8 ms·
While it's true that your VPN provider _may_ be lying about their "no logging" policy, at a minimum, you get additional layers of protection. Your source IP is
by thothamon 7y ago
While it's true that your VPN provider _may_ be lying about their "no logging" policy, at a minimum, you get additional layers of protection. Your source IP is masked. A subpoena would be required to reveal your source IP, and perhaps your VPN provider is telling the truth about not keeping logs. If your VPN endpoint is in a different country than your network endpoint, then the legal obstacles get even higher.
Surely you shouldn't depend on that alone. Tor would be a wise additional layer of protection, if applicable. But to suggest that you get no privacy benefit at all from a VPN is like saying your host may be compromised, so you might as well use regular telnet rather than SSH.
- bureaucrat 7y agoThey _were_ also not disclosing that they were hacked last year. https://web.archive.org/web/20180504001844/https://8ch.net/b/res/7948898.html#7950919 https://web.archive.org/web/20180504001844/https://8ch.net/b... Yes, people would rather give their entire packet to a hacker than five eyes, wouldn’t they?
- Zush8phoog 7y agoNordVPN, according to this leak https://web.archive.org/web/20190603203749/https://ghostbin.com/paste/azk4r https://web.archive.org/web/20190603203749/https://ghostbin.... was logging client connections as recent as 2018 despite claiming they do not log https://nordvpn.com/features/strict-no-logs-policy/ https://nordvpn.com/features/strict-no-logs-policy/ see openssl/server.cfg it should contain special lines to disable logging https://www.lowendtalk.com/discussion/107379/how-to-disable-logging-on-openvpn-server https://www.lowendtalk.com/discussion/107379/how-to-disable-...
- Izmaki 7y agoThis. If we always assume the worst, we may as well stop using passwords or strong ones anyway, because we can assume that our machines per definition are hacked and local network infiltrated. Not happening, right? That’s what i thought...
- chinhodado 7y agoYeah, I hate extreme opinions that say not to do something just because it's not 100% effective. It's like saying don't bother using a lock because all locks can be picked and cut anyway.
- technion 7y agoI consulted to an organisation that spent multiple years refusing to allow any form of MFA. Everyone agreed it was extremely important and some password protected data was very sensitive. But the conversation about authenticator apps always got bogged down with risks about malware on phones. I would get asked "will you stake your career on it never happening?" Of course not. Therefore "for security reasons" we never supported authenticator apps. Of course it was pointed out that people might lose hardware tokens, so they didn't happen either. Because mobile MFA isn't perfect, I had directives to stick with easily phished passwords for years.
- ben509 7y ago> I would get asked "will you stake your career on it never happening?" Of course not. "Let's make a bet over whether a customer reports an authenticator app gets hacked before a customer's account without an authenticator is broken into. If the authenticator app is hacked first, I'll resign. If an account with no 2FA is compromised, you resign."
- sjy 7y agoThis is probably just meant to be a joke, but I have been in that situation before and I don't think offering to gamble away your job would be an effective way to convince others to accept your advice on risk management. I still don't know how to effectively convince others to take on new risks in order to avoid bigger risks presented by the status quo. Given the additional risk that my risk assessment is deficient, doing nothing is usually the easier decision.
- cs02rm0 7y ago
- nwmcsween 7y agoIf you were running a VPN service would you rather: a. Pay for legal counsel and fight court orders for someone paying $10/mo or b. Just give up all info?
- freehunter 7y agoFor someone paying $10/mo? No. For the trust of my thousands of customers paying $10/mo and to keep my public reputation afloat? Hell yes. A VPN service that hands over customer information constantly will very quickly go out of business.
- kingbirdy 7y agoAs mentioned in the article, HideMyAss gave up customer info in 2012 and is still in business today.
- JohnJamesRambo 7y agoHow would anyone know?
- song 7y agoExactly, PIA did that twice and I know quite a few people who use them because they've proven they don't keep logs in court.
- jeffdavis 7y agoYour reasoning assumes that a VPN couldn't hurt, but it can. If someone wants to track you and you don't have a VPN, they need to compromise your ISP. If you do have a VPN, they need to compromise your ISP or your VPN.
- danShumway 7y agoAm I not understanding your argument? > they need to compromise your ISP or your VPN Part of the point of a third-party VPN is that the ISP/router can't tell what you're doing -- you assume that they're untrustworthy. Compromising the ISP would be useless, unless your VPN is for some reason sharing the same info with your router, in which case... install a competent VPN client. I don't see how you're adding an additional failure point, you're just moving the same failure point somewhere else. Yes, once the VPN endpoint makes the request, an ISP can still intercept it. But this is one of the few cases where adding an additional network hop very likely does not matter at all for your privacy. Once your request is going over the open Internet there are already so many opportunities for people to spy on it. The benefit is in disassociating that request from you, not in hiding it once it goes public.
- fulafel 7y agoThe confidentiality protection is not really absolute - the encrypted VPN traffic is susceptible to traffic analysis[1]. For example, your traffic pattern fingerprint could be correlated and matched to your online identity if your ISP and an ad network or another globally positioned middleman actor colluded on it. [1] A term of art in intelligence & cryptanalysis, https://en.wikipedia.org/wiki/Traffic_analysis https://en.wikipedia.org/wiki/Traffic_analysis
- GhettoMaestro 7y agoRespectfully, unless your adversary is the NSA, and they are targeting you, your argument is full of shit.
- 7y ago
- hermitdev 7y ago> A subpoena would be required to reveal your source IP, and perhaps your VPN provider is telling the truth about not keeping logs. I doubt this is necessarily true in the US due to the 3rd party doctrine (which I abhor). I think they may refuse and request a subpoena, though. But, nothing stopping a company (generally) from handing over your data if asked for. Maybe T.O.S?
- djsumdog 7y agoWell in America, we have National Security Letters, which are a legal cluster fuck on their own.
- wglb 7y agoBut the article points out that your IP address is irrelevant in tracking these days.
- luckylion 7y agoIt's not for legal repercussions, though. If you were engaging in file sharing, your IP is pretty much all that matters. The article is just wrong the way it is. It would be correct if it was titled "Don't use VPN Services as your only means to ensure perfect privacy".
- mandukya 7y agoThe article makes a strong case. And no, it isn't "wrong as it is". This whole VPN business sounds like a big scam everyone keeps promoting to everyone.
- dx034 7y agoIt's not. I know of several instances where IP is at least used as a filter. Esp. the combination of user agent and IP require no JS and can help you to track users across domains easily for small to medium sized websites.
- wglb 7y agoYes, if it is available it can be used. The point of the assertion is that you can be tracked even if your IP address is obscured, mangled, or spindled.
- icedchai 7y agoYes, exactly! I use VPN exclusively for downloading movie torrents so I don't get nasty letters from my ISP. I have a friend who has gotten several such letters.
- parliament32 7y ago>A subpoena would be required to reveal your source IP, and perhaps your VPN provider is telling the truth about not keeping logs. Not to mention the legal trouble for an LEO to be granted a subponea in a different country. By the obstacle of "a different legal system protects this part of my data chain" alone a VPN is worth it. Say you use a Russian VPN provider. Sure, they can see that you're connecting to whatever site, but the actual data is protected end-to-end by TLS (hopefully). Meanwhile your local ISP can see you're connecting to something in Russia, full stop. For someone to track you down, they'd have to get the compliance of both your ISP and your Russian friends... AFAIK, there are exactly zero cases on record where this has been successfully done.