9 ms·
Linked to US intelligence services. Makes you wonder how many VPN services are run by governments?
by cybralx 6y ago
Linked to US intelligence services. Makes you wonder how many VPN services are run by governments?
- java-man 6y agopretty much all of them, no?
- fakedang 6y agoWell.... Tor started off as a government tech right?
- lucb1e 6y agoThat a government funded mixnet research in the 80s doesn't mean that VPNs are government-run, if that's what you are trying to say (honestly I'm not sure what exactly you're saying, the two have very little to do with each other).
- schoen 6y agoBy the way, you're off by a decade on when NRL did the onion routing research -- it was in the 90s rather than the 80s. https://en.wikipedia.org/wiki/Onion_routing#Development_and_implementation https://en.wikipedia.org/wiki/Onion_routing#Development_and_...
- lucb1e 6y agoThanks, I didn't know that. It was meant more illustratively than as an accurate time indication, but nevertheless it's good to be correct and now I know.
- nyolfen 6y agothe US state dept funds the tor project to this day
- fakedang 6y agoMy point was that one of the most secure ways of browsing the internet was essentially a government spin off from the 90s. So it's not hard to presume that the government has its fingers in a lot of other things built to hide/obscure user activity.
- lucb1e 6y agoWell please prove me wrong but having talked to people like Roger Dingledine and Jacob Appelbaum in person and knowing a thing or two about how the Tor Project works, I have zero reason to think that this funding influences the security of Tor in any way, which is what "having its fingers in it" sounds like. The USA not funding the Tor project would, as far as I have been able to discover, not have changed anything about how likely it is that the USA or any other government has access to Tor users' data. If there are intentional bugs (bugdoors) inserted by any contributor, then those would be kept separate from any public funding it receives. Perhaps I'm not cynical, skeptical, or well-read enough though, so again, please point me towards anything that would suggest otherwise. Then as for VPNs, they're again a very different thing. Funding research or a non-profit is very different from operating a commercial entity under a guise while abusing the trust anyone places in it. The comparison seems to me like comparing funding for general car safety or emission research with suggestions that the government operates one or multiple taxi services in order to learn who goes where. It's not that governments don't setup fronts or operate commercial entities under a guise ever, but rather that I have yet to hear of doing it for the purpose of surveilling random people (you have to get lucky in that anyone of interest signs up for yours, targeted marketing or no) that are not suspected of anything. Aren't fronts usually to enable targeted investigations or do specific actions unnoticed? Like, they might operate a VPN so it doesn't look weird if their secret operators use those IP ranges as well, but the main goal wouldn't be to spy on users (not saying they wouldn't do that on the side, of course, but it's getting more far-fetched).
- grahoho 6y agoThis link should explain it: https://surveillancevalley.com/blog/fact-checking-the-tor-projects-government-ties https://surveillancevalley.com/blog/fact-checking-the-tor-pr... The author of this book did FOIA requests to various entities but most of them got predictably shot down for national security concerns. This one obscure government agency, Broadcasting Board of Governors, wasn't covered by these exemptions. So the author read the emails between BBG and the Tor Project maintainers and found that when they received a bug report, rather than fixing it they reported it to their sponsors. The government would then exploit the bug for years before the Tor guys got around to fixing it.
- markus_zhang 6y agoSo is the real solution such that you purchase internet service from another country and build your own VPN?
- lsllc 6y agoIt's trivial to set up a FreeBSD instance with IPSec using StrongSwan on something like a Digital Ocean or Vultr instance in a country that suits (both D.O. and Vultr have regions in US, Europe and Asia/Pac Rim). But it depends on what you're trying to do. If it's something like get access to shows on Netflix or the BBC iPlayer, then this is a good technique. I think for privacy, it might be OK; while the German or Australian govts. might share data with the US, probably Singapore, Korea, Japan or India doesn't. if you're up to something more nefarious then maybe you need something stronger like Tor.
- machinelabo 6y agoNot trivial at all for vast majority of the VPN users. You know the people that buy VPN services because they saw it in a Youtube video as a sponsor.
- lsllc 6y agoFair point.
- claudeganon 6y agoBoth Korea and Japan are client states in the U.S. empire, with large US military presences and drastic interventions in their domestic politics. They absolutely collaborate with the US on everything.
- markus_zhang 6y agoSo I guess the best thing is to route through say US, Russia, EU and China?
- chiefalchemist 6y agoWhy only VPN services? If you were in the Intelligence business would you stop there?
- ardy42 6y ago> Linked to US intelligence services. Makes you wonder how many VPN services are run by governments? I don't recall details, but IIRC, there are (or were) a few popular VPNs in China that were used to circumvent the firewall that functioned fast and reliability despite the anti-VPN crackdowns. I've read speculation that they were likely collaborating with Chinese police/security forces to help them keep tabs on the VPN-using community in order to better anticipate threats to their power. Facebook ran similar free VPNs for a similar reason: to gather intelligence on users to anticipate competitive threats: https://en.wikipedia.org/wiki/Onavo https://en.wikipedia.org/wiki/Onavo.