They have a higher amount of customers who think they need protection. They are an obvious target for surveillance.
And as TFA says:
> VPN providers that lied about "no logs" never faced any meaningful consequences. https://www.theregister.com/2011/09/26/hidemyass_lulzsec_con...
My argument is: Some/many providers are known to abuse user data, are required by law to store them. Are actively and legally selling the data.
Most VPN providers don't do that. Some might, but a lower probability is still better than knowing that the ISP is legally required to store your data and give them to the authorities.
(this really depends on the country, in some countries ISPs are required not to store connection data, in others they are)
For some ISPs the abuse of user data is a known fact. So VPN is just the safer bet. But don't get me wrong, I'm not claiming this is impossible, it's just less likely.
What makes you think VPN is different.
https://www.washingtonpost.com/graphics/2020/world/national-...
How long did the USA keep it hidden that they owned the Swiss company that manufactured encryption devices for other countries?
They are extremely adept at finding ways to use the secret knowledge without blowing their source. A good example of this is the scene in _The Imitation Game_ after they break the Enigma code for the first time, but Alan Turing explains that they can’t notify the allied ship convoy without leaking that fact.
If you need to protect yourself against the most sophisticated surveillance programs, a lot of opsec will be required.
VPNs can protect you against some creep in a public WiFi spying on your DNS request. It can protect against some low-tech state run mass surveillance.
Can you say "as long as you have nothing to hide"?
We’ve known since WW2 and maybe further that governments have used surveillance against innocents and people they didn’t like.
There is nothing preventing programs of that sort being used for industrial espionage.
With this in mind, I'll link my prev comment: https://news.ycombinator.com/item?id=43095936
> Israel’s supply chain attack on Hezbollah’s pager source
You know, James Mickens, a CS researcher at Microsoft had a very related article (PDF), "This world of ours": https://www.usenix.org/system/files/1401_08-12_mickens.pdf
See Figure 1. He calls it the "Mossad / Not-Mossad threat model" :) (but, joking aside, it's good to identify oneself on a scale, or expectations for some system scale-wise and property-wise (incl. which security properties, esp. privacy vs. anonymity!) before looking closer at it.
With a VPN your employee can't track what websites you're visiting over the WiFi in the break room (looking for a new job, visiting the union website for legal advice).
The hotel can't track what you're doing on their WiFi.
While traveling to not really democratic countries the government can't spy on you (in many muslim countries the typical US/European browsing behavior is probably illegal).
> While traveling to not really democratic countries the government can't spy on you (in many muslim countries the typical US/European browsing behavior is probably illegal).
Aren’t these two threat models already completely different?
IMHO if an authoritarian government considers what you’re doing to be a crime, you should not be doing it over a VPN you saw advertised on a billboard
It's about who you trust more. Your decision to make.
Maybe the staging environment the auditor looked at doesn't log anything, but what about production? Maybe it doesn't log anything today, but who says it didn't yesterday, and that they won't turn logging (back) on tomorrow?
At least where I live, there is strict legislation governing what ISPs can or must collect, and what they do with that information. Offences under that telecommunications interception legislation come with prison sentences, and so there is a strong incentive for individual employees to comply.
For some people, moving that exposure to a VPN provider mitigates their risk. For others, it increases it.