Many free mobile VPN apps are based in China or have Chinese ownership
zdnet.com
zdnet.com
It doesn't matter where they're based. If you pay with a credit card under your real name the burden of risk is always on you and if the company has agreements with whichever jurisdiction you are in then they will collaborate with LE.
that said, trust is fickle: The ultimate example of why not to put trust in companies was WoSign/StartCom.
WoSign acquired Startcom because they were a trusted fresh player with a still untarnished name and available cheaply (also thanks to Eddy Nigg and his investor Wes Kussmaul who both saw no conflict of interest and indeed claimed in public Eddy didn't know who the buyer actually was until it was too late).
When somebody shows up with a fat cheque and tells your VPN company that Christmas came early, and that they're being bought out, then you have no reason to continue to trust or? Yet people do continue to trust (see the N.N. Taleb Turkey problem). People then are forgetting their trust assumption actually doesn't hold when main mode of growth for the company is M&A and not product development & innovation.
When trust is just a commodity that can be acquired and resold willy-nilly by some people with enough cash, then the product/service is automatically snake-oil (no matter if the crypto and the implementation of the software is 100% rock solid and was written by gods).
For VPN's a good rule is to choose a neutral company that has very little in common with you. If you are doing shit in Iran don't use an Iranian VPN company. likewise if you do shit in Russia then US/UK VPN should be safer than a VPN located in Cyprus.
If you do "shit" against Turkey, with a VPN in Australia while you are based in Taiwan that's 3 jurisdictions and much better than doing shit against Turkey connecting from Australia with your VPN based in Australia.
Finally it is best not to do shit, but sometimes doing shit is the only way crimes by governments and those in power can be exposed.
Edit: right?
Firefox has good settings you can set in about:config [1].
If you don't have WebRTC disabled, there's a good chance a service can get your public IP address directly.
[0] https://panopticlick.eff.org/ [1] https://www.privacytools.io/#about_config
The article author sounds surprised but it is quite logical if you think about it.
It was recently sold to a foreign owner and stopped provided any Chinese based services - if you send them some emails in Chinese, you get English responses. Pretty clear sign that they quit the Chinese market for whatever reason.
Well, I'm not very sure, but we had few crack downs on VPN selling recently in China, some people even received prison time plus fine.
It's not very safe to operate VPN company in China, so maybe the best way is to sell that hot potato to whatever who wants to take it. The only exception is probably "Game Accelerator"(s) which is a special type of VPN that only transports game traffic.
For Chinese apps, we can only imagine that the government does really police the ban or that they are honey pots...
And there is a university net, it's slightly less blocked than public nets.
They've charged someone for selling VPN online, but charging users is effectively unprobable due to the sheer number, but since Chinese laws are generally vague, judges and prosecutors are easily influenced and arbitrary on party security cases, they can always pick couple guys off to make a statement or set an example, like Sabotaging Computer Systems.
Not even people in Qinghua (number one uni in China, if you don't count central party school) I know, know of anything that amounts to that.
The very same thing with MPLS, and allegedly "physically uninterrupted" links to HK. They also have GFW on them.
There is nothing that amounts to "officially permitted VPN" in China. That's a myth.
The only thing that amounts to that are microwave to HK/Macau, HK SIM, VSAT, or a cable across Sham Chun, and all of this is being actively looked for by police and three letter services.
Study is two years old, but I doubt it's gotten any better. (Source, PDF: https://research.csiro.au/ng/wp-content/uploads/sites/106/20...)
At least with a paid service I might think that my money ... could be enough to sustain the company. At least it could be.
I would assume a free service would have to be selling your information just as a matter of policy / economics.
With a paid VPN service, part of the attraction is that you're one of quite a few users on any given server at any given time.
Edit: If your only goal is to get past stuff that's blocked, that's different. Though if you get a VPS, you're still using an IP in a range that's likely to be blocked if a service doesn't want VPN traffic.
That's the correct model for onboarding with free services, not offering a free service tier with restricted speeds.
It's simply stupid as a user to forward all of your traffic to another company for free. Thus any VPN that offers such a service does not believe in fully educating its users of the dangers involved in using a VPN, and are operating at an ethical boundary.
You surely can't be suggesting that this didn't come up in meetings, and that the opportunity cost wasn't determined and taken into account when offering this trial service.
The painlessness of the service, along with the encouragement to generate as many new account numbers as needed while testing, along with allowing full feature access without throttling, meant that I generated two weeks' worth of trials before finally deciding Mullvad was right for me.
But now I know they are right for me, and as I said in an earlier post I am now a customer for life. As long as nothing changes, that will remain so, and I will, as I am now, frequently proselytize their service and encourage others to try them out for free. I'd say they calculated the opportunity cost correctly.
You can easily pay an ISP $50/mo for broadband, so why should you trust a paid VPN that will handle all your traffic for only $5-8/mo on top? Is the difference all infrastructural costs? What about those cheap $3/mo VPNs? Where do you draw the line?
I think it is more that the costs of running an ISP are much higher, you do not only need peering, but the networks including the last mile need to be put in the ground and maintained. Plus, in to some extend, people in areas with high-density populations subsidize expansion into lower-density areas.
The VPN market is really different. In principle anyone could start a VPN using just a VPS (it wouldn't be the best, but many VPNs are terrible anyway).
Not a VPN that supports P2P filesharing, but a VPN where the users are the "servers", like Hola used to be before it started sucking (can't even select country now without paying).
P2P VPNs don't offer much in the way of privacy, decentralization is only better in theory here. For unblocking services, many normal VPNs can do this fine as well.
Is this really something desirable? It seems like it would be asking for somebody to commit crimes using your connection (without the plausible deniability/justification that you are running a VPN company).
Yes, offer them free VPN, what good is encryption if you're connected to a server they own/have influence over?
I guess this is more effective because dissents is a very small subset of vpn users, and application layer encryption makes it hard to extract much information even if you can monitor vpn traffic.
"If you aren't paying for it, you are the product".
Also, VPN isn't a magic cure for the disease of privacy violation. You are just choosing to trust the people running the VPN service over the people running your ISP. Should you trust a VPN company more than your ISP? I really can't say, but VPN isn't a magic fix.
Does it mean that if you do pay for a product, that you still can't "be the product"?
Blanket statements shouldn't be anyone's motto.
But either way, you give away DNS log, http data, and possibly forced affiliate link when shopping online.