Stories
Slash Boxes
Comments

SoylentNews is people

posted by martyb on Saturday July 18 2020, @02:40AM   Printer-friendly

VPN firm that claims zero logs policy leaks 20 million user logs:

The VPN company in the discussion is a Hong Kong-based UFO VPN owned by Dreamfii HK Limited.

[...] Discovered by researchers from Comparitech on July 1st, 2020; the exposure occurred due to the database hosted on an Elasticsearch cluster being left without any password.

[...] Worth 894 GB, the data allegedly included plaintext passwords, IP addresses, timestamps of user connections, session tokens, information of the device, and OS being used along with geographical information in the form of tags.

[...] This, as Comparitech has rightly pointed out, goes against the service provider's privacy policy and the promises of a zero log policy it has communicated to its users:

UFO VPN does not collect, monitor, or log any traffic or use of its Virtual Private Network service, under any circumstances, on any platform.


Original Submission

This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
(1)
  • (Score: 4, Informative) by RandomFactor on Saturday July 18 2020, @03:05AM (12 children)

    by RandomFactor (3682) Subscriber Badge on Saturday July 18 2020, @03:05AM (#1023215) Journal
    --
    В «Правде» нет известий, в «Известиях» нет правды
    • (Score: 0) by Anonymous Coward on Saturday July 18 2020, @03:14AM (7 children)

      by Anonymous Coward on Saturday July 18 2020, @03:14AM (#1023224)

      Picking a VPN provider may be a crapshoot, but you can do better than Hong Kong, a wholly pwned subsidiary of China.

      • (Score: 2) by Runaway1956 on Saturday July 18 2020, @03:39AM (6 children)

        by Runaway1956 (2926) Subscriber Badge on Saturday July 18 2020, @03:39AM (#1023234) Homepage Journal

        Yes, you can. I use PIA, which seems to have bought out by an Israeli intelligence agency. Since I'm not anti-Semitic, I don't have much to worry about. I am somewhat anti-Zionist, but that's acceptable, since even some Jews are anti-Zionist.

        --
        Hail to the Nibbler in Chief.
        • (Score: 4, Interesting) by DECbot on Saturday July 18 2020, @03:52AM (1 child)

          by DECbot (832) on Saturday July 18 2020, @03:52AM (#1023238) Journal

          I use PIA, which seems to have bought out by an Israeli intelligence agency. Since I'm not anti-Semitic, I don't have much to worry about. I am somewhat anti-Zionist, but that's acceptable, since even some Jews are anti-Zionist.

          I urge you to think critically about that. I have a strong suspicion that the Jews in Israel are more likely to be Zionist and even moreso the ones in the government tasked to monitor communications and liaison with Western governments.

          --
          cats~$ sudo chown -R us /home/base
          • (Score: 1, Interesting) by Anonymous Coward on Saturday July 18 2020, @04:51AM

            by Anonymous Coward on Saturday July 18 2020, @04:51AM (#1023253)

            They don't need him ideologically aligned as long as he's useful in pushing their larger agenda, which is more easily pursued through the rightwing arm of US politics.

        • (Score: 3, Interesting) by Anonymous Coward on Saturday July 18 2020, @04:03AM

          by Anonymous Coward on Saturday July 18 2020, @04:03AM (#1023243)
        • (Score: 2) by sjames on Saturday July 18 2020, @07:55AM

          by sjames (2882) on Saturday July 18 2020, @07:55AM (#1023289) Journal

          I'm not so sure. A Hong Kong VPN is a bit more likely to leak your data, but is less likely to 'leak' your data to U.S. copyright trolls or DEA in a form they could use against you.

        • (Score: 0) by Anonymous Coward on Saturday July 18 2020, @10:47AM (1 child)

          by Anonymous Coward on Saturday July 18 2020, @10:47AM (#1023321)

          Jews are allowed to be anti-zionist. You goyim will do as your betters tell you.

    • (Score: 2) by maxwell demon on Saturday July 18 2020, @01:34PM

      by maxwell demon (1608) Subscriber Badge on Saturday July 18 2020, @01:34PM (#1023357) Journal

      Obviously "no log policy" here doesn't mean that there is a policy of having no log, but there is no policy about having log.

      Oh, they said they keep no log? Well, of course they didn't keep them, they gave them away to the whole net!

      --
      The Tao of math: The numbers you can count are not the real numbers.
    • (Score: 1, Informative) by Anonymous Coward on Saturday July 18 2020, @05:39PM (2 children)

      by Anonymous Coward on Saturday July 18 2020, @05:39PM (#1023429)

      В «Правде» нет известий, в «Известиях» нет правды

      FTFY. Keep your Russian classics grammatically correct. :)

      • (Score: 1) by RandomFactor on Monday July 20 2020, @03:01AM (1 child)

        by RandomFactor (3682) Subscriber Badge on Monday July 20 2020, @03:01AM (#1023948) Journal

        If you can't trust an AC, who can you trust?
         
        Updated :-)

        --
        В «Правде» нет известий, в «Известиях» нет правды
        • (Score: 2) by fraxinus-tree on Monday July 20 2020, @07:24AM

          by fraxinus-tree (5590) on Monday July 20 2020, @07:24AM (#1024003)

          I thought it was intentional. For someone speaking Russian it was obvious enough not to be a honest spelling mistake.

  • (Score: 3, Informative) by Arik on Saturday July 18 2020, @03:12AM

    by Arik (4543) on Saturday July 18 2020, @03:12AM (#1023219) Journal
    If you do business with the PRC, or from territory they control, you keep logs.
    --
    If laughter is the best medicine, who are the best doctors?
  • (Score: 2, Funny) by fustakrakich on Saturday July 18 2020, @04:02AM (13 children)

    by fustakrakich (6150) on Saturday July 18 2020, @04:02AM (#1023242) Journal

    So, what's left? Where do people find a secure connection? The Sunday classifieds are probably still the best way to hide a message

    --
    La politica e i criminali sono la stessa cosa..
    • (Score: 1) by Zinnia Zirconium on Saturday July 18 2020, @04:55AM (12 children)

      by Zinnia Zirconium (11163) on Saturday July 18 2020, @04:55AM (#1023254) Homepage Journal

      Run your own VPN server and turn off your own logs.

      • (Score: 2) by jasassin on Saturday July 18 2020, @05:14AM (10 children)

        by jasassin (3566) <jasassin@gmail.com> on Saturday July 18 2020, @05:14AM (#1023261) Homepage Journal

        Run your own VPN server and turn off your own logs.

        What? Are you serious?

        --
        jasassin@gmail.com GPG Key ID: 0xE6462C68A9A3DB5A
        • (Score: 2, Funny) by Zinnia Zirconium on Saturday July 18 2020, @05:28AM (9 children)

          by Zinnia Zirconium (11163) on Saturday July 18 2020, @05:28AM (#1023266) Homepage Journal

          I'm doing it right now. And because I'm running my own VPN server on a VPS registered to me and paid for with a credit card in my own name that means I'm getting none of the cover-your-ass-by-hiding-in-a-crowd protection that most people expect when they think of the letters V P N. But hey at least I know I'm not logging me.

          • (Score: 2) by Bethany.Saint on Saturday July 18 2020, @11:53AM (1 child)

            by Bethany.Saint (5900) on Saturday July 18 2020, @11:53AM (#1023337)

            But ... how do you do illegal things without it being traced backed to you?

            • (Score: 0) by Anonymous Coward on Saturday July 18 2020, @05:01PM

              by Anonymous Coward on Saturday July 18 2020, @05:01PM (#1023419)

              That's not what a VPN is for... A VPN is for ComSec

          • (Score: 2) by maxwell demon on Saturday July 18 2020, @01:37PM (6 children)

            by maxwell demon (1608) Subscriber Badge on Saturday July 18 2020, @01:37PM (#1023359) Journal

            Actually, if you provide VPN for anyone without keeping log files, then of course you can use your own service also yourself. And without logs, no one can prove that it was you who did those things, rather than one of your customers.

            --
            The Tao of math: The numbers you can count are not the real numbers.
            • (Score: 2) by hendrikboom on Saturday July 18 2020, @02:57PM

              by hendrikboom (1125) on Saturday July 18 2020, @02:57PM (#1023383) Homepage Journal

              no one can prove that it was you who did those things, rather than one of your customers

              Unless they use a warrant to enter your premises and confiscate the devices where you stored the products of your illegal acts.

              -- hendrik

            • (Score: 0) by Anonymous Coward on Saturday July 18 2020, @08:23PM (3 children)

              by Anonymous Coward on Saturday July 18 2020, @08:23PM (#1023477)
              Would it be possible to create a legal entity and an AI to run a VPN (or other ) service where there's no actual human in charge officially and legally?

              Customers/users are charged to cover expenses and make a profit. The AI would hire consultants + lawyers to do stuff like "reproduce" aka make other independent similar entities - because inevitably the parent entity would eventually get corrupt (consultants or lawyers screw up or successfully betray the "trust" despite safeguards) or "die" via some accident etc.

              For bonus points have the AIs pick mates and share "genes" (sex) when reproducing.
              • (Score: 0) by Anonymous Coward on Saturday July 18 2020, @10:21PM (2 children)

                by Anonymous Coward on Saturday July 18 2020, @10:21PM (#1023527)

                The very act of creating a legal entity requires making some other legal entity responsible for its actions. And unlike the Earth, it cannot be turtles all the way down.

                • (Score: 1) by khallow on Sunday July 19 2020, @03:06AM (1 child)

                  by khallow (3766) Subscriber Badge on Sunday July 19 2020, @03:06AM (#1023614) Journal
                  There's only so much responsibility one can hold. To use the classic Skynet example, how much responsibility can a long dead US military hold for the creation of an AI superpower bent on human extinction? You going to sue someone?
                  • (Score: 2) by fraxinus-tree on Monday July 20 2020, @07:15AM

                    by fraxinus-tree (5590) on Monday July 20 2020, @07:15AM (#1024001)

                    You don't have to try that hard.

                    There is still quite a few jurisdictions where one can create a company A owned by company B which is in turn is owned by company A.

                    Usually done for debt "management", but you can use your imagination.

            • (Score: 2) by corey on Sunday July 19 2020, @04:15AM

              by corey (2202) on Sunday July 19 2020, @04:15AM (#1023633)

              What about buying some cloud server time, set up a VPN on it and then the recipient only sees AWS or Azure.

              Use a weak password so the deniability is someone else got in and abused the VPN, for if shit hits the fan.

      • (Score: 2) by Opportunist on Saturday July 18 2020, @08:19AM

        by Opportunist (5545) on Saturday July 18 2020, @08:19AM (#1023291)

        Preferably via servers that belong to someone else and you compromised so you're not going to be held responsible for not having logs when the feds collect it.

  • (Score: 4, Informative) by leon_the_cat on Saturday July 18 2020, @05:57AM

    by leon_the_cat (10052) on Saturday July 18 2020, @05:57AM (#1023269) Journal
  • (Score: 0) by Anonymous Coward on Saturday July 18 2020, @06:27PM

    by Anonymous Coward on Saturday July 18 2020, @06:27PM (#1023448)

    Mullvad looks pretty good, though i would prefer they accept Monero/XMR instead of BTC with logged address.

    https://mullvad.net/en/ [mullvad.net]

(1)