Live data from Hacker News

PIA VPN to be acquired by malware company founded by former Israeli spy

telegra.ph

241–250 of 381 posts

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#241
post #42

Earlier quoted context omitted.

Changing of ownership fundamentally resets the trust we all had in PIA, which was due to you having proven in court you deliver on what you declare. And in the VPN world, trust is fundamental. I am still surprised you didn't see this coming.

I think an increase in ownership base fundamentally makes it easier to trust an entity, especially in a public company setting where transparency is a must. Rather than trusting 1/1 owner of a company you just need to trust 1/n with significant control. The original PIA group will maintain significant control.

This is entirely backward from actual security principles.

Any increase in the number of people involved in a security related decision multiplies the chance that bad decisions/compromises will happen.

Cf the definition of compartmentalization.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#242

Earlier quoted context omitted.

> When they advertise that they have hundreds of servers in a dozen or so countries... ... they're often lying. In particular, servers in exotic locations are almost always the result of "creative" routing, and are physically located in a more standard country. https://restoreprivacy.com/vpn-server-locations/

Could anyone who's more familiar with routing than me explain how these "virtual locations" work at a technical level? As far as I understand the VPN companies in question don't maintain boxes at those locations and an Azerbaijani IP address for instance literally gets routed to a machine in the UK. How is this possible? I always thought that IP addresses were tied to the location assigned to them by ICANN / regional…

You register as ISP with e.g. RIPE, buy some IP blocks from an ISP in the country you want to pretend to be in, and then announce them via BGP from your actual location.

Due to IPv4 shortage, we're actually seeing a lot of chinese and european companies buying IP addresses in AFRINIC space, from african ISPs, and using them in their own countries.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#243
post #4

This article and articles like this miscast Kape in an incorrect light. To be clear, in the past the company was known as CrossRider and provided a developer SDK that could be used to integrate with browsers. Unfortunately, CrossRider didn't do enough to prevent malware (like platforms these days and their fake news) and the platform was used by some bad people for bad purposes. When the new management team of CrossR…

Here's an idea or two.

Wireguard. Stop sitting on your hands complaining about how wireguard isn't mature, and support it with the generic native apps (now there's even a (beta) windows client). The network address selection issue requires engineering effort, but wireguard itself is most likely not going to address that soon, because it's designed to be a minimal vpn codebase, so why don't you engineer a solution yourself? Or use NAT like nordvpn apparently does.

Explicit stock OpenVPN support. You kind of do this, but it's still difficult or off-putting for non-technical users to figure out which config to grab and how to install the stock client. On your setup page, make sure you're providing a link to the stock (windows) openvpn client and install instructions for Mac and major linux distros, so that people who don't trust your binary blob installer can use the generic one (minus all the fancy stuff like pretty config for auto-selection of endpoint, showing port number, DNS and kill switch things). Make sure to provide sample configs that are up to date and usable.

Nobody has to trust your software if you make it easy to use a generic client instead.

I realize Wireguard is tricky because it doesn't have ephemeral net address selection built into the protocol, but can you please just get that support done? What is your dev team doing if they're not doing that? They don't have to maintain openvpn, unless continually tweaking the custom UI is their prime focus. I'm tired of OpenVPN's instability and risk from its gigantic codebase. I don't care if wireguard has lurking bugs that make it insecure against the NSA. The NSA is not my threat model. You can support wireguard while cautioning everyone that you don't trust it as much as openvpn, and then let them make the choice based on how much they trust you, how much they trust wireguard, and how much they trust Matthew Green's audit of openvpn.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#244

Earlier quoted context omitted.

His LinkedIn indicates that he was a developer in the unit that created the Student Virus... Spy has a broad definition but it probably fits for a SigInt developer in the Israeli military.. https://en.wikipedia.org/wiki/Unit_8200

Stuxnet was created by the NSA in a joint operation with 8200. And yes there are 50,000 ex-8200 alumni, so calling all of them spies is kind of absurd

Calling them spy may be wrong, but I certainly won't ever work with, or use technology made by people who worked for an intelligence agency. That's something over which I'd also terminate friendships.

And many people have a similar mindset, so it's understandable to report this information, and make consumer choices based on it.

That said, Israel should probably consider solutions like other countries with mandatory military service have, e.g. in Germany (until it stopped being mandatory) it was possible to avoid military service by spending the exact same time instead working in social services, e.g. hospitals, daycares, retirement homes, etc.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#245
post #193

Earlier quoted context omitted.

Start here (from Simon Davies, the founder of Privacy International): http://www.privacysurgeon.org/blog/incision/how-the-online-g... They are as bad as, and often indistinguishable from, the least salubrious corners of online advertising in their tracking and data gathering. Unfortunately their determination to keep feeding off addicts and keep tracking the whales is what has driven their data abuses. Responsible ga…

As someone who has worked in the online gambling industry I can say that this article is very outdated and on some points misinformed. Things have changed a lot since 2010, and he is wrong even about how things worked back then. > It is routine for sites to demand the transmission of passport and credit card scans, drivers licenses, utility bills and other personal documents. All the available evidence indicates that…

What you're forgetting to mention is that none of the "improvements" is due to the industry itself. ALL of it has come from government regulation and threats from legislators to ban online gambling unless the casinos clean up their act.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#246

Earlier quoted context omitted.

> Did you really need more resources? For what? Yes, to bring freedom thru privacy to people, The coming battle against privacy and free speech is by far the strongest and worst yet; the narrative and our voices are quickly getting quashed. Without the ability to communicate privately and speak freely, at best democracy is at risk; and at worst, humanity, or what it has meant to be human until now, itself may be at r…

* a battle hardened fraudster. Failure is not the fastest way to learn when that failure is achieved through fraud. I was on the verge throughout all of these news, but now finding out about you hiring Karpeles and now reading how you defend it really made me cancel all the subscriptions and never come back again.

Agree. People that have no ethics or integrity tend to always revert to mean. People that I know that sell harmful products seem to have an uncanny ability to find ever more harmful ways of profiting.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#247
post #165

Earlier quoted context omitted.

> Did you really need more resources? For what? Yes, to bring freedom thru privacy to people, The coming battle against privacy and free speech is by far the strongest and worst yet; the narrative and our voices are quickly getting quashed. Without the ability to communicate privately and speak freely, at best democracy is at risk; and at worst, humanity, or what it has meant to be human until now, itself may be at r…

So what exactly is the gameplan, how are you going to change the world by selling your stake?

Great question.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#248

Earlier quoted context omitted.

How can users verify that PIA doesn't log?

You can only infer that as the result of court case demanding logs. And even then, it would have to be born out of the discovery process that PIA was truthful, in my opinion. Yet that only gives you comfort that they hadn't maintained logs up to that point. You have no guarantees from that point forward, which is what we're all concerned about. We aren't concerned about PIA's past operations, but rather what this new…

Or they claim no logs in court cases while making them anyways. Thereby creating cover.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#249

Earlier quoted context omitted.

Stuxnet was created by the NSA in a joint operation with 8200. And yes there are 50,000 ex-8200 alumni, so calling all of them spies is kind of absurd

Calling them spy may be wrong, but I certainly won't ever work with, or use technology made by people who worked for an intelligence agency. That's something over which I'd also terminate friendships. And many people have a similar mindset, so it's understandable to report this information, and make consumer choices based on it. That said, Israel should probably consider solutions like other countries with mandatory…

Spoiled brat living under Uncle Sam's protection feels entitled to give advice to non-effete countries whose armies have actually seen combat since the 1940s.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#250

It's not just PIA. Nord VPN, ProtonVPN, etc all have ties to or owned by shady companies. It you want real anonymity, use tor. If you want to change your internet access location, lease a VPS, and set up OpenVPN/Wireguard on it.

ProtonVPN? i thought they are privetly owned.

That's correct, ProtonVPN is not affiliated or related to any other company. ProtonVPN AG (Switzerland) is a 100% wholly owned subsidiary of Proton Technologies AG (Switzerland), which also develops ProtonMail. All of this is in public record at the Swiss commercial register: http://ge.ch/hrcintapp/externalCompanyReport.action?companyO...
Post reply on HN