Allegedly, they are using their customers as botnets to resell traffic from residential IPs, mostly for scraping, through their other business "Oxylabs".
Allegedly, they are using their customers as botnets to resell traffic from residential IPs, mostly for scraping, through their other business "Oxylabs".
The idea was never that NordVPN was reselling the network connections of NordVPN customers; it was always that they were, on their backend, originating NordVPN customers traffic from maybe-sketchily-sourced IP addresses.
Here is a paragraph I wrote a couple years ago on the topic of how centralized VPN companies manage to bypass blocks by content providers (such as Netflix).
> One VPN company that actually seems to do "well" at this is NordVPN: they've even managed to provide access to Disney+! Someone did a deep analysis of how this worked a while back (an article which has since been deleted, weirdly, but a copy can be found on the Internet Archive). They are "linked closely with a Lithuanian data mining company called Tesonet" which also runs Oxynet, which in turn advertises itself to have "32M+ residential proxies…100% anonymous proxies from all over the globe with zero IP blocking", which the author of that analysis believes is how NordVPN is originating their traffic... and how did they get all of those IP addresses? The contention was that they seem to be stealing them, convincing random products to embed malware that attaches them to the Oxynet essentially-a-botnet.
https://news.ycombinator.com/item?id=21664692
http://web.archive.org/web/20191128170008/https://medium.com...
I am basing the second part on this research: https://www.docdroid.net/kOP3JAh/tesonet-web-of-lies-pdf
I'm not a conspiracy theorist, but the relations of Tesonet, NordVPN and Oxylab is creepy at best.
People make the allegation that NordVPN is routing some of Oxylabs' traffic, because that's exactly what HolaVPN and Bright Data (previously known as "Luminati") does. (See https://archive.is/aJY0F ) And Luminati Networks sued Tesonet for patent infringement on this.
Just the corporate structure of Tensonet in itself should make people stay away from any of their VPN products.
Source: ex-employee.
"Consenting and fully aware individuals become a part of a residential proxy network in return for a financial reward or some other benefit. When they choose to participate in our suppliers’ pools, they consent that a part of their internet traffic and a small amount of the device’s hardware resources will be used for a variety of business cases."
Does anyone that uses NordVPN know how explicit this is in their client/agreement? If they are even using it...
I don't opt in to anything like this (as far as I know). Looking at the preferences, I don't see something that sounds like it maps to the consent above. So ... I'm not really sure.
This is why their marketing campaigns are so aggressive. They completely rely on the unsophisticated masses, to whom a computer is a magical box of fairy dust that plays Netflix shows.
And that’s perfectly fine - computers are a tool, enabling valuable usecases for everyone.
Of course. But the arbitrage of that knowledge leaves open all kinds of profitable businesses, including shady VPNs.
However, I also think this is the only way to bypass streaming sites blocking VPNs - the whole reason for using such a service in the first place.
IMHO the shadiness is only around consent and not the means. Unfortunate, but such is reality.
Since oxylabs allows selecting a proxy at a very granular location, it should be possible for researchers to get a bunch of these dodgy browser extensions and correlate which are forwarding oxylabs traffic.
Nothing in their license agreement and no settings for this at all.
Doesn't appear they are recruiting devices into this residential proxy service.
First of all, I want to reiterate that I purposefully used the word "allegedly" because I have no proof. I only have a smoking gun https://archive.is/bQo0O .
Second of all, I want to explain that it is very difficult to verify any of your points.
> you can easily [...] look through the code. As you can see majority of it is open source.
Yes. This is correct, but at the time of writing this comment, the source has been made available only 9 hour ago. https://github.com/NordSecurity/nordvpn-linux
The whole thing is one giant "Initial commit" of what looks like millions of lines of code. Auditing this code will take months for single motivated person. There is little to no comments. "Just read the code" is difficult in this context. Also routing traffic through the client can be done just with 2 lines of code enabling kernel ip forwarding, and another line of code adding a nft/iptable rule to nat traffic from NordVPN to the outside world. This is looking for a needle in a haystack if this is obfuscated.
Also your Windows and MacOS clients (which are the most used by non-power-users) are not opensource, at the time of writing. So these ones could still be doing what has been alledged. This would be fine, since it's most likely most of your users.
> you can easily check it using Wireshark
This is also not that easy. If, as alleged, Oxylabs resells millions of NordVPN IPs to thousands of Oxylabs customers, you only have 1/1000 chance to be the botnet of the day. So you would need to be running Wireshark the one day out of 2½ year to see the traffic going through with Wireshark.
Yes this is true even with NordVPN, which I bought specifically to be able to watch Netflix on when expressVPN didn’t work.
It’s not obvious at all. Netflix could be doing something as simple as checking the IPs or could be actually checking the use of VPN at a system level. Both are equally valid readings of the GP comment.
Any solution that requires me to reach behind my TV and plug in my laptop is already not easy.
With Netflix you just punch your password into your smart TV and you're watching content.
It even syncs progress across devices, works on all my devices (doesn't work in the Apple ecosystem).
If Nord VPN is really bouncing your traffic out of some other residential customer's connection, that would be a lot harder to detect. And a lot more ethically questionable if the other user doesn't realize they're doing it.
I dunno if SSL encrypts the entire HTTP payload or not but could you even figure out the URL’s being requested using a tool like wireshark?
Host names: Very likely, unless you're using SNI.
I keep thinking the "e" is for "enhanced" encryption, i.e. "eSNI 2.0", but what I'm thinking of is actually called ECH (for "encrypted client hello"): https://blog.cloudflare.com/encrypted-client-hello/
Using VPNs for Streaming is selling point #1 for tons of people.
I had whole home VPN configured and I couldn't access NFLX streaming content from the house. Getting Netflix traffic to bypass the VPN is incredibly difficult without hacking the client side code to have it update the bypass rules on-demand in response to the client side JSON payloads - or hook into DNS resolution and do VPN bypassing there based on a regeular expression of the origin and the returned records.
The way NFLX works under the hood, from the client's perspective, is that it makes an initial request to a service hosted in AWS. That service stitches together the list-of-lists on the home page. Then you select a film to watch, it again reaches out to a service hosted in AWS to ask to stream the content. This is really straightforward to get working with whole home VPN, you just bypass the VPN for those origins (using DNS queries to get the IP blocks) and you are golden. A little cron job could keep that IP bypass list fresh and it worked well enough to get through the UI.
But then the AWS service responds with a list of streams you are licensed to watch and URLs that point to their location. Those URLs point to Netflix's OpenConnect CDN hosts. Nearly every time I went to stream, I'd pull a different origin for the content and that would route back through the VPN. The list wasn't stable, so I couldn't compile a comprehensive list of origins to route around the VPN with.
So NFLX blocks VPNs to protect their licenses, which I understand. But their architecture made it impossible for me to allow their service to bypass my VPN. So any device I wanted/needed to use NFLX on had to have a direct connection to the internet.
Never had an issue, been signed up for years.
It’s possible to set up your own solution I believe but I don’t have the time for that currently.
Not affiliated or anything and I’d do your own research on them but I much prefer this as they only see that traffic from me.
Specifically to watch The Walking Dead if I am honest.
I assume someone was detecting if you were using a VPN and testing and it somehow made it into production. I emailed them and never heard back.
Granted ... I get why a retailer with financial activity going on might want to know if a VPN was used to possibly apply extra scrutiny to the purchase.
I used to work for a company that explicitly changed the prices on the site if the request traffic came from a competitor IP address.
Of course this was a hundred years ago in a land far away. I don’t know how much success you’d have even finding your competitors IP’s these days.
"Exit node" users and VPN customers don't need to be in the same set, though: It's entirely possible that the VPN operator buys residential IP forwarding volume and includes access to it as part of their product offering.
That doesn't make things much better for unwitting users sharing their internet connectivity with insufficient or no education, though...
To be honest, apart from botnets, it’s really the only way a company could “legally” get access to millions of residential IPs.
I asked this question, the answer from this other company was "we would close your account". But they were unable to explain clearly to me how and if they monitored this.
In fine, I think this is your responsibility, you basically voluntarily installed some malware.
If someone else is doing illegal things on your IP address then you could blame the (users of the) service to avoid liability. Still you could find yourself targeted by a lawsuit. I wonder if Oxylabs' terms protect you in this case.
Most routers and other clients that aren’t updated very frequently still only support OVPN.
They also offer WG connections if OVPN bothers you so much.
Their FAQ confirms this, assuming you trust them. https://mullvad.net/en/help/no-logging-data-policy/#no-logs
If a provider can sell a VPN for $1/month as a loss leader and make $5/user after selling all data, what keeps a $10/month VPN from making >$15 doing the exact same thing?
Mullvad is the best privacy-focused VPN, hands down.
That might well be true, but anonymous payments are no proof, or even supporting evidence, for your claim.
It could still be very lucrative to resell data in the form of "users who access foo.com often also access bar.com" – and you can probably see why that could easily be deanonymizing.
Private Internet Access and ProtonVPN both have tenuous relations to shady stuff. Private Internet Access got purchased by the same company that made Cyberghost (malware), but so far nothing bad has come of it. AFAIK they're also the only VPN that has been truly court-tested.
ProtonVPN has some really weird circumstantial stuff related to TesoNet.
Any other VPN I wouldn't trust by default. Shady business sector.
Not all VPN providers sell data (DNS or otherwise). Some operate for privacy-driven reasons and actively seek to be good stewards for their customers.
But I don't buy into the idea that anyone can say "ALL VPN PROVIDERS" do a thing.
I believe NordVPN's open sourcing effort here (whether genuine or not) is motivated by pressure from Proton's open source.