*** Note that Proton has a commercial interest in VPNs. This may be biased reporting ***
https://www.cnet.com/tech/services-and-software/proton-vpn-report-location-tracking-privacy/
With a fast VPN, your speed loss will be virtually unnoticeable.
Using a virtual private network is a surefire way to keep your information private when browsing the internet. But a new report from Proton, released on Wednesday, exposes some major holes in that concept.
A VPN is a tool that encrypts your internet behavior and hides your IP address and physical location, with the goal of keeping your identity and identifying information secure. But 64 of the VPN apps downloaded in the US, Proton found, are owned by Chinese companies and contain trackers that collect all sorts of user information, including device IDs, network information, device models and mobile carrier data.
And 25% of the apps in question were found to actively track your location.
In June alone, these apps were downloaded over 13 million times.
Narrowing down the numbers further, Proton found that 31 of those Chinese-owned VPNs use shell companies registered in jurisdictions such as Singapore, Hong Kong and the UK to further hide their identities.
An authoritarian government like China’s could use this information to track a person’s location. So if a public official, someone in law enforcement, a journalist or even someone attending a protest was using one of these VPNs for safety, this flaw would expose them to potential threats.
It should be clear that China isn’t the only country where companies harvest the data these apps collect, but it’s near the top of the list. Israel, Russia and the Five Eyes countries — Australia, Canada, New Zealand, the UK and the US — all have companies collecting tracking data from millions of people.
Transparency is a big issue here, with a load of bad VPN apps being readily available for download through Apple and Google. Proton’s report points out that both companies require developers to submit their own paperwork to verify their apps, with little verification (and no independent audits) being done on Apple’s or Google’s part. Apple and Google didn’t immediately respond to requests for comment.
This lack of guardrails in the verification process makes it hard to decipher which virtual private network apps protect your privacy and do what their policies promise and which are virtually doing the opposite.
“Proton's report is yet another example of why it's so important to know who's behind your VPN and what data they're collecting,” CNET Senior Writer Attila Tomaschek said. “It's also another reminder that just because a VPN app is popular in Apple's or Google's app marketplaces, it doesn't necessarily mean that the VPN app is safe to use.”
If you’re looking for a VPN, Tomaschek points to VPNs like Proton and ExpressVPN, which regularly rank near the top of CNET’s VPN recommendations. Each virtual private network is put through a rigorous testing process that includes a thorough examination of the app’s privacy policy, transparency reports, audits, corporate structure and legal jurisdiction.
When all else fails, avoid any VPN that is murky about any of those key principles. “Instead, opt for a trustworthy VPN that is crystal clear about where it’s based, who’s behind it and how it protects user privacy,” Tomaschek said.
(Score: 4, Interesting) by Bentonite on Tuesday September 01, @02:33AM (12 children)
That happens to be true - of course at least ⅙ of VPNs have proprietary cr…apps that track the users location and do other spying too.
VPNs frankly don't give you privacy (as all your activities are correlated with a single hop to a single IP, or a small set of IP's, that isn't used by that many people).
If you want to do private web browsing, you really need to use tor instead.
The only practical use for 3rd party VPNs is to carry out unauthorized copying of modern slop (why would you do that?) and let the company deal with the copyright trolls for you.
(Score: 5, Informative) by janrinok on Tuesday September 01, @03:16AM (11 children)
That gives you some privacy, but unfortunately it has other weaknesses. Imagine if you will that you are a user of a fictitious site that consists of 2 people. One always uses TOR while the other doesn't. You are immediately recognisable by your use of TOR. TOR is useful when there is a lot of traffic but on a site where only a very small proportion of users are hiding behind it becomes another almost unique feature of the user. TOR gives you anonymity but nothing more.
TOR users imagine that they are buried alongside thousands of other communications - which they are for various intermediate 'skips'. But TOR exit nodes are publicised very well and the same users are, for some reason or other, only using a very small subset of those exit nodes. I don't know why this should be the case. So it is impossible to identify who you are in meat-space (unless perhaps you are one of the very big players!) but it does provide another element that helps to fingerprint connections. When combined with other data it would allow a user's participation to a small site to be linked together.
(Score: 4, Informative) by Bentonite on Tuesday September 01, @08:08AM (10 children)
It was never "TOR", the network is Tor and the software is tor.
For users connecting without Tor, they cycle between a handful of IP addresses at most - making that a far more unique feature of the user.
Also, if a business or the government asks the ISP for the address of the user assigned an IP, the ISP will usually tell them.
There also exists surveillance malware for tracking devices, distributed as libraries for cr…apps, which reports the current GPS location and the current IP address, which goes right into GeoIP databases.
As a result, if a tracking device has ever connected to your network, you should assume that your IP addresses are now assigned to a location in some GeoIP database and that any websites you browse could likely work out your address, just from your IP.
With Tor, you cycle between many different IP's - over time you have a pool the size of all the exit nodes.
If there are 2 or more users that use Tor, the site cannot uniquely identify either user without more information and the more Tor users, the bigger the anonymity set gets.
Tor is now well known, but small sites sometimes still don't even know what Tor is and don't care until some jerk decides to use Tor (some of which who proceed to see 1000 normal users using Tor and 1 jerk and decide to ban Tor - rather than dropping the false assumption that 1 IP address == 1 person and putting certain parts of the site between accounts instead).
While by default a session uses a limited subset of exit nodes, you can regularly change sessions, thus getting a new subset, or modify the software to use all the exit nodes randomly.
(Score: 4, Informative) by janrinok on Tuesday September 01, @02:29PM (9 children)
If what you say is true, then statistically you shouldn't use the same exit node often. But it is not true - it is what everyone expects and it is what everyone was told would happen, but it is not what happens in actual fact. Many TOR users in our experience are limited to about a dozen or so different IP addresses. As I said, I do not know why this should be. It is especially true of anyone using 'Private' windows. Tor-Browser is better as long as you regularly request a new route.
As an example your parent IP address has been used 28 times in recent months and your grandfather post 24 times. That doesn't seem very random to me, and looking at all of your posts you have used only a handful of the published exit nodes.
TOR was originally an abbreviation of The Onion Routing. Abbreviations are usually reported in capital letters, just like NASA and NATO used to be. Now people get lazy and write Nasa and Nato, and they renamed the network Tor. The alpha version of Tor, developed by Syverson and computer scientists Roger Dingledine and Nick Mathewson and then called The Onion Routing project. it might be trendy to use 'Tor' now but it wasn't originally like that. That's the problem with getting old. But I can see little to be gained by me nit-picking and as long as we both know what the other is talking about it doesn't seem that important.
By all means try it for yourself. Create a mini-server and keep connecting to it via TOR, say once an hour. Let me know the results. The relatively few TOR users on this site do not have a wide dispersion of IP addresses as individuals, but different users have different sets in some cases. The majority of users on this site use neither TOR nor a VPN, but the VPN is the most common method after using their provider. Users are usually not trying to hide.
We are not such a site.
Which is exactly what I said. In fact we can NEVER identify who somebody is, we can only say that different comments probably originate from the same source. Content is the key, but there are other factors such as activity times, repeated misspelling, repeated word patterns etc. Everyone does it. It all depends on a user's personal security. Somebody who keeps essentially repeating the same message may soon have used all of his usual IP addresses. And we have over a million comments to play with. We have successfully linked accounts to comments submitted using TOR. You can do it yourself. You can probably identify posts made anonymously by other people without even knowing an IP address.
I suspect that some people are using AI to rewrite their comment so that they avoid some of the traps that I have mentioned. They look like a bot instead....
As for content,:
We haven't banned TOR, ever. And you posted that with your username. See? It isn't difficult. Multiple accounts would be sock-puppeting of course.
(Score: 2) by Bentonite on Tuesday September 01, @11:30PM (1 child)
Damn, I guess I better stick with .onion's then.
I'll try it soon™ - but I'm not sure you'll want to wait that long for the results.
It is an acronym that stands for; "the onion routing", or "the onion router" or "Tor's onion routing".
The stylistic choice made from the start was that only the first letter would be capital; https://blog.pastly.net/posts/2021-02-22-tor-spelling/ [pastly.net]
Clearly I wasn't referring to this site - considering that there's an .onion available (too bad it's often down - but it's now up).
There has been free software anti-stylometry software available long before LLM's existed; https://directory.fsf.org/wiki/Anonymouth [fsf.org] but it seems some sort use LLM's instead of the real thing.
I clearly wasn't referring to this site.
It's incredible anyone would think that I have time to post with multiple accounts (I've of course been accused of sock-puppeting before over someone else's account).
(Score: 0) by Anonymous Coward on Wednesday September 02, @05:37AM
They might be onion's at your end, but they still convert to hashes when they reach the site.
(Score: 1, Troll) by Bentonite on Thursday September 03, @12:39AM (6 children)
I tested with ~10,000 requests via tor with torsocks isolate.
The results are statistically sound - there were ~1000 unique IPv4 addresses (torsocks doesn't support IPv6 sadly), which is ~⅓ of the ~3000 working exit relays; https://metrics.nothingtohide.nl/flag/exit/ [nothingtohide.nl]
The way tor works is that faster relays have more of the exit consensus and are thus are more likely to be used (some exits may have an exit policy to not including port 443, thus such relays won't ever be used for a HTTPS session over port 443).
Tor also by default changes the circuit every 10 minutes, meaning if any comments are posted within 10 minutes, the comments are send from the same IP.
You're confusing the combination of statistical and exit consensus bias, with the confirmation bias of having 2 accounts you suspect are from the same person (maybe your stylometric analysis's are often correct, but it is likely you have incorrectly correlated 2 separate people at least once), with a lack of randomness.
Regardless, it's really creepy you're assigning IP addresses to comments long term and perving with them - good thing tor makes such perving ineffective.
(Score: 0) by Anonymous Coward on Thursday September 03, @10:47AM
(Score: 2) by janrinok on Thursday September 03, @11:16AM (4 children)
It's a database. If you want to be able to view past discussions, journals, polls and comments, then some link has to be present between them. So if we want to see your previous activity ( e.g. for karma, to revoke a moderation that someone else has made on your comment, or to look at a previous discussion that you might have had), we can do so for everything since you created your account. I can do the same for my activity - all 12 years worth. If you have an account we have got to keep a record of lots of data so that we can recreate pages on demand. But it is only tied to your username. So unless you have compromised 'Bentonite' somewhere you are still 'anonymous' as far as the world is concerned.
If you do not like the idea that we use a database you can suggest a change to the staff and we can put it to a community discussion and vote. Or you are free to go elsewhere (which will also probably use a database...) I'm sure that with you programming skills you will be able to suggest a better solution and even assist in a rewrite.
As an AC has pointed out - is that how your browser works or have you written a special script to enable you to comment, moderate or whatever? If your figures are accurate you were doing at least approximately 8 connections per second over a 24 hour period. Somehow I don't believe that is a valid test or you are pulling figures out of the air to 'prove' your point. None of which disproves the fact that the connection that we see is limited to a small number of IP addresses.
(Score: 2) by janrinok on Thursday September 03, @01:28PM (1 child)
I have sent you an Admin-to-User message with some (hopefully) useful information.
You choose the entry point of TOR, but you do not control the exit point, which is all we see.
(Score: 2) by Bentonite on Friday September 04, @12:57AM
I haven't received such message, but I wouldn't bother re-sending it - I know how tor works.
(Score: 2) by Bentonite on Friday September 04, @12:51AM (1 child)
There is a difference between a normal database that stores needed information (such as comments and the username that the comments are from) and a pervert database that assigns IP addresses to comments long term (as there are only perverted reasons to do the latter).
But that doesn't matter, as anyone can get around the issue with tor.
Any browser than accesses tor, uses tor, thus testing with a script that uses torsocks is a valid test.
I tested with my server, with `torsocks --isolate wget https…` (new circuit every connection), so I didn't have to manually interface with a browser and wait 11 minutes to make the next connection (so max circuit dirtiness @10 min is reached and the circuit re-rolls).
You seem to be worse at math than me, which explains your lack of understanding of statistics.
I suggest GNU units, as that makes calculations easy;
10,000 requests over 24hr is a request every ~8 seconds;
You have: 10000/24hr
You want: sec
reciprocal conversion
* 8.64
With scripting and multiple tor instances, 8 requests/second on average would be feasible too.
(Score: 2) by janrinok on Friday September 04, @06:29AM
To disable various external attacks on the site we have to have the ability to block specific IP addresses. Most of this is done automatically and depends on how frequently the IP address is being used for abuse. Therefore there has to be a list of IP addresses along with the information relating to its current status (blocked, open, etc). This is normal for many servers on the internet.
The best way of seeing repeated abuse is by looking periodically at specific IPs of interest i.e. those which are repeatedly or frequently used. This very often identifies the source which can be blocked. Therefore the list of IPs has to be maintained over time.
Sock puppets are also sometimes identified based on their behaviour over an extended period of time, which includes the IP addresses that they use when connecting to the site. The IP information is crucial to this. In addition, various fake accounts and instances of abuse (particularly in journals) have been identified and controlled in a similar manner.
The software that we are using is based on software written in the late 1990s. At the time, computer processing power restraints (it was designed to run on 286/386 CPUs) and best practices indicated that the most efficient way to do this was to use a database and to process it when the site is not particularly busy. That is exactly what we have today.
Very few people have offered to help maintain the site software and, those that have, have had plenty to do just to keep the site running. kolie's work over the last year and a half has made the site far more reliable, although there are still areas that require attention. This is time consuming work because we do not know that there is a problem until it happens. At which point someone has to try to pin it down to a specific area of code based on the site not functioning as it should. If that is a crash where do you start looking? kolie has also improved the logging so he is able to identify some problems promptly and the rectify them. Others can only be fixed by restarting Rehash or whatever seems to be the most likely area of concern.
If you don't like the way the site works then put your money where you mouth is, step up, and start helping to (re)write the code. Don't just complain or criticise - do something positive and contribute.
(Score: 5, Insightful) by ledow on Tuesday September 01, @07:44AM (1 child)
"I don't want to be tracked, so I'm going to put all my traffic through an unknown endpoint at a 3rd party company in a foreign jurisdiction which I then link to payment details...."
3rd-party VPN is the single dumbest thing I've ever heard of.
(Score: 4, Insightful) by zocalo on Tuesday September 01, @09:57AM
3rd party VPNs are fine for all that, but if you're trying to do something a little sketchy and a least try and remain anonymous then there are free 3rd party VPN options that will do that without having to provide and legitimate details other than a disposable email address. Or, if you know what you are doing, some have crypto payment options, but that quite probably also has its own anonymisation issues since many only accept BTC.
They're tools. Like all tools their utility and efficacy depends on the task at hand and your expectations for quality of the results. The real issue is the marketing hype has led a lot of people to see all their privacy problems as a nail and a 3rd party VPN the hammer to bang it in with.
UNIX? They're not even circumcised! Savages!
(Score: 4, Interesting) by Runaway1956 on Tuesday September 01, @01:05PM
At least 3/4 of people use a VPN to avoid geofencing, and/or for file sharing. Watching your favorite Netflix episode is of far more consequence than "Who is tracking my internet activity?"
The vast majority of people don't understand that they are tracked, and when made to understand, hardly care. Only a small subset of us even has an opinion on the subject.
Is Israel tracking me with PIA? I can't be certain. The article seems to suggest they are. But, their potential tracking doesn't bother me as much as ubiquitous corporate tracking right here in the US bothers me.
I've been considering moving to Proton VPN to avoid possible Israeli tracking. I know that Switzerland has strong privacy laws, while Israel doesn't seem to have any at all.
Tradeoffs. There are always tradeoffs. This article is little more than food for thought, and may influence which VPN I use going forward. I certainly won't be signing up with some random VPN with ties to China!
I said what I said. - Sophie Cunningham
(Score: 2, Informative) by Anonymous Coward on Tuesday September 01, @03:35PM
Using a VPN is just playing the odds, but yeah, the odds are better if you don't the service from a corrupt country, like pretty much anything outside of Europe. Though I will grant its usefulness for defeating geofencing. It is impossible to verify where your data is going, or where it's coming from. Besides, no VPN can protect you from the malicious hardware recording every keystroke and sending it to Utah and/or Beijing.
(Score: 2) by DadaDoofy on Tuesday September 01, @07:03PM
There is nothing "private" about surreptitiously collecting your info. If they are selling their service as a Virtual Private Network, they are committing fraud and should held legally accountable.
If they are giving it away "free", well then, you're getting what you paid for...
(Score: 1) by Chromium_One on Tuesday September 01, @07:40PM
Of course every single VPN knows at least roughly where their users supposedly are, by proxy of requiring a user IP address to function. The next question is if they store any data from this connection past when the session is ended, what data is logged, and if the user believes any claims to the contrary.
When you live in a sick society, everything you do is wrong.
(Score: 3, Interesting) by mcgrew on Tuesday September 01, @08:14PM
Using the internet on your phone is begging for trouble. Losing your phone could be as bad as losing your wallet, or worse.
I do my commerce the old fashioned way: on a computer hard wired to the router. If I lose my phone (or it breaks or somebody steals it) all I've lost is the price of a new phone.
The "patriotic" Defense Secretary Hegseth carries an American flag in his jacket's snot rag pocket.