Seven VPN firms claiming No Logs leaks 1.2TB of data and 20M user logs

upnorth

Level 68
Thread author
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,458
The VPN company in the discussion is a Hong Kong-based UFO VPN owned by Dreamfii HK Limited.

Perhaps, the most ironic moments in the cybersecurity world occur when those who promise to protect your online privacy cannot guard their own turf. We’ve seen this happen from time to time with security firms getting hacked themselves. Another similar case has emerged recently when the database of a Hong Kong-based VPN provider called UFO VPN was exposed with more than 20 million users logs. Discovered by researchers from Comparitech on July 1st, 2020; the exposure occurred due to the database hosted on an Elasticsearch cluster being left without any password.

Worth 894 GB, the data allegedly included plaintext passwords, IP addresses, timestamps of user connections, session tokens, information of the device, and OS being used along with geographical information in the form of tags. The implications of this are pretty dangerous in that not only user accounts are at risk of being taken over by malicious actors but users can also be tracked online. Furthermore, using the session tokens, any encrypted data that someone gains access to could also be decrypted rendering the entire concept of encryption useless in this scenario.
 

upnorth

Level 68
Thread author
Verified
Top Poster
Malware Hunter
Well-known
Jul 27, 2015
5,458

blackice

Level 39
Verified
Top Poster
Well-known
Apr 1, 2019
2,868

klepto

Level 2
Jun 14, 2020
77
TBH, I don't even know what is the alternative for a vpn would be. Possibly DoH and hope https keeps you safe?
 
  • Like
Reactions: Dave Russo

Fuzzy_Bunny

Level 4
Sep 19, 2019
148
If you talk about privacy disconnect from internet, stop using phones and TVs.
You will never be anonymous on internet, no matter what you do.
Just accept that and stop thinking and looking for solutions
 
  • HaHa
Reactions: Dave Russo

Cortex

Level 26
Verified
Top Poster
Well-known
Aug 4, 2016
1,465
Though these VPN's have shown themselves to be untrustworthy, it don't mean that all VPN's also lie about there data retention - The issue is Free, Cheap & VPN cannot exist in the same sentence - There are many threads with i want a good free VPN, AV, whatever - People today want something esp in PC program for nothing & with a VPN server space & bandwidth are not cheap or free - There are some VPN's I trust to a degree, IVPN, ExpressVPN. Mullvad, Perfect Privacy for example.

The problem is none of these are anything like cheap - If you disdain VPN's & feel this latest revelation is amusing or even funny that's sad., your ISP could be less than trustworthy also? If you want a VPN be prepared to pay in excess of £100 a year minimum (I do)

@security123 - You obviously dislike any VPN & use every opportunity to point this out, I disagree with you totally - Pointless discussing it as it's been done 100s of times? You seem obsessed with attack surfaces, are you wanted by many governments? :p:p:p
 
Last edited:

CyberTech

Level 44
Verified
Top Poster
Well-known
Nov 10, 2017
3,250
@security123 - You obviously dislike any VPN & use every opportunity to point this out, I disagree with you totally - Pointless discussing it as it's been done 100s of times? You seem obsessed with attack surfaces, are you wanted by many governments? :p:p:p
dIS0skV.jpg
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top