New Update [Surfshark VPN] Started to Temporarily log partially and maybe long term IP.

Sorrento

Level 9
Verified
Well-known
Dec 7, 2021
402
Been giving IVPN a try mainly for fun, pretty good so far - It's often said you need to trust your VPN as much as your ISP - The thing is after reading my ISP's privacy policy, there is no privacy, they will use your browsing history to target ad's etc & more - Plus your ISP here is obligated to save your history for one year.
 

jogs

Level 22
Verified
Top Poster
Well-known
Nov 19, 2012
1,113
Can users be tracked by their MAC address?
Like if some one wants to track who is visiting a particular website, he get hold of the MAC address of all the visitors and compare them with the database from the ISP.
 

Stopspying

Level 19
Verified
Top Poster
Well-known
Jan 21, 2018
814
So they changed the Terms Recently and started to Temporarily logging now as long as you are connected and 15 min after you disconnect




Link ( Simply search via CTRL+f "15 "


Also they started to log your IP + Device identifer in the apps which they refer in the Privacy policy as "Website"


Also

mind you "Website" means their Website OR App as they explained.

Source


just search the lines I quoted sentences via CTRL + F to verify it yourself.

the Privacy policy this post is about was updated 25.08.2022

it could be that they worded the website and app thingy weird.
but then still the 15 min log / the log as long as your connected + 15 min still stays.

I've been in email contact with Surfshark Customer Service about it being unusable for much of this year, currently I cannot get any version that I have of the VPN .exe file (6 versions) to install and be recognised by the Surfshark Systems. Its been like this for over two weeks, I'm refusing to uninstall other software that they claim may be conflicting with Surfshark, that is the easy way out for them, it all worked together prior to the recent v 4.2.2 update, so I know that the problem is with Surfshark as the apps they suggest be removed have not been updated.

I've been talking to them about the Terms of Service and Privacy Policy, as you point out here show that logging occurs. yesterday I was told that "I fully understand your concerns but No-logs Policy is one of the most important features of our Services. It means your activities are not in any way logged, retained, or transferred to third parties when you connect to our Services. We do not collect any information about what you do online (your visited IP addresses, browsing history, session information, used bandwidth, connection time stamps, network traffic, or any other similar data)." A link to the Privacy Policy that this comes from was provided.

I've responded by quoting the bit that you highlight from their Terms of Service which states "To prevent service abuse, our servers store your user ID and connection time stamps, but this information is automatically deleted within 15 minutes after termination of your session." I've asked how these two conflicting statements equate, as even if it is stored for 15 minutes of less, the User ID and connection time stamps is still data that is personal and they log it.

I'll update when I get a reply. This may not be immediate as I am away for a week.


 
Last edited:

Stopspying

Level 19
Verified
Top Poster
Well-known
Jan 21, 2018
814
I remember when Surfshark re-located to the Netherlands that there was a lot of concern about this move from an island in the sun that was commonly felt to be a better location for a VPN provider. The Netherlands is part of 'Nine Eyes' - Five Eyes, Nine Eyes, 14 Eyes (What to Avoid in 2022)

Surfshark states "We can ensure such policy as we are based in the jurisdiction, which does not require data storage or reporting, and processes related to provision of our Services are automated."

I don't trust any country that is in 5/9/14/** Eyes to be a jurisdiction that won't comply with demands from 'authorities' for data. I think that this is worth bearing in mind alongside this disclosure that Surfshark does some logging, even if only for a maximum 15 minutes. It is not the VPN that I subscribed to, it has a different jurisdiction, its Terms of Service and Privacy Policy are not exactly transparent, transparency seems to be becoming more of an issue for this company since it relocated/joined with Nord/ started adding more and more services.

BTW I have been informed by Surfshark that the AV "..was a highly requested tool from our customers". I do not see much discussion online by users of this AV or know anyone who requested and uses it, do you?
 

Attachments

  • Surfshark jurisdiction - 28.08.22.PNG
    Surfshark jurisdiction - 28.08.22.PNG
    44.1 KB · Views: 72
Last edited:

Stopspying

Level 19
Verified
Top Poster
Well-known
Jan 21, 2018
814
I remember when Surfshark re-located to the Netherlands that there was a lot of concern about this move from an island in the sun that was commonly felt to be a better location for a VPN provider. The Netherlands is part of 'Nine Eyes' - Five Eyes, Nine Eyes, 14 Eyes (What to Avoid in 2022)

Surfshark states "We can ensure such policy as we are based in the jurisdiction, which does not require data storage or reporting, and processes related to provision of our Services are automated."

I don't trust any country that is in 5/9/14/** Eyes to be a jurisdiction that won't comply with demands from 'authorities' for data. I think that this is worth bearing in mind alongside this disclosure that Surfshark does some logging, even if only for a maximum 15 minutes. It is not the VPN that I subscribed to, it has a different jurisdiction, its Terms of Service and Privacy Policy are not exactly transparent, transparency seems to be becoming more of an issue for this company since it relocated/joined with Nord/ started adding more and more services.

BTW I have been informed by Surfshark that the AV "..was a highly requested tool from our customers". I do not see much discussion online by users of this AV or know anyone who requested and uses it, do you?

I've been in email contact with Surfshark Customer Service about it being unusable for much of this year, currently I cannot get any version that I have of the VPN .exe file (6 versions) to install and be recognised by the Surfshark Systems. Its been like this for over two weeks, I'm refusing to uninstall other software that they claim may be conflicting with Surfshark, that is the easy way out for them, it all worked together prior to the recent v 4.2.2 update, so I know that the problem is with Surfshark as the apps they suggest be removed have not been updated.

I've been talking to them about the Terms of Service and Privacy Policy, as you point out here show that logging occurs. yesterday I was told that "I fully understand your concerns but No-logs Policy is one of the most important features of our Services. It means your activities are not in any way logged, retained, or transferred to third parties when you connect to our Services. We do not collect any information about what you do online (your visited IP addresses, browsing history, session information, used bandwidth, connection time stamps, network traffic, or any other similar data)." A link to the Privacy Policy that this comes from was provided.

I've responded by quoting the bit that you highlight from their Terms of Service which states "To prevent service abuse, our servers store your user ID and connection time stamps, but this information is automatically deleted within 15 minutes after termination of your session." I've asked how these two conflicting statements equate, as even if it is stored for 15 minutes of less, the User ID and connection time stamps is still data that is personal and they log it.

I'll update when I get a reply. This may not be immediate as I am away for a week.


Following up on the points I raised with Surfshark on their Terms of Service and Privacy Policy seemingly contradicting themselves by stating that they do log some data the response I got was - "The information is incredibly minimal and without it, our VPN simply wouldn't function.
Also, it is important to know that we have no way of accessing these logs and they get deleted almost instantly."

Considering the contradictions Surfshark have made in their documents, along with claiming a 'no-log' policy when there is some logging ocurring I will take everything that they say with a pinch of salt. There is also a lot that they don't seem to be saying, or at least making users aware of clearly. The email that I got from them last Friday (Check out what’s new at Surfshark this August!) announced the manual Wireguard connection and new apps for Windows, iOS and LInux. There was nothing about any changes to the Terms of Service and such like. I wonder why?!

Honesty and openness are important when it comes to trusting businesses, especially when it comes with taking money from customers. It is not happenning with Surfshark from what I see.
 

Slerion

Level 5
Thread author
Verified
Well-known
Feb 24, 2016
247
Surfshark also started Censoring the reddit community and removing the posts which got traction
This is the post they left up ( for now )


See here for more deleted posts.
 

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,035
SurfShark VPN 's latest practice of deleting data 15 min after the session ended is in line with some other VPNs like Mullvad VPN, OVPN and VPN.ac. They do erase some logs after the session ended

WireGuard VPN: Secure and Fast, But Bad for Privacy?

Quote

Mullvad and OVPN erase IP address logs after the VPN session ends​

Another way VPN providers have addressed the problem with logs is to configure their servers to erase data logs when the session ends.

Two examples of this are with Mullvad and OVPN, both of which are secure VPN services based in Sweden.

OVPN explains:

We have programmed our VPN servers so that user information is not stored forever in the VPN server’s memory. Users who have not had a key exchange for the past three minutes are removed, which means we have as little information as possible.
Mullvad takes a similar approach:

We added our own solution in that if no handshake has occurred within 180 seconds, the peer is removed and reapplied. Doing so removes the public IP address and any info about when it last performed a handshake.

Unquote

For VPN.ac


Quote

Does VPN.ac keep connection logs?​

Previously, VPN.ac would keep connection logs for 24 hours. However, in 2021, they changed their policy to only keep basic connection logs while the VPN session is active. In other words, VPN.ac keeps no logs of their users, but basic connection logs are generated (and automatically erased) with each VPN session.

Unquote
 

Slerion

Level 5
Thread author
Verified
Well-known
Feb 24, 2016
247
SurfShark VPN 's latest practice of deleting data 15 min after the session ended is in line with some other VPNs like Mullvad VPN, OVPN and VPN.ac. They do erase some logs after the session ended
...
theres a huge difference between circumventing Wireguards issues /shortcommings while keeping it minimal with logs ( like the 2 vpn you mention do ) aka having "logs" ( more like a address so customers can connect which WG simply "needs" to function )

or keeping flat 15 min logs for any protocol and connection just because and it isnt needed at all.
 

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,035
theres a huge difference between circumventing Wireguards issues /shortcommings while keeping it minimal with logs ( like the 2 vpn you mention do ) aka having "logs" ( more like a address so customers can connect which WG simply "needs" to function )

or keeping flat 15 min logs for any protocol and connection just because and it isnt needed at all.
The reason is not important. The end result is the same.

If the company keeps the data for say 1 week or 1 month then I'll say it's unacceptable
 
Last edited:

Indingo

Level 1
Jun 15, 2020
23
The reason is not inportant. The end result is the same.

If the company keeps the data for say 1 week or 1 month then I'll say it's unacceptable

Im sorry, either you have no idea what you are talking about or your are shilling for surfshark for some reason. Its not the same at all.

Wireguard as a protocol has an issue where it by its very nature has to keep a user key while the connection is active, which is why small disconections last for a very short time, unlike OpenVPN which will fully drop your connection. Many (better) VPN companies have subverted this with a 180s switch for clearing active connections.

Surfshark however, can probably see what your doing actively while connected (?to prevent abuse or other reasons) and more than that, if authorities seize the servers within a 15 minute window they will have access to the connection log data and can probably correlate traffic this way, potentially de-anonymising a user, let alone if Surfshark gets a request from authorities in an active lawful warrent, they could be forced to give active connection information with timestamps and user account ID's directly to authorities and if the user did not pay for the account with cash, they could easily be tied to their payment info (real world identity)

Don't try to shill for a company who is quit literally hiding the changes to their privacy policy in bad faith, insead of informing all users by email (which would cause a mass exidous from the company) which shows they are more about money than their users or ethics.

Why use a VPN?
 

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,035
Im sorry, either you have no idea what you are talking about or your are shilling for surfshark for some reason. Its not the same at all.

Wireguard as a protocol has an issue where it by its very nature has to keep a user key while the connection is active, which is why small disconections last for a very short time, unlike OpenVPN which will fully drop your connection. Many (better) VPN companies have subverted this with a 180s switch for clearing active connections.

Surfshark however, can probably see what your doing actively while connected (?to prevent abuse or other reasons) and more than that, if authorities seize the servers within a 15 minute window they will have access to the connection log data and can probably correlate traffic this way, potentially de-anonymising a user, let alone if Surfshark gets a request from authorities in an active lawful warrent, they could be forced to give active connection information with timestamps and user account ID's directly to authorities and if the user did not pay for the account with cash, they could easily be tied to their payment info (real world identity)

Don't try to shill for a company who is quit literally hiding the changes to their privacy policy in bad faith, insead of informing all users by email (which would cause a mass exidous from the company) which shows they are more about money than their users or ethics.

Why use a VPN?
15 min window......a mission impossible act? Otherwise previous cases of raids by the authorities on the server centers would reveal such.

BTW, I believe many VPN companies would collaborate with the authorities when there're unlawful activities with their servers which constitute an abuse. And I believe the T&Cs would spell out such that the provider would not hesitate to take monitoring/termination actions and to provide the relevant data of the abuser, if any, to the authorities upon request

You must remember that the VPN provider can see your activities, where you are coming from and where you are going...........if they want to........to avoid abuse of their servers.

If I'm a VPN provider I definitely do not want my company to be shut down just because you abuse my service for your tiny subscription amount.

So, you can rest comfortably with the points you have raised.
 
Last edited:
  • Applause
Reactions: Sorrento

Indingo

Level 1
Jun 15, 2020
23
15 min window......a mission impossible act? Otherwsie previous cases of raids by the authorities on the server centers would reveal such.

BTW, I believe many VPN companies would collaborate with the authorities when there're unlawful activities with their servers which constitute an abuse. And I believe the T&Cs would spell out such that the provider would not hesitate to take monitoring/termination actions and to provide the relevant data of the abuser, if any, to the authorities upon request

You must remember that the VPN provider can see your activities, where you are coming from and where you are going...........if they want to........to avoid abuse of their servers.

If I'm a VPN provider I definitely do not want my company to be shut down just because you abuse my service for your tiny subscription amount.

So, you can rest comfortably with the points you have raised.

If you are a Surfshark user and have to rationalise and generalise a companies poor behavior so you can feel like the company is still good and you can continue using it, then be my guest but don't try and trick others into the delusion. Objectively, any VPN company that is privacy focused and has a history of trust, which there are few, would never do this. In fact some of the better ones are independantly audited to prove they don't do what Surfshark is doing.

TLDR: Surfshark has shown and is actively censoring its user base to avoid people learning of the change to their pruvacy policy in bad faith. I have absolutely no idea how a rational and sane person can defend this unless you either really don't want to change your VPN or your shilling for Surfshark for some reason.
 

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,035
If you are a Surfshark user and have to rationalise and generalise a companies poor behavior so you can feel like the company is still good and you can continue using it, then be my guest but don't try and trick others into the delusion. Objectively, any VPN company that is privacy focused and has a history of trust, which there are few, would never do this. In fact some of the better ones are independantly audited to prove they don't do what Surfshark is doing.

TLDR: Surfshark has shown and is actively censoring its user base to avoid people learning of the change to their pruvacy policy in bad faith. I have absolutely no idea how a rational and sane person can defend this unless you either really don't want to change your VPN or your shilling for Surfshark for some reason.
I'm using SurfShark VPN and I can accept the deletion of data 15 min after the session ends More than that I'll will not accept. And I don't commit crime using their servers so I have no worry

Further changes in their privacy policies, if any, would require my further assessment.
 
Last edited:
  • Applause
Reactions: Sorrento

Indingo

Level 1
Jun 15, 2020
23
I'm using SurfShark VPN and I can accept the deletion of data 15 min after the session ends More than that I'll will not accept. And I don't commit crime using their servers so I have no worry

Further changes in their privacy policies, if any, would require my further assessment.
That's good for you who probably lives in a western country free of persecution, but imagine if you were a dissident or whistleblower or in a country that persecuted you for your beliefs, 15 minutes could cost you your life. Its not about getting away with crimes, its about ethics, hiding/obscuring this information and not telling your customers (on purpose) could very much, in a real sense be a very real threat for some people.
 

HarborFront

Level 71
Verified
Top Poster
Content Creator
Oct 9, 2016
6,035
That's good for you who probably lives in a western country free of persecution, but imagine if you were a dissident or whistleblower or in a country that persecuted you for your beliefs, 15 minutes could cost you your life. Its not about getting away with crimes, its about ethics, hiding/obscuring this information and not telling your customers (on purpose) could very much, in a real sense be a very real threat for some people.
Don't anyhow guess and don't anyhow imagine, for I don't live in a western country. What you mentioned don't apply to me
 
  • HaHa
Reactions: Sorrento

Slerion

Level 5
Thread author
Verified
Well-known
Feb 24, 2016
247
Official mod post from Surfshark Cause people kept asking while the mods kept deleting posts so they kinda were forced to post something.



Why didnt they simply use +1 and -1 solutions like some more privacy focussed VPN use...
or simply use the Logged devices they anyway log in the account?



i mean they clearly have the logs to handle that already and the ability to "disconnect" devices and even all devices regarding to a account.
So i dont see why they need the 15 min log on top.
 
Last edited:
  • +Reputation
Reactions: I Walk MY Way

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top