If I had to guess, it would be PIA: the most popular, the most accessible, and the most affordable US-based VPN.
When a VPN is run by NSA, of course it will stand up in all courts. How would a state surveillance agency let its tool be so publicly destroyed? And it doesn't have to keep any logs at all. They can just be forwarded in real-time, based on a set of filters and rules ("URLs that are requested by <IP>", "IPs that are requesting <URL>").
I would also like to know the motivation for a US intel agency to want to run a VPN. It seems to me like it wouldn't be worth the bother: VPNs aren't illegal in the US, so it would be too hard to convince everyone to use theirs. Spies, etc. could just use private ones they control. They'd just see a bunch of crap from unsophisticated people.
Seems to me like it would be more likely for US law enforcement to want to do something like that, but I'm skeptical they have the resources.
We know from leaks that the steal industry secrets.
> If I had to guess, it would be PIA: the most popular, the most accessible, and the most affordable US-based VPN.
If I had to guess, the state surveillance agency-run VPN would be one that's still accessible from China. I understand (but I could be wrong) there are still a few that manage to evade the blocks and provide good service despite all the crackdowns. Chinese state security has many more reasons to want to watch domestic VPN traffic than the US does. Their motivation is proven by the fact that they've spent the effort to build and maintain the "Great Firewall," and crack down on VPNs that bypass it.
It would be reasonably clever for the Chinese to crack down on all the VPNs that they don't control, funneling all the "illicit" traffic to the few VPNs they do control. It would make spying, monitoring dissidents, etc. much easier for them.
The NSA and other US intelligence agencies probably don't care very much about anyone that's dumb enough to need to use public VPN. Seems like the only people who would care in the US are domestic law enforcement, like the FBI.
Where do you plan to announce when you're ready to name names? I may have some need in the future to use a VPN in China and would like to be aware.
Also props on your mail service, it's very impressive. If it had been released a bit earlier, I think I'd have been a customer.
Like ProtonMail, the ProtonVPN team is distributed, split between Geneva, Skopje, Vilnius, and San Francisco. Tesonet (one of the biggest IT firms in Vilnius) was previously used as outsourced HR before we incorporated our own entity in Vilnius. We have similar arrangements for our staff in San Francisco, Prague, and Skopje. The above poster's intentions are a bit suspect, given that he's the co-founder of PIA...
But your entity's business address in Lithuania is still Tesonet's HQ. And Tesonet runs the entire technical infrastructure needed for a VPN service. So, are you partners or competitors?
I wasn't that familiar with your company before today but I can tell you that I won't be a customer at any time in the future based on your comments.
- ProtonVPN UAB lists Tesonet's CEO as a director
- ProtonVPN UAB is operated from Tesonet HQ in Vilnius, Lithuania
- ProtonVPN UAB uses previous Tesonet's technical employees
- ProtonVPN uses IP address blocks that belong to Tesonet
- ProtonVPN mobile app is signed by Tesonet
It seems, that ProtonVPN is a free VPN service by a data mining company from Lithuania.
Proton has also been thoroughly audited/vetted by third parties, including Mozilla: https://blog.mozilla.org/futurereleases/2018/10/22/testing-n... and also the European Commission which partially funds Proton: https://protonmail.com/blog/eu-funding/
Any data mining claims are categorically false, and doing data mining would also subject us to fines of 20 million Euros as discussed here: https://protonvpn.com/blog/is-protonvpn-trustworthy/
The problem is that, without a publicized investigation, there is absolutely no way for users to verify no-logging claims by VPN providers. The same is so for Tor relays. And Tor deals with that by using three-relays circuits. In order to connect users with online activity, adversaries would need access to logs from multiple relays.
One can do the same, albeit more crudely, using nested VPN chains. It's quite easy, using pfSense VMs as VPN gateways.
One privacy tool that I'd like to see is a program that takes a .ovpn file and user credentials and outputs a pfSense config file which the user just has to import.
Following a guide like yours is quite a bit of work and somewhat error prone. Few users will be able and willing to do that.
There is the argument that, in doing the setup manually, users come to understand what they're doing. But yes, it seems that most are put off by it all.
Tor still does better than anything else. I don't think it's worth scaring people away from using Tor, because whatever else they'd be using instead is certainly worse.
EDIT: Parent comment originally said words to the effect of "Reminder that Tor has no defence against global traffic analysis".
It's possible to guard against global traffic analysis by establishing permanent fixed-bandwidth links between each node and sending traffic along them even when they aren't assigned to a circuit (or the circuit is idle). Then there is nothing to passively analyze because the amount of traffic between each node is always the same.
The problem is that this consumes a very large amount of bandwidth.
If you instead ask yourself "how many Tor nodes are out there"[1], and then ask yourself "what is the NSA's annual budget"[2], the concept of a global active adversary makes me a bit nervous.
[1]: http://torstatus.blutmagie.de [2]: https://www.theverge.com/2013/8/29/4672414/leaked-snowden-do...
And does not run 100%bandwidth all day and all night.
Resisting global traffic analysis for the purposes of deanonymization is not so easy. The issue is that if every time Alice sends ~476MB of traffic, Bob promptly receives ~476MB of traffic, it's not hard to deduce that Alice is talking to Bob. To fix that, the amount and timing of the traffic Bob receives needs to be independent of the traffic Alice is sending him. Which is possible but inherently comes at an efficiency cost.
I can imagine a global passive adversary that could log all Internet traffic, and make it searchable. The NSA can somewhat do that. But even the NSA can't retain everything for more than a few days, if even that. So even retaining necessary data for a match would be a stretch. Let alone having the processing power needed to do the matching.
We're talking about an attacker that can see every byte going over the wire, encrypted or not it's still able to measure the volume of data itself.
> Well, first thing, you don't send many MB directly to someone. You put it on a Tor onion file-share site, and PM the link via Tor.
In that example the attacker wants to determine the location/IP of the hidden service itself. It's pretty well known that high traffic / volume hidden services are some of the easiest targets for global traffic analysis.
> I can imagine a global passive adversary that could log all Internet traffic, and make it searchable. The NSA can somewhat do that.
They don't have to log the data itself simply the meta data and in specific the volume of data sent between vertices in the graph. Various agencies have openly admitted they keep this information and it's not considered "protected" in their view.
This is simply a graph analysis problem, similar to how Bitcoin is pseudo-anonymous unless you use specific methods that aren't built into the core protocol.
And about onion file-sharing sites. With OnionShare, you can create a site just for that transfer.
If Alice uploads the file and Bob downloads it immediately then you haven't gained anything. Bob has to wait some time for it to work, which means you didn't actually need a low-latency anonymity network to begin with. You can't use it for things that actually need real-time communication, like for live streaming or anything interactive.
I agree about unworkability for real-time communication. But there, you want to keep messages small. And use padding. Trying to make live streaming anonymous is nontrivial.
I mean, if only 100 people use I2P, and some traffic has gone over I2P, you can quite easily narrow it down to the set of 100 people.
I'd be delighted to be proved wrong.
Can you elaborate on this? I am not familiar with the term "nested VPN chains", is this a specific configuration supported by pfSense?
I quote sound because as another commenter mentioned, without trusted third party audits it's all marketing...
And as the Snowden leaks have shown being located outside the US is not even a speed bump to the NSA being able to access your communications.
Mullvad gets around this by not storing customer information. As others have pointed out, your "account" is just a long number. You top it up any way you want (including sending cash in an envelope if you are truly paranoid).
So I do believe that it stands a better chance of being fully anonymous & private than a US counterpart.
If you click on the Almanac News source in your link, it states:
>"John Allan Arsenault, general counsel for London Trust Media, a VPN company, testified about how many VPN companies, including his, intentionally don’t retain logs of internet activity of their clients so that they cannot be produced in response to subpoenas from law enforcement or others."
Note it doesn't say they don't log only that they don't retain them. So it's quite possible that the subpoena process simply lagged behind the log retention window. Also the claim in only for "internet activity" and nowhere do we see that defined. Does that include client authentication?
Then article then goes on to state:
>"Arsenault said he could not find any record of Ross Colby subscribing to the VPN service when he searched using Ross Colby’s two known email addresses, which he received from law enforcement."
Could not find is not the same thing as there was nothing to search.
[1] https://torrentfreak.com/vpn-providers-no-logging-claims-tes... [2] https://torrentfreak.com/ipvanish-no-logging-vpn-led-homelan...
Also the first link continues its insistence on using the phrase "user activity" logging. That's a rather nebulous term. Nowhere is "user activity" defined and it's certainly not a term that meaning in the context of syslog/journald. Does "user activity" logging preclude RADIUS authentication?
We don't log, period. By stating that we don't retain logs, it means that we don't EVER retain them, not even for 0.001ms.
Hope this helps.
I am also very curious how support and operations troubleshoot client issues in the absence of any logging.
Furthermore an independent audit is still far more credible than believing something is true simply "because the CEO said so."
OTOH, I don't like the way (ie. tone) the co-founder is discussing in this thread. I find that unprofessional.
That said, I'm biased; I'm a ProtonVPN customer.
Here's the catch: I don't assume I'm anonymous with it. Just enough anonymous to use it for copyright infringement.
At this point though I am so impressed with WireGuard when my ProtonVPN sub expired I really just want a good VPN provider which supports that.