Software

Databases

Seven 'no log' VPN providers accused of leaking – yup, you guessed it – 1.2TB of user logs onto the internet

Maybe it was the old Lionel Hutz play: 'No-logging VPN? I meant, No! Logging VPN!'


A string of "zero logging" VPN providers have some explaining to do after more than a terabyte of user logs were found on their servers unprotected and facing the public internet.

This data, we are told, included in at least some cases clear-text passwords, personal information, and lists of websites visited, all for anyone to stumble upon.

It all came to light this week after Comparitech's Bob Diachenko spotted 894GB of records in an unsecured Elasticsearch cluster that belonged to UFO VPN.

The silo contained streams of log entries as netizens connected to UFO's service: this information included what appeared to be account passwords in plain text, VPN session secrets and tokens, IP addresses of users' devices and the VPN servers they connected to, connection timestamps, location information, device characteristics and OS versions, and web domains from which ads were injected into the browsers of UFO's free-tier users.

UFO stated in bold in its privacy policy: "We do not track user activities outside of our site, nor do we track the website browsing or connection activities of users who are using our Services." Yet it appears it was at least logging connections to its service – and in a system anyone could access if they could find it.

More than 20 million entries were added a day to the logs, according to Comparitech, and UFO happens to boast on its website it has 20 million users. Diachenko said he alerted the provider to the misconfiguration on July 1, the day he found the unprotected database, and heard nothing back.

Oh, it gets worse

A few days later, on July 5, the data silo was separately discovered by Noam Rotem's team at VPNmentor, and it became clear the security blunder went well beyond UFO. It appears seven Hong-Kong-based VPN providers – UFO VPN, FAST VPN, Free VPN, Super VPN, Flash VPN, Secure VPN, and Rabbit VPN – all share a common entity, which provides a white-labelled VPN service.

And they were all leaking data onto the internet from that unsecured Elasticsearch cluster, VPNmentor reported. Altogether, some 1.2TB of data was sitting out in the open, totaling 1,083,997,361 log entries, many featuring highly sensitive information, it is said.

This exposed cluster contained, we're told, at least some records of websites visited, connection logs, people's names, subscribers' email and home addresses, plain-text passwords, Bitcoin and Paypal payment information, messages to support desks, device specifications, and account info.

"Each of these VPNs claims that their services are 'no-log' VPNs, which means that they don’t record any user activity on their respective apps," Rotem's team said. "However, we found multiple instances of internet activity logs on their shared server. This was in addition to the personally identifiable information, which included email addresses, clear text passwords, IP addresses, home addresses, phone models, device ID, and other technical details."

Using a free VPN? Why not skip the middleman and just send your data to President Xi?

READ MORE

VPNmentor created an account with one of the providers, and spotted that new account in the logs, specifically "an email address, location, IP address, device, and the servers we connected to." VPNmentor alerted the providers involved to get the cluster removed from public view, as well as HK-CERT, though it seems no action was taken to immediately rectify the situation.

On July 14, Diachenko, we're told, warned UFO VPN's hosting provider that the database was unsecured, and the next day, it all disappeared from sight, some 18 days after the system appeared in search engine Shodan.io.

UFO VPN, for one, blamed the coronavirus for preventing its staff from securing the database's networking. "Due to personnel changes caused by COVID-19, we’ve not found bugs in server firewall rules immediately, which will lead to the potential risk of being hacked," it said in a statement. "And now it has been fixed."

UFO also claimed its logs were kept for traffic-performance monitoring only, and were anonymized even though some of the log entries seemingly contained people's IP addresses, and account tokens and secrets. So that's going from "no logs" to "OK, some logs," we note.

The provider also insisted there were no clear-text account passwords in the logs, so that data must be something else, such as a session token, and that "some feedback sent by users themselves contain email addresses, however, the number is very small, less than one per cent of our users."

Comparitech and VPNmentor disagreed, with the latter saying UFO's statement was "incorrect." "Based on some sample data, we do not believe this data to be anonymous," Comparitech's Paul Bischoff added. "We recommend UFO VPN users change their passwords immediately, and the same goes for any other accounts that share the same password."

Finally, it's worth mentioning UFO's software is developed by Dreamfii HK Limited, which receives all the aforementioned VPN providers' sales transactions, and appears to ultimately control those VPN brands. Dreamfii could not be reached for comment.

'Widespread'

Kenneth White, a security researcher, told us the misconfiguration revealed just how dishonest some VPN providers can be, and that netizens should dose up on more than a bit of skepticism, and not fall for the marketing hype, when selecting an organization through which they'll tunnel their internet traffic.

"It's disappointing but honestly not terribly surprising to see yet another breach from a popular commercial VPN service," White, who is also security principal at MongoDB, told The Reg in a personal capacity.

"In this case, the effects are even more widespread because of a common industry practice called white labeling, in which smaller VPN providers rebrand a larger service and piggy back on their network, infrastructure, and software. In this case, there seem to be at least seven VPN providers whose customer data was leaked, completely contrary to their marketing claims of 'no logging.'"

"The vast majority of companies that operate these services use patently false marketing, have very murky corporate provenance, and in some cases are literally run by convicted financial crime felons, so of course they will claim 'strong privacy and security' protections when in fact they offer neither," he continued.

"The few providers that have undergone some sort of third-party audit are at best able to show a narrow point-in-time snapshot of some portion of their technology. It's well known in the industry that highly placed search-engine ad campaigns for VPN services routinely fetch upwards of seven figures. The average consumer is simply outmatched, and these companies prey on people's fears. It's a disgrace."

White was also scathing on Twitter:

The Register suggests savvy readers wishing to encapsulate at least part of their traffic may want to roll their own VPNs using Trail of Bits' Algo, Google's Outline, or WireGuard, all of which are open source.

Or use a VPN provider, and build into your threat model the fact it can see everything your ISP would otherwise be able to see. ®

Send us news
71 Comments
Get our Weekly newsletter

Global chip shortage probably won't let up until 2023, warns TSMC: CEO 'still expects capacity to tighten more'

Automotive supply is a 'top priority', analysts told

TSMC this week warned the ongoing global shortage of semiconductor supplies will probably continue throughout this year and next.

CEO C.C Wei confirmed to analysts on the chip manufacturing giant's financial earnings call that it will invest $100bn in building more manufacturing plants and hiring thousands of engineers to step up production and capacity rates, though it's going to take time.

"To install the capacity, it won't be available until 2023," Wei said. "This year and next year I still expect capacity to tighten more. In 2023, I hope that we can offer more capacity to support our customers, and in time start to see the supply chain's tightening released a little bit."

Continue reading

Walmart’s Indian outpost FlipKart picks industrial giant’s India-US joint venture for Chennai data center

E-commerce wing to also get a huge fulfillment center for Q3 2022

Indian e-commerce company FlipKart, majority owned by US behemoth Walmart, has chosen AdaniConneX to build its third data center in Chennai. It is expected to be one of the largest private cloud deployments in the country,

AdaniConneX is a joint venture between Adani Enterprises, one of India’s largest multi-infrastructure organizations, and global data center operator EdgeConneX. The two formed a partnership in February to develop and operate both full scale and edge data centers throughout India, largely powered by renewable energy. The joint venture aims to develop 1GW of data center capacity over the next 10 years.

Meanwhile, affiliate Adani Logistics Limited will build and lease FlipKart an almost 50,000-square-metre fulfillment center in its Mumbai logistics hub. The facility, slated for operation in the third quarter of next year, will potentially store up to 10 million units of inventory and create about 2,500 jobs.

Continue reading

Mobile app security standard for IoT, VPNs proposed by group backed by Big Tech

ioXt Alliance aims to bring 'transparency and visibility'

On Thursday the ioXt Alliance, an Internet of Things (IoT) security trade group backed by some of the biggest names in the business, introduced a set of baseline standards for mobile apps, in the hope that IoT security may someday be a bit less of a dumpster fire.

The announcement of the new Mobile Application Profile [PDF], a certification program covering best practices and requirements to keep mobile apps safer than the low bar of vendor discretion, comes from the collaboration of more than 20 ioXt member companies like Amazon, Comcast, Google, and others.

"This security baseline helps mitigate against common threats and reduces the probability of significant vulnerabilities," said Brooke Davis and Eugene Liderman, from Google's Android security and privacy team, in a blog post.

Continue reading

Zorin OS 16 beta claims largest built-in app library 'of any open source desktop ever'

Linux for Windows switchers: smooth user experience, if users steer clear of Windows apps on Wine

Zorin OS 16 Linux has moved into beta, promising improved performance and a more extensive application Store covering Flathub and Snap as well as old-style repositories.

Zorin is a Linux distribution aimed at switchers from Windows or Mac, and endeavours to offer a polished user experience and a minimum of fuss. It is offered in both free and commercial versions, with the paid-for Ultimate Edition priced at £39 ($53), and free Core, Lite and Education editions.

The Lite edition uses the XFCE minimalist desktop, while the others have a custom GNOME-based desktop GUI. The extras in the Ultimate edition are additional desktop layouts, one imitating macOS, additional bundled applications and games, and installation support. A note on “why does it cost” puts the emphasis on supporting the project rather than the value to the user.

Continue reading

Ever wondered what it's like working for Microsoft? Leaked survey shines a light on how those at the code coalface feel

Lowest scoring sections were 'performance' and 'deal', but it looks like it could be a lot worse

You aren't the only one feeling like you're giving more than you're getting from your employer – a chunk of Microsofties are of the same opnion.

A leaked employee survey seen by Business Insider gives an insight into what it is like to toil within the walls of Redmond.

Microsoft itself did not wish to comment on the poll, it being leaked and all, but the company conducts such surveys annually.

Continue reading

Deno 1.9 update includes proposal cold-shouldered in February, now hyped as '3x faster' performance bump

Plus HTTP/2 web server written in Rust

Deno 1.9 hit the streets this week touting new features including an HTTP/2 server written in Rust.

An alternative to Node.js, Deno is a runtime for TypeScript and JavaScript on the server, based on the V8 JavaScript engine also used by Google Chrome. It was created by the original developer of Node.js, Ryan Dahl, to improve on what he saw as mistakes in Node.js. A clue to the name may be found in the code "node".split("").sort().join("");.

Deno has always provided an embedded web server, std/http, written in TypeScript. According to the Deno team, "std/http's major down side is that it is HTTP/1.1 only – with no easy path forward towards HTTP/2." The solution was to adapt Hyper, an HTTP/2 server coded in Rust, to become Deno's web server. Deno itself was built in Rust. The new server "improves hello-world throughput by 48 per cent," according to the team, though the API is not yet stable.

Continue reading

Oracle pumps $1.2bn into Nashville campus as search for southern comfort goes on

Mayor thrilled with $175m up front for Guitar Town infrastructure projects

Oracle is continuing its journey into the heart of the southern United States with a $1.2bn investment in a new campus in Nashville, set to create 8,500 new jobs.

Big Red's new base in Tennessee is set to include 1.2 million square feet of office space along the East Bank of the Cumberland River.

"We are thrilled that Oracle is ready to make a billion-dollar bet on Nashville," Mayor John Cooper said in a news release. "Oracle will bring a record number of high-paying jobs to Nashville and they will pay upfront all the city's infrastructure costs. This is a huge win for our city."

Continue reading

Pigeon fanciers in a flap over Brexit quarantine flock-up, seek exemption from EU laws

It won't fly. 'We are collateral damage'

Things have taken a tern for the worse for the Royal Pigeon Racing Association, which is seeking an exemption from the EU for a law that takes flight tomorrow, so their birds can participate in a long distance European race.

In the trans-Channel races, the UK flying rats birds are released from France, after which they wing it across the water in an attempt to beat each other and previous speed records. The new EU animal control regulation [PDF], which comes into effect on 16 April, is in-heron-tly a problem for the fanciers because their feathered friends won't be in beak condition to participate. Under the hawk-ward new rule, the birds would need to be quarantined in France for weeks before the race. Participants feel they've been flocked over as their frequent fliers need daily exercise to stay in shape.

Prior to Brexit, Alan Todd, a member of Winlaton Homing Society in Gateshead, explained to the BBC: "They would leave here on Thursday, get to France on Friday and race back to Britain on Saturday."

Continue reading

It was Russia wot did it: SolarWinds hack was done by Kremlin's APT29 crew, say UK and US

And Positive Technologies has been slapped with American sanctions

Russia’s infamous APT 29, aka Cozy Bear, was behind the SolarWinds Orion attack, the US and UK governments said today as America slapped sanctions on Russian infosec companies as well as expelling diplomats from that country’s US embassy.

One of the sanctioned companies is Positive Technologies, familiar in the West for, among other things, in-depth research exposing vulnerabilities in Intel’s hardware security architecture.

Formal attribution of the SolarWind hacks, echoing tentative findings made by Kaspersky Lab, came in a US Treasury Department statement issued this afternoon.

Continue reading

University of Hertfordshire pulls the plug on, well, everything after cyber attack

Another UK institution topples at the hands of miscreants

The University of Hertfordshire has fallen victim to a cyber attack that has resulted in the establishment pulling all its systems offline to deal with the situation.

The result has been a suspension of all online teaching today and in-person, on-campus teaching only happening if computer access is not required. The university's Wi-Fi is down and there is no student access (either in-person or remote) to its computer facilities.

A look at the British university's status page makes for grim reading. Last updated 12 hours ago (at time of writing) even cloud services, such as Office 365, are disrupted. VPN access and data storage are also offline as well as email and the University Business Systems.

Continue reading

Last chance to grab an iPhone Mini as savvy analyst reckons Apple will scrap it next year

Incoming iPhone 13 could be final slimline version

All good things come to an end. And pointless things, too, with Apple reportedly planning to discontinue the iPhone Mini after the next iteration expected later this year.

The warning came from Ming-Chi Kuo, a financial analyst with a track record for correctly predicting Apple's product roadmap. Per his sources, Apple plans to launch four handsets in 2022: two each with 6.1 inches of screen real estate, and a further two measuring 6.7 inches.

The iPhone Mini, with its diminutive 5.4-inch display, was conspicuously absent from his research notes. But this might not be much of a surprise. Although Apple hasn't offered a model-by-model sales breakdown of the iPhone 12, it is believed that consumer appetite for the smaller iPhone 12 Mini was tepid at best. We've asked analysts to share shipment data.

Continue reading