Live data from Hacker News

UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

comparitech.com

91–100 of 240 posts

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#91

Earlier quoted context omitted.

Piggybacking off of this, Private Internet Access (PIA) has actually had their no logging policy "proven in court" via this method multiple times. [1][2] Full disclosure: I work at PIA. [1] https://torrentfreak.com/vpn-providers-no-logging-claims-tes... [2] https://torrentfreak.com/private-internet-access-no-logging-...

Is there any way to prove that is not NSA, say, and set up to only catch the biggest fish, or to always present parallel construction for criminals caught this way?

That's an interesting philosophical question.[1][2]

[1]https://en.wikipedia.org/wiki/Burden_of_proof_(philosophy)#P... [2] https://en.wikipedia.org/wiki/Evidence_of_absence

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#92
post #51

Earlier quoted context omitted.

How? I mean how do you measure VPN services? I never understood why people working in tech would ever trust a VPN service? A VPN is seeing all your traffic, and you have to take their word that they do not log any of it? I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.

The only standard you can really trust is when they actually get subpoenaed and don't have anything to give to the court. An example of this is Private Internet Access.

ExpressVPN also had the same situation and had no logs available.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#93
post #61

Earlier quoted context omitted.

Is your comment implying that VPNs are only used for copyright infringement? Primary use of VPNs I see is to get onto my workplace's network.

Surely your company is not using a consumer provider like NordVPN or this UFO VPN company though?

I don't know of any company that would be using a public VPN service for anything related to work. Typically "work VPNs" are running on systems that the employer controls, set up by someone employed by the company, and meant solely for employees to connect to - there is no reason any company would want or need to use a public VPN provider for their corporate network VPN. It just doesn't make any sense to me why you would suggest it.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#94

Earlier quoted context omitted.

What about chaining VPNs? Even at 2 they'd have to cooperate to unmask your traffic, right? Somewhere in the back of my mind is stored that minimaxir does this, but I couldn't confirm it with a quick search. Edit: I was actually thinking of mirimir.

Provider#1 only knows all traffic goes to provider#2. Provider#2 knows everywhere your traffic goes. They don’t know your IP, but you need to login, so they know who you are anyways.

I think you need 3 levels. First level gets you to the second level. 2nd gets access to web-based email and bitcoin or single-use credit card payment to get the third level, which accesses data.

Obviously you use assumed identity.

With only two layers you'd need to access emails, say, for account confirmation direct from your own system; with 3 you put a VPN in that gap.

Do VPNs re-pack and modify the timing on packages they pass on to clients? It seems like they're need to if they're too avoid coordination attacks.

I'm recalling how a research paper showed an extraordinary high number of pages visited (80%) over HTTPS could be identified using page size alone. If a TLA is watching all traffic into and out of a VPN's server can they pair upstream traffic to downstream clients at all?

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#95
Why would you trust a VPN when any TLA/CIA/NSA/FBI can set up 1/10/100 options relatively cheaply. Unless you go through TOR or use a false MAC address you have no guarantees, even then fingerprinting and fake TOR exits points are a serious risk if you are trying to be truly anonymous.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#96
post #16

What's the most trustworthy VPN that HN users recommend? My 3 year subscription to my local one is about to run out! Looking for advice on what is trusted nowadays!

No such thing. You would be better off renting an inexpensive VPS and running your own VPN on it. Public VPN services have to be the one of the greatest lemon markets to have ever existed: You want people's private data? People will pay you to give it to them. Go ahead and sell the service for less than it costs due to the boatloads of data that you get. People realize this, so you end up getting a disproportionate n…

Practically all traffic over a VPN is encrypted because most traffic going over them is encrypted, so I'm not sure how much traffic a VPN provider is really going to be able to sell. They aren't really going to be see very much of what you do if you take even some basic precautions like using HTTPS websites, or using SSL newsgroups, etc. Maybe bittorrent isn't encrypted? I can't imagine that it wouldn't be encrypted but I am not as familiar with how that works.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#97
post #27

Earlier quoted context omitted.

I would never do business with Private Internet Access. https://news.ycombinator.com/item?id=21584958 (you can google to find more-- this was just a quick result)

Despite this, they claim to be working on a way to verify their privacy claims. I don’t understand how, but if they succeed it will be noteworthy and might redeem them a fair bit

They could get a security researcher, or three, to look over their systems? Then maybe invite large consumer groups to send an expert to take a look (they could come armed with info on users, that they could check up on, in order to try and confirm they weren't being fed a whole fake server?

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#98
Know what's valuable? Internet traffic from people who think it's important enough to hide, and who have technical skills to get jobs with them. The value of privacy viewed this way would mean that a truly private VPN service would be hugely expensive, like the way a new Rolls Royce is priced at 50x that of what you need to get from A to B.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#99
post #59
post #53

Earlier quoted context omitted.

Won't amazon cancel them when they keep getting copyright letters? Or do vpns have some other use I am not aware of.

VPNs do have some legitimate uses. Encrypting traffic over malicious networks (e.g. your average airport wifi) is probably the most common one for the average legal user. Getting an IP address in a given country is another sometimes legal use. I honestly don't know if you can do this with your average commercial vpn, but the technology is also good for many things like setting up virtual networks (hence the name) so…

Just how insecure is airport WiFi these days with SSL and HSTS? I don't normally worry about it, and suspect people who still counsel against it of lazy FUD.

I'd notice pretty quickly if someone was MITMing all of my traffic. I guess they could MITM a third-party Javascript site that wasn't being served with HSTS. Normally that would just give them all the information I already give to Google or Facebook and the hundred other shitbags that run JS on the sites I browse, but if they got really lucky they could pretend to be some third-party payment provider that didn't use HSTS or I hadn't used before.

Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]

#100
Unsecured Elasticsearch, once again.

(https://www.theregister.com/2020/07/17/ufo_vpn_database/)

So ES has insecure defaults, I get that and it's been discussed to death.

But who the heck, in this day and age, exposes clusters directly to internet traffic? I don't care what the defaults or security measures you have. DONT EXPOSE SERVERS.

Place them inside a VPC, preferably a private one(in AWS parlance, behind a NAT GW). Use _something else_ to send traffic to them. If you are on AWS or similar (but not Azure I guess), add a load balancer to it. So now access would require creating a new load balancer, pointing to the servers in question, adding listeners on the desired ports, and configuring the appropriate security groups. Only then you can send external traffic. On the specific ports you configured on both listeners and security groups only.

Do this everywhere and you are in a much better shape. You still need to configure servers correctly, but if you mess up, nothing happens, unless you mess up many other things in an error cascade.

Post reply on HN