7 ms·
At first I thought it was a blog. No, this is a company. So, their privacy page (https://servury.com/privacy/ https://servury.com/privacy/): > Server Logs > Li
by mk89 10mo ago
At first I thought it was a blog. No, this is a company. So, their privacy page (https://servury.com/privacy/ https://servury.com/privacy/):
> Server Logs
> Like all web services, our servers may log:
> IP addresses of visitors
> Request timestamps
> User agent strings
> These logs are used for security and debugging purposes and are not linked to your account.
That's already a huge breach in comparison to mullvad privacy page. (https://mullvad.net/en/help/no-logging-data-policy https://mullvad.net/en/help/no-logging-data-policy)
- afro88 10mo ago> That's already a huge breach in comparison to mullvad privacy page. And the "3 data points, that's it" of the blog post
- ybceo 10mo agoThose data points refer to what is stored in the database and is tied to your 32 character credential. Web server logs were not tied to user credentials in any way.
- kevin_thibedeau 10mo agoIPs are PII. They can be tied to an identity.
- organsnyder 10mo agoEven user agents are often specific enough to be considered PII.
- IlikeKitties 10mo agoI mean technically yes but I find THAT kind of logging utterly benign.
- procaryote 10mo agoThey're good enough for fingerprinting and matching against other logs. Also: > // What we DON'T collect: > - IP addresses (not logged, not stored, not tracked) > - Usage patterns (no analytics, no telemetry, nothing) > - Device fingerprints (your browser, your business) so, I've read one blog from this company, and already they're lying or incompetent
- tensegrist 10mo agoi hate to point it out, but that was written by an llm that probably wasn't prompted precisely enough to not make up comforting thoughts like that
- pxc 10mo agoIndeed, the whole thing reads like it was written by an LLM.
- ybceo 10mo agoI agree 100%. I went ahead and disabled all logging in Apache just now. Will update the privacy page to reflect this within the hour.
- drink_machine 10mo agoShouldn't you have spent some time to think through basic things like this before trying to write an opinion piece on anonymity? Certainly it shows a lack of depth of understanding.
- ybceo 10mo agoI disagree. Like I said earlier : Web server logs were not tied to user credentials in any way, they were used for debugging purposes and could not have been used to identify users.
- drink_machine 10mo ago[flagged]
- ybceo 10mo agoI went ahead and took action on the criticism as soon as I saw the parent comment. All apache access logs are piped to /dev/null now. I'm not here to debate, the reason I posted here is to hear what people thought and see how I could improve my platform based on the criticism.
- navigate8310 10mo agoI appreciate your opinion on anonymity, but, it's nothing more than, "trust me bro". And being a US company that further tingles the spidy sense.
- joemazerino 10mo ago
- willtemperley 10mo agoI initially liked the sentiment but the offering doesn’t appear to add up. Unfortunately the real private cloud, if it exists, is bare metal and can’t really be sold as a subscription.
- givemeethekeys 10mo agoDo as I say, not as I do! /s