VPN Services That Take Your Anonymity Seriously
torrentfreak.com
torrentfreak.com
I'd wait a few years and then use said data to slowly infiltrate various groups - looking to grab the big fish that are hopefully well separated from the VPN service and then take them down quietly.
Hell - I might even turn a nice little profit on the side.
Reality check: if your credit card details are visible to a third party - you're not anonymous.
Note: I don't actually believe the above to actually be the case in reality - but one must remember that stuff like Room 641A weren't that long ago (http://en.wikipedia.org/wiki/Room_641A).
This is an example of where worst case thinking, despite its negative reputation, can help protect oneself from falling prey to the faulty assumptions that bring down complex systems (Will the generators kick in on time? What if the VPN provider is already compromised? Did we double check that after cleaning the safety valves - we didn't block any of them?).
In that case, you would be a governmental entity which does not care much for the rights of your citizens. Instead, pick a service in a country with a transparent, low corruption-government. I suggest the Scandinavian countries.
As a blunt example, if you want to properly run a data-sensitive company and be imune to (for example) USA requests to violate anonymity of your customers, you need to ensure at least the following:
(a) the company itself is beyond reach of USA - as in examples of UK, Sweden and others caving in to USA requests for things that would/should be legal in these countries but illegal in USA;
(b) you and any personell are beyond reach of USA - again, there are examples such as Kim Dotcom, McKinnon, Assange;
(c) the company internet resources are beyond reach of USA - examples such as revoking DNS names of spanish companies for transmitting internet-TV in compliance with spanish laws, or some of Mega's non-US domain names revoked before even starting operations;
(d) the company money flow is beyond reach of USA - examples of Visa&Mastercard or Paypal blocking payments to sources such as Wikileaks or, IIRC, distributors of (locally legal) console modchips.
As a Swede, I certainly wouldn't trust the Scandinavian countries for this. It's not uncommon to hear politicians claim that internet anonymity and encryption altogether should be completely abandoned.
Also, ISPs typically have numerous laws that forbid eavesdropping, VPNs don't. And seeing as how the government can always ask to get any information they want from any VPN provider (and that the VPN provider is, supposedly, legally obligated to keep records of their customers (in many countries, including Sweden)) using a VPN might be the worst thing you could possibly do, if you want anonymity or integrity. I'm guessing that most VPNs in Sweden straight up Lie about this, when this issue was hot a few years ago you either couldn't get a straight answer or you got one that admitted to record keeping - many (including many of those on torrentfreaks list) just stated that they had to, by law, keep records and that they had to hand them over if asked (with a court order). The law hasn't changed what I know, the PR department of VPN providers probably has though...
And even if they don't have any records to share, who is to say they can't, by request, eavesdrop on current traffic.
For it to have any real effect I'd choose a VPN that is in another country than the one you are in. Although this will probably not have any real effect either if you attract some serious attention, especially considering that unlike an ISP, a VPN provider could legally betray it's customers without an court order (in exchange for being quiet about it).
uhh, stuxnet.
No, they don't understand IT.
In a few years the political caste will consist of people from the facebook generation and beyond. And some of them will understand IT.
There are restrictions on freedom of speech in just about every country btw.
Therefore I'd say it's more important to have an I government than a G government, because it is easier for a government to go from G to E than it is to go from I to C.
Remember that it was US pressure that drove the recent unpleaseantness in .se and TPB were able to succesfully defend themselves there for many years - and most countries currently willing to stare down threats of US trade sanctions aren't exactly havens of privacy and net freedom.
The pro net freedom countries currently correlate with G&C governments, it seems.
Anyway, I sort of like the incompetence level in Greece. They haven't been able to set up a land registry, so that the government could collect property taxes. That sounds promising from the point of view of setting up a privacy-respecting net service. There is a mostly reliable supply of electricity and communications, and it's not a very bad a place to live.
I totally agree. Luckily more and more VPN providers accept Bitcoin payment, so that problem is solved (if you don't connect your wallet to your ID, that is) [1]. I think the more challenging part is not sending personally identifiable information through your VPN or encrypt it properly. Much of the Web is architected to identify you based on the most mundane technical information, like your browser string, cookies, the way you type or those little data leeks that happen here and there.
[1] http://www.bestvpnservice.com/blog/vpn-providers-with-bitcoi...
ps. No, I don't use a VPN. But I like to stay informed.
Which is not easy.
Either you have to mine your bitcoins or you have to trust a third party to exchange your bitcoins in order to disconnect the transaction history from you. But you do have to trust that third party.
Those are the only solutions that I know of.
[1] https://localbitcoins.com/ [2] https://www.google.com/#hl=en&q=bitcoin+laundry
The sad part is that since the history is public, if you goof up and reveal your identity sometime in 2015 your actions of today might also get revealed. To any third party. Potentially way worse than any sort of currency ever used; but the only thing people talk about is how bitcoin is this anonymous currency...
Doesn't really sound like government to me...
Tor is the right solution here, not a VPN.
Remember that a "node run by the CIA", can just mean that the ph.d. student that required some resources from the IT department has a handler. Said student might even think the thing isn't monitored -- although I suspect it would be easier to to involve the admin, then keep him/her in the dark.
I'm curious about what the exact ratios would be, if there were a way to find this out (probably not).
I've thought about running an exit node, but I'm not willing to sacrifice my own safety and freedom to do it. The only solution seems to be buying hosting anonymously (bitcoins?), and making sure you only log in to the server over Tor.
I'm sure government agencies run Tor exits, which means they'll see the middleman node's IP addresses and whatever traffic the originator sent (usually HTTPS). They can't do much with that.
In the UK and US, it's easy to buy pre-paid credit cards with cash.
I'm not really sure how much good a VPN will do with this much surveillance. I feel it's only going to get worse. CCTVs feeding into said datacenters? Web, traffic, and dash cams? As long as the common man "has nothing to hide" they don't seem to care.
"Reality check: if your credit card details are visible to a third party - you're not anonymous."
But that's missing the point since keeping the users' activity anonymous is what matters... not that they are customers.
After attending a local security conference last year (Kiwicon), I briefly tried to see how anonymous I could make myself online. In NZ, we're lucky to have anonymous prepaid credit cards -- "Prezzy Cards" -- which our postal service sells.
Turns out that several VPN services (I ended up using hidemyass.com) will accept them. Alongside an anonymous mail service for the actual account, it's pretty straightforward to head to an internet cafe, boot your laptop into something like Tails, and then create a completely anonymous VPN connection.
Not that I'd personally go to that extent, but it's nice to know that you can achieve a reasonable degree of anonymity online.
More information here: http://en.wikipedia.org/wiki/Strip_search_prank_call_scam#In...
I was just surprised that, with a little effort, it wasn't actually that hard to gain a markedly greater degree of anonyminity than you'd usually have.
It is still possible to do the following:
1) Wiretap the VPN.
2) Correlate with bandwidth/time.
3) Keep logs as a VPN provider.
4) Hack the VPN and do something evil (log, change content)
5) Block access to/from the VPN.
6) Correlate access logs with the VPN IP address (not always applicable, not all providers give unique IP addresses)
The VPN provider doesn't have to want to betray you to do so.
I could create "ProTurboVPN" and promise "anonymity", privacy and no logging, "nobody's touching your data!" but it won't stop the above problems.
Even if I want to save the world as a VPN provider, I might not be able and it's safer to remember that than pretend I can and in the process, get someone into trouble.
The internet wasn't built with anonymity in mind; eventually an IP address has to be tied to a paying customer. Is there any way we can build on today's technology to ensure anonymity on a grand scale? I.e., so that your grandma is surfing anonymously, even though she doesn't know it, using the iPad she just bought?
In a little more detail, when connecting through a circuit of Tor routers R1 -> R2 -> R3, the encryption looks something like this.
client <- E1(E2(E3(msg))) -> R1 <- E2(E3(msg)) -> R2 <- E3(msg) -> R3 <- msg -> server
It's not perfect, though. If you can see the traffic between the client and R1 and between R3 and the server and you're being reasonably clever you can probably break Tor's anonymity. (This is what's called an 'end-to-end correlation attack'.)There are no existing mainstream VPN providers who have strong technical controls to protect user privacy OR anonymity.
There's Tor, and some other systems like that, which make a stronger technical case for anonymity.
There's still a place for VPNs, but it's not as an anonymity service.
On the other hand, I'd want all services to have high security built in -- your mainstream mail provider, mainstream note-taking service, etc. Some of that is technical (a "hostproof" architecture if possible, good internal audit on administrative interfaces, personnel security, etc.). But then, you're one of a mainstream company's customers, vs. a subscriber of the "illegal activity hiding service".
There are "mainstream" uses of VPNs (business, local-privacy, desire to defeat geolocation, firewall-busting, etc.), for which they're great. There are some purposes (anonymity) for which they're horrible. There are things like file sharing in contravention of your ISP's policies or national law where they may work but might not be the best solution -- I'd really go with a seedbox instead of running peer to peer traffic over a VPN.
Tahoe-LAFS might be the best project right now.
I have a couple more questions: 1. how can I use Tor with VPN the most efficient/anonymous way? should I connect VPN -> Tor or Tor -> VPN? 2. Can you point me to good resources about privacy/anonimyty online and linux configuration for privacy?
Thanks for help.
Related: https://thepiratebay.se/legal
If I had a ton of money, and wanted to be really, really anonymous, could I pay all of them, tunnel through all of them somehow, and then get 13 layers of privacy? (And very high latency!)
How about two - are there two of them that I could somehow run one inside the other? Maybe I'd have to surf from a VM using one of them, running on a machine using another of them?
PC->Router1(VPN3)->Router2(VPN2)->Router3(VPN1)->Modem
All three encrypted. I am also using Tor on top of this because as someone else said this is a static version of the onion system. I've pretty much accepted the fact that if someone chooses to find out what I am doing they will find a way, but I am going to make it as difficult as possible.
Its even better if you make your tor nodes public and let other people use them too, to make it more difficult to correlate traffic sent from/to the server with you.
Anyway i am currently looking for something similar to Amazon silk and Opera Turbo, where the server downloads the page, compress it and send it back to you. Extremely useful for low bandwidth connection, as well as providing half of the VPN function.
Does anyone know of software / scripts / services that are available?
"No one is going to go to jail for you". If a VPN provider is legally required to log your activity or face jail time, guess what? you're getting logged! To assume otherwise is just asking for trouble.
All of this is better addressed in this slidedeck.
As another commenter suggested, they could all be honeypots.
If I was going to trust my life to the anonymity of my data transfer, the last service I would want to be using is a VPN.
When it comes to law enforcement, I suppose there are differences in which approach they take depending on where the VPN-service is located. If law enforcement did what you suggest frequently in the country where I live, it would be presented as a scandal and would be the death of the VPN-service in question.
Of course, you must choose a service you trust to not actually keep logs, and give out non-unique IP-adresses. However, if I lived in a country where I could not trust my government, I agree with you, I would avoid VPN-services located there.
also just because they do it now, doesn't mean that tomorrow they wont just turn on the logging... if you want anonymity and privacy you can only trust yourself and your own setup, leaving it at the hands of others is a huge exposure, as a sidenote since you are also using the services of a company that might attract the wrong sort of people that also migh expose you to potential problems (they give you up wrongfully, bad logs, payments to that company, the list goes on...)
Really? Why would a company that has no presence in the US have to comply with the DMCA? I see that one danger might be having it's domain seized, but AFAIK only if it's one of the domains controlled by US companies (.org, .com, .net, ...).
Seems like a lot of "didn't do the homework" in this article
As for Tor, I doubt that anyone is using that for work, but I also doubt that many are really using it for anything illegal. To be sure, there are the Silk Road-type sites, but Tor speeds are not conducive to piracy (and Bit Torrent is highly discouraged on the Tor network).
Especially in the case your work really doesn't offer real VPN to their corporate network, it is the next best thing to have. (Especially when they are affordable) You could have VPN looped through your home, but in this age of bandwidth capping, it is getting a less appealing option.
Through packet level filtering at the firewall it’s possible to
apply rules to an entire shared server, blocking the abuse
immediately. For example, let’s say someone decides to use
TorGuard to unlawfully promote their Ugg boots business (spam).
In order for us to block this one individual, we simply implement
new firewall rules, effectively blocking the abused protocol for
everyone on that VPN server. Since there are no user logs to go
by, we handle abuse per server, not per user.
Seems like a silly way to handle it since eventually none of their servers will be able to access the internet.Anyway - does some of the services allow for independent audit of their systems to confirm that the policies they claim are real and enforced?