6 ms·
Changing of ownership fundamentally resets the trust we all had in PIA, which was due to you having proven in court you deliver on what you declare. And in the
by _joe 7y ago
Changing of ownership fundamentally resets the trust we all had in PIA, which was due to you having proven in court you deliver on what you declare.
And in the VPN world, trust is fundamental.
I am still surprised you didn't see this coming.
- sneak 7y ago> And in the VPN world, trust is fundamental. Why do you say this? Isn't it generally believed that most/all large VPN services are monitored specifically by the governments of the countries in which they operate?
- icelancer 7y ago...no?
- sneak 7y agoWhy would VPN providers be excluded from national governments' internet surveillance systems? If anything, I'd think they'd get extra scrutiny.
- Razengan 7y agoHow can we verify that?
- icelancer 7y agoYou can't generally prove someone isn't beating their wife. https://en.wikipedia.org/wiki/Loaded_question https://en.wikipedia.org/wiki/Loaded_question
- Razengan 7y agoWhen the concern is our privacy and secrecy, isn’t it better to err on the side of caution than trust naively? What if it were a matter of health? Should we trust before verifying? Would it still be a “loaded” question?
- matt4077 7y agoBy that logic everyone and everything is corrupt, monitored, etc. Including the hardware you might install your own VPN node on, all messenger apps, all phone lines, the mail, and so on. Your best friends are all spies. Your bedroom is bugged. That would mean there is absolutely no way to improve your privacy and you might as well do nothing.
- ta999999171 7y agoI was with you until your second paragraph.
- Razengan 7y agoBy your logic you should trust every ad on the web, click on every flashing button, and eat or drink every thing any random stranger offers you. No? Oh is there a line?
- nurettin 7y agoVodafone runs a large vpn, and I know from the people who sell them logging services they are obligated by the governments of multiple nations to keep url logs for a number of months that vary depending on the target's information retaining laws.
- jeltz 7y agoMullvad on the other hand does not log anything at all (other than their Stripe payments where they try to keep data minimal). Is that in violation of the Swedish law? Maybe, but as long as one of the medium sized ISPs, Bahnhof, is still fighting the law in court I cannot foresee any court cases against small fry like Mullvad or any of the other Swedish VPN providers.
- RealStickman 7y agoThe difference is probably that Sweden isn't as privacy unfriendly as the USA, despite being part of the fourteen eyes programme.
- thejynxed 7y agoTo their own citizens sure, but they have had absolutely no qualms about invading the privacy of those who are not their own citizens, which is the entire point of the 'Eyes' programs.
- jeltz 7y agoI think it is more about us being culturally less friendly towards secret court orders, and with just handing over customers to the authorities without proper process. Does our sigint operations monitor Mullvad's exit and entry nodes in Sweden? Maybe, but I do not think Swedish authorities will be able to force Mullvad's staff to silently add a backdoor. I mean they have not yet managed to get Bahnhof to comply with the current law since Bahnhof argues that some EU directive makes the Swedish law illegal.
- tssva 7y agoUnlike many countries includingany European countries the US does not require logs to be kept. Also legally national security letters can not require monitoring of the contents of communications but only compel the recipient to produce existing records regarding the communications. For a VPN service that did retain logs a NSL could require them to be turned over; however, for one which doesn't there would be nothing to turn over and a NSL can't compel the collection of such information when it doesn't exist. A NSL which tried to exceed these restrictions can be fought in court.
- rasengan 7y agoI think an increase in ownership base fundamentally makes it easier to trust an entity, especially in a public company setting where transparency is a must. Rather than trusting 1/1 owner of a company you just need to trust 1/n with significant control. The original PIA group will maintain significant control.
- oefrha 7y agoThe problem with trusting 1/n is that my trust in you is compromised when you choose to associate with an unscrupulous party, so even that 1/n is no longer trustworthy. (Long time PIA subscriber who cancelled over the news of acquisition.)
- zentiggr 7y agoThis is entirely backward from actual security principles. Any increase in the number of people involved in a security related decision multiplies the chance that bad decisions/compromises will happen. Cf the definition of compartmentalization.