Live data from Hacker News

NordVPN sued by Torguard for blackmail [pdf]

torguard.net

101–110 of 164 posts

Re: NordVPN sued by Torguard for blackmail [pdf]

#101

Earlier quoted context omitted.

I'm not sure, their response could be fabricated too. I'm interested in if Torguard has any evidence of them physically approaching their employee. > Within an hour of this in-person and unannounced visit, the same TorGuard contractor received unsolicited correspondence from an employee at NordVPN. This correspondence stated that NordVPN had received certain of TorGuard’s confidential and trade secret information and…

What if I told you that a lot of these "VPN providers" were shell companies built to explicitly facilitate access and tools for crime / espionage with the premise of having users there as cover.

Not something that many HN posters will be familiar with, but if you're a holder of significant pieces of ARIN or RIPE IP space, you'll inevitably be approached by a number of suspicious looking companies that want to "rent" your ipv4 space (by the /24 block) for VPN/proxy usage.

The end result if you actually fall for their bullshit is that your IP space will be listed in every RBL until the end of time, and will have a bottom 5% rank in every IP space reputation/antifraud system until the heat death of the universe.

Every time I've been approached by these clowns, I've spent a cursory 3 to 5 minutes trying to find an actual business behind it (names of real humans, street address that isn't just a mailbox, location of real ISP infrastructure equipment at some real IX points) and failed to find anything resembling a legitimate ISP.

Re: NordVPN sued by Torguard for blackmail [pdf]

#102

Earlier quoted context omitted.

Oh trust me, I'm well aware of "VPN providers". Just checkout luminati.io . See how they offer an SDK so "You can offer the user a choice between advertisements or a bit of background data usage"? I asked, and they are only interested in partners with 100k active users a month. Right, like a legitimate company with that many users is going to use luminati. Or oxylabs.io who I think owns luminati? I'm also aware that…

+1 on ssh + vps. People will say it isn't as anonymous as the shared vpn's and while that is somewhat true, it is still more than sufficient to remove your home IP from logs. Short of scary letters and warrants to the VPS provider, people won't really know who you are. You can also automate the rebuilding of proxy nodes to get new IP's, as most VPS providers have an API for automated rebuilds.

Are there any high quality VPS providers that have a way to sign up and pay anonymously with Monero (or similar), manage via tor browser, etc?

Re: NordVPN sued by Torguard for blackmail [pdf]

#103
I used to be one using and praising ProtonMail, but after the Tesonet scandal turned me around. The worst evidence for me was their responses, how they were constantly calling it a "smear campaign by PIA", often not providing any plausible explanations. Duh, PIA published it and put work into raising public awareness. They are competitors, they found your dirty laundry and published it, duuuuh. Whoever discovered it, doesn't matter, they couldn't respond to the actual facts, only repeating the annoying combination of words "smear campaign". I don't trust a single VPN provider and would rather trust my exit point to my ISP which is regulated by local laws, rather then trusting it to god know whom god knows where. I would be happy to see the issues of Tesonet and their links to NordVPN and ProtonMail/VPN raised again!

Re: NordVPN sued by Torguard for blackmail [pdf]

#104

Earlier quoted context omitted.

Oh trust me, I'm well aware of "VPN providers". Just checkout luminati.io . See how they offer an SDK so "You can offer the user a choice between advertisements or a bit of background data usage"? I asked, and they are only interested in partners with 100k active users a month. Right, like a legitimate company with that many users is going to use luminati. Or oxylabs.io who I think owns luminati? I'm also aware that…

More on how luminati and other "residential ip" providers work here: https://medium.com/@xianghangmi/resident-evil-understanding-...

Wow, very interesting read. Thanks for bringing this to light.

Re: NordVPN sued by Torguard for blackmail [pdf]

#105

Earlier quoted context omitted.

I'm not sure, their response could be fabricated too. I'm interested in if Torguard has any evidence of them physically approaching their employee. > Within an hour of this in-person and unannounced visit, the same TorGuard contractor received unsolicited correspondence from an employee at NordVPN. This correspondence stated that NordVPN had received certain of TorGuard’s confidential and trade secret information and…

Regarding the DDoS part, the claim seems to be that the attacks were based on the secret information NordVPN possessed: "35. The DDoS attacks directed against TorGuard were based upon the Information— the nature and way they occurred and were timed made it patently obvious that the attacker had obtained the Information from Collective 7 and was utilizing it as a roadmap for DDoS attacks."

See that's the first part of the story to me were both stories make a bit of sense. Nord says they discovered a configuration file with IP addresses that still worked.

If those were infrastructure IP's, and not otherwise public, that would certainly make more sense as to how Torguard believes Nord was responsible.

I know they used the timing like Black Friday as evidence that it was a competitor carrying out the attacks, but they have lots of competitors, so I was really confused as to how they settled on Nord as the attacker.

Re: NordVPN sued by Torguard for blackmail [pdf]

#106

Earlier quoted context omitted.

I'm not sure, their response could be fabricated too. I'm interested in if Torguard has any evidence of them physically approaching their employee. > Within an hour of this in-person and unannounced visit, the same TorGuard contractor received unsolicited correspondence from an employee at NordVPN. This correspondence stated that NordVPN had received certain of TorGuard’s confidential and trade secret information and…

What if I told you that a lot of these "VPN providers" were shell companies built to explicitly facilitate access and tools for crime / espionage with the premise of having users there as cover.

[deleted]

Re: NordVPN sued by Torguard for blackmail [pdf]

#107

Earlier quoted context omitted.

+1 on ssh + vps. People will say it isn't as anonymous as the shared vpn's and while that is somewhat true, it is still more than sufficient to remove your home IP from logs. Short of scary letters and warrants to the VPS provider, people won't really know who you are. You can also automate the rebuilding of proxy nodes to get new IP's, as most VPS providers have an API for automated rebuilds.

Are there any high quality VPS providers that have a way to sign up and pay anonymously with Monero (or similar), manage via tor browser, etc?

This here is assuming you don't have a nation state actively trying to track you down. Otherwise see [0]

One option is to use basically any provider + prepaid visa cards. Just access the website over tor or a VPN you semi trust. Sure it's technically traceable but not without a lot of trouble.

Keep in mind that once the VPS provider is issued a subpoena they still have access to your connecting computer's IP. They then have to issue a subpoena to your ISP for your account information. The only way to hide your IP is to use a proxy or a vpn... Oh wait, yeah that's the issue. See [0]

I personally just recommend using whatever you'd like, Vultr, DO, scaleway, etc. Feralhosting isn't anonymous but they uh... don't care what you really use it for cough torrents cough.

[0] If you're REALLY trying to be fully anonymous then you'll need to put on your blackhat. I would start with planting a raspberry pi in a business, library, coffeeshop, etc. You can use that IP as a starting point. You won't want to use only that one IP most likely, so you're going to need more proxies/servers, most common method is botnets. This really isn't worth the trouble to 99.9999% of people.

Edit: I guess I'm estimating there are ~7,000 people in the world who it's worth the trouble to do.... Actually that might be accurate, cool! :D

Re: NordVPN sued by Torguard for blackmail [pdf]

#108

Earlier quoted context omitted.

Oh trust me, I'm well aware of "VPN providers". Just checkout luminati.io . See how they offer an SDK so "You can offer the user a choice between advertisements or a bit of background data usage"? I asked, and they are only interested in partners with 100k active users a month. Right, like a legitimate company with that many users is going to use luminati. Or oxylabs.io who I think owns luminati? I'm also aware that…

More on how luminati and other "residential ip" providers work here: https://medium.com/@xianghangmi/resident-evil-understanding-...

Looks like Luminati is also explicitly getting developers to put a luminati proxy client into their apps and have users opt into using that instead of getting fed advertisements.

https://luminati.io/faq

Between your link, and the luminati faq's, I definitely have more questions then when I started looking at these articles.

Re: NordVPN sued by Torguard for blackmail [pdf]

#109

Earlier quoted context omitted.

Are there any high quality VPS providers that have a way to sign up and pay anonymously with Monero (or similar), manage via tor browser, etc?

This here is assuming you don't have a nation state actively trying to track you down. Otherwise see [0] One option is to use basically any provider + prepaid visa cards. Just access the website over tor or a VPN you semi trust. Sure it's technically traceable but not without a lot of trouble. Keep in mind that once the VPS provider is issued a subpoena they still have access to your connecting computer's IP. They th…

I've tried using prepaid cards with VPS providers and only found one that still took them (as of a couple years ago). Most won't take gift cards (prepaid visa) any more.

Re: NordVPN sued by Torguard for blackmail [pdf]

#110

Earlier quoted context omitted.

More on how luminati and other "residential ip" providers work here: https://medium.com/@xianghangmi/resident-evil-understanding-...

Looks like Luminati is also explicitly getting developers to put a luminati proxy client into their apps and have users opt into using that instead of getting fed advertisements. https://luminati.io/faq Between your link, and the luminati faq's, I definitely have more questions then when I started looking at these articles.

Luminati didn't start off like that. They started by burying what they were doing in a "free" vpn.

I asked, and they are only interested in partners with 100k active users a month. They REALLY REALLY wanted to talk to me over skype. Right, like a legitimate company with that many users is going to use luminati.

The use case of luminati is almost entirely grey/black hat. Their history is laughably sketchy. Unless anybody knows of any apps that use the SDK and ask for permission, I suspect that FAQ page is just for show. Again you have to be a big player to even use it, it's not a stretch to believe they don't "enforce" the consent rule.

Post reply on HN