How one small American VPN company is trying to stand up for privacy
arstechnica.com
arstechnica.com
But given Snowden's work, we'd be foolish to assume the collaboration is limited to this fact.
An additional use, and the one I use VPNs for from time to time, is to throw off ad-network information and avoid over-disclosing information about myself.
If the government wants to snoop on you, a VPN is one NSL away from having full access to all future use unless you hide your identity and money trail very carefully.
Quoting Andrew Lee: “However, to remain in the US, meant, as well, the relinquishing of my access to the PIA systems/network. Administrators, developers and co-founders everywhere can relate to the difficulty of doing so, but the reality is that it was a requirement if I was to remain here. This policy is in place, and relinquished access I have.”
There's significantly more information in the original article.
The scary part is if it's a secret court order, the service provider is gagged and threatened with legal action if they publicly disclose the fact they're complying with a Government request. Being an American based company all the more makes it too easy for the NSA to get the information if they need it. This article does not make me feel any less insecure about my privacy.
As Doctorow mentions in his article, the basic idea is not new -- it originated in 2004 with Jessamyn West, a librarian trying to fight back against the FBI trying to look at patron's reading habits, and the accompanying gag order. In that case, it was:
> a sign on the wall of her library reading "THE FBI HAS NOT BEEN HERE (watch very closely for the removal of this sign)."
[1]: http://www.theguardian.com/technology/2013/sep/09/nsa-sabota...
It also will take a pretty clear Chinese wall between builders and operators of a service, or even an arms length multi entity relationship (eg a meta VPN provider sells sells fairly turnkey VPN nodes to operators, who then run them; maybe a third entity which does billing for end users and rev shares everything out). Much more like Tor than the commercial VPN services of today.
The corporate VPN world is different, and the simple "torrent shit on comcast" or "watch Netflix on vacation" market is way easier.
IFF lavabit is resolved successfully, you may be able to trust a US provider for general privacy stuff, but that is months or years off.
I've read through lavabit's filing and I'm not sure the factual predicates are as strong as they possibly could be. So they could lose on narrow grounds and still leave the door open for other companies to argue that it is possible to create a reasonable expectation of privacy for its customers in their metadata.
However if lavabit loses and the decision is written broadly, you are right that it is probably game over for any system that requires you to trust the subject to US jurisdiction operator in any way.
Unfortunately, I've been delayed (due to a fairly major motorcycle versus Jeep accident that has me laid up) but I've been considering offering a similar service (as well as Tor relays, including an exit node or two).
For those of you who (might) use such services, what would it take for you to trust a provider? An AUP/ToS stating "we don't log", a so-called "transparency report", a warrant canary, payment via Bitcoin?
I think the lifetime value of a VPN customer is >$50 (accounts tend to churn but it is be same people getting new ones, in my experience with VPNs from before; users either fall into the long term customer bucket or use then for single purposes).
I've only seen their ads or promo stuff in very targeted places, as well as bitcoin (which is more them sponsoring it due to early involvement with bitcoin), so even high cpm would make sense. People go to " top VPN provider" lists with intent.
I see anchor free and hidemyass much more in general ads and forums. AF is free and ad supported, and mega capitalized, so that is probably why they go for random high volume stuff