It's the tragedy of success in the privacy industry.
This type of argument contains the assumption that it would be too much trouble for them/not worth it to monitor an affluent anarchist or semi- anti-authortitarian with an above-average IQ.
We've seen that A) their resources are as virtually unlimited as their paranoia B) tech developments have driven down the cost of sophisticated surveilance strategies C) xkeyscore and all of the other releases is confirmation.
This type of argument does us all a disservice by subtly shaming those who care about state-surveilance of private (and peaceful) citizens who value their privacy and/or who exercise their right to actively participate in progressive movements that challenge the establishment.
We've already seen that the NSA actively targets people searching for privacy tools (e.g. Tails, Tor). The act of using a VPN is mildly interest-provoking, so it's far from crazy to suspect that someone might try to scrape everything happening there in case some of it is interesting.
How is/was this claim substantiated?
You should not trust what people tell you over the internet.
You're still better using independent VPN clients, but I would not trust them at all if the installer actually has malware.
Just be careful with the bespoke VPN clients as they are very juicy targets for MITM attacks. I know I would be going after VPN software if I wanted to do ex-filtration for a small subset of users trying to hide their tracks from governments and ISPs.
[0] https://technet.microsoft.com/en-us/sysinternals/bb963902.as...
Care to provide anything substantial (e.g. net dumps or screenshots at least)?
> and they were C&C servers
How do you know that, have you MITMD your connection? Do you have anything besides generic spooky words?
Yes, with another Sysinternals tool called TCPView https://technet.microsoft.com/en-us/sysinternals/tcpview.asp...
You don't even need an AV product, you can spot malicious activity by eye alone.
On macOS, I just created a new "PIA" service in Network. Is there any reason to use Viscosity instead of the macOS VPN client?
IPSec is typically considered secure, but it's allegedly compromised in some implementations and/or weakened during the standardisation process.