You should not have any expectation of privacy or security from consumer VPN services (if you want that, obtain Tor Browser or Tails as your needs require). They provide a means to choose roughly where your client traffic comes from, and that's it. The rest is marketing bullshit.
They're probably sufficient for low-key deflection of DMCA notices if you're torrenting shit--rightsholder enforcement companies aren't exactly able to undertake nation-state level investigations for what they do.
This always has been and always will be the security rabbit hole. (Well, one of them.)
How do you define "know for a fact"? Even if you personally know a person managing an egress node, how do you know they aren't operating on behalf of someone else?
Edit to add: Also, it’s public knowledge that TOR is funded by the DoD, it seems extremely feasible that they privately control a sizable chunk of nodes. Based on what I know of American 3 letter agencies, I don’t think one could resist designing a “secure” system only they can listen in on.
I consider TOR a very secure messaging channel between you, the other party, and the American government (metadata only, but that’s really not too big of a limitation in this case).
The design of the system is resilient to some nodes being under hostile control, too.
Some nodes can be under hostile control, but as the number increases the likelihood increases that they can link entry to exit based on timings. I consider it quite likely that the us govt can say “hey Germany/UK/Fance/etc., we have this batch of exit times, do any of your nodes correspond on entry?” or vice virce.
As an aside, the five eyes countries collaborate much more closely with one another than they do with France or Germany (or that was the case when I read about this after the Snowden leaks.)
That doesn't mean traffic can be deanonymized. Tor as a whole isn't compromised in any meaningful sense even if the exit nodes are. Large parts of the original white paper concerns this.
It’s not that I trust them but I’d rather some random company across the world has my jerk off logs rather than my ISP who hands my habits to my government and all its favoured cohorts.
The NSA is simply not most people's threat model, and if they _are_ running it, it probably means that someone shadier is not. I'm using a VPN because I don't want my ISP to see what I'm browsing, don't want end sites to know who I am, want to watch American Netflix, and because the country I'm in tries to block all adult sites. The NSA is welcome to all of this traffic _shrug_
Full disclosure: I work at PIA.
[1]https://torrentfreak.com/vpn-providers-no-logging-claims-tes...
[2]https://torrentfreak.com/private-internet-access-no-logging-...
[1]https://en.wikipedia.org/wiki/Burden_of_proof_(philosophy)#P... [2] https://en.wikipedia.org/wiki/Evidence_of_absence
Degree of proof is a relative: Maybe a terror organisation use PIA, NSA go fishing for evidence PIA has nothing. Terror org assassinate NSA head. PIA could be a front, but NSA head had to be willing to lose his life to hide the fakery, and terror org wasn't a big enough fish ... more likely you're currently in a coma. Lots of places for false premises to creep in.
Dial it back, is there a point where there'd ever be enough evidence?
The whole company is shrouded in secrecy. After speaking at length with an ex-employee of PIA who now maintains this open-source iOS VPN client:
many (most?) employees and contractors at PIA have no idea of the identify of their direct managers.
Imagine working for a company and not knowing your manager's real name. Now imagine trusting that company with your internet traffic.
Unless ... could be First for Business Internet VPN services ... ;o)
https://blog.getfoxyproxy.org/2017/11/04/secret-service-subp...
As for PrivateInternetAccesss / PIA, I would not trust them at all. No one knows who the founders and executives are. After speaking at length with an ex-employee of PIA who now maintains this open-source iOS VPN client,
even many (most?) employees and contractors at PIA have no idea of the identify of their direct managers. All work is done remotely and using encrypted chat sessions without video.
PIA is incorporated in British Virgin Islands where apparently shareholders, owners, etc can "enjoy" complete privacy.
It should be a red flag to you that if a founder or executive won’t reveal his identity, there is a possibility those people represent a nation state or other organization (not necessarily governmental) that you would not give your private data to if you knew their identity up-front.
Essentially, you describe that they provide bulletproof hosting (or network access), and no one does anything to deal with them. Simply because they are a VPN provider. And reply to officials with “Sorry, we have no data”. That's hard to believe.
The point of VPN services is obfuscating your ISP-assigned IP address. And hiding your traffic from your ISP, which both knows who you are, and is generally vulnerable to your government. With VPN services, conversely, you can pick ones that are less vulnerable to your government. And if you use nested VPN chains, you can fully obfuscate the relationship between your meatspace identity and your site traffic.
So as long as you don't reveal your meatspace identity through your online activity, you can be at least somewhat anonymous online. And if you add Tor to the mix, you can be even more anonymous. And by hitting Tor through nested VPN chains, you're less vulnerable to deanonymization through Tor compromise. Such as the relay early vulnerability that CMU researchers exploited to deanonymize Tor users and onion sites.
It's pretty difficult. You can't say anything for sure, it's all trust. That's why you should be so strict.
When you host your own end point you still have to trustits provider of course, but of course the incentive (concentrated, specific user traffic data) for abuse is much reduced.
But how anonymous are you actually? Are you sure your traffic can't be connected to you? Certain you set everything up correctly?
With my provider of choice, because I trust them reasonably much (sure feels like jinxing it), I don't have these worries.
- Credit only Word of mouth, but it depends what type of VPN you're looking for. So again, word of mouth these days.
> I never understood why people working in tech would ever trust a VPN service?
-I do, quite a bit actually, I need to connect to another network but region specific.. They are a tool for as you say 'in tech' to work.
> A VPN is seeing all your traffic, and you have to take their word that they do not log any of it?
- At least in Europe that doesn't fly. It does depend on your provider though. Thats why you shop around.
- On this point, I will argue that running your own VPN is better, but so is running your own web hosting. It depends on your priorities.
> I use free tier AWS servers across the globe with wireguard. It might not be perfect, but I still prefer that than using a VPN service.
- Good for you. Enjoy.* You only need two VPNs assuming you just want to protect against either of them linking your browsing history back to your identity and selling that information.
* The second one must be paid for in a reasonably anonymous manner (ex Bitcoin) and only ever accessed via the first VPN in the chain.
* You're fine to pay the first one in a more traditional manner.
* The two providers must be completely unrelated.
* It is highly preferable that the two providers be in different legal jurisdictions (both from each other and yourself).
* This won't protect against a highly motivated criminal investigation.
Primary use of VPNs I see is to get onto my workplace's network.
I honestly don't know if you can do this with your average commercial vpn, but the technology is also good for many things like setting up virtual networks (hence the name) so you can do things like access your home computer from anywhere without exposing it to the internet.
I'd notice pretty quickly if someone was MITMing all of my traffic. I guess they could MITM a third-party Javascript site that wasn't being served with HSTS. Normally that would just give them all the information I already give to Google or Facebook and the hundred other shitbags that run JS on the sites I browse, but if they got really lucky they could pretend to be some third-party payment provider that didn't use HSTS or I hadn't used before.
A browser is a very complex tech stack and it wouldn't surprise me in the slightest if there were vulnerabilities exploitable with a MITM. An airport would be a natural place to try and attack computers, lots of people with lots of money many of whom are doing things like moving that money around and many of whom won't think twice about connecting to an unsecured public hotspot.
There's also all the other apps on your computer, how frequently do you think electron-app-foo-bar updates it's chrome version and what are the chances it's using one outdated enough that there are known openssl vulnerabilities against it?
I don't think third party non-HSTS traffic is that much of a concern these days, both firefox and chrome block http traffic from https pages by default.