Tuesday, December 6, 2011

Hidemyass.com Turns into a Showmyass VPN Service: Why Jurisdiction Matters when You Choose a VPN Service?

by Lana Holy, Editor BestVPNReviews.com

In September the FBI arrested a member of the hacking organization LulzSec who was using the hidemyass.com (HMA) VPN service to hide his IP and traffic data. It is alleged in the indictment that Cody Kretsinger of Phoenix, Arizona, used the hidemyass.com VPN servers to attack Sony Pictures and eventually steal confidential data from Sony, which was released online and via Twitter. Sony claims the attack cost them over $150 million. 

The reaction on the web and in blogs has been enormous, with hackers worldwide dismayed by HMA’s VPN service apparently shopping Kretsinger to the FBI; particularly as HMA is a UK VPN service and could not have been directly ordered to do so by the Feds but via the UK courts. HMA claims that the out-of-country request made its way through the UK court system and a judge ordered HMA to release the IP information of Kretsinger, who went by the handle “recursion”. But the time line, HMA’s defense of its actions and the indictment suggest otherwise. 

At its website and TOS, HMA appears to say that it doesn’t keep logs and it doesn’t cache its users’ data, so how did this happen? HMA now defends itself by stating that they and all other VPN services know when a specific individual logs onto a server and logs off and that if a crime is committed, the HMA VPN service provider can determine who that individual is, check the originating IP and track the customer through his/her credit card or other payment details. So HMA’s claim that it doesn’t log a user’s data seems misleading. It was a marketing ploy to bring in the sheep, and now a few have been slaughtered. 

HMA defends itself at its blog: “Being able to locate abusive users is imperative for the survival of operating a VPN service, if you cannot take action to prevent abuse you risk losing server contracts with the underlying upstream providers that empower your network. Common abuse can be anything from spam to fraud, and more serious cases involve terrorism and child porn.” 

The news that this VPN service retains user details created havoc amongst hackers and outraged responses throughout the community seems to suggest that the HMA VPN service has seen its best days. 

The issue raised by HMA in its defense is actually beside the point. All VPN service providers have to survive and maintain a server network and whitelisted IPs. If all the IPs are blacklisted, the server network would be shut down and the VPN service is out of business. This part of the defense by HMA is legitimate but trivial. If there is spam or illegal torrents activity on the network, the VPN service has no choice but to shut down the offending user. But this does not mean calling in the Feds. The VPN service simply cancels the membership or subscription of the offending user and that’s that. The problem with HMA’s position is jurisdiction. HMA resides in the UK and is vulnerable to wide ranging court orders that other jurisdictions would not be affected by. So HMA’s defense is disingenuous and HMA knows that but are trying to: 

a. Claim all other VPN services are in the same boat so it does no good to leave HMA’s VPN services 

b. Ignore the main issue of jurisdiction because it is not convenient for HMA management to relocate to a more effective jurisdiction 

c. Mislead its subscribers and market a fundamentally poor product because of the Jurisdiction vulnerability. 

Further, HMA has not been altogether forthcoming about its actual jurisdiction until the current blowup. Up until now everyone that used HMA had to guess their actual jurisdiction. This lack of honesty on the part of HMA had tragic consequences. A user on a VPN service needs to know three things: 

1. What is the VPN server location he/she is on 

2. What is the country he/she is in 

3. What is the nationality and location of the management of the VPN service 

With this crucial information a VPN user can make sure that the server he is on is NEVER in the country he is in and is not in the location of the management of the VPN service; and moreover if he is doing some black activities (dissidents take note) that those activities’ target are not in the country of the management of the VPN service. Unfortunately because of HMA’s lack of forthrightness about location, the LulzSec hackers committed crimes in the UK, in the very country of HMA’s headquarters, putting the management of HMA directly in harm’s way. So the jurisdictional issue immediately killed any protection HMA could have afforded the hacking group. In this, both HMA and LulzSec were culpable if not downright stupid. 

Are there any VPN services that could have acted differently given the same circumstances? 

Yes, a VPN that manages its servers from a jurisdiction that has no treaties with the major trading groups: Europe, UK, USA, Japan, etc. If an offshore VPN had this problem, it would not respond to a similar subpoena because neither the USA nor UK would have any authority to enforce the court order. And as long as no crimes were committed in the local jurisdiction, the feds would not be able to persuade the local authorities and the offshore VPN service could thumb its nose to the foreign orders. 

Of course, to protect their server network, an off shore VPN service would still kick off abusers that download illegal films and commit spam. Strangely enough it is spam and illegal film downloads that command the most attention and is stopped worldwide irrespective of jurisdiction because VPN services cannot stay in business without a server network. No one can stay in business – Universities, companies, telcos, etc without a clean server network. 

A USA, UK or European VPN is bound to attract court orders and management will obey them or go to jail themselves. Even worse are ISPs turned VPN services like strongvpn.com and other VPNs that are hosts (convert a couple of VPS servers and start a VPN service) and are regulated by governments and ordered to log and cache data for up to seven years (no matter what is claimed by the VPN service). It is surprising that the hacker community was so naïve about HMA; but HMA did trick everyone by not revealing its actual UK jurisdiction. 

So why would you put yourself in the hands of a European or UK or USA based VPN? Just go offshore and the risk is far less because the VPN can avoid court orders; although it can’t avoid abuse reports. You won’t go to jail for downloading a movie, just kicked off the network, but all other kinds of activities cannot be targeted by law enforcement offshore because the directors of the companies are not in jurisdictions that anyone can threaten. It’s not that the offshore VPN service management is braver than HMA’s management, it’s just commercially viable for them to obtain business by the very fact that they are in the better jurisdiction and can sell the point as part of their marketing package. The HMA guys (and all VPNs like them) by definition are vulnerable because of their jurisdiction. You can’t expect directors of companies living in the UK, Europe or USA not to obey court orders. But you can expect directors of off shore companies not to comply because they are not at risk. So go offshore and be safer. My choice VPN service is vpn4all.com because it has over 30 locations, automated change IP functionality, a straight forward TOS and Privacy Policy, and very good technology for avoiding restrictive firewalls. Something they call Point to Point. What I don’t like about vpn4all.com is their live support which is not that helpful. The email support is fine and if you get into trouble they help out with a teamviewer session. Altogether it’s the only solid offshore VPN service but because of their location in the Seychelles, that makes them outstanding in my view.

0 Responses to “Hidemyass.com Turns into a Showmyass VPN Service: Why Jurisdiction Matters when You Choose a VPN Service?”

Post a Comment

Your comments Will Help Me To Improve...

All Rights Reserved Geek OddBlogger | Maintained by OddBlogger