PureVPN Logs Helped FBI Net Alleged Cyberstalker
torrentfreak.com
torrentfreak.com
She had a laptop in her room with no login and a file containing passwords. The accused stole all of her account details and taunted her in person using information she had written in a private journal that she hadn't shared with anybody.
He was also using his work computer to access her iCloud, Google Drive, etc. and then send bomb threats, child porn, personal diary entries and sexually explicit photos to her contacts, school and family.
After he was fired he wanted access to that computer, which his employer refused. They reformatted the drive but the FBI picked it up and found all of these artifacts on that machine (including the PureVPN software and account).
This is a case where the FBI have started with a suspect and then worked backwards to build a criminal complaint. In those cases it is much easier to look at his financial records, find that he paid for a VPN service, subpoena the VPN provider for account records, and then link that VPN account and service with IP access as another data point for the criminal complaint.
In this case it was even easier - they had the VPN provider and account details, along with a host of other evidence, on his computer.
This isn't a case of starting with an IP address and then working back through a haystack to find a suspect - but rather affirming a link that was suspected, and found, to exist.
He didn't compartmentalize his real identity from his psycho stalker identity, and this combined with the accused horrible real-world behavior is what lead to his arrest.
[0] https://www.justice.gov/opa/press-release/file/1001841/downl...
Expect more charges to be added.
If proven it’s just an easy way to get higher sentences and thus more leverage in making plea deals.
It must be for property or money. I am not following. When did Lin try to gain money or property using fraud? It just doesn't make sense to 'throw on wire fraud' - the charge in the US is more serious than rape or kidnapping.
Disclaimer: I am not a lawyer. This is not legal advice nor advice of any kind. Do not commit wire fraud.
> PureVPN's Privacy Policy: We do NOT keep any logs that can identify or help in monitoring a user's activity.
> TorrentFreak: However, if one drills down into the PureVPN privacy policy proper, one sees the following:
> Our servers automatically record the time at which you connect to any of our servers. From here on forward, we do not keep any records of anything that could associate any specific activity to a specific user. The time when a successful connection is made with our servers is counted as a ‘connection’ and the total bandwidth used during this connection is called ‘bandwidth’. Connection and bandwidth are kept in record to maintain the quality of our service. This helps us understand the flow of traffic to specific servers so we could optimize them better.
> TorrentFreak: This seems to match what the FBI says - almost. [followed by further explanation]
Just further confirmation that these lip-service policies used by VPN's are completely meaningless. Remember this the next time you use a commercial VPN for "privacy".
Usual misinformation, the company only reinstalled the Windows Operating System (clearly without reformatting the volume(s)), as in the affidavit:
regmedia.co.uk/2017/10/08/lin_complaint_pacer.pdf
(point 37, page 16).
Also, according to the affidavit, what actually comes out from PureVPN is only that the same user connected to them from two different IP's, corresponding to home/work of the suspect. (point 52, page 22)
And that some traces of use of PureVPN were found in (the unallocated space of) the work computer. (point 58, page 24)
Simplified, IMHO 99% (maybe 99.99%) of the case is based on non-PureVPN derived evidence.
> "If the partition you've chosen contains files from a previous Windows installation, these files will be moved to a folder named Windows.old"
If you then click OK Setup will then create a Windows.old folder, move the old Windows dir, user dir to Windows.old and then install as normal.
If you delete the existing partition during the setup (or its a fresh drive), Setup needs to create a new partition(s) and will do it automatically if you wish, after which it will do a quick format.
EDIT: Reading the pdf they point too it states that the OS was reinstalled, leading to data deletion but they were able to find various artifacts in unallocated space. So they may or may not of formated the drive, but most likely at least delete the partition, but even a full format doesn't zero out the drive (unless you give format.exe the /p: argument).
A "normal", "full" format will wipe the volume, the /P command is implied unless /Q is specified (since Vista, but previous versions didn't have the /P at all), the /P:count parameter is to add (why?) to do it a number of times, using random characters:
https://ss64.com/nt/format.html
>/P:count Zero every sector on the volume. After that, the volume will be overwritten "count" times using a different random number each time. If "count" is zero, no additional overwrites are made after zeroing every sector. This switch is ignored when /Q is specified.
More clear here:
https://www.lifewire.com/format-command-2618091
>/p:count = This format command option writes zeros to every sector of the drive: once. If you specify a count, a different random number will be written to the entire drive that many times after the zero writing is complete. You can not use the /p option with the /q option. Beginning in Windows Vista, /p is assumed unless you use /q [KB941961].
Anyway, I wanted to also highlight how since the company where he worked was specifically a "software company" (I mean not a mom and pop shop around the corner or similar) the IT guys over there should have wiped the disk anyway, possibly using the SecureErase ATA command (that wipes also not normally accessible disk areas), it should be "standard" procedure.
Unless the /q parameter is used (or the "Quick Format" option is chosen) the format command will 00 the volume.
Of course if the task at hand is "reset a computer removing traces of what the old employee did and have a brand new OS" using a "Quick Format" is not particularly smart, I should have written "without reformatting properly".
Precisely so. It would not have been approved for general public use if that was not the case.
Also login time, connecting IP and logout time. So no traffic is stored, just that you logged in and were connected for X amount of time.
Google discloses that the victims account was accessed by a set of IPs. Those IPs are known to belong to PureVPN. A list of people connecting to those IPs as clients is requested by the FBI. The connection logs validate their suspicions.
Even if they acted on a subpoena, it means they had the logs nonetheless. Which still makes them liars and they are deceiving their customers.
I believe choosing a trustworthy vpn is an actual challenge.
The fact that this nut-job called Ryan Lin got caught is fantastic. But I want to choose if a company has data about me or not. What if the data exchange doesn't happen with FBI, but with malicious individuals.
I use https://protonvpn.com and I trust it. A transparent team with an already successful product (protonmail) working towards making privacy the norm. A group of scientists, not hackers or liars.
Well, VPN can protect your privacy up to a certain degree. If you go over it, there are always methods to dig you out, especially FBI is the one hunting.
The only possible way to protect your privacy is use anonymous services like Tor etc. But even those services can't guarantee 100% anonymity as there are still have way to compromise them.
So, I guess just don't broke the law then.
If the user here hadn't used his work computer and had paid the vpn account with bitcoin (using another email address), it would've been much, much harder for the FBI to track him.
How would PureVPN records be able to show which GMail account he was accessing? This will all be HTTPS.
Source: https://www.emptywheel.net/2017/10/09/purevpn-doesnt-need-to...
If they were ordered to keep some logs, they should say "We do NOT keep any logs that can identify or help in monitoring a user's activity, except in the event that we have been ordered to do so."
Since PureVPN is committed to freedom, and doesn't support crime,
we will only share information with authorities having valid subpoenas,
warrants, other legal documents or with alleged victims having clear proof of any such activity.
So I think it's likely they would link connection records back to individual users, and if you did that enough times (perhaps only 2 or 3 occurances?), you'd know which individual user was responsible without any detailed logs?It doesn't mean they'll go to court to protect your identity in a criminal case, you'd be very foolish to expect any company you're paying $10 a month for to do that for you as an individual.
"No logs" sounds to me like they don't keep any logs.
Both claims are in the first paragraph of the privacy policy though, if you don't read even the first paragraph of a privacy policy for a service you're buying to get privacy, I don't know what you'd expect!
IE they had a suspect, went to their employer, they gave over a laptop and found evidence from info on the hard disk.
PureVPN doesn't/can't guarantee you own computer doesn't log stuff in memory cache etc on the harddisk.
Somethings missing here.
[edit]
51. specifically states how other VPN's were used to track him, then generically says in 52. PureVPN was also used. Fits well with tristanj's comment.
Looks like he forced the FBI to unleash hell. Let's not forget parallel construction https://www.reuters.com/article/us-dea-sod/exclusive-u-s-dir... with the NSA and other intel agencies: "It's him, now go find evidence that will hold up in court"
In this case: run your own VPN endpoint on a security hardened BSD or Linux box with your own hardware (preferably in your own rackspace or at a hosting location which is trustworthy)
You are welcome.
In another country where you paid with bitcoin or prepaid credit cards, otherwise the IP's assigned to that hosted server will be associated with you and offer zero protection from an FBI raid.
Seems like they've straight up lied about their capabilities.
That said, there are always some logs. The VPN provider may not keep session logs, but their upstream could easily log connections to the PureVPN boxes. You can use the upstream log to cross reference with gmail account accesses of potential suspects and you can establish a link.
Not to mention that no US based company is going to fight a subpoena/gag order from the US authorities for a lowlife online stalker.
edit: I see now that PureVPN is based out of Hong Kong, so the statement about subpoena may not apply.
https://thatoneprivacysite.net/vpn-comparison-chart/
I heard good things about https://vcp.ovpn.to/ but I doubt that I will work in China. But if you don't need a VPN in China I would go with ovpn.
That said F stalkers, I won't cry if they catch him/her.
Sadly, we live in a world where too often, emotion and reactionary tendencies guide people's opinions.
Scarily, these opinions often become law.
And since too many of these people hold power, the only solution I can see is to blend in or hide.
Another way is: there are two options. Either we have strong anonimity on the Internet, or the authorities have the power to catch criminals. Which one do you think would win in a vote?
I don't know if this was a rhetorical question with an implied and obvious answer, but to me it actually is a curiosity, I have no idea which one would win a vote.
Those who paid attention knew that Trump needed to win votes in specific states, not on the Upper East Side or in the Bay Area just like those who pay attention realize that only places like Bay Area or Upper East Side would have people voting for anonymity vs. ability of police to solve crimes.
probarbly some lame story will come back if any , by purevpn, as if fbi did some mitms from their services / on their services, they would probarbly not be allowed to speak of the details of how this was done and what was done..
purpose of vpn is to hide your location mainly, if u want it to protect u from your countries agencies, don't pick one in your own country and be very specific on what one you chose... >.> seems like a case of poor choice and awareness on the user's part more than the vpn provider, who is probarbly unable to stop these kind of intrustions by the agencies without getting taken down...
Why just use one? Go to a Russian one, then tunnel everything through a US one, then to a German one
Could you elaborate on that? I'm going to China soon and don't know if I should trust commercial VPN providers. I was under the impression that if I use SSL/TLS it's impossible to MITM my connection.
https://arstechnica.com/information-technology/2017/03/googl...
Google chrome can detect a google cert that is not legitimate because it has embedded the certificate fingerprints in the browser for its public certs. We don't have that benefit elsewhere.
Might some state actors have cert signing ability. You be the judge.
The countermeasure is certificate pinning, but that is typically implemented only for a handful of sites; e.g. Google with Chrome.
It's not that simple - it depends on the implementation, otherwise if your browser trusts root cert which was issued by chinese gov, what's to stop them doing the mitm? I mean, they issued the cert.
However to mitigate this, VPN providers (some of them) implement checks to make sure they only trust particular root certs, which makes doing mitm much harder.
Re your trip to China I would not be worried about that though - 30 % of Internet users in China are using VPN's daily so it's not like you will be flagged and get locked for using a VPN. Pick one of the reputable ones (NordVPN?) and you should be good.