Kape Technologies buys ExpressVPN for $936M
alternativeto.net
alternativeto.net
However, their software was treated as malware by companies such as Malwarebytes and Symantec begging one to ask, how can such a company despite rebranding itself change the shoddy culture that it had?
But the connections don’t end there. The very first CEO of Crossrider, Koby Menachemi, happened to be once a part of Unit 8200 which is an Israeli Intelligence Unit in their military and has also been dubbed as “Israel’s NSA.” Teddy Sagi, one of the company’s investors was mentioned in the Panama Papers which were leaked in 2016."
https://www.hackread.com/israeli-firm-kape-technologies-expr...
Speaking of China, it has always been strange how well ExpressVPN worked there even during high pressure moments where all other vpn operators bit the dust, with some already wondering a few years ago if there wasn't something more shady going on. Eventually I ended up using some self managed shadowsocks servers and it's been a while, so no idea what the current state of affairs is, but I'm even less convinced to use them now.
This is the nature of VPN companies. You must do your research. Sadly most consumers don't do their research and blindly trust that the VPN provider has their best interests at heart.
Should that mean we trust a provider that has zero scandalous pasts? Hardly. Treat every VPN provider as if they peddled malware in the past I say.
1. Mozilla VPN is built on top of it.
2. Cheap and stable price. 5€/month.
3. Ability to pay by cash.
4. Founded and based in Europe (Sweden).
But if you need security, roll your own VPN. You can set up a Digital Ocean droplet as one. It's a pain, but you only need to do it once.
I'm not sure there's much of a persuasive reason to use any of these big providers. That's why they always fall back on claims of security – unsophisticated users always fall for it.
https://www.theverge.com/2019/10/21/20925065/nordvpn-server-...
This is precisely the point that the threat model bares its fangs. You can ignore it, but you should be aware that you're putting all your faith in that service.
A hypothetical Good VPN doesn't exist in China, for example, because they're legally not allowed to do what you suggest. Many of us don't live in China, but some do. Even outside of China, is it really true that a VPN service will simply give LEO the finger when they ask "Who was downloading child porn off your servers?" I'm skeptical they can.
I'll add that rolling your own means you're the only one exiting that IP address, so if your threat model involves websites profiling you and/or alternative accounts that won't help.
If the threat model is a government, Tor is the only safe solution, and only after extensive training and safeguards. Using anything else is actually-crazy.
If you are outside the US this is sufficient protection for many people. For example even close US allies (eg five eyes) have to go through the US court system to get this warrant, and that is a slow, annoying process when you aren't based in the US.
It raises the level of friction to meaning it will only happen for somewhat major investigations. If you are a major drug dealer, then yes, they'll do it. If they catch you with some small amount of some drug, then it's unlikely they'll chase it.
The original article is deleted for some reason, though.
On the other hand, there are other sketchy things about express VPN.
I know that it’s just my paranoia but I tend to assume any Internet service I don’t have a direct control of is logging things and will give up those logs when asked. (We’ve already seen plenty of that). I’d feel less safe tunneling over some company’s network than not doing it at all.
With that the use case I have for them is very limited. I prefer to route through my home network instead. That being said my ISP is not hostile to its users so I understand people who have one that is.
I mostly just use Pi-Hole to drop bad traffic, Quad9’s filtered endpoint over DNSCrypt and Ubiquiti’s built in threat defense and honeypot and AdGuard on the client side for some basic security and privacy and employ some common sense when browsing the internet.
Well it's either that or make every user an endpoint to go around the IP blacklist like that one provider did, but I can't remember which one.
Although I don't mind people practicing safe hygiene, little do they know a VPN has very little to do with big techs ability to actually vacuum up data about them.
And I think that number of countries with internet restrictions is growing, not shrinking.
I recently engaged in some infrastructure consulting work for a small startup(10 people). They're 100% distributed, no office, everything operates out of Google Drive, Docs, and Gmail.
One of the first questions they asked was if they need a VPN to keep their corporate communications and file transfers secure.
It's also sold using the same scare tactics that Anti-Virus is sold. By making people think their connections are insecure unless they use a VPN. So it pulls in a lot of the less tech savvy people who will most likely just use it for Netflix and further encrypting their traffic.
I don't think it's a bubble because countries are trying to implement all these weird laws and monitor the internet more and more. The UK for example wanted to introduce identity checks for consuming Porn. They can't do that when you can VPN to some other country.
Are there any VPN services that actually do this? AFAIK all of them get blocked (i.e. they are known IPs). I've even tried to spin up a Digital Ocean server to route my traffic and Netflix blocked it.
Many other benign aspects of life need it too, if the same conveniences are desired with no adjustment.
It's nice if you haven't noticed.
When nxdomains resulted in me landing on some page from my ISP, I started using a VPN. I'm perfectly fine with my ISP snooping my traffic IFF all they get is gibberish.
But by and large I agree, most people are duped into believing it's somehow more secure.
1. NSO Group aka the "use our tool to hack activists/political opponents"-as-a-service company, is founded by *former members of Israeli intelligence and their Unit 8200*.
2. Kape Technologies, whose software is labeled as malware by companies such as Malwarebytes and Symantec, founded by *former members of Israeli intelligence Unit 8200*
3. Black Cube, the spy-for-hire company that the likes of Harvey Weinstein hired to collect dirt on those suing him: founded by *former members of Israeli intelligence Unit 8200*
Needless to say, it's looking like using HolaVPN, an Israeli P2P VPN (founded by, you guessed it, *former members of Israeli intelligence*), is a colossally bad idea.
I'm fully aware that Unit 8200 alumni are very prolific when it comes to founding tech startups in Israel in general, but that doesn't change how brazen their industry is when it comes to selling sophisticated spyware to very bad people/governments.
> ExpressVPN says in a statement that it knew the 'key facts' of the employment history of one of its executives, Daniel Gericke. On Tuesday Gericke was revealed in court records to have worked on the UAE's hacking and spying operation
> https://www.vice.com/en/article/3aq9p5/expressvpn-uae-hackin...
I mean... would you hire Kevin Mitnick's company? Lots of people do (apparently, considering they've been in business this long), but yet he's a former "criminal". It really is a tricky analysis. Who knows hackers better than a former hacker? But how can you trust a "former" hacker? Hmm...
[0] https://en.wikipedia.org/wiki/ToTok_(app)#Surveillance_tool_...
[1] https://www.reuters.com/investigates/special-report/usa-spyi...
The software isn't anything special, and the hardware and network connections to actually run the VPN are probably a very small part of their margins - certainly not worth nearly 1 billion dollars.
Just the sort of thing you see in the real world. It's much easier to lock down access for a network with less people using it.
A network with more people starts to find all the edge cases where your lock-down rules break legitimate things, which results in calls to your boss from people with the clout to make you change stuff.
Similar for reporting, alerting, etc. Volume and variety of traffic can force you to be more lenient in larger networks. Or lose any real effectiveness because your signal/noise ratio is now bad.
Execution is everything. And there are no guarantees when it comes to execution. That’s what the cost of acquiring an otherwise “simple” business is: the cost to guarantee successful execution of a business/product plan.
You're suggesting that either ExpressVPN was a really good business with sophisticated secret sauce, strong technical chops, and capital assets probably worth $1B (validated by people with lots of money being willing to pay for it), or that I and other HN commenters are wrong about the sophistication and it's really worth peanuts because OpenVPN can be run on most routers or any Linux box.
The latter is obviously false, but the former is not necessarily true - instead, what I and other users are pointing out is that they're really selling is their users, and implying that the buyer expects to be able to extract more than $1,000,000,000.00 of value from them. As you pointed out, you see this sort of comment when a social network or many other kinds of startups with lots of users are sold.
The point is that the users are the product in this transaction.
Not necessarily.
If you're Joe Schmoe who just wants to not get nastygrams over using Popcorn Time or a tweaked Kodi box pulling movies from torrent sites, you may be a lot more concerned about hiding your usage from your ISP than you are from some foreign government that doesn't care about you. For that user, PIA (or ExpressVPN, or NordVPN, or whoever else is out there) may be a perfectly viable option.
- Kape with Cyberghost, PIA and ExpressVPN
- Tesonet with NordVPN, and allegedly a couple more most known, but there is no strong proof, so I'd rather not list them here.
- PIA
- ZenMate
- ExpressVPN
And unless I interpret the article incorrectly, they bought all of these over the last 3 years.
They also bought VPN review sites (affiliate marketers as I prefer to call them) and changed the rankings, according to this article:
https://restoreprivacy.com/kape-technologies-owns-expressvpn...
Particularly considering they own multiple VPN providers, so can probably squeeze overheads to increase margins, and also that much market control might allow you to increase prices across all brands you own due to reduced competition (as long as you don't tell anyone that's what you are doing - naughty naughty).
Of course foreign governments are already at the heart of all these VPN providers anyway.
(Except for getting around geo-blocking, of course)
But VPNs don't enhance your privacy though - you're trading your ISP's snopping for your VPN operator's snooping - and TLS makes it all irrelevant.
TLS solves part of the problem with ISP snooping, sure. The ISP does still know which IPs I'm accessing though and since SNI information isn't encrypted, so they may even know the hostname. There's more to it than reading the contents of sites I visit.
I'm also not fond of my ISP-issued IP trivially pin-pointing the town I live in. I'm less fond of the way trackers and advertisers use that information. Routing my traffic through a VPN addresses that point as well.
Maybe some day we'll see wide deployment of IPv6 addresses that don't reveal geographic location. Maybe some day we'll have encrypted SNI everywhere. Maybe some day 100% of all network traffic, HTTP or otherwise, will use TLS. But, we're not there today. A VPN provider is a nice stopgap measure.
I'd argue that is an enhancement of my privacy. It's had a nice secondary benefit of avoiding ISP throttling or peering disputes.
I have since been a happy paying customer and also recommended it to a couple of my friends.
A shame.
It looks like the next-best guide that hasn't been corrupted by referral money is privacytools.io, which currently recommends Mullvad, ProtonVPN, and IVPN. https://www.privacytools.io/providers/vpn/
I have used both Mullvad and TunnelBear. I bought a year of TB. It's on all the time and I forget it is there.