Live data from Hacker News

UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

comparitech.com

101–110 of 240 posts

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#101

Earlier quoted context omitted.

Is there any way to prove that is not NSA, say, and set up to only catch the biggest fish, or to always present parallel construction for criminals caught this way?

That's an interesting philosophical question.[1][2] [1] https://en.wikipedia.org/wiki/Burden_of_proof_(philosophy)#P... [2] https://en.wikipedia.org/wiki/Evidence_of_absence

I like you. I tend towards pyrhonism (or maybe I don't!) so I appreciate that response.

Degree of proof is a relative: Maybe a terror organisation use PIA, NSA go fishing for evidence PIA has nothing. Terror org assassinate NSA head. PIA could be a front, but NSA head had to be willing to lose his life to hide the fakery, and terror org wasn't a big enough fish ... more likely you're currently in a coma. Lots of places for false premises to creep in.

Dial it back, is there a point where there'd ever be enough evidence?

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#103

What's the most trustworthy VPN that HN users recommend? My 3 year subscription to my local one is about to run out! Looking for advice on what is trusted nowadays!

I generally trust Mozilla/Firefox and they just released a VPN. It is nice to be able to outsource my VPN research to them as well, since there aren’t many orgs I trust like that. It works well so far.

Firefox is using Mullvad for their VPN product.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#104
post #60
post #51

Earlier quoted context omitted.

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

> I never understood why people working in tech would ever trust a VPN service? It’s not that I trust them but I’d rather some random company across the world has my jerk off logs rather than my ISP who hands my habits to my government and all its favoured cohorts.

For all you know, your government is running that VPN you’re using

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#105
post #51

Earlier quoted context omitted.

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

The only standard you can really trust is when they actually get subpoenaed and don't have anything to give to the court. An example of this is Private Internet Access.

FoxyProxy posted one of their Secret Service subpoenas along with their reply. TLDR; they said they have nothing to give:

https://blog.getfoxyproxy.org/2017/11/04/secret-service-subp...

As for PrivateInternetAccesss / PIA, I would not trust them at all. No one knows who the founders and executives are. After speaking at length with an ex-employee of PIA who now maintains this open-source iOS VPN client,

https://passepartoutvpn.app/

even many (most?) employees and contractors at PIA have no idea of the identify of their direct managers. All work is done remotely and using encrypted chat sessions without video.

PIA is incorporated in British Virgin Islands where apparently shareholders, owners, etc can "enjoy" complete privacy.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#106

What's the most trustworthy VPN that HN users recommend? My 3 year subscription to my local one is about to run out! Looking for advice on what is trusted nowadays!

I generally trust Mozilla/Firefox and they just released a VPN. It is nice to be able to outsource my VPN research to them as well, since there aren’t many orgs I trust like that. It works well so far.

https://vpn.mozilla.org/

I'm barely literate in this area but their site suggests it's just mullvad under the hood. Not that that's a bad thing

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#107

Earlier quoted context omitted.

The only standard you can really trust is when they actually get subpoenaed and don't have anything to give to the court. An example of this is Private Internet Access.

Piggybacking off of this, Private Internet Access (PIA) has actually had their no logging policy "proven in court" via this method multiple times. [1][2] Full disclosure: I work at PIA. [1] https://torrentfreak.com/vpn-providers-no-logging-claims-tes... [2] https://torrentfreak.com/private-internet-access-no-logging-...

I wouldn't trust PIA for anything.

The whole company is shrouded in secrecy. After speaking at length with an ex-employee of PIA who now maintains this open-source iOS VPN client:

https://passepartoutvpn.app/

many (most?) employees and contractors at PIA have no idea of the identify of their direct managers.

Imagine working for a company and not knowing your manager's real name. Now imagine trusting that company with your internet traffic.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#108
post #74

Earlier quoted context omitted.

I trust VPN services for the one thing they're good and useful for: hopping over geo-fences for content. You should not have any expectation of privacy or security from consumer VPN services (if you want that, obtain Tor Browser or Tails as your needs require). They provide a means to choose roughly where your client traffic comes from, and that's it. The rest is marketing bullshit. They're probably sufficient for lo…

Why would I assure myself that Tor is safe either? Do we know for a fact that government agencies don't control the majority of the egress points?

> Do we know for a fact

This always has been and always will be the security rabbit hole. (Well, one of them.)

How do you define "know for a fact"? Even if you personally know a person managing an egress node, how do you know they aren't operating on behalf of someone else?

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#109

Unsecured Elasticsearch, once again. ( https://www.theregister.com/2020/07/17/ufo_vpn_database/ ) So ES has insecure defaults, I get that and it's been discussed to death. But who the heck, in this day and age, exposes clusters directly to internet traffic? I don't care what the defaults or security measures you have. DONT EXPOSE SERVERS. Place them inside a VPC, preferably a private one(in AWS parlance, behind a NAT…

Also, don't use 0.0.0.0/0 in a security group rule!

P.S. Azure has load balancers and security groups too- in fact their security groups are better than AWS's in some ways such as supporting thousands of rules instead of only 50.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#110
post #64
post #18

Earlier quoted context omitted.

I have been using Mullvad for the last few years: https://mullvad.net/en/ I don't have much to base it on but they seem trustworthy, and I've seen them recommended here before.

Why not just use Bitcoin or gift card?

Not the person you're responding to, but bitcoin isn't that anonymous. Much more than a credit card, but less so than cash.
Post reply on HN