Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

71–80 of 281 posts

Re: VPN – Very Precarious Narrative

#71
post #29

Earlier quoted context omitted.

> It does not permit the ISP to give subscriber information to the copyright holder directly unless ordered to do so by a court. With honest VPNs, court orders won't yield anything.

Sure. OP is still pulling that claim out of his nether regions, though

You've researched this topic more than me. My citation is just knowing lots of people who have received the warning notices and concluded (quite reasonably IMO) that their ISP and/or government is more interested in the rights of copyright holders than those of their customers / citizens and sought solutions to that problem through VPN services.

The point of my post was not about this particular legal issue but about the general fact that ISP choice being largely limited by physical location means that it is easier to choose VPN providers that have interests more aligned with mine than ISPs. Whether ISPs are forwarding threatening letters from copyright holders or giving them contact information directly is not particularly germane to this point.

Re: VPN – Very Precarious Narrative

#72

I have kind of a lot of issues. First, the downplaying of IP location lookups. If you do a lookup on my home IP address, it'll get you within 5 miles of my house. From there, the only other information you need is my name and potentially one or two more details like a birthday (easy, I use my real name online) and you can get access to my voting data -- and that'll give you an actual address, not just a zip code. OP…

Why would everyone have to move to Tor? It already works, and the are good solutions for securely running it, like whonix. (Much better than just Tor browser alone, which is still necessary.)

Compare that to random commercial VPN app...

Re: VPN – Very Precarious Narrative

#73

Earlier quoted context omitted.

> They can be forced to log There is no legislation in the US that can be used to do this [1]. Some very misguided companies may voluntarily log, but those that care about privacy or, at the least, realize that holding people's data is a liability, won't make poor decisions like that. [1] https://en.wikipedia.org/wiki/Data_retention#Failed_mandator...

Oh come on now. The US Government forces tech companies to share information all the time. http://www.msnbc.com/msnbc/us-government-threatened-yahoo-bi... They certainly can, and will, go after any company they want to, without referencing any specific US legislation.

ISPs and VPNs have different laws then, for example, email providers. Further, Yahoo Mail, would be storing data (thus "voluntary" logging, or in their case, there's few ways around it to deliver their services in any kind of usable way).

I repeat, after having evaluated this quite deeply, that there are no mandatory data retention laws in the US, period, for ISPs and VPNs. This is contrast to quite a few jurisdictions, and the poor actions taken by ISPs and VPNs in said areas seem to speak louder than words.

That being said, I can relate to the author. Trusting a random service without any reason to trust is definitely blind. However, trust can be earned, over time, and validated, but should never be absolute. Trust is earned, daily, forever.

That being said, at the end of the day, the best bet is to remove trust from the equation - to get closer to a zero knowledge state, thus creating zero trust.

We're working toward that, every single day, and I would love to hear from anyone that's interested in helping or has thoughts.

Re: VPN – Very Precarious Narrative

#74
post #67
post #59

Earlier quoted context omitted.

Perhaps not (I’m not certain about the issue), but they can be forced to hand over their private keys to let the NSA [ed: or other agency] do the logging for them – as happened with Lavabit.

s/NSA/DOJ.

Good catch, although... I looked it up, and apparently in Lavabit’s case the demand (under the Stored Communication Act) was actually issued by the FBI?

Re: VPN – Very Precarious Narrative

#76
post #70

Earlier quoted context omitted.

FSM == Flying Spaghetti Monster?

Russian intelligence service: https://en.wikipedia.org/wiki/Federal_Security_Service

Huh? I didn't ask about the FSB (the first initialism). I asked about FSM (the last).

Re: VPN – Very Precarious Narrative

#77
post #27
post #20

Earlier quoted context omitted.

So what protection does a foreign VPN provider have from the NSA? The answer: None.

If your threat model includes NSA you need to reconsider lot more than just a VPN

Windows Defender oughta do it /s

Re: VPN – Very Precarious Narrative

#78
post #10
post #4

Earlier quoted context omitted.

We also have multiple documented cases of "no-log VPNs" submitting their logs to law enforcement. I even linked to one case in my post. What's your point here, exactly? Because my point was you have to trust either party. Oh, and btw, here in Europe, it is actually illegal for ISPs to give connection data away for non-law-enforcement purposes. It's sad that there are some US-American ISPs that have a record of sellin…

Which case are you talking about? You have no links in the "no-log" section. Other fatal flaws in that section, fwiw >Starting with the obvious, if you pay for a VPN service, they have to keep your user account and associated payment information and your payment history. So, unless you are using a fake identity and an anonymous credit card (is that even possible these days?), your VPN account will be linked to your a…

Bitcoin has very little anonymity as well BTW. Probably less than credit cards.

Re: VPN – Very Precarious Narrative

#79
post #16

Damn. I don't even know where to begin. It's true that VPN services at best provide less anonymity than Tor does. And that some, such as HideMyAss (which pwned that LulzSec dude) provide none. But PIA clearly does, as demonstrated now in two criminal investigations.[0] Of course, in both cases, defendants pwned themselves through poor OPSEC. But at least PIA didn't give them up. And the Facebook example. Nobody payin…

Of course one has to wonder how much of that "poor OPSEC" is actually just parallel construction. The linked article doesn't sound like it. But on the other hand with the way mass market VPN software generally works, how many people are going to be absolutely sure that all of their traffic definitely went out the tunnel? The FBI having access to an NSA-provided tool that takes some IP addresses and returns other "ass…

Sure, a lot of it may be parallel construction. We do know that the NSA shares with the FBI and other TLAs.

If your threat model includes the NSA or the like, VPN services are at best a minor hindrance. Possible options include Tor and "anonymously" using WiFi hotspots.

I only know of one fundamental fail for Tor: the relay-early bug that CMU exploited. The others have involved Firefox and Windows bugs. People using Whonix in Linux hosts, and hitting Tor through nested VPN chains, would have been safe from any attack that I've heard of. But then, maybe I just haven't heard of the juicy ones.

I've tried the "anonymously using WiFi hotspots" approach. It's a pain in the ass. And in today's high-surveillance environment, I believe that it's a dumb idea.

It's true that VPN leakage is a serious risk. But you can use firewall rules to prevent DNS and traffic leaks. Or you can use VPN services whose client apps do that for you.

Also, I'm talking about desktop use. Doing any of this on mobile devices is a lot harder, I think. I'm not sure that I'd even bother.

Re: VPN – Very Precarious Narrative

#80

Earlier quoted context omitted.

Logs are worth a lot of money to advertisers if your customers can't effectively avoid the process.

And a lot of money to a lawyer who will sue the ISP under privacy laws if it comes to light. It has to be clearly stated in the signed contract that your data will be shared with third parties, in what way and how they will be processed. The company involved would definitely lose any Privacy Shield provisions for the EU and potentially peering rights. Losing enough peering is identical to being disconnected. Class su…

I didn't get any money when my cell provider was caught multiple times selling my location history to anyone with a buck, including dangerous vigilantes.
Post reply on HN