Hacker News new | ask | show | jobs
by Bender 2 days ago
If I were a governmental body I would do everything I could to keep citizens using paid VPN's and big CDN's. Money trails are easy to follow and the majority of people are just paying with their bank. It makes people feel safe and more likely to expose certain behaviors. Paid VPN's can say they do not have logs whilst having real time lawful intercept API's. A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions.

Ban VPN's and people will fall back to the myriad of open source alternatives that can be a bit harder to peel back and get logs assuming any exist in the first place. This was a thing some time ago. Many of the malware and pirate groups were sharing Tinc meshes though as expected there would at times be one person in the group that would be the weakest link and expose the entire group. Expand the numbers of people doing this and the probability of a few groups using decent operational security will increase. This probably deserves it's own write-up.

3 comments

> A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world.

This is backward.

How many ISPs do you have to choose from? Only a couple because there is limited and local infrastructure. How many have business entities in your country? All of them, because it’s a physical location based business.

How many VPN providers (not counting resellers) do you have to choose from? How many are not located in your country?

Most people aren’t using VPNs to commit crimes so significant that they need to be intercepted and unmasked by global law enforcement. Most just want privacy, but if crimes are committed it’s usually piracy or something similar. If we were seeing situations like you’re thinking where police are piercing through VPNs, we’d be seeing evidence of it. Parallel construction theories aren’t going to cover everything for all of time.

You’re also underestimating the difficulty of coordinating criminal investigations across countries. It’s really hard to arrange this and legally expensive. If VPN providers were getting constant requests from countries everywhere to intercept traffic it wouldn’t be a secret. We’d be hearing stories from VPN companies advertising it loudly as one of their selling points for being located in a country which doesn’t require international cooperation.

Governments would also be making moves to block payments or connections to VPNs in those exempt countries, diverting people to their compromised VPNs.

It’s not 4D chess. Connecting to a VPN in another country isn’t completely unbreakable legally, but the reason governments are going after it is because it makes it so much harder or impossible to unmask that it interferes with goals of being able to unmask internet users doing things they don’t want.

Instead of backward I would say it's looking in from a different window. Both your dilemma and the one I described can both be true. I am not suggesting to not use a VPN but rather load-balance and cycle through a mesh of user-provided VPN's that do not have a money trail so that neither your local ISP nor a big juicy centralized provider have your data.

As for disclosure of people being busted I would expect gag orders, the violation and prosecution of which can in some cases be worse than whatever the crime may have been. In the USA judges can hold people for contempt.

Yes that's pretty much it. You sign to not talk about it, and the obligatory no pirating ever again clause.
Most of the big VPN companies known from advertisments all over the internet are probably honeypots of the usual countries.
Add to that that half of these companies are registered in obscure offshore locations where it is practically impossible to even find out who are the ultimate owners.
Of all possible scenarios this seems one of the least bad. Government is less likely to sell you out and they can't really use the information to prosecute you legally without revealing "oh btw we were behind that VPN", which is kind of a one time trick.
Parallel construction has been a thing for a very long time to get around this.
Not probably - most of them are confirmed.
Which ones are confirmed and where's the evidence?
Why so secretive? Share the list.
coughs in agressive nord vpn ads
if you didn't roll it yourself you need to assume that someone is snooping on you

maybe mullvad is legit but their leadership keeps leaning to dubious causes

No need to roll your own. There are many open source VPN's, proxies and much more. When dozens, hundreds or thousands of people share and forward load balance their traffic across hundreds of self hosted networks it gets a lot harder to perform attestation and attribution. The reason to cycle through many VPN/proxy networks would be the assumption that a percentage of them are vigilante owned and operated.

That's the easy part. The harder part is to encourage people to be fearless, keep their mouth shut and let their lawyers do all the talking.

by rolling your own they don't mean write a VPN from scratch, but host a VPN on a VPS.
The term "rolling your own" as it applies to the internet means writing your own code. For example, "rolling your own encryption" would mean writing your own protocols, algorithms, ciphers, hash formulas, etc...

Hosting something on someone else's servers is "server or VPS renting". Self hosting implies running something on your own servers you own and fully control.

So lets run with they mean running it on a VPS. That is still better than all the delicious eggs in one big basket but it's also risky as there is a money trail and most VPS providers can live-clone, live-migrate a VM to capture and perform forensics all memory contents without impacting performance. If going this route I would try to get one of the cheap "gaming" physical servers and try to find a way to pay that is hard to track. One can at least update the firmware, change all the IPMI accounts and lock it down a little bit.

On a bigger scale one can get their own colocation space. KimDotCom for example had a massive colo in Equinix in Ashburn, VA that ran for a very long time.

If you did roll it yourself, you definitely aren't anonymous because there is only one user of the VPN IP address.
What do you mean with "leaning to dubious causes?" I was under the impression mullvad was fine.
The blue haired are upset someone supports political views unapproved by them. It was on here some time ago and a fierce discussion.
The point of VPNs often is hiding in the mass. Rolling your own kind of defeats that purpose.
Even very basic browser fingerprinting will still identify you. The IP address is just one of many data points.
The point isn’t to hide yourself from the destination.

It’s to hide along the journey there.

Fingerprinting is usually insufficient for law enforcement.
Interesting theory. My own theory is that the big corporations want to siphon off more data from people. That is, I think, the main agenda. See android recently stating that everyone has to give up their age. Next step will be ID (though probably, in order to verify the age, one has to give up the ID anyway, so age sniffing could be called ID sniffing).
For what it's worth, two or more things can be true or even partially true. I think all options should be on the table to discuss potential mitigations. Incentives and incentive driven laws can be difficult to prove out. Probably best to just find mitigating options and controls.
The age thing is because of laws mandating it