Live data from Hacker News

PIA VPN to be acquired by malware company founded by former Israeli spy

telegra.ph

231–240 of 381 posts

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#231

Earlier quoted context omitted.

The bottom line is, in 2019 if any of my relatives asked me which VPN to use I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider as a MITM to ALL your internet activity. Only then would I highlight the benefits of VPNs in regards to internet freedoms and circumventing bad content blocks where users want to pay to acc…

> I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider I'm not your great-grandfather, but I also didn't really know (or think of) this. I kinda always thought about VPNs as intranets. I also assumed that browsers are easy enough to hack that you don't need to do a full MITM on the entire network. I also assumed most…

I believe the most common case would be selling the user traffic, assuming the VPN knows who you are (through billing for example although given your traffic their are a variety of ways even if you did an anonymous signup), they could then say "Hey Ben reads a lot of technical blogs and spends a lot of time on console.cloud.google.com, Triplebyte you should plaster him with ads because that will totally work".

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#232
post #4

This article and articles like this miscast Kape in an incorrect light. To be clear, in the past the company was known as CrossRider and provided a developer SDK that could be used to integrate with browsers. Unfortunately, CrossRider didn't do enough to prevent malware (like platforms these days and their fake news) and the platform was used by some bad people for bad purposes. When the new management team of CrossR…

Thanks for confirming that PIA is full of shit with this comment. Mullvad never looked better.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#233
post #75

What do people use these VPN services for? Is it mostly for pirating, or public wifi users, or people that don't want their ISPs to know what they're doing? It all seems like niche use cases.

Can you live without Wikipedia? It is blocked in China and in Turkey.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#234

Earlier quoted context omitted.

That is a great question - all of our information is public whereas most other VPN companies go out of their way to hide where they are located and who they are. Verification and transparency are more important than trust.

How can users verify that PIA doesn't log?

You can only infer that as the result of court case demanding logs. And even then, it would have to be born out of the discovery process that PIA was truthful, in my opinion. Yet that only gives you comfort that they hadn't maintained logs up to that point. You have no guarantees from that point forward, which is what we're all concerned about. We aren't concerned about PIA's past operations, but rather what this new partnership means for their future behavior.

I realize your question is most likely rhetorical, but I felt the need to articulate my concerns.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#235

Earlier quoted context omitted.

Genuine question. Why?

Well, I actually wouldn't trust anyone with that. But Amazon, less so. Because they're totally profit driven. And wouldn't think twice before pwning me. I want to remain pseudonymous. Basically so I don't need to worry about damaging my meatspace reputation. And what would be the point of going to all that trouble, if I were going to compromise myself?

Sorry, I just realised my question was super ambiguous as to which part of your post I was asking "Why" to. I was specifically asking why you go to such large efforts to obscure your identity.

You've answered that, but it definitely seems a lot of effort to go to.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#236
post #4

This article and articles like this miscast Kape in an incorrect light. To be clear, in the past the company was known as CrossRider and provided a developer SDK that could be used to integrate with browsers. Unfortunately, CrossRider didn't do enough to prevent malware (like platforms these days and their fake news) and the platform was used by some bad people for bad purposes. When the new management team of CrossR…

I hope you understand why people are extremely reluctant on forgiving and forgetting, especially involving something as sensitive as a VPN which, in some cases, can truly be a matter of life or death.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#237
post #95

Earlier quoted context omitted.

Given Kape's past history, I'm skeptical that PIA will be able to maintain their current levels of privacy regarding data mining and logging. I'm willing to give PIA the benefit of the doubt and accept that they believe they'll be able to do so, but as is the case in mergers like these, sometimes you simply lose that battle with your new corporate partner. My fear is that they end up doing the same level of shady act…

> Since PIA was in debt, it doesn't sound like maintaining the current service as is would be profitable. Private Internet Access is very profitable [1] and our new partner’s action of merging with PIA speaks louder than words whether privacy is important to them. [1] https://investors.kape.com/~/media/Files/K/Kape-IR/reports-a... (Slide 5)

Outsider here, no dog in this race. Never used a VPN, never really knew much about PIA until the recent merger, but very invested in privacy enhancing technologies. Here's a piece of feedback from that perspective:

I think the critical thing you're missing here is that it doesn't matter if Kape is trustworthy, it matters whether people see it as trustworthy. And you're not in a position to change the latter, no matter how much you talk about the former, because you have a conflict of interest.

The other thing is, you need to be able to explain the merger.

If PIA wasn't profitable, the merger looks bad, because that means that Kape is going to find other ways to monetize it.

If PIA was profitable, the merger is just confusing as heck, because why screw up a good thing? And confusion is bad, because people want security from a VPN. Not the computer kind, the emotional kind. Big upheavals like mergers throw that out the window, so you need to manage that transition very, very carefully.

You're not doing that, so far.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#239

Earlier quoted context omitted.

The bottom line is, in 2019 if any of my relatives asked me which VPN to use I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider as a MITM to ALL your internet activity. Only then would I highlight the benefits of VPNs in regards to internet freedoms and circumventing bad content blocks where users want to pay to acc…

> I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider I'm not your great-grandfather, but I also didn't really know (or think of) this. I kinda always thought about VPNs as intranets. I also assumed that browsers are easy enough to hack that you don't need to do a full MITM on the entire network. I also assumed most…

It modifies who your targets are. You can try to attack people with malicious websites, but in that scenario you can only attack people who manage to visit your malicious site. (this example should be considered to include advertising iframes and such.)

A VPN provider, however, has a captive audience and can be certain who they are attacking.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#240
post #4

This article and articles like this miscast Kape in an incorrect light. To be clear, in the past the company was known as CrossRider and provided a developer SDK that could be used to integrate with browsers. Unfortunately, CrossRider didn't do enough to prevent malware (like platforms these days and their fake news) and the platform was used by some bad people for bad purposes. When the new management team of CrossR…

PIA was the first, that I was able to find at the time, that had an fully functioning android app for your service. I've used PIA ever since whenever I needed VPN services.

Like every service I use, I plan to take into account what I learn about them and then watch and see what they do.

Post reply on HN