Live data from Hacker News

UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

comparitech.com

121–130 of 240 posts

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#121
post #64

Earlier quoted context omitted.

Why not just use Bitcoin or gift card?

Not the person you're responding to, but bitcoin isn't that anonymous. Much more than a credit card, but less so than cash.

Bitcoin ATM/local bitcoin -> sell for monero/mixer -> buy monero.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#122
post #74
post #51

Earlier quoted context omitted.

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

I trust VPN services for the one thing they're good and useful for: hopping over geo-fences for content. You should not have any expectation of privacy or security from consumer VPN services (if you want that, obtain Tor Browser or Tails as your needs require). They provide a means to choose roughly where your client traffic comes from, and that's it. The rest is marketing bullshit. They're probably sufficient for lo…

Is the rest marketing bullshit because of insurmountable technical challenges or is it because you have to __trust__ the VPN service? I.e. if I were to somehow think up a business model that included some novel level of transparency, could I provide a VPN service that could honestly claim to provide privacy and security to its users?

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#123

VPN providers are something you should have especially high standards for. They are largely unregulated, can see all of your meta data and have an economical incentive to sell it (IIRC some big player has been caught doing that). If a provider shows even the slightest amount of fishiness, instantly discard them (NordVPN immediately comes to mind, with their weird influencer marketing campaign).

> VPN providers are something you should have especially high standards for.

We need to implement standards of practice for this, let find a legal head to see how it can be done.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#124
post #99
post #59

Earlier quoted context omitted.

VPNs do have some legitimate uses. Encrypting traffic over malicious networks (e.g. your average airport wifi) is probably the most common one for the average legal user. Getting an IP address in a given country is another sometimes legal use. I honestly don't know if you can do this with your average commercial vpn, but the technology is also good for many things like setting up virtual networks (hence the name) so…

Just how insecure is airport WiFi these days with SSL and HSTS? I don't normally worry about it, and suspect people who still counsel against it of lazy FUD. I'd notice pretty quickly if someone was MITMing all of my traffic. I guess they could MITM a third-party Javascript site that wasn't being served with HSTS. Normally that would just give them all the information I already give to Google or Facebook and the hund…

Personally I don't worry about it, but I wouldn't blame other people for doing so.

A browser is a very complex tech stack and it wouldn't surprise me in the slightest if there were vulnerabilities exploitable with a MITM. An airport would be a natural place to try and attack computers, lots of people with lots of money many of whom are doing things like moving that money around and many of whom won't think twice about connecting to an unsecured public hotspot.

There's also all the other apps on your computer, how frequently do you think electron-app-foo-bar updates it's chrome version and what are the chances it's using one outdated enough that there are known openssl vulnerabilities against it?

I don't think third party non-HSTS traffic is that much of a concern these days, both firefox and chrome block http traffic from https pages by default.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#125
post #51

Earlier quoted context omitted.

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

> how do you measure VPN services? It's pretty difficult. You can't say anything for sure, it's all trust. That's why you should be so strict. When you host your own end point you still have to trust its provider of course, but of course the incentive (concentrated, specific user traffic data) for abuse is much reduced. But how anonymous are you actually? Are you sure your traffic can't be connected to you? Certain y…

If you VPN service, only provide VPN, then a (free tier) AWS server in a foreign country + wireguard would do the same. Sure, AWS could log the outbound traffic for that account, but AWS only has an email address from me, not a credit card like a VPN service. Feels like the exposure is far less.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#126
post #119
post #74

Earlier quoted context omitted.

I trust VPN services for the one thing they're good and useful for: hopping over geo-fences for content. You should not have any expectation of privacy or security from consumer VPN services (if you want that, obtain Tor Browser or Tails as your needs require). They provide a means to choose roughly where your client traffic comes from, and that's it. The rest is marketing bullshit. They're probably sufficient for lo…

I also use my AWS free tier EC2 + wireguard for hopping over geo-fences. It is free, and my traffic is encrypted from my device to the remote EC2 server.

I’ve tried that but all the content providers seemed to know I was using a VPN. Any tips?

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#127
post #81
post #53

Earlier quoted context omitted.

Won't amazon cancel them when they keep getting copyright letters? Or do vpns have some other use I am not aware of.

I use a VPN to keep Comcast from logging and selling my data to third parties. The client is always on and running on my PC.

I do the same, but again using remote AWS (free) servers. Which is funny sometimes, I realize that some website are suddenly in german because I am using my Berlin server, instead of my US one.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#128
post #51

VPN providers are something you should have especially high standards for. They are largely unregulated, can see all of your meta data and have an economical incentive to sell it (IIRC some big player has been caught doing that). If a provider shows even the slightest amount of fishiness, instantly discard them (NordVPN immediately comes to mind, with their weird influencer marketing campaign).

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

> I mean how do you measure VPN services?

- Credit only Word of mouth, but it depends what type of VPN you're looking for. So again, word of mouth these days.

> I never understood why people working in tech would ever trust a VPN service?

-I do, quite a bit actually, I need to connect to another network but region specific.. They are a tool for as you say 'in tech' to work.

> A VPN is seeing all your traffic, and you have to take their word that they do not log any of it?

- At least in Europe that doesn't fly. It does depend on your provider though. Thats why you shop around.

- On this point, I will argue that running your own VPN is better, but so is running your own web hosting. It depends on your priorities.

  > I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.
 
 - Good for you. Enjoy.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#129

I wouldn't trust any VPN under China's sphere of influence.

That's actually not an entirely crazy idea if you're trying to hide from Western governments. Are you more worried about the Chinese government coming after you? Likewise, if someone in China is trying to hide from the Chinese government, it might not be a bad idea to use an USA based VPN. Maybe string up a bunch of VPNs in regions that are at least somewhat hostile to each other and it might be too hard to track an…

What’s stopping China from using your data as a bargaining chip to trade for some data they want from, say, CIA?

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#130
post #51

Earlier quoted context omitted.

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

all of your traffic? Or just insecure DNS/HTTP requests?

All the traffic... but not all the time. At home, if I work, then I use the corporate VPN. Otherwise, no VPN, except when I need to appear like my traffic comes from another country. For instance, I just have (AWS) tiny server in Europe with wireguard. So, easy to switch. I share the servers with my family as we are all scattered around the globe and still like to watch our European shows/replay.
Post reply on HN