ExpressVPN employees complain about ex-spy's top role at company
reuters.com
reuters.com
If you think you want a VPN for "privacy", use Tor Browser. If you want a VPN for any other reason that "normal people" think they want a VPN, you're probably wrong.
Why do we even give these companies the time of day?
(Small clarification - Most people who want VPNs should use a proxy instead. It fits the use case better. Those still exist and don't route ALL of your device's traffic over the tunnel.)
I find YouTube in my country is just filled with content being pushed because it's local to my country. Some VPN exit points have less local content pushing, which gives me more options. Eastern European content is really good, but also completely missing from American YouTube suggestions.
That said, I've had websites flat-out refuse me because of using Mullvad (not just because it's a VPN, but a supposedly "disreputable" VPN). Meaning blackhats love it. Meaning it works.
How can one be so certain that this is the case? The only thing that's for sure is the claim they do not keep any evidence. I don't have anything against this VPN, it's really just an inherent trust problem with any provider. You take their word for it and be smart/ethical enough not to have any sketchy activity when you use it because there's a pretty good chance logs are being kept.
I don't mean to make this personal to you but it's weird seeing a tech-literate crowd like HN act naive when it comes to VPN usage, based on arguments like "oh X is shady you should use Y instead, it's 100% private!".
My point being, don't expect that doing extremely dumb shit online means any service, no matter how reputable, that may aid you do so will have your back.
For example, why wouldn’t China run a few top VPN companies — or at least compromise them? The benefit would outweigh the costs. So they shield you from piracy lawsuits and the like, they gain data to blackmail and compromise key figures later on.
The main issue is that they all seem to advertise themselves as these privacy and cybersecurity services first, while ignoring all the other added benefits.
I'm not saying VPNs are worthless - I'm on one right now for work. Commercial VPNs, for most people who purchase them, are completely worthless.
And I very much doubt that tunneling your connection through a VPN can improve ping.
Yea... as someone who used to play a lot of online games, this was always a surefire way to increase ping time lol. "Crap, my VPN is still on... brb"
Surprisingly this can be the case as long as the combined link to VPN + target is better than the direct link to target. Keep in mind that the target might be geo distributed.
Like driving, going over 2 highways might be fasted than going over a direct dirt road, or a longer road might be faster because the direct road is congested.
Was this a bug in Overwatch? Almost certainly, but the VPN was an effective workaround.
Is that surprising? I think that's what you would expect, and it's what the above commenter is suggesting (quite reasonably IMO) is very unlikely.
I think the issue is that you're implying the road to the target is a dirt road, but the road to the VPN is a highway, which seems a bit questionable.
[1] https://eu.forums.blizzard.com/en/overwatch/t/lower-ping-whe...
You get a hash value that's roughly unique to the browser-device configuration. You don't know from that hash where the user is located. You have to pair the hash up with geolocation services to get that info. Once you do that though, you get a decent idea of if the person is changing their IP, but there's still no way to tell what the 'real' IP is. You just end up with a unique ID that's associated with a handful of different IP addresses.
A world where every second funny video you might have found on Reddit leaves you with a cryptic message that some "rights holder" doesn't permit you to see it (and denies you from joining the fun everyone else seems to be having in the thread).
A world where you cannot buy half of the cool stuff you want (and everyone else seems to be having) because you cannot even see the online store where it is sold.
A world where you're even denied access to old and seemingly public domain e-books.
Open your eyes. This is the world most of us live in.
We're not on commercial VPNs because we love to, but because often there is no other way. They are in a sense invaluable when it comes to geo-restrictions, even though I agree with you that they are worthless for many of the reasons they claim to exist.
"Turn on VPN, network performance improves" is a regular occurrence these days.
*Disclosure: ExpressVPN has sponsored my podcast in the past (tho I don’t handle ad sales fwiw) and I’ve always chosen to do the “this is how I watch X service in X country” use case in ad reads, b/c that’s the value in it for me vs rolling my own Wireguard/Tailscale setup (I actually have Tailscale setup for my home network).
False advertising I’d say
We have no illusion that a third party VPN adds any security; we use it for this reason. I vpn to my personal colo machines when away from home.
(Also: I don't think anyone has mentioned this yet, as maybe it is somehow "gauche" to do so, but one of the top reasons people use VPNs around the world is because they want to browse porn and they don't want people around them to know. At some point, the people in the apartment next door to me figured out my wi-fi password and seemingly felt the correct solution to this issue was to use me for their porn browsing, but it was then all the more awkward when I figured out why my network was slow and knew all of the porn sites they were browsing. Most people seem more OK with the idea of paying a company like ExpressVPN--even if they are legitimately run by "spies"--to be their dedicated porn access point than hoping that someone else more locally won't find out what sites they are browsing.)
That seems implausible.
WEP can be broken with: https://www.aircrack-ng.org/
WPS can be defeated with: https://tools.kali.org/wireless-attacks/reaver
Or your ISP may be one of the big ones - Comcast, Time Warner, etc or whatever they are in other countries, and you may legitimately not trust them either.
My ISP is required by law to be an informant for government agencies, so the VPN can only be equal or better than my ISP.
That said if you live in the UK the government logs your internet history to be used against you at their convenience. Using a vpn like mullvad.net that you can buy with bitcoin and no details prevents the government logging my history, thats worth the £5 a month.
> This site was conceived and built by IVPN to challenge aggressive marketing practices in the VPN industry.
> VPNs do not effectively solve this issue. Most modern browsers can detect the geographic location of a device based on data from GPS, available Wi-Fi networks and GSM/CDMA cell IDs and will submit this information to websites requesting it.
Did I miss something? Even the ad-tech browser will ask the user before sharing that?
I'm not sure what country you live in, but in the US, all the big ISPs might as well be run by the government, at least when talking about privacy. Private VPN companies are far more trustworthy, all else being equal.
How? I don't see how being a VPN company as opposed to an ISP makes a difference in regards government seizure or request of logs.
When one party with auditors says they will protect your privacy, and the other openly spells out in their stated policies that they will run roughshod over your privacy, cataloging and trading your data as much, as long, and as insecurely as they like...
You don't have to trust the former party a lot to recognize the lesser evil.
Separately from that, I still do wonder whether, if you subscribe to a VPN that has well-examined security practices and whose reputation depends on such practices, whether it still may have value over relying on the security over a local ISP which may not have as much expertise or reputation investment with respect to security.
I'm not arguing, just trying to understand the issue better.
No. I don't think this was ever a consensus. When is the last time you've used a (sensitive) website that is not run over HTTPS? Unless the CAs (or the certs) are compromised, you have no reason to use a VPN when on public Wi-Fi, because it is encrypted with this so-called "military grade encryption" that VPN providers love to mention.
Edit: forgot to add, if the CAs or the certs are compromised, VPNs won't help anyway.
It's less of an issue when every site you connect to uses https, and every app you use employs ssl/tls for its connections. That is common practice these days. Getting man-in-the-middle'd on airport Wi-Fi is less feasible these days than it was 10 years ago. The attacker would have to also install a certificate on the user's device. I welcome corrections if I'm wrong.
VPNs aren't obligated to tell you the truth. They don't have to have good security or even honor what they say on the front page. People trust marketing, not actual policy or actions - just look at Apple. Still waiting on "HMA" VPN to go out of business because they handed over users to the FBI. They're still around and claim No Logs just like everyone else, just like ProtonMail did until this month.
https://arstechnica.com/information-technology/2021/09/priva... https://hacker10.com/internet-anonymity/hma-vpn-user-arreste... https://www.theregister.com/2011/09/26/hidemyass_lulzsec_con...
I think the "consensus" I'm referring to may actually have been from at least 10 years ago. I'm an old-timer!
Thanks for the feedback
I’ve never had reliable VPN working over public wifi/mobile network, unless I roll my own custom protocol that masquerades as HTTP traffic.
No, with SSL and https now the default for 90%+ of the web, you can be sure no one is casually listening in.
Isn't using Tor browser trusting a group of unknown people as well (nodes)? I hear all the time theories that Tor is a giant honeypot
Plus ISPs can detect tor use by its customers just from packet patterns. I don't want to be flagged as a tor user by either my ISP or the sites I visit.
The only other option is to set up your own ISP either in a colo rack or on a cloud VM. That's going to cost $50-$100 month plus your time fiddling with it and any network overages
What about Tor over VPN, so that your ISP can't see that you're using Tor? That is, the VPN hides your usage of Tor from your ISP and Tor hides your browsing from the VPN (and since many VPN services even advertise Tor support, its not like it would be suspicious, plus you can pay for many VPN's with cryptocurrency while I definitely can't hide my identity or location from my ISP).
As far as I can see, normal people are asking for VPNs to access Netflix catalogs of other countries.
so replace a vpn, which might be logging your traffic, for a service which absolutely is logging your traffic?
Tor is an anonymity service, not a privacy service.
- the exit node knows the second-to-last node, the cleartext data and the destination,
- each intermediate node knows the previous and next nodes,
- the entry node knows the sender and the second node.
And using HTTPS prevents the exit node from knowing the cleartext data.
This doesn't enable any individual node to know who sent what to whom, assuming that the whole path isn't entirely controlled by one person.
HTTPS can mitigate some of that, just like it can for VPNs, but the site you're going to is still very much visible.
Don't get me wrong, Tor is a very useful service if anonymity is your goal, but it requires a solid understanding of what can go wrong, which torproject provides a decent list for: https://support.torproject.org/faq/staying-anonymous/
Not in a sense that defeats privacy, since the exit node doesn't know the sender.
With Tor and HTTPS, no Tor node sees the cleartext data, and no node can associate me with the server I'm contacting. That sounds very much private to me.
> https://support.torproject.org/faq/staying-anonymous/
I've read these warnings, but I don't see anything that would defeat privacy if Tor is used correctly.
I've always seen this argument but it's never made sense to me.
For starters I absolutely don't trust my ISP. I know they are collecting, storing, likely selling my data and that they are 100% going to comply with any government requests from my government (I don't even trust that they would only respond to legal requests).
Years ago I used to use AirVPN. They claimed:
> AirVPN started as a project of a very small group of activists, hacktivists, hackers in 2010, with the invaluable (and totally free) help of two fantastic lawyers and a financing from a company interested in the project and operated by the very same people.
Maybe they're lying but at least there's some chance they actually care about privacy.
But even if they don't care about privacy at all and are lying, at the very least they are based in Italy and have their servers spread throughout Europe. Additionally you can pay via crypto (which gives you more anonymous payment options than your ISP). Simply being in another country then the one I live in makes it much harder for my government to arbitrarily request my data.
Yes if I want to do highly illegal activity that is going to get my government interested in me I absolutely don't think that would be enough. But if I want privacy from routine surveillance this seems like a fantastically better option that 100% giving up.
Seems obvious to me that many of the top VPN providers are operated by intelligence agencies or have ties to data brokers: they can afford to operate the services at an initial loss for the benefit of information learned later.
For example, touting that a VPN is operated outside of a country with ties to the “five eyes” doesn’t seem like a benefit, it likely means they can operate with impunity on your data.
VPN A IP: 4321
VPN B IP: 6543
---
Unless I'm missing something, the request would go like this:
VPN A sees that 1234 is going to facebook.com
VPN B sees that 4321 is going to facebook.com
facebook sees that request is coming from 6543
Am I misunderstanding the technology, or didn't VPN A see everything?
https://en.wikipedia.org/wiki/Carnivore_(software)
And this was the very very crude version, what is happening today is obviously light years ahead of what Carnivore was...
We really need a "*Moore's Law For Surveillance Capabilities Multiplying by X Every N Period*"
If you want online anonymity, use Tor. And torrent with a seedbox.
Using Tor is:
1. a huge PITA 2. a red flag 3. potentially exposing me to unsavory actors
Mullvad VPN seems like the best choice.
Long term I’ll probably just solve this by setting up a VPN server at home, so I can tunnel through to my local services and protect myself from wifi endpoints I use on the go.
My understanding is that most people use a VPN to either watch the foreign catalogs of streaming services or insert a third party in a foreign country to make themselves less tempting targets for random enforcement of copyright laws.
Obviously they don't advertise like this because these activities are illegal.
I, a tech savvy person, have no issue creating an SSH proxy server in any country in seconds.
But I also make online video games, and the US sanction system means I must block people from accessing our services; even if they have a copy of the game.
They did nothing wrong, my company isn’t even US based: we just used a cloud provider and all of those are US based.
So, I encourage those users to use a vpn if one is available to them.
Kevin Poulsen's book Kingpin, about the takedown of CardersMarket, describes how the FBI ran a VPN service as a honeypot for quite a while as part of the operation, logging everything that passed through it. As you say, it could be anyone on the other end of that connection.
This is nonsense. It depends entirely on your goals. It's important to me that my ISP doesn't know what I'm doing while I couldn't care less if my VPN provider does. I also need to circumvent geoblocking from time to time.
1. my threat model is not my government. It seems that the TLAs have thoroughly pwned our privacy for a long time now. (please note that I am in no way advocating for this mass surveillance, but I don't see that I have much choice in the matter)
2. My threat model includes my ISP. I am forced to use a scummy ISP who would openly steal my data if I let them. Same with my mobile provider.
3. My threat model includes the data thieves who have obvious business models built around selling my stolen data to the highest bidder.
4. My threat model includes black hats and script kiddies.
5. Do I trust my VPN provider? Eh. A little. For now. The thing is, I trust them more than #s 2,3,4 above. What other choice do I have?
You're starting with the (completely correct) observation that any VPN is not guaranteed to be secure, confidential, or private, and then making an argument as though it were the case that every reputable VPN is equivalent to every untrustworthy ISP. I think that's why your argument doesn't make sense to me: I don't think there's an equal chance that a VPN provider with a good reputation is going to sell me out as my ISP.
It's axiomatic in risk management that there is no way to completely remove all risk. Running a proxy and Tor is not a guarantee of security any more than running the world's shadiest VPN is, though it's obviously more secure by far. But, it's a question of what the acceptable level of risk is, and what the marginal cost to reduce that risk is. For many people, a $5-10 (non-shady) VPN is a perfectly reasonable step to take.
Your ISP could still figure out which sites you are visiting by what IP addresses your traffic gets pointed to, but I'd be willing to wager that the bulk of their data collection for the purpose of advertising comes from logging DNS requests, since it is far easier to do and captures 99.99% of their customers habits.
This won't do anything to protect your IP from being sniffed out by media companies when seeding copyrighted torrents, but that has never been a major concern in my house. This is probably also meaningless if you are being targeted for surveillance.
We use a commercial VPN at our company because it provides a mechanism for traffic encryption for employees who might be connecting from insecure networks. Sure most sites use HTTPS but there is still some unencrypted traffic like CDN or similar.
It’s not a cure all or some privacy guarantee, it’s just that for us, the risk of our employees browser history being stolen by that VPN for some nefarious purpose is just less than the risk of information leaking via insecure network.
If I were to use a VPN service, this news would certainly disqualify ExpressVPN from my list of possible options.
I imagine that if I were working for a company like that out of belief in the mission that this news would be difficult.
That idea of insider knowledge turned to the client's benefit might be utilized here - but yes it is a bit less comforting in contexts where the legal duty to client does not apply.
Besides that, I think Kape is highly suspect, and the whole VPN space is filled with marketing of false promises and FUD.
You will have one single IP and you won't share IP with hundreds of other people thus being flagged.
I have never been blocked from a site when using my VPS, including sites that otherwise block VPNs, I think they don't care for whatever reason.
Doesn't mean they can't know, they will, but they seem to not care?
Some websites might do.
Only way you can get a completely "native" experience is for someone to set up a VPN in a computer connected to a residential connection in the country you want appear in.
If you're going to use a VPS for anything remotely sketch you probably don't want to go with a reputable provider - they're reputable for a reason.
What strange ToS clause would those fall under? Skimmed the DO ToS and found nothing, while they also have a separate page promoting the deployment of your own VPN
He must've made a nice packet of money. Must have taken care of his retirement - the company's even promoting him. Some citizen's family is now at risk, or already imprisoned without a legal process. This must've come as a shock to the Human Rights community. VPN usage is universal there. And this is the tip of the iceberg - surely we know how fine of a dragnet the FBI has. Iran, China, Saudi Arabia, UAE, there's a long list of nations that'd like to snoop on their own people wherever they may be living. Like someone said, Tor is the way to go (tails).
Honestly, how stupid do you have to be to believe this?
Seriously?
So either he lied or they are lying. I'm not an expert in American employment laws but would have assumed that one of the conditions of employment would be disclosing/reporting being under a federal investigation.
Is it reputation? Integrity? Is the reasoning purely financial?
Then ask whether the company operates in a way that suggests they'd do the profitable thing over the right thing if they think they might get away with it. Does that picture look realistic?
As an example, look at Apple. Leaving the tangential discussion about scanning iCloud photos for CSAM aside, they are a company that claims to care about users and about privacy. Whereas every other company is literally trying to send all data to the cloud, Apple is telling us they're working to process everything they can on the device itself.
What would happen if they were caught selling location data? Caught allowing companies direct access to data aggregated from users that they explicitly say they're not collecting? They'd stand to lose literally many billions of dollars of sales because the thing differentiating them from everyone else would be erased.
Which is greater - those billions of dollars of sales as a premium device maker, or those scraps of money they'd make from underhandedly selling data?
Now look at the same scenario but with Facebook, or Google - is it the same? No, because we have no realistic expectation of privacy with either company. They're in the news quite often because they're doing nefarious things, allowing access to data most people didn't even know they're collecting, yet people aren't really doing things differently because of the news.
Imagine the same with companies like ExpressVPN. How much would a disclosure hurt them? How much money could they possibly make by selling private data? Do they employ the kind of people who'd take the gamble between the two?
Proton logged IPs in response to Swiss court order and handed over that data after the order was received. They do not log IPs otherwise. And bear in mind, the specific request in question here had the involvement of the French state as well.
(To be fair, Orchid has for some reason decided to hide multiple hops behind an advanced settings panel currently; I feel like this must have been some kind of miscommunication internally, and I annoyingly-to-me don't directly do the development on the front-end app; but it is supported, if slow.)
Like, if you want to, right now, you can run a Sentinel node... and then you just get to "be the spy" and collect all of the information about the users who select your node. They claim this isn't possible, but that makes no sense and I can tell you from first-hand experience that it is... they seriously seem to think that because their code is distributed using a docker container that no one can either edit its behavior or add logging around it? It is really awkward, actually :(.
And, worse, part of the goal of these "decentralized VPN" projects is to let you not care so much about which node you are using... which means that, over time, you are likely to eventually use an attacker as your exit node (which is actually somewhat intrinsically "dangerous" anyway, even with multiple hops, as, if you allow any non-authenticated--in the cryptographic sense of that term--traffic to go through your tunnel, as even with multiple hops the final node can edit the traffic).
(I am very curious, BTW, what your specific use case is with split tunneling that isn't being supported currently by Mysterium.)
Or AWS self hosted VPN?
> Does the service limit your usage of a single IP address?
From the linked page listed as a yes in the features list.
don't trust services that promise things they can't deliver and you cannot vet properly.