Rejecting data demands, ExpressVPN removes VPN servers in India
expressvpn.com
expressvpn.com
https://www.cnet.com/tech/services-and-software/what-is-kape...
https://www.reuters.com/technology/kape-technologies-buys-ex...
Pepsi and Coca cola.
Lots of small coke companies exist too, to use my analogy again.
- A loyal Mullvad customer
Mullvad for obvious reasons is used for less... wonderful usecases. It's not uncommon for websites to block you due to abuse from that exit. ASN blocking is rather common with mullvad too though that's less avoidable.
I have less info on Nord, although I can see it has about 4x the ip's. No idea if they are more diverse network wise. Their accepted payment methods suck though.
Mullvad seems to come out pretty clean whenever these shady VPN providers show up on the news again. Being able to use them by just transferring some crypto to the right address without even needing to enter a username or email address seems pretty good. If you ever forget your account number, you're out of a month's worth of service at most and can just generate a new account when needed. It's the only commercial VPN I put a moderate amount of trust in, even though I've never used their service.
Edit: Not sure why the downvotes but I don't live in the US, if that matters.
https://www.eff.org/deeplinks/2017/03/small-isps-oppose-cong...
(I.e. I assume success to be a death knell for a service like this.)
I’m not a customer, but I’ve considered it from a privacy perspective (in that I could just route general browsing through it to block a layer of data harvesting). The problem is that I don’t know what authority they have to push back if pushed by the right actor (who inevitably will knock on the door at some point).
yup. So was The Great Suspender.
This is why privacy is a one-way circuit breaker kind of system. Once you give your privacy away, you can never assume anything about how your data is used. No matter the entity, you simply cannot trust that they will hold your data secure and use it in your best interests. Even Apple, hell even Signal, has leaky bits and "side channels" that can, and you must assume will, be subverted.
VPN services are well off the mark in terms of privacy protection. That the ~~marketing~~ propaganda is so focused on the opposite is an abomination.
So there’s really no reason for Signal to try and hide one is merely using Signal. Best to focus on securing content.
> TLDR: The old maintainer appears to have sold the extension to parties unknown, who have malicious intent to exploit the users of this extension in advertising fraud, tracking, and more. In v7.1.8 of the extension (published to the web store but NOT to GitHub), arbitrary code was executed from a remote server, which appeared to be used to commit a variety of tracking and fraud actions. After Microsoft removed it from Edge for malware, v7.1.9 was created without this code: that has been the code distributed by the web store since November, and it does not appear to load the compromised script. However, the malicious maintainer remains in control, however, and can introduce an update at any time. It further appears that, while v7.1.9 was what was listed on the store, those who had the hostile v7.1.8 installed did NOT automatically receive the malware-removing update, and continued running the hostile code until Google force-disabled the extension.
AFAIK (IANAL etc.) for that to happen several changes to Swedish laws would be required. And the follow up question would be what those demands possibly would be? And of course Mullvad's technical ability to comply?
For some comparison, you could look at the Swedish ISP Bahnhof, which quite publicly fights against the Swedish implementation of the data retention and requests by Swedish authorities. Repeatedly getting Sweden slapped by the EG court. (Which could also be compared with how Signal responds to requests for information about their users which they don't collect.)
There are (again AFAIK, IANAL) no NSL like laws in Sweden.
Everything from cloud vendors, ZScaler, Cisco AnyConnect are technically offering access to private networks with a mix of public internet &/or intranet
Bottom of page 3 says:
> Data Centres, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers, shall be required to register the following accurate information which must be maintained by them for a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration as the case may be:
> a. Validated names of subscribers/customers hiring the services
> b. Period of hire including dates
> c. IPs allotted to / being used by the members
> d. Email address and IP address and time stamp used at the time of registration / on-boarding
> e. Purpose for hiring services
> f. Validated address and contact numbers
> g. Ownership pattern of the subscribers / customers hiring services
Seems to me like it would target all of them. But I just searched for "VPN", didn't read the full document yet.
When I'm in a hotel or otherwise need to use a local wifi I use the VPN client to connect back to one of my own machines, not that I care a lot if Kape can see my traffic.
And, I thought the debate for more needs of privacy, and given the threats have been proven to even come from governments (snowden/NSA, pegasus), was settled, visibly it isn't if even on HN such argument is given in the context of such a clear subject. The overstepping body there is the government, not the busines imo.
By not being a VPN provider? A private VPN isn't hard to make.
If the intent is just to access the Indian web, then sure. I’m sure there are plenty other non-privacy-aware VPNs that let you do that though.
> Data Centres, Virtual Private Server (VPS) providers, Cloud Service providers and Virtual Private Network Service (VPN Service) providers, shall be required to register the following accurate information which must be maintained by them for a period of 5 years or longer duration as mandated by the law after any cancellation or withdrawal of the registration as the case may be:
> a. Validated names of subscribers/customers hiring the services
> b. Period of hire including dates
> c. IPs allotted to / being used by the members
> d. Email address and IP address and time stamp used at the time of registration / on-boarding
> e. Purpose for hiring services
> f. Validated address and contact numbers
> g. Ownership pattern of the subscribers / customers hiring services
https://www.cert-in.org.in/PDF/CERT-In_Directions_70B_28.04....
I'm not sure about the privacy angle but if you spin up a node on a cloud provider, install a VPN on it, do your thing and then destroy it, wouldn't it serve just as well as any of these? Apart from the technical complexity of this, how different is it from using a commercial VPN provider?
Now that a global vpn company has removed its servers out of India, does it mean its customers (while using that vpn service) is blocked from accessing the said website?
Or is there some other implication here?
Curious to know.
How does this work then? How can you have a Indian IP address, while the server is located in the UK?
As a super high level example, your ISP's core router would advertise to other ISP's routers that it serves 10.123.x.x IPs, so any IP address in that block gets sent to that router. Then within your ISP, the router in your area would advertise that it serves 10.123.45.x, so it receives packets for IPs in that more specific block from the core router. So your IP would have to be within the 10.123.45.x block, because that's what the router serving you is assigned.
Any delivery of anything on your phone at least goes to a nearby cell tower but probably exits on your IP from your wifi, and has your address as a requirement. Seems very easy.
Uber Eats, Doordash, etc all know the address of your ip as a requirement to perform their services.
In some cases, traceroutes from different locations around the world can be used to roughly triangulate the location. Though you may find the datacenter to be inside of earth if the IP is actively being used for unicast :)
When it comes to VPNs, stick to the ones that are wholly owned, based, and operated in the EU.
Wondering why anyone is still using ip-based geolocation. The most popular use for VPN's is mocking your location to Steam and Netflix. Could be these players allow mock locations because it gives them revenue..
Why geo ip? Naivety/ignorance coupled with the outdated business logic that segmenting audiences to skim customers to the max will continue to be the winning strategy. It rarely come from within IT brainstorming, those in denial or sticking to short sighted green are the business strategists also being vaguely sold that controlling can be done (and to some degree yes it can be so long as consumers bases don't in their majority adopt privacy measures and moan when being unlegitimately denied access) On the more forgiving side, it does help easily monitor kiddy attacks altogether, if there is no market in Takjistan, why bother looking at false vs true positives coming from there, dumb scripts are dumb but can still be costly for the network management team.
- Content providers care because they want to sell exclusive per-region licenses.
- Netflix doesn't really care, in fact the may benefit from more content available to their users.
The end result is that Netflix will do the bare minimum to keep the content providers satisfied.
Steam is more of a concern because they have different prices per region. But IIRC they use your billing address, not your IP location which is harder to spoof.
Geolocation is largely a feature in products and in licensing because there is big purchasing power difference between rich and poor countries.
Netflix has been more tolerant in the past of region bypass than others for the same reason they didn't crackdown on password sharing but won't be in the future.
[1] The actual prices we pay might vary in both countries depending on promotion and tie ups etc, but these are list prices of which those components would be applied.
There are myriad ways of buying a subscription, including gift cards, third party tie-ups etc, it won't be easy to implement a fool proof solution which works for all of them, especially without degrading user experience.
It is more likely that problem is not big enough for Netflix that it wasn't worth investing that kind of effort.
Similar to how they are handling password sharing now, it is perhaps possible they will look into this in the future as margins tighten and pressure increases as they keep loosing subscribers to competition.
I don't think there's a reasonable alternative. If you ask users for their location they can just lie, if you use the JS geolocation API they can trivially deny or spoof it. If you base it on billing address you're locking out people who are traveling, which seems unwanted (especially for long-term travel).
So instead they end up playing a cat and mouse game to try to block VPNs.
Do people really believe this bullshit? Empty claims of servers running "in memory" as a meaningful defense against surveillance?
Please note that I am not arguing in favor of their advertising or to say that it is successfully avoiding surveillance. But, do you believe that no-disk boot, assuming it actually takes place, is a positive thing, or not?
I admit I misconstrued your original comment to be a criticism of the technology rather than the fact that this VPN company advertises as such. Nonetheless I do think no-disk-boot is not useless as a technology and if you have any disagreement I would love to hear it, as someone who uses a VPN (not expressVPN) that says they use the same setup.
the answer is, yes. even an infintesimally smaller attack surface is better than an infinitesimally larger one, all other things being equal
if your threat model is three letters agencies, vpns and tor are a fig leaf
This is one of the use cases for why you might want a VPN, if you trust a VPN company more than your ISP.
A VPN is just paying for putting your trust in a VPN brand rather than an ISP brand. I don't see why that's such an offensive business to so many HN users.
Because the assertion VPNs - apparently unlike every other ISP - do not log or monetize your data is simply laughable, especially as so many are based in third-world countries, set up by shell entities and have almost no accountability for any of their claims.
When express has their servers seized in turkey, there was no usable data on them.
I know you are super paranoid, but that still doesn't make my point wrong, or using a VPN wrong. Again, if you trust a vpn more than your ISP, that's pretty legitimate in many countries.
I certainly wouldn't trust my life to an unaudited VPN, but I think your two main points are pretty compelling -- 1) the business model is of large VPN companies is based on trust. They have very explicit, business interest in not violating that trust. 2) in one case we know of, when seized, the servers didn't have actionable information on them.
Does that mean every VPN company is trustworthy? Of course not. Does it mean that things could change at any time? Of course.
- If the computer is powered off, moved or confiscated, there is no data to retrieve.
- Running the system in RAM does not prevent the possibility of logging. It does however minimise the risk of accidentally storing something that can later be retrieved.
https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...
Their services terminate TLS locally for most tiers of service (Even with the “Government Community Cloud”), so you need to be careful and use VPNs in any scenario where a foreign interest may be interested in what your employees are up to.