What if it were a matter of health? Should we trust before verifying? Would it still be a “loaded” question?

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#222
post #4

This article and articles like this miscast Kape in an incorrect light. To be clear, in the past the company was known as CrossRider and provided a developer SDK that could be used to integrate with browsers. Unfortunately, CrossRider didn't do enough to prevent malware (like platforms these days and their fake news) and the platform was used by some bad people for bad purposes. When the new management team of CrossR…

The bottom line is, in 2019 if any of my relatives asked me which VPN to use I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider as a MITM to ALL your internet activity. Only then would I highlight the benefits of VPNs in regards to internet freedoms and circumventing bad content blocks where users want to pay to access content but are arbitrarily denied.

VPNs are not the type of consumer product you EVER want to have acquired by ANYBODY. Not by Google, or Facebook, a US company, a Russian company, a Japanese company, NOBODY. Was this not extremely obvious when the deal started to form?

You've made a lot of promises that nothing will change, but those are empty promises given the history of post-acquired companies, as well as the vpn market as a whole. You have a lot of work to do following up on those promises, and until you do you will not have the same level of trust as you once did.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#223

Earlier quoted context omitted.

The VPN that I connect directly to, I pay with a credit card. They know who I am, so why bother trying to hide. All other VPNs in my chains, I pay with Bitcoin that's been mixed multiple times. I have a bunch of Whonix instances that I use for mixing and storing Bitcoin. They all hit Tor through nested VPN chains. Each one has an Electrum wallet. It gets its Bitcoin from another Whonix instance through a mixing servi…

Genuine question. Why?

Well, I actually wouldn't trust anyone with that.

But Amazon, less so. Because they're totally profit driven. And wouldn't think twice before pwning me.

I want to remain pseudonymous. Basically so I don't need to worry about damaging my meatspace reputation.

And what would be the point of going to all that trouble, if I were going to compromise myself?

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#224
post #4

This article and articles like this miscast Kape in an incorrect light. To be clear, in the past the company was known as CrossRider and provided a developer SDK that could be used to integrate with browsers. Unfortunately, CrossRider didn't do enough to prevent malware (like platforms these days and their fake news) and the platform was used by some bad people for bad purposes. When the new management team of CrossR…

The bottom line is, in 2019 if any of my relatives asked me which VPN to use I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider as a MITM to ALL your internet activity. Only then would I highlight the benefits of VPNs in regards to internet freedoms and circumventing bad content blocks where users want to pay to acc…

> I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider

I'm not your great-grandfather, but I also didn't really know (or think of) this. I kinda always thought about VPNs as intranets. I also assumed that browsers are easy enough to hack that you don't need to do a full MITM on the entire network. I also assumed most normal people don't use VPNs.

What would the most common attack vector through a VPN be? My guess would be targeting people that use pirate streaming sites / streaming through proxy IP.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#225
post #133

Earlier quoted context omitted.

>The merger between Kape and PIA affords PIA the resources needed to bring privacy to the mainstream. You were one of the most, if not the most successful VPN provider for years. Did you really need more resources? For what? The main benefit of PIA is the expectation for extra privacy. No matter how you look at it, selling to Kape is a strong signal that's not a priority. Similar, for hiring Karpeles to do your secur…

> Did you really need more resources? For what? Yes, to bring freedom thru privacy to people, The coming battle against privacy and free speech is by far the strongest and worst yet; the narrative and our voices are quickly getting quashed. Without the ability to communicate privately and speak freely, at best democracy is at risk; and at worst, humanity, or what it has meant to be human until now, itself may be at r…

* a battle hardened fraudster.

Failure is not the fastest way to learn when that failure is achieved through fraud.

I was on the verge throughout all of these news, but now finding out about you hiring Karpeles and now reading how you defend it really made me cancel all the subscriptions and never come back again.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#227
post #132

Earlier quoted context omitted.

I'm not sure there's such a thing as a former Israeli spy. That being so, this may be a Mossad operation, in which case the US is powerless to do anything about it.

That unit is part of the Israeli army, and Israel has conscription so inevitably a lot of people will end up there. Should none of them be trustworthy?

[deleted]

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#228
post #146

Earlier quoted context omitted.

Mullvad on the other hand does not log anything at all (other than their Stripe payments where they try to keep data minimal). Is that in violation of the Swedish law? Maybe, but as long as one of the medium sized ISPs, Bahnhof, is still fighting the law in court I cannot foresee any court cases against small fry like Mullvad or any of the other Swedish VPN providers.

The difference is probably that Sweden isn't as privacy unfriendly as the USA, despite being part of the fourteen eyes programme.

Unlike many countries includingany European countries the US does not require logs to be kept.

Also legally national security letters can not require monitoring of the contents of communications but only compel the recipient to produce existing records regarding the communications. For a VPN service that did retain logs a NSL could require them to be turned over; however, for one which doesn't there would be nothing to turn over and a NSL can't compel the collection of such information when it doesn't exist. A NSL which tried to exceed these restrictions can be fought in court.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#229
post #57

Earlier quoted context omitted.

Yes.

I see no cryptocurrency option for renewal. https://keybase.pub/mirimir/ExpressVPN.png

I believe there's been a bit of confusion, and they were talking about Mullvad.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#230
post #207

Earlier quoted context omitted.

> Similar, for hiring Karpeles to do your security (like he hasnt lost us enough already). Wait... What?!! I just had to look this up[0]. How did I miss this news? Now... I'm all for second chances in general, but there need to be limits, and my understanding of the MtGox case, is that on top of being responsible for terrible security practices, Karpales lied about the intrusions. I was actually kinda on the fence be…

I actually subscribed to PIA before realising this, too. It's weird nobody else is even mentioning it in these threads - trusting a proven fraud like Karpeles for your privacy and security needs is a bit insane if you have other alternatives.

I didn't know that either. Here's a couple quotes from an article about how Mark ran MtGox:

> Beneath it all, some say, Mt. Gox was a disaster in waiting. ... A Tokyo-based software developer [says it] didn’t use any type of version control software [and] he says there was only one person who could approve changes to the site’s source code: Mark Karpeles. ... “The source code was a complete mess,” says one insider.

> The 1,719 lines of commented PHP code...include code to access individual customers’ Bitcoin wallets and to process transactions. ... Anyone who had access to the server running this code could have easily redirected transactions or pillaged the Bitcoin wallets.

https://www.computerworld.com/article/2476003/the-php-that-s...

Post reply on HN