Top VPNs recording users, potentially leaking data when visiting their websites
vpnpro.com
vpnpro.com
It really doesn't bother me if a VPN company uses trackers and other tools to optimize their own website, other than the fact that some third parties may have good reason to believe that a visitor uses a VPN if the person visited the VPN's website. That says nothing (or very little) about how private you are when actually using the VPN.
The VPN industry is all about manufacturing rumors about your opponents.
and their info section shows that they only analyzed websites. "In order to analyze these websites..."
i get what you mean, but i think that's a bit more about reading comprehension than what they've been doing.
Case in point:
> Remember, these trackers are made so that they can track your online behavior, and follow you wherever you go on the internet. Having even 1 of them on your website really defeats any argument for ultimate privacy and anonymity.
Tell me that isn't trying to scare the reader into thinking the trackers can follow your activity while using the VPNs.
nonetheless, the research is still valuable. not very surprising that those antivirus companies with vpns have such huge numbers of trackers
"Top VPNs Recording Users" <-- By itself, this sounds bad and forces me to read the article to get more info. Most people won't, and it muddies the water. Recording users implies that they are somehow recording the browsing history of people using their VPNs. This is the immediate connection a non-technical and technical person would make here. Let's be honest.
"Potentially Leaking Data When Visiting Their Sites" <-- What does this even mean. I am leaking what data, and how would I be leaking it to their site? Why is this pertinent and what does it have to do with them recording users? Are they recording users history and leaking it to their own sites?
So many questions, so much click-bait. The net result is that I had to waste time trying to figure out whether this article was correctly backing up what its title conveyed. I have now given them ad-views, trust the VPNPro website even less, and the web is less well off in general because some > 0 amount of people will start mistrusting VPNs and VPN-review sites.
It's like a title saying "US government tracks travelers when they visit the US"
I wouldn't right off the bat assume that the US gov't is tracking all travelers all the time. I'd assume it's only when they land in the US
I'd rewrite your example as below in order to more clearly illustrate how I view the VPN title:
US DoHS Keeping Track On World travelers movements, potentially leaking data when visiting the US.
Note the main title, then the comma, and then the minor clarification. Firstly, the "main" point is at the beginning so that's the one that has the most effect and evokes an emotional response that colors the entire reading. Secondly, the last portion is separated with a comma, adds two points, doesn't clearly state how it modifies the first part of the title and is also ambiguous on its own. It vaguely confuses that tracking happens when they visit the US with the interpretation that the tracking happens all the time but only leaks when they visit the US. It also allows your interpretation that they only tracking while they visit the US. The comma should at the very least have been an "and".
If we wanted a real title that wasn't click-bait, here is my stab at it:
Top VPN providers record website-visitor's click/browsing behavior on their sites, potentially leaking it to metric providers with various degrees of anonymization.
OR.
Analysis of User-Behavior Tools On VPN Providers' Sites. <- This last one shows we can have an honest internet that isn't driven by click-bait, and could instead rely on the integrity of publications and the authors.
Even with you changes it still looks easy to tweak or turn into click bate. "Potentially" is a weasel-word, because even safe things could potentially go wrong.
"Every time you fart you spread germs, potentially infecting everyone in the room around you with cholera or other diseases"
> I don't know what you can see, but the
> full title shows that it's about websites
"Top Virtual Private Networks recording users, potentially leaking data when visiting their web sites"When the acronym is expanded, the title strongly suggests a problem with the networks, not VPN providers.
"Top VPNs are recording users and potentially leaking their data when they visit their website"
I had to truncate it here to fit
You would think a company whose core product is supposed to be about privacy would be extra careful to respect its customers' privacy on their own website.
I think you make a valid point, but there's a difference between their sales pipeline and their actual product. These VPN providers are businesses, and they're trying to optimize their sales. What demographics are most interested in their products? How did they get there? Does Google Analytics (or Facebook, or similar) have profiles on people shopping for VPNs? Are there advertising patterns that could have better ROI for attracting users?
I'm not defending the ethics of major VPN providers -- they certainly don't all have stellar records -- but I would be surprised if any major SaaS company didn't track user behavior on their brochureware/sales pages.
Great. But being privacy-conscious organizations, the VPN providers are surely including a clear and explicit opt-in/opt-out to any kind of data collection. Right?
Checks nordvpn’s site
Whoops. Nevermind.
All of these VPN services lean really hard into the fear factor for marketing, and this article seems no different. Just identifying a minor worst-case risk on their competitor's sites, extrapolating that risk and hoping no one notices these are websites (not services), and bundling it up nicely in an SEO-friendly blog post. VPN services are notoriously suss when it comes to disclosure anyway, but they're largely marketing to the lowest common denominator of the privacy-paranoid.
Next week's cruft article: "Your VPN provider knows your IP address"
Rinse and repeat.
Which VPN providers are using replay scripts on their website from services that don't properly exclude passwords, payment information, and PII from the replays?
That's actually worth reporting about. The rest seems like fearmongering.
As for them even selling privacy, while I don't trust major ISPs, at least there are more eyes on them. You generally have no idea who's operating a VPN, so even that's dubious.
Shoooockkeer of the century
so, in total: a regular business
of course, if you want "absolute" privacy and security, NONE of these VPN companies will fit the bill
https://arstechnica.com/gadgets/2017/05/how-to-build-your-ow...
https://github.com/pivpn/pivpn
Wireguard is faster & easier to set up for mobile devices.
Do you think it's possible to have real privacy/security for someone who faces state suppression a la Edward Snowden?
It's really not the "third parties" to blame here for the most part. You can make a viable business from selling a VPN service in exchange for money with a contractual requirement that you be respecting privacy in particular ways, so that you can actually get in trouble for not doing it.
But when Shady VPN Corp. starts offering the "same" service for "free" under a different contract because they're logging everything and selling your data, and then all the customers go over there because who doesn't like a free lunch, whose fault is that really?
Of course it is. But it's also the case that doing the opposite of whatever idiots do isn't necessarily smart.
It's like the thing where people say don't use Google because "if you're not the customer you're the product" but then the same people are pushing Microsoft products that not only charge you money but then still do the same thing as Google or worse.
If you're not paying them then you can guess how they're making money, but just because you are paying them doesn't mean they're not doing the same thing. You still have to read the fine print.
I block the website trackers anyway, so clearly I don’t approve of them. But TBF this has nothing to do with your experience as a customer.
Like a live test of a theoretical concept. Privacy over marketing. At some point, they have to improve their offerings and user experience. But I wonder if they went for the quickest option out of the box (there are lots of shady third parties there) or if they considered doing something a bit safer based on their needs.
I know lots of marketers that want A LOT of tools and get A LOT of data -- and not really sure what to do with that data
Shoutout to AirVPN, run by actual hacktivists: https://airvpn.org/mission/
Hell, I'm pretty sure, the guys at AirVPN are aware that working for their goals actually reduces their potential customer base, but the mission is more important, it just needs to be financed, and it appears to be going well.
Profit-oriented VPNs would probably (secretly) support legislation inhibiting digital freedoms to make more money.
Also, you can probably guess who's more likely comply with authorities in legal issues...
Find yourself a good VPN provider, worth staying loyal to, and save yourself from future headaches. When I first signed up on AirVPN, they were charging 54€ per annum, now, last I checked half a year ago, they have three-year plans for 45€. I wish them continued success!
but there's always such in-house/first party trackers like Piwik that i'm pretty sure these "good" VPNs in the list at the bottom with only 0/1 trackers are using