> Linked to US intelligence services. Makes you wonder how many VPN services are run by governments?
I don't recall details, but IIRC, there are (or were) a few popular VPNs in China that were used to circumvent the firewall that functioned fast and reliability despite the anti-VPN crackdowns. I've read speculation that they were likely collaborating with Chinese police/security forces to help them keep tabs on the VPN-using community in order to better anticipate threats to their power.
Facebook ran similar free VPNs for a similar reason: to gather intelligence on users to anticipate competitive threats: https://en.wikipedia.org/wiki/Onavo.
That a government funded mixnet research in the 80s doesn't mean that VPNs are government-run, if that's what you are trying to say (honestly I'm not sure what exactly you're saying, the two have very little to do with each other).
Thanks, I didn't know that. It was meant more illustratively than as an accurate time indication, but nevertheless it's good to be correct and now I know.
My point was that one of the most secure ways of browsing the internet was essentially a government spin off from the 90s. So it's not hard to presume that the government has its fingers in a lot of other things built to hide/obscure user activity.
Well please prove me wrong but having talked to people like Roger Dingledine and Jacob Appelbaum in person and knowing a thing or two about how the Tor Project works, I have zero reason to think that this funding influences the security of Tor in any way, which is what "having its fingers in it" sounds like. The USA not funding the Tor project would, as far as I have been able to discover, not have changed anything about how likely it is that the USA or any other government has access to Tor users' data. If there are intentional bugs (bugdoors) inserted by any contributor, then those would be kept separate from any public funding it receives. Perhaps I'm not cynical, skeptical, or well-read enough though, so again, please point me towards anything that would suggest otherwise.
Then as for VPNs, they're again a very different thing. Funding research or a non-profit is very different from operating a commercial entity under a guise while abusing the trust anyone places in it. The comparison seems to me like comparing funding for general car safety or emission research with suggestions that the government operates one or multiple taxi services in order to learn who goes where. It's not that governments don't setup fronts or operate commercial entities under a guise ever, but rather that I have yet to hear of doing it for the purpose of surveilling random people (you have to get lucky in that anyone of interest signs up for yours, targeted marketing or no) that are not suspected of anything. Aren't fronts usually to enable targeted investigations or do specific actions unnoticed? Like, they might operate a VPN so it doesn't look weird if their secret operators use those IP ranges as well, but the main goal wouldn't be to spy on users (not saying they wouldn't do that on the side, of course, but it's getting more far-fetched).
The author of this book did FOIA requests to various entities but most of them got predictably shot down for national security concerns. This one obscure government agency, Broadcasting Board of Governors, wasn't covered by these exemptions.
So the author read the emails between BBG and the Tor Project maintainers and found that when they received a bug report, rather than fixing it they reported it to their sponsors. The government would then exploit the bug for years before the Tor guys got around to fixing it.
That link reads very much like a conspiracy theory blog, "shocking revelation", "Anyone who questioned this [was] attacked, ridiculed, smeared and hounded into silence", "But the facts wouldn't go away."
The content is worth following up on, though. Those emails are as if written in an alternate reality, where Roger Dingledine is a government agent. They seem hard to believe, but scrolling down there is a PGP signature with the right key ID. I can't verify the sig, the email that I'd have to type over is many pages long and I'd be fighting line endings and it might never match and I'd not know if it's due to a mistake on my part or because the message doesn't match the sig so it wouldn't prove anything anyway. The signing key ID is also a short one (64 bits) so it could also be forged with some effort. I've reached out on IRC some hours ago to see if they deny it, as there is nothing on the Tor Project's blog, but have yet to get a response.
It's trivial to set up a FreeBSD instance with IPSec using StrongSwan on something like a Digital Ocean or Vultr instance in a country that suits (both D.O. and Vultr have regions in US, Europe and Asia/Pac Rim).
But it depends on what you're trying to do. If it's something like get access to shows on Netflix or the BBC iPlayer, then this is a good technique. I think for privacy, it might be OK; while the German or Australian govts. might share data with the US, probably Singapore, Korea, Japan or India doesn't. if you're up to something more nefarious then maybe you need something stronger like Tor.
Part of the point of a VPN service is your IP represents thousands of users and no or very temporary logs are kept. Spinning up a one or dozen user VPN on a data-center IP where they definitely keep logs gives you none of that. Any complaint will immediately be forwarded or linked to your credit card. To see this in action go make one and then bittorrent some hollywood movies. You will get the scare letter emails forwarded to you within a month.
Want to get a data center account that takes crypto only? They are often shady, bad, unreliable and expensive, probably run by another gang that have their own issues.
Thanks. I have always been wondering how the "hackers" (not in the sense of the way described in "How to be a hacker") managed to protect their traces while hacking other people's computers/networks. For sure many of them are gov entities so natually it's a lot easier to cover their tracks, but many of them are not.
I'm not sure what is currently beeing used, and I guess that really depends on what exactly you are doing. But I know that often infected Computers are used as a VPN or Shadowsocket to cover ones tracks. Combine that with several layers of protection and it gets harder and harder to track one down
Both Korea and Japan are client states in the U.S. empire, with large US military presences and drastic interventions in their domestic politics. They absolutely collaborate with the US on everything.
You don't need the EU, they are probably more infiltrated then Japan, just listen to the german/french discussion (Germany believe that Europe can't have it's own army without US support...because of "nuclear"...France is pissed)
> “well my use case for wfh involves uploading 1 TB a day”, but no, that’s not normal
1.2 / 30 = 40GB a day. Seems fairly low to me. Considering families with children attending online school as well, then clump in streaming services such as Netflix.
Especially considering there's multiple games out there now that are 60+ gigs. My guess based on the unifi graphs of my connection for 7 people is that our biggest consumers are Netflix, and game downloads. One roommate alone ate over 150 gigs in game downloads in the last month.
>The department has not disclosed the exact location of the monolith, fearing explorers may try to seek it out and "become stranded". The big horn sheep wildlife officials were counting are native to many parts of southern Utah, where the terrain is rugged.
The point still stands, it shouldn't be allowed. It's a natural area for animals and it is a dangerous location. Those well trained/equipped who would normally explore areas like this would be fine -- but this could encourage people with less experience to venture into these areas unprepared for what they will face.
That terrain in Utah is no joke and many people have gone missing in those areas.
It’s not a natural location for animals. It is federally managed land for camping, hunting, and 4 wheeling.
Inexperienced people die venturing into nature all the time. The solution is to warn and educate people, not discourage them from enjoying the outdoors.
Its a big place, and only a few busy Rangers. I imagine folks can just drive in unnoticed. And die of exhaustion or dehydration once they've had a breakdown, lost their way, run out of gas or whatever. Where in that process do we have an opportunity for education? Other than the Darwin sort.
This is true of any wilderness. We should put a warning poster at the obvious trailheads and let the rest of the idiots die.
A more aggressive strategy might involve teaching children in schools not to walk out into the desert without water, or into the ocean if you can’t swim
I built something similar to this[1] for when I'm dealing with hosts I don't have complete control of -- to block outgoing connections. Now it seems there might be a more widespread use case.
Custom DNS servers are available on Big Sur. My home network uses pfSense as a gateway for LAN. This gives more options blocking outbound connections or routing connections thru a VPN connection based on certain conditions.
There are other tools available as well to collect 'cloud' data. Such as Magnet AXIOM Cloud[1] and Cellebrite UFED Cloud[2]. These still require legal process in most cases.