|
|
|
|
|
by Bender
2 days ago
|
|
If I were a governmental body I would do everything I could to keep citizens using paid VPN's and big CDN's. Money trails are easy to follow and the majority of people are just paying with their bank. It makes people feel safe and more likely to expose certain behaviors. Paid VPN's can say they do not have logs whilst having real time lawful intercept API's. A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions. Ban VPN's and people will fall back to the myriad of open source alternatives that can be a bit harder to peel back and get logs assuming any exist in the first place. This was a thing some time ago. Many of the malware and pirate groups were sharing Tinc meshes though as expected there would at times be one person in the group that would be the weakest link and expose the entire group. Expand the numbers of people doing this and the probability of a few groups using decent operational security will increase. This probably deserves it's own write-up. |
|
This is backward.
How many ISPs do you have to choose from? Only a couple because there is limited and local infrastructure. How many have business entities in your country? All of them, because it’s a physical location based business.
How many VPN providers (not counting resellers) do you have to choose from? How many are not located in your country?
Most people aren’t using VPNs to commit crimes so significant that they need to be intercepted and unmasked by global law enforcement. Most just want privacy, but if crimes are committed it’s usually piracy or something similar. If we were seeing situations like you’re thinking where police are piercing through VPNs, we’d be seeing evidence of it. Parallel construction theories aren’t going to cover everything for all of time.
You’re also underestimating the difficulty of coordinating criminal investigations across countries. It’s really hard to arrange this and legally expensive. If VPN providers were getting constant requests from countries everywhere to intercept traffic it wouldn’t be a secret. We’d be hearing stories from VPN companies advertising it loudly as one of their selling points for being located in a country which doesn’t require international cooperation.
Governments would also be making moves to block payments or connections to VPNs in those exempt countries, diverting people to their compromised VPNs.
It’s not 4D chess. Connecting to a VPN in another country isn’t completely unbreakable legally, but the reason governments are going after it is because it makes it so much harder or impossible to unmask that it interferes with goals of being able to unmask internet users doing things they don’t want.