Live data from Hacker News

PIA VPN to be acquired by malware company founded by former Israeli spy

telegra.ph

311–320 of 381 posts

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#311
post #279

Earlier quoted context omitted.

This is exactly my rationale. The fact that you have to explain that the company that bought you is not shady is writing on the wall, even if you have a good explanation. For the record, I think the explanation is pretty decent. But PIA is a commodity product from a technical perspective. It's the trust and reputation that's not the commodity, and being bought by a shady company ( even if it's "formerly shady") you d…

Trust is a fleeting concept. If you used PIA only for the trust and not for the verifiable transparency, then we have failed you. You can't trust some random VPN on internet. Anyone could have set it up. You can only verify. Don't trust. PIA will continue on its mission to increase transparency and set a new standard and expectation in the industry. With PIA, we will make sure you know what you're getting. Some may c…

How do you propose we verify the transparency? I legitimately have no idea how I can verify what specifically is running on your servers.

It seems to me that the entire VPN industry has a huge inherent information asymmetry since it is incredibly difficult for an end consumer to confirm any claims a provider makes about the quality of their product. Economic theory tells us that results in a market for lemons [1]. We just end up with a bunch of low price and low quality products provided by shady companies because it simply isn't cost effective to compete against those options with a quality product whose quality can't be verified. For a technically savvy end user, you are probably better off rolling your own VPN with open source software you compile yourself rather than trusting any of these black box VPN providers.

[1] - https://en.wikipedia.org/wiki/The_Market_for_Lemons

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#312
post #279

Earlier quoted context omitted.

This is exactly my rationale. The fact that you have to explain that the company that bought you is not shady is writing on the wall, even if you have a good explanation. For the record, I think the explanation is pretty decent. But PIA is a commodity product from a technical perspective. It's the trust and reputation that's not the commodity, and being bought by a shady company ( even if it's "formerly shady") you d…

Trust is a fleeting concept. If you used PIA only for the trust and not for the verifiable transparency, then we have failed you. You can't trust some random VPN on internet. Anyone could have set it up. You can only verify. Don't trust. PIA will continue on its mission to increase transparency and set a new standard and expectation in the industry. With PIA, we will make sure you know what you're getting. Some may c…

Much like a conflict of interest, appearance of mistrust is akin to mistrust. You are associating with groups that have demonstrated minimal trust and ethics and allowed abuse of their platform. Worse than that, you are passing you business, product, and any existing or future data to a mistrusted group. I won't be part of that transition.

You intentionally placed your product in the hands of this group knocking your own reputation down several pegs below competitors if not out of the picture entirely. Lip service won't win me back.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#313
post #279

Earlier quoted context omitted.

This is exactly my rationale. The fact that you have to explain that the company that bought you is not shady is writing on the wall, even if you have a good explanation. For the record, I think the explanation is pretty decent. But PIA is a commodity product from a technical perspective. It's the trust and reputation that's not the commodity, and being bought by a shady company ( even if it's "formerly shady") you d…

Trust is a fleeting concept. If you used PIA only for the trust and not for the verifiable transparency, then we have failed you. You can't trust some random VPN on internet. Anyone could have set it up. You can only verify. Don't trust. PIA will continue on its mission to increase transparency and set a new standard and expectation in the industry. With PIA, we will make sure you know what you're getting. Some may c…

Speaking for myself, you have indeed failed me. Before I read your comment, I had now idea that PIA offered "verifiable transparency". I still do not know what you mean by that phrase and how I as a mere user can even begin to verify your transparency.

I did use PIA for the trust, I lost that trust and I will therefore stop using PIA.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#314
post #279

Earlier quoted context omitted.

This is exactly my rationale. The fact that you have to explain that the company that bought you is not shady is writing on the wall, even if you have a good explanation. For the record, I think the explanation is pretty decent. But PIA is a commodity product from a technical perspective. It's the trust and reputation that's not the commodity, and being bought by a shady company ( even if it's "formerly shady") you d…

Trust is a fleeting concept. If you used PIA only for the trust and not for the verifiable transparency, then we have failed you. You can't trust some random VPN on internet. Anyone could have set it up. You can only verify. Don't trust. PIA will continue on its mission to increase transparency and set a new standard and expectation in the industry. With PIA, we will make sure you know what you're getting. Some may c…

The PIA clients are closed source, and can't be verified. (They also run as root....)

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#315
post #133

Earlier quoted context omitted.

>The merger between Kape and PIA affords PIA the resources needed to bring privacy to the mainstream. You were one of the most, if not the most successful VPN provider for years. Did you really need more resources? For what? The main benefit of PIA is the expectation for extra privacy. No matter how you look at it, selling to Kape is a strong signal that's not a priority. Similar, for hiring Karpeles to do your secur…

> Similar, for hiring Karpeles to do your security (like he hasnt lost us enough already). Wait... What?!! I just had to look this up[0]. How did I miss this news? Now... I'm all for second chances in general, but there need to be limits, and my understanding of the MtGox case, is that on top of being responsible for terrible security practices, Karpales lied about the intrusions. I was actually kinda on the fence be…

Mark Karpeles defrauded a customer in France before he bought MtGox and moved to Japan. He was found guilty of fraud when tried in absentia because he skipped town and left. When MtGox was hacked and the hot wallet was wiped out, Mark didn't even bother to stop using a known compromised hot wallet. Over 3 years he never bothered to ever rotate keys for the hot wallet, even though he already knew it was compromised when it was wiped out in the original hack. Mark publicly touted how MtGox was using cold storage for 95% of all Bitcoins in MtGox at all times and that the keys for those Bitcoins were secured such that you needed to compromise two out of three geographically separate locations in order to rob the cold wallets. None of that was true, and Mark knew that the exchange was insolvent from the day he bought it.

https://bitcointalk.org/index.php?topic=23938.msg1177353#msg...

His solution to the problem was to make a trading bot with an innovative new strategy of "buy high, sell low". That trading bot was something that he publicly denied multiple times and it wasn't funded with Bitcoins or dollars to trade, it just made trades without having any funds allocated to begin with. Even ignoring that the deposited funds were stolen the exchange didn't have any hope of being able to be solvent because the Willy bot just added funds to the exchange out of thin air. The charitable interpretation of Marks actions is that he was too incompetent to even realize that his trading bot was losing mountains of cash and too incompetent to realize that he was always draining cold wallets but never filling them back up and too incompetent to ever bother to run "SELECT SUM(BTC) FROM accounts". The only BTC left on the exchange was the cold wallet that was discovered afterwards because Mark Karpeles was so incompetent and cavalier with customer funds that he quite literally forgot about one of the cold wallets lying around with 200,000 BTC in it. If he hadn't forgot about that wallet, he would have kept dumping it in the hot wallet to let the thief siphon off and push the scam out another 6 months before it collapsed. Even at the point that withdrawals were frozen entirely and all of the money that Mark knew about was gone he still was spouting off B.S. about how it was transaction malleability, it's not our fault, your money's not gone we just have to fix this bug, etc.

PIA's business is built on trust and rasengan decided to hire Mark Karpeles as their CTO. I honestly can't think of anyone who I would trust less as a CTO than Mark Karpeles. I'm not being sarcastic, I genuinely can't think of someone as bad as Mark for a role like CTO. There's not a chance in hell that I'm going to give PIA another cent based on that alone, even ignoring the most recent Kape debacle.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#316
post #314

Earlier quoted context omitted.

Trust is a fleeting concept. If you used PIA only for the trust and not for the verifiable transparency, then we have failed you. You can't trust some random VPN on internet. Anyone could have set it up. You can only verify. Don't trust. PIA will continue on its mission to increase transparency and set a new standard and expectation in the industry. With PIA, we will make sure you know what you're getting. Some may c…

The PIA clients are closed source, and can't be verified. (They also run as root....)

You can manually set up the VPN connection with the OpenVPN client, NetworkManager, etc etc

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#317
post #260
post #4

This article and articles like this miscast Kape in an incorrect light. To be clear, in the past the company was known as CrossRider and provided a developer SDK that could be used to integrate with browsers. Unfortunately, CrossRider didn't do enough to prevent malware (like platforms these days and their fake news) and the platform was used by some bad people for bad purposes. When the new management team of CrossR…

Maybe. But I won't risk it.

That is exactly where I'm at also. I have recommended PIA to countless others. I will now wait and see if PIA is still the tool that it was before the acquisition.

Unfortunately for PIA, Kape has done nothing to gain my trust and has done multiple things to erode it. This is an uphill battle for PIA.

Good luck!

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#319
post #279

Earlier quoted context omitted.

This is exactly my rationale. The fact that you have to explain that the company that bought you is not shady is writing on the wall, even if you have a good explanation. For the record, I think the explanation is pretty decent. But PIA is a commodity product from a technical perspective. It's the trust and reputation that's not the commodity, and being bought by a shady company ( even if it's "formerly shady") you d…

Trust is a fleeting concept. If you used PIA only for the trust and not for the verifiable transparency, then we have failed you. You can't trust some random VPN on internet. Anyone could have set it up. You can only verify. Don't trust. PIA will continue on its mission to increase transparency and set a new standard and expectation in the industry. With PIA, we will make sure you know what you're getting. Some may c…

if you are really all about transparency then would you like to explain why someone from your company was caught red handed trying to smear other VPN providers?

https://i.imgur.com/xg52ous.jpg

https://www.reddit.com/r/sevengali/comments/9dgexs/why_to_av...

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#320
post #146

Earlier quoted context omitted.

Vodafone runs a large vpn, and I know from the people who sell them logging services they are obligated by the governments of multiple nations to keep url logs for a number of months that vary depending on the target's information retaining laws.

Mullvad on the other hand does not log anything at all (other than their Stripe payments where they try to keep data minimal). Is that in violation of the Swedish law? Maybe, but as long as one of the medium sized ISPs, Bahnhof, is still fighting the law in court I cannot foresee any court cases against small fry like Mullvad or any of the other Swedish VPN providers.

>but as long as one of the medium sized ISPs, Bahnhof

An ISP named themselves "train station"?

Post reply on HN