Live data from Hacker News

UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

comparitech.com

131–140 of 240 posts

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#131
Oeck claims no-logs and details how they've achieved that (they don't even have hard drives). Support is responsive, you'll be responded to by those who actually built the platform. They're planning support for WireGuard.

Unfortunately they have admins in Australia which has some pretty hefty laws similar to those in the US (look at gag-orders issued, and recent responses to media outlets for publishing vetted and leaked data). You can find their intro post in Whirlpool forums.

They configure a PXE and have a system in place for distributing the OS in each region (and thus each data center).

For debugging issues they try to replicate things on a local environment and my assumption is if there's any networking issues, they likely have a node on the same data center they can remote to, to test connectivity issues - however functional issues require replication locally. No SSH access to the box.

So I think for now, Oeck or Mullvad are good choices. I only wish these services did 1 thing differently - and that is, release a live video stream of their server farm's rack and video-document the entire process of compiling and shipping their hardware, as well as the systems in place for loading the OS to ensure no exfiltration data from malicious services or agents on the box.

This could be done relatively cheaply - I'm surprised none of the VPN providers have yet. A fish-eye lens attached to a webcam on a rack would be cheap to install. It's the closest thing we have to proof a VPN server hasn't been owned without a zero-day. If you're using up-to-date services, a LEO, government or APT using a zero-day to own your server is really the only means of exfiltrating user data in this environment.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#133
post #119

Earlier quoted context omitted.

I also use my AWS free tier EC2 + wireguard for hopping over geo-fences. It is free, and my traffic is encrypted from my device to the remote EC2 server.

I’ve tried that but all the content providers seemed to know I was using a VPN. Any tips?

Weird... I did the test, and clearly I cannot watch shows on European TV website, and when I select one of my European server, then I can watch the shows. Something must be off with your setting.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#134

Earlier quoted context omitted.

Running your own VPN provides no privacy, since you're the only user. Of course other VPNs don't provide privacy either. The belief that they do is due to marketing, and misunderstanding what the "Private" part of VPN means: it means that two non-publicly routable IP networks (10/8, 172.16/12, 192.168/16) are virtually joined into one network. VPN companies took advantage of this (and that the connection is usually e…

This is such a deeply misleading statement. Privacy fundamentally is about keeping things private ... from someone . If that someone is everyone, then nothing is private. Any sufficiently powerful entity can just overpower you, torture you into submission, guarantee a backdoor into a system you thought was cryptographically private, etc. I for one do pay for a VPN service, because it keeps my home traffic stream priv…

Right, I overspoke. It provides no extra privacy, against anyone except your ISP. If they're the threat, AND you're able to safely assume that the VPN provider is less of a threat, THEN it provides some privacy.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#136
post #133

Earlier quoted context omitted.

I’ve tried that but all the content providers seemed to know I was using a VPN. Any tips?

Weird... I did the test, and clearly I cannot watch shows on European TV website, and when I select one of my European server, then I can watch the shows. Something must be off with your setting.

It depends on the service. Not everyone does it, but many services ban the Amazon, Azure, Google, DO, and many other AS sources simply because they won't originate "normal user" traffic.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#137
post #51

Earlier quoted context omitted.

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

The only standard you can really trust is when they actually get subpoenaed and don't have anything to give to the court. An example of this is Private Internet Access.

Until they introduce some technical measures to provide some degree of anonymity to clients (of the paid service, of all things), all VPN providers should be treated the same way. They share the same business model of making money by selling kindergarten grade technical service and promises of “security” to the same crowd of clueless people by the same methods that include widespread misleading advertising, and now you tell me that some of those are actually freedom warriors.

Essentially, you describe that they provide bulletproof hosting (or network access), and no one does anything to deal with them. Simply because they are a VPN provider. And reply to officials with “Sorry, we have no data”. That's hard to believe.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#138
post #99
post #59

Earlier quoted context omitted.

VPNs do have some legitimate uses. Encrypting traffic over malicious networks (e.g. your average airport wifi) is probably the most common one for the average legal user. Getting an IP address in a given country is another sometimes legal use. I honestly don't know if you can do this with your average commercial vpn, but the technology is also good for many things like setting up virtual networks (hence the name) so…

Just how insecure is airport WiFi these days with SSL and HSTS? I don't normally worry about it, and suspect people who still counsel against it of lazy FUD. I'd notice pretty quickly if someone was MITMing all of my traffic. I guess they could MITM a third-party Javascript site that wasn't being served with HSTS. Normally that would just give them all the information I already give to Google or Facebook and the hund…

I’d be more concerned about other stuff, which a vpn doesn’t solve. Look up SMB relay attacks, netbios, and Responder. An average win10 laptop will disclose creds to anyone

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#139

Unsecured Elasticsearch, once again. ( https://www.theregister.com/2020/07/17/ufo_vpn_database/ ) So ES has insecure defaults, I get that and it's been discussed to death. But who the heck, in this day and age, exposes clusters directly to internet traffic? I don't care what the defaults or security measures you have. DONT EXPOSE SERVERS. Place them inside a VPC, preferably a private one(in AWS parlance, behind a NAT…

Also, don't use 0.0.0.0/0 in a security group rule! P.S. Azure has load balancers and security groups too- in fact their security groups are better than AWS's in some ways such as supporting thousands of rules instead of only 50.

Azure can even configure mutual authentication between the LB & the underlying servers, which would cause any direct server access to result in a 401[0].

0 - For API servers. I'm not sure if you could configure this with services like Elasticsearch.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#140
post #79
post #51

Earlier quoted context omitted.

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

You can chain several unrelated VPN providers.

To elaborate on this a bit:

* You only need two VPNs assuming you just want to protect against either of them linking your browsing history back to your identity and selling that information.

* The second one must be paid for in a reasonably anonymous manner (ex Bitcoin) and only ever accessed via the first VPN in the chain.

* You're fine to pay the first one in a more traditional manner.

* The two providers must be completely unrelated.

* It is highly preferable that the two providers be in different legal jurisdictions (both from each other and yourself).

* This won't protect against a highly motivated criminal investigation.

Post reply on HN