UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
comparitech.com
comparitech.com
During that period, we failed our users. The data exposure was real. It resulted from allowing a third-party SDK to emit runtime logs, combined with a misconfigured server-side logging system that was accessible without authentication. That architecture should never have existed, and the criticism we received at the time was entirely justified.
I deeply regret that we put users in that position. I also understand that no explanation can undo the harm that was done. Still, once the severity of the issue was fully understood, it became critical to make fundamental changes and to be clear about what those changes were.
All client-side and server-side connection logging was disabled, including debug and development logs.
Sensitive fields were removed at the data-structure level so they cannot be recorded, even unintentionally.
The logging pipeline was rebuilt to require authentication, with strict least-privilege access controls and encryption applied both in transit and at rest.
Additional safeguards were added to the CI/CD pipeline so that any attempt to reintroduce connection-related logging is automatically blocked.
Today, user connection data cannot be accessed through internal APIs for a simple reason: it is no longer collected. This does not make past mistakes acceptable, but it reflects the seriousness with which this failure has been treated.
I am sharing this solely to take responsibility and to be transparent about what was learned. I am also willing to answer technical questions or listen to any concerns.
(https://www.theregister.com/2020/07/17/ufo_vpn_database/)
So ES has insecure defaults, I get that and it's been discussed to death.
But who the heck, in this day and age, exposes clusters directly to internet traffic? I don't care what the defaults or security measures you have. DONT EXPOSE SERVERS.
Place them inside a VPC, preferably a private one(in AWS parlance, behind a NAT GW). Use _something else_ to send traffic to them. If you are on AWS or similar (but not Azure I guess), add a load balancer to it. So now access would require creating a new load balancer, pointing to the servers in question, adding listeners on the desired ports, and configuring the appropriate security groups. Only then you can send external traffic. On the specific ports you configured on both listeners and security groups only.
Do this everywhere and you are in a much better shape. You still need to configure servers correctly, but if you mess up, nothing happens, unless you mess up many other things in an error cascade.
P.S. Azure has load balancers and security groups too- in fact their security groups are better than AWS's in some ways such as supporting thousands of rules instead of only 50.
0 - For API servers. I'm not sure if you could configure this with services like Elasticsearch.
You can achieve a similar effect in AWS, by declaring only the LB's security group as the source in servers' security group ingress rule.
Any requests sent directly to the servers simply wouldn't connect.
AWS and GCP load balancers are more like an endpoint. Your network is otherwise unaffected.
If you don't have the budget for a nat/load balancer or want to just keep it simple, a simple iptables rule would do! Then test with nmap regularly to see if it's correct.
It's not such a big budget in any of the big cloud providers.
And my point is: if you don't need access, you won't even have such load balancer. Unless someone goes out of their way to provide access to your server, no external access will exist.
It's a design problem in my opinion. By default, listening on 0.0.0.0/0 should exclude loopback interfaces by the OS. That way, anything makig incorrect assumptions would fail and would require correction. Second, cloud firewall rules should imply deny all when "none" is selected. That way, having no protection is the same effort as adding at least one manual rule.
But yes, if it's your own server, everyone should remember that regular Linux features are darn powerful, too.
If you use some provisioning tool you can have the same thing with IPtables. But why are you on AWS if you don’t want to used the features Amazon provides?
VPC is more akin to a glorified virtual switch/bridge.
I'm a huge fan of beginner tutorials that include security as a default, rather than having it as the thing you do last - and then commonly in actual project work all the development gets done against an insecure cluster in dev, then someone turns security on at the end, it all breaks and you now have a group of stressed-out people only incentivized to remove the thing that is now delaying the project at the very last moment. Makes for some easy mental gymnastics.
You can see it here: https://www.youtube.com/watch?v=K-2iZ_lJVag
That was done explicitly because of issues like that. Security isn't a feature, and the fact that your product keep leaking details is not the fault of the user the 100th time this happens.
I'm glad RavenDb is still going well.
It's nice to assume that everyone setting up backend services for the multitude of companies out there have gone through accredited training and have years of strong production experience with security chops.
The reality is that because the gap between technically inclined and technically clueless is so large, anyone who can stumble through an online tutorial can be seen as "experienced" to someone who isn't.
I'm not sure what the answer is, but this is going to keep happening - maybe a 3rd party service that evaluates "Getting Started" guides for backend services? If basic security protocols are not covered, they get a red mark, and business owners could use that as an indicator of whether their tech folks could potentially screw it up.
[1] https://aws.amazon.com/blogs/aws/amazon-elasticsearch-servic...
[2] https://medium.com/@vishnunarang/how-to-migrate-elasticsearc...
I can see developers crunched for time (or businesses, money) not taking the additional steps to get there... And this is the same deal for Redis/memcache, which is another reason I think we see those exposed sometimes too.
(To be clear, the additional costs are minor compared to a big business budget, they would be more detrimental to a low (~<400/month) budget project .. or a team that can't dedicate 300-600 man hours to implement this)
[1] https://www.theregister.com/2020/07/17/ufo_vpn_database/
UFO, Secure, Pure VPN, etc
But, there are few reasons to actually use a VPN nowadays, there was a discussion on HN a few days back, but I cannot seem to find it at the moment.
Edit: Found it: https://news.ycombinator.com/item?id=23566390
If I was working at UFO and saw the risks to my fellow citizens created not just by the company's poor security but their willingness to descieve customers I'd worry the company would quietly hand over whatever the Chinese authorities asked for - no "warrant canaries" or truth in advertising - and if probably look to throw a figurative grenade into their operations. If that meant data exposure, better now before they perfect the application of the new security laws then later when everyone feels comfortable and the CCP is just sucking up all of UFO's traffic and logs.
If a provider shows even the slightest amount of fishiness, instantly discard them (NordVPN immediately comes to mind, with their weird influencer marketing campaign).
Primary use of VPNs I see is to get onto my workplace's network.
I honestly don't know if you can do this with your average commercial vpn, but the technology is also good for many things like setting up virtual networks (hence the name) so you can do things like access your home computer from anywhere without exposing it to the internet.
I'd notice pretty quickly if someone was MITMing all of my traffic. I guess they could MITM a third-party Javascript site that wasn't being served with HSTS. Normally that would just give them all the information I already give to Google or Facebook and the hundred other shitbags that run JS on the sites I browse, but if they got really lucky they could pretend to be some third-party payment provider that didn't use HSTS or I hadn't used before.
A browser is a very complex tech stack and it wouldn't surprise me in the slightest if there were vulnerabilities exploitable with a MITM. An airport would be a natural place to try and attack computers, lots of people with lots of money many of whom are doing things like moving that money around and many of whom won't think twice about connecting to an unsecured public hotspot.
There's also all the other apps on your computer, how frequently do you think electron-app-foo-bar updates it's chrome version and what are the chances it's using one outdated enough that there are known openssl vulnerabilities against it?
I don't think third party non-HSTS traffic is that much of a concern these days, both firefox and chrome block http traffic from https pages by default.
It’s not that I trust them but I’d rather some random company across the world has my jerk off logs rather than my ISP who hands my habits to my government and all its favoured cohorts.
The NSA is simply not most people's threat model, and if they _are_ running it, it probably means that someone shadier is not. I'm using a VPN because I don't want my ISP to see what I'm browsing, don't want end sites to know who I am, want to watch American Netflix, and because the country I'm in tries to block all adult sites. The NSA is welcome to all of this traffic _shrug_
Full disclosure: I work at PIA.
[1]https://torrentfreak.com/vpn-providers-no-logging-claims-tes...
[2]https://torrentfreak.com/private-internet-access-no-logging-...
[1]https://en.wikipedia.org/wiki/Burden_of_proof_(philosophy)#P... [2] https://en.wikipedia.org/wiki/Evidence_of_absence
Degree of proof is a relative: Maybe a terror organisation use PIA, NSA go fishing for evidence PIA has nothing. Terror org assassinate NSA head. PIA could be a front, but NSA head had to be willing to lose his life to hide the fakery, and terror org wasn't a big enough fish ... more likely you're currently in a coma. Lots of places for false premises to creep in.
Dial it back, is there a point where there'd ever be enough evidence?
The whole company is shrouded in secrecy. After speaking at length with an ex-employee of PIA who now maintains this open-source iOS VPN client:
many (most?) employees and contractors at PIA have no idea of the identify of their direct managers.
Imagine working for a company and not knowing your manager's real name. Now imagine trusting that company with your internet traffic.
Unless ... could be First for Business Internet VPN services ... ;o)
https://blog.getfoxyproxy.org/2017/11/04/secret-service-subp...
As for PrivateInternetAccesss / PIA, I would not trust them at all. No one knows who the founders and executives are. After speaking at length with an ex-employee of PIA who now maintains this open-source iOS VPN client,
even many (most?) employees and contractors at PIA have no idea of the identify of their direct managers. All work is done remotely and using encrypted chat sessions without video.
PIA is incorporated in British Virgin Islands where apparently shareholders, owners, etc can "enjoy" complete privacy.
It should be a red flag to you that if a founder or executive won’t reveal his identity, there is a possibility those people represent a nation state or other organization (not necessarily governmental) that you would not give your private data to if you knew their identity up-front.
Essentially, you describe that they provide bulletproof hosting (or network access), and no one does anything to deal with them. Simply because they are a VPN provider. And reply to officials with “Sorry, we have no data”. That's hard to believe.
It's pretty difficult. You can't say anything for sure, it's all trust. That's why you should be so strict.
When you host your own end point you still have to trustits provider of course, but of course the incentive (concentrated, specific user traffic data) for abuse is much reduced.
But how anonymous are you actually? Are you sure your traffic can't be connected to you? Certain you set everything up correctly?
With my provider of choice, because I trust them reasonably much (sure feels like jinxing it), I don't have these worries.
You should not have any expectation of privacy or security from consumer VPN services (if you want that, obtain Tor Browser or Tails as your needs require). They provide a means to choose roughly where your client traffic comes from, and that's it. The rest is marketing bullshit.
They're probably sufficient for low-key deflection of DMCA notices if you're torrenting shit--rightsholder enforcement companies aren't exactly able to undertake nation-state level investigations for what they do.
This always has been and always will be the security rabbit hole. (Well, one of them.)
How do you define "know for a fact"? Even if you personally know a person managing an egress node, how do you know they aren't operating on behalf of someone else?
Edit to add: Also, it’s public knowledge that TOR is funded by the DoD, it seems extremely feasible that they privately control a sizable chunk of nodes. Based on what I know of American 3 letter agencies, I don’t think one could resist designing a “secure” system only they can listen in on.
I consider TOR a very secure messaging channel between you, the other party, and the American government (metadata only, but that’s really not too big of a limitation in this case).
The design of the system is resilient to some nodes being under hostile control, too.
Some nodes can be under hostile control, but as the number increases the likelihood increases that they can link entry to exit based on timings. I consider it quite likely that the us govt can say “hey Germany/UK/Fance/etc., we have this batch of exit times, do any of your nodes correspond on entry?” or vice virce.
As an aside, the five eyes countries collaborate much more closely with one another than they do with France or Germany (or that was the case when I read about this after the Snowden leaks.)
That doesn't mean traffic can be deanonymized. Tor as a whole isn't compromised in any meaningful sense even if the exit nodes are. Large parts of the original white paper concerns this.
* You only need two VPNs assuming you just want to protect against either of them linking your browsing history back to your identity and selling that information.
* The second one must be paid for in a reasonably anonymous manner (ex Bitcoin) and only ever accessed via the first VPN in the chain.
* You're fine to pay the first one in a more traditional manner.
* The two providers must be completely unrelated.
* It is highly preferable that the two providers be in different legal jurisdictions (both from each other and yourself).
* This won't protect against a highly motivated criminal investigation.
- Credit only Word of mouth, but it depends what type of VPN you're looking for. So again, word of mouth these days.
> I never understood why people working in tech would ever trust a VPN service?
-I do, quite a bit actually, I need to connect to another network but region specific.. They are a tool for as you say 'in tech' to work.
> A VPN is seeing all your traffic, and you have to take their word that they do not log any of it?
- At least in Europe that doesn't fly. It does depend on your provider though. Thats why you shop around.
- On this point, I will argue that running your own VPN is better, but so is running your own web hosting. It depends on your priorities.
> I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.
- Good for you. Enjoy.The point of VPN services is obfuscating your ISP-assigned IP address. And hiding your traffic from your ISP, which both knows who you are, and is generally vulnerable to your government. With VPN services, conversely, you can pick ones that are less vulnerable to your government. And if you use nested VPN chains, you can fully obfuscate the relationship between your meatspace identity and your site traffic.
So as long as you don't reveal your meatspace identity through your online activity, you can be at least somewhat anonymous online. And if you add Tor to the mix, you can be even more anonymous. And by hitting Tor through nested VPN chains, you're less vulnerable to deanonymization through Tor compromise. Such as the relay early vulnerability that CMU researchers exploited to deanonymize Tor users and onion sites.
We need to implement standards of practice for this, let find a legal head to see how it can be done.
Except that it gives them a direct avenue into your network for their own surveillance and other network attacks ... If you think comcast injecting their own JS into http pages is bad, wait you see what the d̶a̶r̶k̶ ̶a̶r̶m̶y̶ CPC could do with such power...
(I'm not suggesting China is doing anything like that right now. But, even if they are not, I wouldn't rule out the possibility that some day the China-West relationship might deteriorate to the point that it becomes something they might consider. )
Unfortunately they have admins in Australia which has some pretty hefty laws similar to those in the US (look at gag-orders issued, and recent responses to media outlets for publishing vetted and leaked data). You can find their intro post in Whirlpool forums.
They configure a PXE and have a system in place for distributing the OS in each region (and thus each data center).
For debugging issues they try to replicate things on a local environment and my assumption is if there's any networking issues, they likely have a node on the same data center they can remote to, to test connectivity issues - however functional issues require replication locally. No SSH access to the box.
So I think for now, Oeck or Mullvad are good choices. I only wish these services did 1 thing differently - and that is, release a live video stream of their server farm's rack and video-document the entire process of compiling and shipping their hardware, as well as the systems in place for loading the OS to ensure no exfiltration data from malicious services or agents on the box.
This could be done relatively cheaply - I'm surprised none of the VPN providers have yet. A fish-eye lens attached to a webcam on a rack would be cheap to install. It's the closest thing we have to proof a VPN server hasn't been owned without a zero-day. If you're using up-to-date services, a LEO, government or APT using a zero-day to own your server is really the only means of exfiltrating user data in this environment.
This is security theatre. Anyone wanting to surreptitiously access the server farm only has to stream an alternate video to defeat this.
No one is safe from a state actor.
I'm saying that staff can be observed as behaving correctly, professionally, and more. This would build trust in the brand from multiple perspective, not just security.
There are been a few cases in which this has turned around public opinion re: trust.
VPNs are only useful for avoiding ISP / local network surveillance like comcast, your workplace, your school, airports, etc and to avoid DCMA scare letters. Making your own with a VPS is worse, since VPSs log on some level and directly forward the DCMA scare letters to you.
Somewhere in the back of my mind is stored that minimaxir does this, but I couldn't confirm it with a quick search.
Edit: I was actually thinking of mirimir.
You could even do it multiple times, like... 7. You would then be, basically, "behind 7 proxies". /s
Obviously you use assumed identity.
With only two layers you'd need to access emails, say, for account confirmation direct from your own system; with 3 you put a VPN in that gap.
Do VPNs re-pack and modify the timing on packages they pass on to clients? It seems like they're need to if they're too avoid coordination attacks.
I'm recalling how a research paper showed an extraordinary high number of pages visited (80%) over HTTPS could be identified using page size alone. If a TLA is watching all traffic into and out of a VPN's server can they pair upstream traffic to downstream clients at all?
Edit: https://proprivacy.com/privacy-news/no-logs-ipvanish-hands-l...
Public VPN services have to be the one of the greatest lemon markets to have ever existed:
You want people's private data? People will pay you to give it to them. Go ahead and sell the service for less than it costs due to the boatloads of data that you get.
People realize this, so you end up getting a disproportionate number of customers that don't worry about you getting their data because they're only using the service to behave abusively... which drives up costs.
So an honest provider has to deal with dishonest competition selling below cost and a customer base that is saturated with problem customers because good customers are savy enough to avoid VPNs.
It does address it, when you factor in an appropriate choice of non-US VPS provider.
Most VPS providers generally insist on recording your identity, probably with government ID, to limit abuse that would otherwise fall onto them. Whereas VPN providers have already made the choice to weather mild abuse complaints.
I have looked into bulletproof VPS providers. They're drastic overkill, expensive, and getting in bed with the wrong sorts of people.
Then don't do that.
Though VPN are not really a strong solution for hiding your identity period. Tor is a more effective tool, but hiding your identity is extremely difficult to do effectively.
> And why does a VPS have any less likelihood of logging your traffic?
They may be too but at least you should expect their business to be viable without doing that, which is better than you can say for VPN services.
You'll be stuck with the shadiest, slowest, most remote VPS in the world if you're unwilling to either give up your personal identity, or lie about it.
The amount of "private data" as a VPN operator isn't a lot. Most sites nowadays are https, so at best you're getting browsing habits on a per-site basis. On the other hand, using a commercial VPN does confer advantages in some cases:
* geo restrictions: commercial vpn have servers in multiple countries, so you can easily switch to one that works. you can achieve the same with cloud servers, but you'll have manually spin them up/down, which isn't convenient
* anonymity: commercial vpns usually have dozens/hundreds of users on one server. You can also switch servers/regions to increase your anonymity set further. This is a much bigger anonymity set than your own private server, which is linked solely to you.
* bandwidth: if you're a heavy traffic user, you'll probably end up paying more. most cloud providers only give you around 0.5TB for a cheap server (within the price of a vpn subscription)
* DMCA/abuse: they handle the DMCA/abuse letters for you. With a self hosted server you'll have to at the very least respond to the ticket they sent otherwise they'll take down your server.
Of course other VPNs don't provide privacy either. The belief that they do is due to marketing, and misunderstanding what the "Private" part of VPN means: it means that two non-publicly routable IP networks (10/8, 172.16/12, 192.168/16) are virtually joined into one network. VPN companies took advantage of this (and that the connection is usually encrypted) to imply that they offer a privacy product.
The main use of a commercial VPN is to bypass region locks and other legal controls that depend on location. Pick a VPN provider (or VPS host) in a jurisdiction that won't cooperate with your home law enforcement. Assume the VPN provider spies on all your traffic.
Privacy fundamentally is about keeping things private ... from someone.
If that someone is everyone, then nothing is private. Any sufficiently powerful entity can just overpower you, torture you into submission, guarantee a backdoor into a system you thought was cryptographically private, etc.
I for one do pay for a VPN service, because it keeps my home traffic stream private from some people - namely my ISP - with high probability.
It also obfuscates various types of traffic I generate and makes it harder, though I agree not impossible, to collate my traffic into a usable form for spying agencies.
For me that’s easily worth paying ~$100/year for someone else to manage, and if they base their business reputation on not collecting logs, etc., there’s enough incentive to trust that while also staying vigilant to verify what I can and switch providers if they are shown to be lying.
Self-hosting a vpn is utterly not an alternative for my use case, not even for technical reasons as I am an engineer who works on production web services all day. Just from a cost effectiveness / value POV, third party vpn vendors are a good solution for me.
I don't have much to base it on but they seem trustworthy, and I've seen them recommended here before.
https://mullvad.net/en/account/create/
That link automatically creates a new account. No names, no email address (except if you set up a PayPal subscription), not even a password. Your account number is literally all you need. They even have a FAQ that provides a generalized database schema.
https://mullvad.net/en/help/no-logging-data-policy/#numbered
Other than the letter I sent from Morocco, I never included a return address.
Best is to make your own, checkout https://github.com/StreisandEffect/streisand for an easy way to set that up.
https://news.ycombinator.com/item?id=21584958
(you can google to find more-- this was just a quick result)
PrivateInternetAccess has fought and won in US court, but they're also US-based.
(I use Mullvad.)
Mullvad is also the provider Mozilla is using for their new VPN service (with fewer features).
You're on a call. You lock the phone. You expect the call to continue right?
This bug is in their new browser. Its in a very early stage. So these bugs are expected
I am giving each of my family in various locations a raspberry pi 4b with wireguard setup.
They are aware of/benefit from this cross country VPN thing too.
https://blog.getfoxyproxy.org/2017/11/04/secret-service-subp...
In their faq they state that they have previously worked on projects such as ThePirateBay... (this is a legit business and service though).
I hope I get to try their VPN soon. Other than that I usually just use a systemwide tor proxy. It's actually quite entertaining how my netflix feed randomly changes based on the current exit node.
- Cash-in-Envelope Payment.
- Chains multiple servers with onion encryption. If there were any logs, they are useless.
- Custom built for privacy, similarities to Tor. Open Souce.
- Multi-Identity: Exit at multiple servers simultaneously.
- No Blockchain! Ie. no distributed and immutable log ;)
- Based in the EU, Austria.
- Public availability within the next months.
Check it out at https://safing.io/spn/
(edit: not that I disagree with you, I honestly don't see a practical way to do that. It's not like security seals have proven their worth in pixels either)
I’m amazed at the smart people that fall for that
The best test are court cases where investigators were stonewalled by a particular VPN provider
If you dont want the US knowing something but dont mind China knowing something, Express VPN got you
The problem with personally operated VPN servers is that all the traffic ties back to a single user: you. This is fine if you're on a malicious network and need secure exit node for your data, but for anonymity (eg. ad tracking, DMCA) it's objectively worse.
They say that they don't collect logs.
They've got no dog in the fight.
See my comment earlier: https://news.ycombinator.com/edit?id=23881148
See my comment earlier: https://news.ycombinator.com/edit?id=23881148
@dang
Edit: I also changed the URL from https://www.hackread.com/vpn-firm-zero-logs-policy-leaks-20-... to what seems to be the original source.