Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 15 submissions in the queue.
posted by martyb on Saturday July 18 2020, @02:40AM   Printer-friendly

VPN firm that claims zero logs policy leaks 20 million user logs:

The VPN company in the discussion is a Hong Kong-based UFO VPN owned by Dreamfii HK Limited.

[...] Discovered by researchers from Comparitech on July 1st, 2020; the exposure occurred due to the database hosted on an Elasticsearch cluster being left without any password.

[...] Worth 894 GB, the data allegedly included plaintext passwords, IP addresses, timestamps of user connections, session tokens, information of the device, and OS being used along with geographical information in the form of tags.

[...] This, as Comparitech has rightly pointed out, goes against the service provider's privacy policy and the promises of a zero log policy it has communicated to its users:

UFO VPN does not collect, monitor, or log any traffic or use of its Virtual Private Network service, under any circumstances, on any platform.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2) by corey on Sunday July 19 2020, @04:15AM

    by corey (2202) on Sunday July 19 2020, @04:15AM (#1023633)

    What about buying some cloud server time, set up a VPN on it and then the recipient only sees AWS or Azure.

    Use a weak password so the deniability is someone else got in and abused the VPN, for if shit hits the fan.

    Starting Score:    1  point
    Karma-Bonus Modifier   +1  

    Total Score:   2