8 ms·
Reminder to NOT use any 3rd-party VPN service if you truly value your privacy. ProtonVPN, PureVPN, Private Internet Access, etc. Do not use those services if
by snacktaster 8y ago
Reminder to NOT use any 3rd-party VPN service if you truly value your privacy. ProtonVPN, PureVPN, Private Internet Access, etc. Do not use those services if you're intending to do some "shady shit". I know first hand that Google has a (semi)-automated web-based process for law enforcement to submit their subpoenas and get the entire access history of a particular Google/Gmail account. They don't get access to the contents of the account, but they get to see IP addresses and user agents that accessed that account in the last N days. A warrant to see the contents of the accounts would be trivial if the investigators wanted to pursue it.
- yourduskquibble 8y agoSo a better option would be to use your Comcast / AT&T / Verizon connection to leak data to the press? Everything on the internet (and really in life) is a chain of trust - there are going to be weak links however far down the rabbit hole you go.
- kinsomo 8y ago> So a better option would be to use your Comcast / AT&T / Verizon connection to leak data to the press? A better option is to use technology that might be better able to provide some verifiable anonymity guarantees, like Tor.
- mirimir 8y agoTrue. But Tor has pwned people too. Most recently, there was the bug that CMU researchers exploited, and then shared with the FBI. Also, many users of Tor browser have been pwned by phone-home malware, which leaked their ISP-assigned IP addresses. Hitting Tor through nested VPN chains would have protected them.
- kinsomo 8y ago> True. But Tor has pwned people too. Most recently, there was the bug that CMU researchers exploited, and then shared with the FBI. Also, many users of Tor browser have been pwned by phone-home malware, which leaked their ISP-assigned IP addresses. Hitting Tor through nested VPN chains would have protected them. It's better, as in closer to trust-no-one, but of course it's not perfect. Especially when we're talking about endpoint security concerns.
- mirimir 8y agoYes, totally agree. I love Tor :)
- angry_octet 8y agoIf you use Tor you can't really trust the machine it is on, all sorts of potential web browser vulnerabilities. (And please don't do GPGing on the same box.) At a minimum, run it in a VM so its upstream IP is an internal NAT address, and so it won't have unique phys IDs like MAC address, which can be traced through the supply chain. Preferably use a VPN for the host machine's connection too, at least to first download the tor client (the subset of IPs which have downloaded a recent tor bundle is quite small). At the very least, firewall the VM so traffic can only go to a tor bridge IP; even then, https (non tor) from a compromised host can identify the tor user, as all tor entry point traffic is logged and possibly has active mitm boxes (varying packet timing, fingerprinting tor versions). Given the overall complexity of getting it right, and the enduring consequences of a single opsec failure, I'm not sure tor is a great option. Sending USB sticks through the mail would probably be safer. (Even then, encrypt them, use a dedicated laptop, don't lick the stamp or leave fingerprints, don't be observed/CCTVed posting them, purchasing the USB sticks, etc.)
- deusofnull 8y ago^^^ I've been repping physical data transfer to people for a while. Veracrypt is a great option.
- mirimir 8y agoGood points. I should have emphasized use of Whonix, which comprises Tor gateway and workspace VMs. Forwarding isn't enabled on the gateway or workspace, the gateway is firewalled, and it doesn't just use TransPort. It exposes a bunch of SocksPorts to the workspace VM, so each app gets its own SocksPort. > all tor entry point traffic is logged and possibly has active mitm boxes That's a broad claim. You need cites for that. Tor relays are run by a large collective of volunteers, and keeping something like that secret would be quite some achievement.
- angry_octet 8y agoOkay, not all gateways. But top by volume, yes. Not by the people running them, but at the network/ISP layer. There was some open source reporting about it in Singapore (not a democracy admittedly) I'll try to dig up. But on the 5th anniversary of the Snowden leaks, why do you find it strange?
- yourduskquibble 8y agoI understand that sentiment but a technological work around (that probably also has captured data points) that would entirely alleviate whatever hypothetical issue the OP is referring to seems at best naive to this layman.
- kinsomo 8y ago> alleviate whatever hypothetical issue the OP is referring to That "hypothetical" the OP referred to is the VPN provider keeping logs (or more logs than they advertise) and providing them when asked to the authorities. It's not really that hypothetical. There was a link here today about a "no log" VPN service that apparently did that. > I understand that sentiment but a technological work around (that probably also has captured data points) Tor is a technology that specifically answers the issue the OP brought up, which is over-trust in a single entity to preserve anonymity. Nothing's perfect, but Tor is better than both the "VPN provider" option the OP was warning people away from and from your snarky "what and use Comcast?" option. > but a technological work around ... seems at best naive to this layman. You'll have to elaborate why the use of better (if imperfect) technology is "at best naive."
- jolene42 8y agoEhem, asking for a friend - is using Tor in conjunction with a third-party VPN service like the ones mentioned above any safer than using Tor regularly?
- mirimir 8y agoOK, so imagine that your friend was using Tor in 2014, while CMU attackers (OK, "researchers") were deanonymizing users and onion sites. They exploited a bug ("relay-early") in Tor, which allowed them to communicate among malicious relays through a back channel. That led to a number of prosecutions. But imagine instead that your friend was connecting to Tor through a VPN service. Even if CMU attackers had been running your friend's entry guard, they would have just seen the VPN exit IP address. Better yet, your friend could have been connecting to Tor through a nested chain of VPN services. Then the FBI would have needed to do lots more work to get your friend's ISP-assigned IP address. The Tor Project, I note, will not agree with my assessment. But so it goes.
- xxpor 8y agoThe fact that they only need a subeona for metadata might change very soon, depending on how the SCOTUS case Carpenter is decided: https://www.oyez.org/cases/2017/16-402 https://www.oyez.org/cases/2017/16-402
- mirimir 8y agoThat's going too far, I think. Sure, you can run your own VPN server, on an anonymously leased and managed VPS. But then, how do you anonymously lease and manage that VPS? As far as I know, your options are pretty much limited to VPN services, Tor and I2P. Also, VPS traffic is readily logged by providers, so your "anonymity" is pretty fragile. Your best bet is distributing trust among multiple parties, such that no one of them can compromise you. VPN use is common, so start with nested VPN chains. Then Tor. If either the VPN chain or Tor resists compromise, then you're still safe. After that, you can use any PM or email that you like. Because it's not connected to your meatspace identity. If content is end-to-end encrypted, the provider has nothing useful to share with adversaries. You and correspondents must, of course, avoid leaking metadata through account names and subject lines.
- TimTheTinker 8y ago> But then, how do you anonymously lease and manage that VPS? At least on DigitalOcean, it’s possible to create an anonymous account (no name required, not even by their TOS) connected to an anonymous email provider and funded by a cash-purchased Visa gift card. And a $5/mo droplet running IKEv2 VPN traffic (see Algo) is very secure and provides more than enough bandwidth/throughput for several people. That would only leave the traffic itself (particularly the IP address(es) that initiate connections to your droplet). DO has a policy of not logging traffic unless an abuse alert is triggered.
- kbenson 8y ago> DO has a policy of not logging traffic unless an abuse alert is triggered. I'd be willing to bet they log all the info about the signup process though, including the IP address used. It's how you prevent abuse. The question then becomes, how do you hide your IP address from the DO signup process. I know, used a VPN! Wait a second...
- thefounder 8y agoYou can use pre-pay internet or public wifi to sign up
- confounded 8y agoCan you explain this a bit more? Are you saying that - Google’s policy could unmask users behind a VPN, via an IP+time correlation attack[0] or - VPN providers who say they don’t keep logs, are actually keeping logs in secret, because of what you’ve seen at Google ? I’m straining to make the connection you’re hinting at. [0] You can now basically buy these from telcos as an identity verification measure, so a VPN seems useful here.
- terminalcommand 8y agoAFAIK basically all legal VPN providers keep logs. If you're providing a service on the net, it is likely that you are required to log all access to your services. The law inforcement officers or prosecutors can simply ask for the history of your traffic. As it does not contain the content of your communication, in most legal systems they do not need any warrant to request this data.
- mirimir 8y agoThat's not so in the US. And generally not so in the EU, as far as I know. What jurisdictions are you speaking of? Cites would be cool too.
- jacquesm 8y ago> And generally not so in the EU, as far as I know. As far as I know the EU does have data retention laws on the books for ISPs. https://en.wikipedia.org/wiki/Data_retention#European_Union https://en.wikipedia.org/wiki/Data_retention#European_Union
- juki 8y agoThe last paragraph under that heading says the directive was declared invalid 2014. > On 8 April 2014, the Court of Justice of the European Union declared the Directive 2006/24/EC invalid for violating fundamental rights. The Council's Legal Services have been reported to have stated in closed session that paragraph 59 of the European Court of Justice's ruling "suggests that general and blanket data retention is no longer possible".[18] A legal opinion funded by the Greens/EFA Group in the European Parliament finds that the blanket retention data of unsuspicious persons generally violates the EU Charter of Fundamental Rights, both in regard to national telecommunications data retention laws and to similar EU data retention schemes (PNR, TFTP, TFTS, LEA access to EES, Eurodac, VIS).[19]
- lightbyte 8y agoPrivate Internet Access has been subpoenaed by the FBI before for user logs and they were unable to comply due to not saving any [1]. That's probably the best reassurance you can get for a VPN. [1]: https://torrentfreak.com/vpn-providers-no-logging-claims-tested-in-fbi-case-160312/ https://torrentfreak.com/vpn-providers-no-logging-claims-tes...
- lr4444lr 8y agoWhat's your alternative suggestion? ISPs will surely give over that information outright. At least a VPN touting privacy has the incentive to avoid putting its entire business at stake if it can't make good on its raison d'être.