Tech CEO pleads to wire fraud in IP address scheme
krebsonsecurity.com
krebsonsecurity.com
> In a 2020 interview, Golestan told KrebsOnSecurity that Micfo was at one point responsible for brokering roughly 40 percent of the IP addresses used by the world’s largest VPN providers
This would be an interesting deep dive for a tech-focused investigative journalist.
the colocation hosts and regional ISPs that will accept VPN operators as dedicated server and 1U server colocation customers are towards the more suspicious end of the hosting segment market spectrum, in my experience.
dig hard enough on a modern vpn hosting company with a slick marketing presence and you'll find like, a cypriot corporation with a cyprus bank account run by a guy who 15 years ago was in the adult website hosting business, who currently lives and works remotely from cambodia. Or similar.
On the one hand, it's effectively a commodity, so there is a lot of competition.
On the other hand, the entire point is to protect the privacy of the customer. So if you're doing it right and any of your customers are actually in need of that privacy protection, you're going to be taking flack from angry jerks who don't like that you're providing it. The same thing happens to people hosting adult websites, so it's the same kind of people who are willing to put up with that in exchange for money.
I'm not so sure.
As far as most of these companies are concerned, "the entire point" is to collect customers' money. The quality of the service they're providing is secondary, beyond that it has to be good enough that customers won't leave -- and the privacy properties of that service are even less important, since most customers aren't equipped to evaluate that.
The ones op is referring too usually only exist to torrent and bypass geolocation content restrictions.
What is the usecase for a paid VPN otherwise?
Added protection against ISP and local snooping of traffic, either for commercial gain or by some local agencies in less-free countries where such things are common.
Bypassing geo restricted content is also a big one, says for people living abroad who want to enjoy access to content from their country of origin, or content that is not locally filtered.
Maintaining privacy when visiting websites that use your geolocation or IP to correlate your visits and profile you for advertisement based on your (more or less) precise location for instance.
Or maybe you want some added privacy when visiting some adult or political sites whose data may be breached or monitored and make your habits more public than you'd want.
In principle a VPN is just another level of privacy protection, as long as it's one that can be trusted, which is probably another issue since apparently not many can.
Also, why do you think a shady person would be likely to reside in Cambodia? Do you have any evidence to support this claim?
b) that's a specific person, but I won't say who, for obvious reasons. Lots of reasons why from the POV of a shady vpn service provider you might want to live offshore and pay as little money in taxes as possible, I suppose, so there's a certain logic to it.
Please keep in mind I have been seeing weird/shady things in internet infrastructure for a very long time. I was helping set up OpenBSD firewalls for online casinos colocated in small island nation states 22 years ago, so I have a certain jaded perspective on these things.
Click farms
Review farms
Residential proxies
Captcha solving services employing people in very low cost of labor locations
Fake tech support scams
Canada revenue agency / IRS scam call centers
Porn website hosting
Anything involving Rob Monster
Bitcoin tumblers
Cryptocurrency exchanges
Fad of the week newly created cryptocurrency
College essay writing services
NFTs
Selling used panties online
Website hosting for services similar to the now shutdown Backpage.com (anything escort or prostitution related)
Buying drugs with cryptocurrency
Much better to build relationships which enable you to get things done by virtue of others wanting to look after you.
For those on the demanding side, it can be a badge of honour not to take "no" for an answer. While those on the other side, are being deliberately placed between a rock and a hard place. Just for another's benefit.
If not unethical, it is at least dishonourable.
That's the part that becomes wire fraud, says the OP. Faked notarizations of people who don't exist.
https://www.popehat.com/2013/02/05/crime-whale-sushi-sentenc...
That might drop you right into the middle of it, but that's the thread in question.
https://mailman.nanog.org/pipermail/nanog/2019-September/102...
https://www.ripe.net/ripe/mail/archives/anti-abuse-wg/2020-A...
Tax the inelastic and all.
This has the secondary benefit of freeing up unused space.
FTFY. CGNAT means consumers get to be behind a double NAT, no port forwarding, poor P2P support, etc. CGNAT is the IPv4 solution of last resort.
That being said I think it is good people are so good at being non-conformist, at least if there was any other solution out there we would more than likely have found it by now.
There are already more devices connected to the internet than there are ipv4 addresses. Already Android devices alone are more than 3 billion, PCs 1.5 billion. The limit is at 2^32 = 4.3 billion.
It would be a better comparison if Mars were already habitable and one only had to move humans over. Because that's all we have to do to make ipv6 suitable.
Then there is the more complex routing tables. ipv4 is highly fragmented so users with many users don't have large contiguous blocks, but multiple smaller ones. This causes routing tables to bloat up, which increases routing overhead of the packets.
Lastly, there is the ridiculousness of paying for ipv4 addresses in the first place. Ideally, companies could just register them, having to pay a small service fee, that's it. In ipv6 this is the case, but in ipv4 you see Amazon paying huge sums for large ipv4 blocks. More importantly though, this cost is also handed down to customers, at least for hosters like Hetzner. For small servers, this can quickly be a significant fraction of the cost.
I'd like to point out some design decisions I love about IPv6:
- 128-bit addresses instead of 32-bit. I can't imagine having a shortage of routable IP addresses for a long, long time.
- I don't have to use NAT if I don't want because there are enough IP addresses to go around. We've grown so used to NAT that we take it for granted, not recognizing it for the ugly hack it is. On my home network, just about every machine has a routable IPv6 address.
- A consistent subnet: it's almost always gonna be a /64. When I lay out my networks, I don't have to regret specifying a /24 and then, as the office grows, wishing I could extend it to a /22. Every IPv6 subnet is big enough.
- A consistent subnet means that you don't need to use a subnet calculator as much.
- Not wasting .0 and .255 addresses (network & broadcast addresses). It's particularly bad with very small subnets (e.g. an IPv4 /30 wastes half its usable IP addresses).
- On that note, I like having my machines being able to have a .0 (::) address. My favorite IPv6 address? 2600::. You can ping it to see if your connectivity is working.
- ::1 is loopback. 127.0.0.1 is lookpback on IPv4, but 127 is a kinda weird number (okay, it's 2^7 - 1, but it's still weird).
- Without NAT I don't have to worry about network collisions when I VPN into corporate ("What? They're using 10.0.0.0/24? That's my home network's subnet! Dang!").
I suppose the evidence I would give to back up my statement is that if it was well designed, it would have been adopted. As it stands, I only find it is supported among the more distinguished services that I use.
For another example, Python 3 has much better design than Python 2, and the difficult adoption a result of having people fix what they had written using the poor Python 2 design, and making it easier to adopt would have meant preserving the poor choices.
I don't know enough about IPv4 vs IPv6 to make a judgment in this particular case, but I don't think your argument broadly in itself here follows.
Most industry participants are just building things that there is market demand for. That is not necessarily enlightened, but it's also no worse than anything anyone in any other industry does.
According to who? Law enforcement is a last resort, and it reports to the people. People are responsible for their own communities. We live here, we benefit from it.