Hacker News new | ask | show | jobs
by AndrewThrowaway 1617 days ago
It is surprising for me how people can't imagine a scenario where:

Some government agency (KGB, FBI, CSI, whatever) comes to VPN, secure mail, etc provider; Informs that some "enemy of the state" is using the service; Demands to overtake the service, install some software etc; Or else CEO of the service is also an "enemy of the state".

From this moment this service is not only "not secure" but directly allows access to your email data, leaks all the keys, passwords, browsing history, logs whatever they want etc.

Yeah VPN will allow you cheat Netflix. Never trust any service to not comply to some government agency.

3 comments

Most people can imagine that scenario. The problem is that there is literally no other alternative. You either use a VPN (which _might_ be compromised), or you don't (in which case your traffic is even less protected).
The only real way out is quitting the country iirc like lavabit. Though even then it's either too late or not in accordance with shareholders for most companies.
Hm, how does the VPN leak email data, passwords etc? Those things should never be passed in cleartext anyway, so I don't see how they can intercept anything except the metadata of what IP addresses you connect you, provided they aren't MITMing SSL somehow.