4 ms·
Discussion 2 days ago (222+ comments): https://news.ycombinator.com/item?id=23876146 https://news.ycombinator.com/item?id=23876146 "UFO VPN claims zero-logs po
by KindOne 6y ago
Discussion 2 days ago (222+ comments):
https://news.ycombinator.com/item?id=23876146 https://news.ycombinator.com/item?id=23876146 "UFO VPN claims zero-logs policy, leaks 20M user logs"
Title is also slightly misleading, multiple sources have 1.2TB, not 2TB.
- system2 6y agoReally doesn't matter how many tb to be honest, I don't even look at the number. Even 1 kb is more than enough.
- KMag 6y agoWell, except that 1 kb is still consistent with "no log", as if they're businesses, they need to keep track of which user names/pseudonyms have paid. A 1 kb leak isn't okay, but at least it's potentially consistent with their promises to their users.
- system2 6y agoYou are missing my point. Any kind of leak means they are logging regardless of the leak size.
- KMag 6y agoMy point is that if the leak is a grand total of "1kb of user logs", it may not be the sort of log you're assuming. If the leak is a 1 kb list of valid usernames and password hashes, how does prove they were violating their "no log" policy? It just proves they were doing access control, which we knew anyway.
- nieve 6y agoIt's the data breach equivalent of the cryptography rule that a break never gets better and usually gets worse. A canary in a coal mine, basically - if 1kb has been leaked you can safely assume a lot more has since that's not an amount that any attacker would bother with under normal circumstances. If they do care it's because they expended a penetration on targeting few or one individuals max and we almost certainly wouldn't see the results. If I saw a dump of 10 email addresses from Hacker News it would be imprudent assume that somehow an attacker had made it in as an admin and yet only accessed those. It would be outright foolish to assume that if there were 10 addresses the damage is inherently less than 10.