*** Note that Proton has a commercial interest in VPNs. This may be biased reporting ***
https://www.cnet.com/tech/services-and-software/proton-vpn-report-location-tracking-privacy/
With a fast VPN, your speed loss will be virtually unnoticeable.
Using a virtual private network is a surefire way to keep your information private when browsing the internet. But a new report from Proton, released on Wednesday, exposes some major holes in that concept.
A VPN is a tool that encrypts your internet behavior and hides your IP address and physical location, with the goal of keeping your identity and identifying information secure. But 64 of the VPN apps downloaded in the US, Proton found, are owned by Chinese companies and contain trackers that collect all sorts of user information, including device IDs, network information, device models and mobile carrier data.
And 25% of the apps in question were found to actively track your location.
In June alone, these apps were downloaded over 13 million times.
Narrowing down the numbers further, Proton found that 31 of those Chinese-owned VPNs use shell companies registered in jurisdictions such as Singapore, Hong Kong and the UK to further hide their identities.
An authoritarian government like China’s could use this information to track a person’s location. So if a public official, someone in law enforcement, a journalist or even someone attending a protest was using one of these VPNs for safety, this flaw would expose them to potential threats.
It should be clear that China isn’t the only country where companies harvest the data these apps collect, but it’s near the top of the list. Israel, Russia and the Five Eyes countries — Australia, Canada, New Zealand, the UK and the US — all have companies collecting tracking data from millions of people.
Transparency is a big issue here, with a load of bad VPN apps being readily available for download through Apple and Google. Proton’s report points out that both companies require developers to submit their own paperwork to verify their apps, with little verification (and no independent audits) being done on Apple’s or Google’s part. Apple and Google didn’t immediately respond to requests for comment.
This lack of guardrails in the verification process makes it hard to decipher which virtual private network apps protect your privacy and do what their policies promise and which are virtually doing the opposite.
“Proton's report is yet another example of why it's so important to know who's behind your VPN and what data they're collecting,” CNET Senior Writer Attila Tomaschek said. “It's also another reminder that just because a VPN app is popular in Apple's or Google's app marketplaces, it doesn't necessarily mean that the VPN app is safe to use.”
If you’re looking for a VPN, Tomaschek points to VPNs like Proton and ExpressVPN, which regularly rank near the top of CNET’s VPN recommendations. Each virtual private network is put through a rigorous testing process that includes a thorough examination of the app’s privacy policy, transparency reports, audits, corporate structure and legal jurisdiction.
When all else fails, avoid any VPN that is murky about any of those key principles. “Instead, opt for a trustworthy VPN that is crystal clear about where it’s based, who’s behind it and how it protects user privacy,” Tomaschek said.
(Score: 5, Informative) by janrinok on Tuesday September 01, @03:16AM (16 children)
That gives you some privacy, but unfortunately it has other weaknesses. Imagine if you will that you are a user of a fictitious site that consists of 2 people. One always uses TOR while the other doesn't. You are immediately recognisable by your use of TOR. TOR is useful when there is a lot of traffic but on a site where only a very small proportion of users are hiding behind it becomes another almost unique feature of the user. TOR gives you anonymity but nothing more.
TOR users imagine that they are buried alongside thousands of other communications - which they are for various intermediate 'skips'. But TOR exit nodes are publicised very well and the same users are, for some reason or other, only using a very small subset of those exit nodes. I don't know why this should be the case. So it is impossible to identify who you are in meat-space (unless perhaps you are one of the very big players!) but it does provide another element that helps to fingerprint connections. When combined with other data it would allow a user's participation to a small site to be linked together.
(Score: 4, Informative) by Bentonite on Tuesday September 01, @08:08AM (15 children)
It was never "TOR", the network is Tor and the software is tor.
For users connecting without Tor, they cycle between a handful of IP addresses at most - making that a far more unique feature of the user.
Also, if a business or the government asks the ISP for the address of the user assigned an IP, the ISP will usually tell them.
There also exists surveillance malware for tracking devices, distributed as libraries for cr…apps, which reports the current GPS location and the current IP address, which goes right into GeoIP databases.
As a result, if a tracking device has ever connected to your network, you should assume that your IP addresses are now assigned to a location in some GeoIP database and that any websites you browse could likely work out your address, just from your IP.
With Tor, you cycle between many different IP's - over time you have a pool the size of all the exit nodes.
If there are 2 or more users that use Tor, the site cannot uniquely identify either user without more information and the more Tor users, the bigger the anonymity set gets.
Tor is now well known, but small sites sometimes still don't even know what Tor is and don't care until some jerk decides to use Tor (some of which who proceed to see 1000 normal users using Tor and 1 jerk and decide to ban Tor - rather than dropping the false assumption that 1 IP address == 1 person and putting certain parts of the site between accounts instead).
While by default a session uses a limited subset of exit nodes, you can regularly change sessions, thus getting a new subset, or modify the software to use all the exit nodes randomly.
(Score: 4, Informative) by janrinok on Tuesday September 01, @02:29PM (14 children)
If what you say is true, then statistically you shouldn't use the same exit node often. But it is not true - it is what everyone expects and it is what everyone was told would happen, but it is not what happens in actual fact. Many TOR users in our experience are limited to about a dozen or so different IP addresses. As I said, I do not know why this should be. It is especially true of anyone using 'Private' windows. Tor-Browser is better as long as you regularly request a new route.
As an example your parent IP address has been used 28 times in recent months and your grandfather post 24 times. That doesn't seem very random to me, and looking at all of your posts you have used only a handful of the published exit nodes.
TOR was originally an abbreviation of The Onion Routing. Abbreviations are usually reported in capital letters, just like NASA and NATO used to be. Now people get lazy and write Nasa and Nato, and they renamed the network Tor. The alpha version of Tor, developed by Syverson and computer scientists Roger Dingledine and Nick Mathewson and then called The Onion Routing project. it might be trendy to use 'Tor' now but it wasn't originally like that. That's the problem with getting old. But I can see little to be gained by me nit-picking and as long as we both know what the other is talking about it doesn't seem that important.
By all means try it for yourself. Create a mini-server and keep connecting to it via TOR, say once an hour. Let me know the results. The relatively few TOR users on this site do not have a wide dispersion of IP addresses as individuals, but different users have different sets in some cases. The majority of users on this site use neither TOR nor a VPN, but the VPN is the most common method after using their provider. Users are usually not trying to hide.
We are not such a site.
Which is exactly what I said. In fact we can NEVER identify who somebody is, we can only say that different comments probably originate from the same source. Content is the key, but there are other factors such as activity times, repeated misspelling, repeated word patterns etc. Everyone does it. It all depends on a user's personal security. Somebody who keeps essentially repeating the same message may soon have used all of his usual IP addresses. And we have over a million comments to play with. We have successfully linked accounts to comments submitted using TOR. You can do it yourself. You can probably identify posts made anonymously by other people without even knowing an IP address.
I suspect that some people are using AI to rewrite their comment so that they avoid some of the traps that I have mentioned. They look like a bot instead....
As for content,:
We haven't banned TOR, ever. And you posted that with your username. See? It isn't difficult. Multiple accounts would be sock-puppeting of course.
(Score: 2) by Bentonite on Tuesday September 01, @11:30PM (1 child)
Damn, I guess I better stick with .onion's then.
I'll try it soon™ - but I'm not sure you'll want to wait that long for the results.
It is an acronym that stands for; "the onion routing", or "the onion router" or "Tor's onion routing".
The stylistic choice made from the start was that only the first letter would be capital; https://blog.pastly.net/posts/2021-02-22-tor-spelling/ [pastly.net]
Clearly I wasn't referring to this site - considering that there's an .onion available (too bad it's often down - but it's now up).
There has been free software anti-stylometry software available long before LLM's existed; https://directory.fsf.org/wiki/Anonymouth [fsf.org] but it seems some sort use LLM's instead of the real thing.
I clearly wasn't referring to this site.
It's incredible anyone would think that I have time to post with multiple accounts (I've of course been accused of sock-puppeting before over someone else's account).
(Score: 0) by Anonymous Coward on Wednesday September 02, @05:37AM
They might be onion's at your end, but they still convert to hashes when they reach the site.
(Score: 1, Troll) by Bentonite on Thursday September 03, @12:39AM (11 children)
I tested with ~10,000 requests via tor with torsocks isolate.
The results are statistically sound - there were ~1000 unique IPv4 addresses (torsocks doesn't support IPv6 sadly), which is ~⅓ of the ~3000 working exit relays; https://metrics.nothingtohide.nl/flag/exit/ [nothingtohide.nl]
The way tor works is that faster relays have more of the exit consensus and are thus are more likely to be used (some exits may have an exit policy to not including port 443, thus such relays won't ever be used for a HTTPS session over port 443).
Tor also by default changes the circuit every 10 minutes, meaning if any comments are posted within 10 minutes, the comments are send from the same IP.
You're confusing the combination of statistical and exit consensus bias, with the confirmation bias of having 2 accounts you suspect are from the same person (maybe your stylometric analysis's are often correct, but it is likely you have incorrectly correlated 2 separate people at least once), with a lack of randomness.
Regardless, it's really creepy you're assigning IP addresses to comments long term and perving with them - good thing tor makes such perving ineffective.
(Score: 0) by Anonymous Coward on Thursday September 03, @10:47AM
(Score: 3, Interesting) by janrinok on Thursday September 03, @11:16AM (9 children)
It's a database. If you want to be able to view past discussions, journals, polls and comments, then some link has to be present between them. So if we want to see your previous activity ( e.g. for karma, to revoke a moderation that someone else has made on your comment, or to look at a previous discussion that you might have had), we can do so for everything since you created your account. I can do the same for my activity - all 12 years worth. If you have an account we have got to keep a record of lots of data so that we can recreate pages on demand. But it is only tied to your username. So unless you have compromised 'Bentonite' somewhere you are still 'anonymous' as far as the world is concerned.
If you do not like the idea that we use a database you can suggest a change to the staff and we can put it to a community discussion and vote. Or you are free to go elsewhere (which will also probably use a database...) I'm sure that with you programming skills you will be able to suggest a better solution and even assist in a rewrite.
As an AC has pointed out - is that how your browser works or have you written a special script to enable you to comment, moderate or whatever? If your figures are accurate you were doing at least approximately 8 connections per second over a 24 hour period. Somehow I don't believe that is a valid test or you are pulling figures out of the air to 'prove' your point. None of which disproves the fact that the connection that we see is limited to a small number of IP addresses.
(Score: 2) by janrinok on Thursday September 03, @01:28PM (1 child)
I have sent you an Admin-to-User message with some (hopefully) useful information.
You choose the entry point of TOR, but you do not control the exit point, which is all we see.
(Score: 2) by Bentonite on Friday September 04, @12:57AM
I haven't received such message, but I wouldn't bother re-sending it - I know how tor works.
(Score: 2) by Bentonite on Friday September 04, @12:51AM (6 children)
There is a difference between a normal database that stores needed information (such as comments and the username that the comments are from) and a pervert database that assigns IP addresses to comments long term (as there are only perverted reasons to do the latter).
But that doesn't matter, as anyone can get around the issue with tor.
Any browser than accesses tor, uses tor, thus testing with a script that uses torsocks is a valid test.
I tested with my server, with `torsocks --isolate wget https…` (new circuit every connection), so I didn't have to manually interface with a browser and wait 11 minutes to make the next connection (so max circuit dirtiness @10 min is reached and the circuit re-rolls).
You seem to be worse at math than me, which explains your lack of understanding of statistics.
I suggest GNU units, as that makes calculations easy;
10,000 requests over 24hr is a request every ~8 seconds;
You have: 10000/24hr
You want: sec
reciprocal conversion
* 8.64
With scripting and multiple tor instances, 8 requests/second on average would be feasible too.
(Score: 2) by janrinok on Friday September 04, @06:29AM
To disable various external attacks on the site we have to have the ability to block specific IP addresses. Most of this is done automatically and depends on how frequently the IP address is being used for abuse. Therefore there has to be a list of IP addresses along with the information relating to its current status (blocked, open, etc). This is normal for many servers on the internet.
The best way of seeing repeated abuse is by looking periodically at specific IPs of interest i.e. those which are repeatedly or frequently used. This very often identifies the source which can be blocked. Therefore the list of IPs has to be maintained over time.
Sock puppets are also sometimes identified based on their behaviour over an extended period of time, which includes the IP addresses that they use when connecting to the site. The IP information is crucial to this. In addition, various fake accounts and instances of abuse (particularly in journals) have been identified and controlled in a similar manner.
The software that we are using is based on software written in the late 1990s. At the time, computer processing power restraints (it was designed to run on 286/386 CPUs) and best practices indicated that the most efficient way to do this was to use a database and to process it when the site is not particularly busy. That is exactly what we have today.
Very few people have offered to help maintain the site software and, those that have, have had plenty to do just to keep the site running. kolie's work over the last year and a half has made the site far more reliable, although there are still areas that require attention. This is time consuming work because we do not know that there is a problem until it happens. At which point someone has to try to pin it down to a specific area of code based on the site not functioning as it should. If that is a crash where do you start looking? kolie has also improved the logging so he is able to identify some problems promptly and the rectify them. Others can only be fixed by restarting Rehash or whatever seems to be the most likely area of concern.
If you don't like the way the site works then put your money where you mouth is, step up, and start helping to (re)write the code. Don't just complain or criticise - do something positive and contribute.
(Score: 2, Interesting) by day of the dalek on Saturday September 05, @02:32AM (4 children)
I have discussed this issue many times over with the staff. The fact is, there is a script, daily_forget.pl [github.com] that is part of Rehash and hasn't been modified in 12 years. It runs every day and purges the IP and subnet hashes from comments that are older than a certain date. I do not know the exact configuration and how old comments have to be in order to have the hashes purged, but multiple staff members have told me at various times that this script does run.
I know for a fact that the first five hex digits of IP and subject hashes are shown to people with editor privileges (SecLev >= 100) for every comment that has the hashes recorded. After awhile, I'm sure staff notice patters that tend to recur, and they learn where a few of the hashes originate from. I never wanted to look at the hashes, so I almost exclusively browsed without logging in for the couple of weeks I had admin access. Then I just walked away from the editor training, and my access was properly revoked. I never looked to see if hashes were still recorded for old comments because I just didn't want to see hashes and was logged out as much as possible. But like I said, multiple staff members have told me that daily_forget.pl does run, and it's been active on this site for a long time.
So I'm not seeing evidence of the "pervert database" that you claim exists. And there's also a valid reason to track IP and subnet hashes for a window of time, so people can't easily mod up their own AC or sock puppet comments.
I've had many discussions with kolie about this over email. He's assured me that the hashes do get purged periodically, and that SN has functioned this way for a long time. I have no reason to believe kolie has been anything other than truthful with me in our interactions, so I believe him.
I've criticized the site many times and argued about this frequently in the journals. I know I've pissed off janrinok quite a few times, and he's not been very happy with me on many occasions. So I have asked the tough questions, and I have zero reason to implicitly defend the staff. In fact, they'd probably tell you that I've frequently been an asshole over email about issues just like this. But I do care about the facts, and all the evidence I've seen says that Rehash contains the functionality to remove old hashes, and that this functionality is used on SN.
Where's your evidence for the "pervert database"?
Stay thirsty, my friends.
(Score: 2) by Bentonite on Saturday September 05, @03:41AM
I was writing generally about databases that store things, not any specific one.
I am pleased that IP's do get purged eventually and aren't kept around forever.
(Score: 2) by janrinok on Saturday September 05, @06:58AM (2 children)
You might be conflating 2 entirely different issues.
Firstly there is the link from comments to their originating IPs which is only displayed to authorised staff.
Secondly, there are the lists of IP addresses themselves which have several functions, including protecting the site from various attacks (DDoS etc), some of which are automated. (As an analogy, many people use Fail2Ban to protect themselves from some attacks) They go back to the very start of the site. Removing them is likely to cause all sorts of problems. It would probably not be a trivial task. Reproducing older page content would not be possible.
I have checked journals of mine and those of "day of the dalek" and can confirm that the software is functioning as stated.
The links from a comment to its IPs are removed after a period of time. This duration is important when investigating moderation abuse, sock puppet activity etc. The link from IPs to comments, moderations, or whatever remains in perpetuity. The requirement was to remove the link from comments to IP addresses after a period of time so that they are not displayed unnecessarily. That has been done.
The links can only ever be seen by someone with the appropriate privileges. If the database existed within the EU it would have to be declared (but its contents would not be viewed) and the duration that data was kept would have to be justified. The US has no equivalent restrictions.
(Score: 1) by day of the dalek on Saturday September 05, @08:58AM (1 child)
What SN does is above my pay grade of $0. So I don't know the specifics of this.
But I am trying to get better privacy protections in my state advocating for this in the legislature. One of the benefits of volunteering to help with campaigns is getting to share my concerns with people who may well be elected in November. While I don't much like Flock cameras, I've been telling elected officials and people running for office that there are even much bigger risks from other businesses like data brokers.
Last year, my identity got stolen, a fraudulent financial account was opened in my name, and I didn't find out until many months later when debt collectors started calling. Despite federal laws to know your customer, the financial institution never requested an ID, and there wasn't any sort of live selfie or other verification. The phone number and email address used weren't mine. There appears to have been no employment verification. They never checked any of the major credit bureaus. Despite the many red flags, they made virtually zero effort to verify the person's identity before letting someone enter in my name, address, DOB, and SSN online, and open a fraudulent account in my name.
When I found out and contested it, the financial institution decided I wasn't liable for the charges, and that manual approval would be needed if the account was used to apply for any other products from the institution. Their response implies that they never even bothered to disable and close the fraudulent account. Since this financial institution is known to sell customer information to data brokers, they may well have shared my name and address along with the attacker's phone number and email address. And that means a criminal's contact information gets mixed in with my real data, and that gets sold to other data brokers. That potentially puts me at risk if I need to have something like a background check done later.
If the account is still open, which I believe it is, and a second attacker managed to access it, they could presumably get personal information like my SSN and steal my identity again. This financial institution already had a massive data breach a few years ago. I never gave them my personal information, so they have no right to it, But because a criminal provided it to them, I believe my personal data is sitting on their servers where it can be misused or stolen again. Let's just say I'm already taking action to hold the financial institution accountable, and I expect to find out if they're going to be cooperative within the next few weeks.
You'd better believe I'm pissed off about the lack of regulations to protect my data. I have zero confidence in the Congress to do a damn thing. So the next time the state legislature is in session, you can count on me sharing my story to anyone who will listen, and I'll be pushing for bills to be introduced that include some very strict privacy regulations. The financial institution is an out-of-state business, so you'd better believe I'll be pushing for any new laws to apply to anyone handing the personal data of any resident of my state.
Perhaps I'll cross-post this in the poll and hope it doesn't get modded as spam.
Stay thirsty, my friends.
(Score: 3, Funny) by janrinok on Saturday September 05, @11:13AM
That is exactly the same pay grade that all SN staff are on too! All pay rises are based on a percentage of our current pay :)