Therein lies the problem. You can't trust VPN providers.
Therein lies the problem. You can't trust VPN providers.
In that way he has to find a way to get the VPN provider to give out my real address. What might be possible with a lot, but for sure not with all of them.
Also think countries, my country does barely have any contracts with other countries for crimes like this. So they would have to use a complicated way to actually force them to give out my data.
In most situations we are already way over the realistic damage done in forms of costs to catch the individual.
Why the 'probably'? Of course, no VPN-provider should be trusted at face value, but do you know of any sources that claim that Private Internet Access is in fact an elaborate honeypot?
One shot? Backdoor and reconstruct in parallel.
Looking at the argument though, even if it is a honeypot blowing it is a one-shot deal. The users are never going to trust PIA nor any other VPN that makes similar claims ever again. That means that they probably wouldn't spring the honeypot, if it is one, for anything but the biggest fish.
Frankly, I think you're all splitting hairs. Most of us understood the point he was making even if the phrasing of that sentence didn't flow as well as you may have liked.
If they are willing to do that, even TOR isn't real protection due to the fact it can and will be breached in the event of an active attack by malicious nodes on both ends of the circuit.
A VPN you can buy relatively anonymously [e.g. disposable gift cards bought with cash] and use with common sense [e.g. Not via your home LAN] are an effective privacy tool.
However, 99% of people aren't going to go through that level of effort which makes them nearly useless for privacy purposes.
A MitM at the local wifi shop is going to know you are and what you are doing.
A MitM at a VPN you paid for with a gift card you paid with cash is just going to know which wifi shop you were at. If you never go back, odds are they can't figure out which customer you were.
I guess that sums up exactly how trustworthy they are.
As far as you know. And that's exactly where the problem lies. You are trusting your adversaries to be honest about who they cooperate with, which is a great way to get screwed over, because your adversaries are adversaries.
So no, it still wouldn't necessarily be "better than not using one". The tradeoff is far more complex than that.
(I was able to find some information leaks in their forums, which I reported responsibly, but a malicious actor could have used to exploit an outdated module.)
Despite my less-than-chilly feelings about the service operator, I certainly wouldn't recommend anyone else trust them. An SSH tunnel over Tor (or even better, something like PORTAL) to protect against malicious exit nodes, where the endpoint is a VPS you rent with bitcoin not connected to your real identity, is preferable.
Best case scenario: They're an illegal operation who's defying local laws.
Worse case scenario: We're being lied too.
Their twitter feed is also a goldmine.
Your link is borderline nonsense.
The only real evidence they give about not using VPN's is when hidemyass proxy gave up some Anon's in 2011. However, it very clearly states in the hidemyass TOS that their service is not to be used in illegal activity, which is exactly what the hackers who they gave up were doing. They only gave up the information after receiving a court order, even though they had seen the hackers in chats saying they used their service, at which point they did nothing until the government stepped in.
http://www.theregister.co.uk/2011/09/26/hidemyass_lulzsec_co...
Yeah, and you have no evidence that I don't have a nice bridge to sell you, so will you buy it?
Trusting by default and requiring evidence to distrust is a poor way to protect your privacy. VPNs - unlike Tor, for example - have no protection against logging by the operators, so why would one trust them? Because they pinky swear they won't log?
Which is pretty much the default for anything you use on your computer.
- You ever install a software program?
- You ever click on a link in your email?
- You ever go to a site that contains malware that installs itself covertly on your PC?
- You ever open a JPG file?
- Use a cloud service?
- Save your pictures to Flickr?
- Ever use social media of any kind?
- Use any Google product or service?
- Use any Microsoft product or service.
The world is FILLED with UNVERIFIABLE information, the fact that people seem to put so much mistrust in a VPN provider when there's thousands of other ways and means to get to your data is well. . .absurd. Talking like you suddenly need some high level of verification that a VPN doesn't log your information when there's literally thousands of other ways to get at that information is completely myopic.
Just like your example with TOR, which recently has been shown to be not only insecure, but readily hackable, yet you seem to trust that far more blindly.
https://theintercept.com/2015/07/16/hackingteam-attacked-tor...
https://pando.com/2014/12/26/if-you-still-trust-tor-to-keep-...
http://siliconangle.com/blog/2013/09/09/not-even-tor-is-safe...
If you're concerned about having "verifiable information" to protect you, you're living in a dreamland.
As for Google and Microsoft, I don't trust them. I give them my info with the expectation that it'll be shared with governments and other companies. I use their services despite that.
VPNs, on the other hand, are built in order to protect your privacy, so the same reasoning can't be applied.
As Tor, and beyond the fact that you didn't even bother to understand the links you posted (the first it's not even about any flaw in Tor), sure, it can be hacked if one manages to control 3000 nodes or have NSA-like capabilities in breaking crypto keys ($1 billion dollar custom-made chips, from your link!).
But a VPN doesn't even need to be hacked - though they can, and probably with less difficulty than Tor - all the operators need to do is set "log = True" in their configuration files. There is not even a semblance of a protection. It's just pinky swearing.
1. Not even about Tor, rather about Tor Browser, which is a modified Firefox and is optional to use (and 100% unrelated to Tor as a protocol or daemon). Complaints about this can be directed to Mozilla.
2. Pando loves to fear-monger about Tor and draw 'conclusions' without actually supporting them. Notice how they represent a blog post stating "incapacitated" (ie. affecting availability) as "exposed" (ie. affecting confidentiality)? Notice how Pando nowhere actually describes how a lot of 'fake' nodes could supposedly compromise users?
That's because they are not making a technical argument, and they don't understand the internals of Tor. They are just publishing a hit piece that sounds vaguely to the untrained ear like it might have some technical merit, without ever actually proving the assertion they're making. And their implied argument is wrong.
3. Ah, an actual issue with Tor. But look at the operative phrase: "The problem boils down to this – around 90% of Tor users are still using older software which can be hacked." It's an issue that has long been resolved, and was an implementation error rather than a fundamental issue with Tor.
--
You're really not the first to try and claim that Tor is "broken" by pointing at a bunch of articles like this. The reality is that none of it actually means that Tor is broken, and the one attack on Tor that does exist (and that is very expensive to pull off) isn't even clearly described in any of these articles.
If you're going to argue about the technical merit and security of different proxying techniques (because that's what they all effectively are), then at least inform yourself to a point where you actually understand how they work internally. Right now, you just look ignorant.
I think icebrained nicely covered the other few points, aside from "installing a software program" and "cloud services" - in which case, I'd recommend you look into package/executable signing, how it provides some guarantee of consistency, and how you can use it to avoid dodgy software builds. This kind of thing is also exactly why many people avoid proprietary software and 'cloud services', by the way.