Live data from Hacker News

PIA VPN to be acquired by malware company founded by former Israeli spy

telegra.ph

341–350 of 381 posts

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#341

For anyone displaced from their VPN by this... Not mine, but another HN user made a tool to automatically create a VPN instance on your choice of cloud provider. https://github.com/trailofbits/algo

And what good does setting up your own VPN instance do? Now people will be able to trace every single bit of your traffic back to your cloud instance and thus to you. The idea of signing up for a VPN provider like PIA or Mullvad is precisely that it's not a personal VPN and you get to hide among the masses / their other customers.

There are many different reasons to use a VPN. Some are legal, some are privacy-related and some are just getting access to sites that are otherwise blocked.

I think your most common reason for using a VPN would be very different based on living in Russia, Sweden, USA and China.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#342
post #61
post #14

Disappointed. I've been with PIA for a few years now and I always recommended them and loved their support. I just cancelled my annual subscription which was due to expire in 100 days. Vote with your wallet. Any recommendations for a new VPN provider?

Get a VPS and run a VPN client to it and/or run Tor. VPN providers suffer adverse selection, catering to powerless customers who don't have their own data centers, but have something to hide. And they know who you are, which Tor exit nodes don't. That makes them juicy targets for spies, not all of whose compromises will be as obvious as a financial takeover.

VPNs are a complete red herring placebo, promoted intentionally to distract you from TOR. TOR is one of the only legitimate anonymizing technologies.

Connecting to your own VPN on a VPS is miles better than a retail VPN service, but even for that I wonder what threat model it serves.

• You can ban outgoing unencrypted network traffic without a VPN (a VPN doesn't solve this either btw).

• You can use DNS-over-TLS without a VPN; that solves a big part of traffic analysis.

• If you only have one VPS and only ever connect through that one tunnel, all you accomplished was moving your effective IP to another place. Oh, and you added an extra counterparty in the middle.

The utility of VPNs is, almost as a dumb proxy, to patch malicious/missing functionality from your first-party connection, e.g.: you live in a country that bans IP ranges outside of its borders, your ISP bans BitTorrent traffic, or your ISP is more cooperative with LEO than your VPN provider is. This has nothing to do with anonymization. The VPN or VPS knows who you are.

It's a confusion between privacy and anonymity.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#343
post #116

Earlier quoted context omitted.

Thank you for taking time to explain your position. I can appreciate the need for resources and why you think this deal is the right thing to do for your company. I've trusted you company enough to use it for years and buy a multi-year subscription. Unfortunately, given the track record of Kape, I can't trust the bundle of Kape+PIA the way I trusted PIA alone. Maybe in the following years this trust will be accumulat…

If you think a platform is responsible for what their developers do with it, then I understand. However, Kape was never directly involved in adware other than providing SDKs that let developers create positive and negative things. To say Kape was involved in adware would be akin to saying the Wright Bros killed millions of people - because they made planes which people used to kill people (which is simply untrue). Ev…

I think there's a difference between providing a generic SDK and providing specific targeted SDK. E.g. if you made libstdc++, nobody is going to blame you for every C++ program using it. But if you made specific malware with specific exploit for a specific vulnerability, and people use it to take over other systems, you may share the blame - even if you yourself never used it. In the latter case, you'd be known as "malware vendor" and your trust profile would be set accordingly. I think this is close to the case for Kape. They targeted specific market with specific product. Now, it's completely their right, nothing illegal, but as well it is my right to stay away from people who are into certain markets and certain business models.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#344
post #189

Earlier quoted context omitted.

If you think a platform is responsible for what their developers do with it, then I understand. However, Kape was never directly involved in adware other than providing SDKs that let developers create positive and negative things. To say Kape was involved in adware would be akin to saying the Wright Bros killed millions of people - because they made planes which people used to kill people (which is simply untrue). Ev…

Did CrossRider have any honest users? From the little I can find on the Internet it seems like a toolkit for building adware with little to no honest uses.

Small correction - I don't think building adware - as long as it's not hidden, not doing clickfraud, etc. - is necessarily dishonest. It's just not the business which you want to be owning your VPN. Just as cheap used car dealership is not necessarily dishonest, but that's probably not where you want to get your banking or medical service.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#345

Earlier quoted context omitted.

This company has no association with the Israeli intelligence whatsoever. Many, many of the Israelis involved in the technology world have served in the IDF Intelligence Corps (being that Israel has mandatory conscription and the intel corps select the best and brightest).

>This company has no association with the Israeli intelligence whatsoever. And then... >My assertion is that companies are not automatically related to the Israeli intelligence even if their founders came from its ranks. It takes decisive contrarian proof to convince me otherwise. Why were you so convinced that there is no association? Maybe there is, maybe there isn't, but what we _do_ know is that the CEO is an ex…

Right, and there are lots of VPNs.

So why use one with anything iffy about it?

However, I gotta say that it's complicated for PIA. There's past evidence of being unable to produce logs for criminal investigators. And now there's the purchase by a firm with an iffy reputation.

However, there's the possibility that said firm was exploited by malware pushers, and not intentionally pushing malware. But still, that's evidence of incompetence, which is also not a good thing for a VPN provider.

And then the CEO's association with Israeli intelligence.

So anyway, it is complicated. But it seems most prudent to wait and see.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#346
I’ve been using PIA for years. Chose them over others because they were more well known and larger, which to me meant they’d be less susceptible to having to enter into shady activity. I’m trusting them with my traffic, after all. This one doesn’t sit well with me, it feels like a betrayal of trust. They have to know that people who signed up to use their service wouldn’t be okay with something like this if it’s as shady as it sounds. Good thing it’s still cyber Monday, I think there might be a few VPN deals going around. Maybe it won’t hurt to to try my luck with one of those.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#347

Earlier quoted context omitted.

>This company has no association with the Israeli intelligence whatsoever. And then... >My assertion is that companies are not automatically related to the Israeli intelligence even if their founders came from its ranks. It takes decisive contrarian proof to convince me otherwise. Why were you so convinced that there is no association? Maybe there is, maybe there isn't, but what we _do_ know is that the CEO is an ex…

Right, and there are lots of VPNs. So why use one with anything iffy about it? However, I gotta say that it's complicated for PIA. There's past evidence of being unable to produce logs for criminal investigators. And now there's the purchase by a firm with an iffy reputation. However, there's the possibility that said firm was exploited by malware pushers, and not intentionally pushing malware. But still, that's evid…

Sure, we'll see, but in the meantime I likely won't take the risk.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#348
post #326
post #104

Earlier quoted context omitted.

Using a VPN is only one piece of maintaining privacy online. It doesn't eliminate the need for end-to-end encryption when dealing with material you wouldn't want third parties to have access to.

A VPN doesn’t maintain any privacy, all it does is switch which set of snoops are monitoring your traffic.

If you're using end-to-end encryption, it doesn't matter that your traffic is being monitored (I mean, that's an oversimplification, as the presence of large amounts of encrypted traffic is notable in itself, but that's outside the scope of this comment).

A VPN is useful in settings where you're dealing with a malicious ISP (for instance, ones that hijack unencrypted HTTP sessions to inject their own HTML) or any untrustworthy third party network. Do I trust my VPN provider more than my ISP? Yes. Do I trust my VPN provider unconditionally? No. That's what end-to-end encryption is for.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#349
post #219
post #217

Earlier quoted context omitted.

I used crossrider at an earlier startup and migrated from it when I could stop supporting IE. It worked pretty well when it worked for cross browser extensions. Our product (TipRanks) brought financial accountability to the market and it was a paid product. Our business model was just plain SaaS. While I am no longer there I think it's a decent and mostly honest company

Thanks for the reply. Did you have any issues with your extension being caught by malware removal programs?

It was misclassified once by an anti virus program. When we asked why they said that it was a known bug when using WinAPI APIs in BHOs (IE extensions)

They fixed it pretty soon. It was also a motivation to drop IE support (and crossrider) but we were mostly happy with them.

Re: PIA VPN to be acquired by malware company founded by former Israeli spy

#350

Is there some sticky mechanism going on here or how is that raengan comment so far on top even with all those comments disagreeing with the content of it?

I'm just a casual HN reader, but my understand is that the up vote button is not to be used as an "I agree" button but rather as a "This is relevant to the conversation" button. That being said, as the comment is by a cofounder of PIA, it is extremely relevant regardless of opinion about this situation.

I'm a regular reader of HN and Reddit and this is not working on Reddit and this would be the first time I see it working anywhere with such a voting system.

You see it often enough here on topics where the overall "circlejerk" is strong and see relevant comments disappear at the bottom.

If you consider how posts are being kept up on the frontpage here, I rather go for the sticky/mod action theory.

Post reply on HN