4 ms·
Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identif
by cycomanic 5mo ago
Why? If I was an intelligence agency and designing a VPN I would simply log all the IPs connecting to my VPN and not rely on statistics on exit nodes to identify the users, even more so because they rely on the users to pick different servers.
- faangguyindia 5mo agoHow would you claim it's a no log VPN?
- LordAtlas 5mo agoI could just...lie.
- haakon 5mo agoYou really think someone would do that?
- ZeWaka 5mo ago*gasp
- im3w1l 5mo agoOne person can tell a lie, but a company consists of many people. You must ensure that only few people know of the logging or there will be a risk of a leak.
- xboxnolifes 5mo agoIntelligence agencies... are generally pretty good at that.
- arcfour 5mo agoAn intelligence agency already consists of more people than you need to run a VPN service.
- im3w1l 5mo agoStill I think it's easier to avoid the need for more people than necessary. "Just lie" sounds like the easiest solution but on closer inspection maybe it is not?
- arcfour 5mo agoBecause if you lie you get infinitely more data than if you don't lie. And if you lie you can do it completely in secret whereas if you don't lie you get articles like the OP exposing the teeny amount of data you're trying to collect. It makes no sense.
- nkrisc 5mo agoLying is almost always the most cost-efficient answer to anything, if you’re not concerned about your trustworthiness, morality, ethics, etc.
- michaelt 5mo agoWell, there should only be a few people with the access needed to discover logging is happening. Just put the logging configuration in whatever secure configuration management tool is storing your TLS keys and suchlike. Make it look like an accidental misconfiguration and if an insider who isn't an NSA mole does somehow discover the logging, there's a fair chance they'll turn a blind eye anyway. After all, if you work at a VPN, publicly outing your employer for logging will tank the business, then you and your colleagues will all be out of a job.
- zahma 5mo agoTheir 3rd party audit didn’t catch this… I guess we’ll see how they respond.
- traceroute66 5mo ago> How would you claim it's a no log VPN? Mullvad have been taken to court over this in relation to a copyright infringement case. TL;DR The judge permitted people to take a fine-tooth comb to Mullvad's infrastructure and no logging was found[1]. [1] https://mullvad.net/en/blog/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised https://mullvad.net/en/blog/mullvad-vpn-was-subject-to-a-sea...
- StilesCrisis 5mo agoIt's not even a hypothetical, this has already happened at least once: https://en.wikipedia.org/wiki/Operation_Trojan_Shield https://en.wikipedia.org/wiki/Operation_Trojan_Shield
- red-iron-pine 5mo agoohhhhh its the ANOM thing. yeah, spicy