u/RecordingSingle9064

A case over Anne Frank’s diary just led the EU’s top court to rule that VPNs are lawful.

The judgment passed by the Court of Justice of the European Union established that VPNs are recognized as "lawful technical tools." It refers to the incident when Dutch and Belgian universities decided to publish Anne Frank's manuscripts online, which is permitted by Belgian law and in the majority of other states where copyright does not exist anymore while in the Netherlands copyright will be valid until 2037.

The interesting part of this story is that the main question was related to the publisher's ability to escape liability in case of blocking the visitors according to the place they are visiting from. The answer is negative; it means that geo-blocking is not the VPN's responsibility but rather an issue for the copyright holder that needs to be solved by them.

It goes directly against the previous decisions made in Spain and France where VPNs have been regarded as "tech intermediaries" that must help publishers with their blocking activities. The European court has decided to go the opposite way.

A teen's diary case has become the strongest legal precedent for vpn-providers in Europe. It is interesting to see whether this decision will help vpn company in Europe.

A case surrounding a teenager's diary has now become the strongest legal precedent for VPN firms across Europe. Is this really against what Spain and France are doing, or simply adding to an already muddled situation?

reddit.com
u/RecordingSingle9064 — 2 days ago

Critical Cisco VPN firewall vulnerability is being actively exploited, no patch available

Cisco has announced this month that CVE-2026-20349, an 8.6 severity vulnerability in its Remote Access SSL VPN service, has been actively exploited. The flaw allows an attacker to crash a device by sending only one specially crafted request without having to authenticate themselves.

The vulnerability impacts SSL VPN, IKEv2 Remote Access VPN, and Zero Trust Network from the affected FTD devices. The Firewall Management Center is not impacted by this security issue, though it may seem like little consolation. Cisco did not mention who is responsible for the attacks, nor which companies and organizations were targeted.

The situation is only getting worse because there is no alternative solution. Cisco clearly states in its advisory that in order to mitigate the effects of this vulnerability, users should either apply the hotfix or update their system to the latest version. There is no room for other solutions.

As if this news isn't bad enough, it came out in the same month when Microsoft released patches for its August Patch Tuesday. Many issues will be fixed, but let's not forget that VPN appliances are usually the easiest victims of the newest attack campaigns.

If your organization is running Secure Firewall with remote access VPN enabled, this isn't a "get to it next sprint" patch.

Anyone here already pushed the hotfix, or still waiting on a maintenance window?

reddit.com
u/RecordingSingle9064 — 5 days ago

Your VPN provider wants to give your AI agent the wheel

PrivadoVPN has recently announced its MCP server compatible with Windows and Mac operating systems, which facilitate the connection, disconnection, and mapping of VPN servers via AI applications including Claude Code and VS Code. Therefore, users will no longer have to perform complex actions to reach the VPN managers.

However, this development is not the first of its kind as Express VPN made the first launching of the technology in March, and Norton has got ahead of its competitor with the first launching of docker-based tunnels operating in such a way that every task done by software works through its own connection. Windscribe has developed a CLI interface and Pure VPN is uses ChatGpt as an assistant in managing VPN.

However, all the service providers have common security features: only local network is used, explicit confirmation is required, and no personal login information is given to AI or terminal. The version of PrivadoVPN works only whithing the local network, thus, nothing from the outside can access it.

However, delegating control to AI requires some level of trust which is totally different from letting the AI use auto-complete. It is wise to know precisely which instructions to give the AI.

Has anyone in this room enabled their AI assistant to handle their VPN configuration?

reddit.com
u/RecordingSingle9064 — 6 days ago

Your smart TV could be sharing your internet connection without you realizing it.

Spur found out that LG webOS apps contained residential proxy code in 42% of the applications and Samsung Tizen apps held 26.5% of the proxy code, which essentially allows the TV to function as an exit node for other people's traffic, in addition to Pac-Man game promoted as “Editor’s Choice” by LG.

People may not be watching over their smart TVs, which makes them an easy target. The SDK is there routing the traffic of different companies through your home’s IP with no information on it being shared or approved.

Last month LG banned this practice and Samsung followed suit this month. Google also aims to put a stop to this practice on Android. Even though the industry is actively responding at this stage, this practice was going on for months before this decision was made.

It is worth checking what kind of applications you have on your TV, especially anything free or less-known. Have you had any experience with such cases?

reddit.com
u/RecordingSingle9064 — 8 days ago

The Government Recommends VPNs... So Why Restrict Them Now?

It is important to note that CISA, which is a genuine US cybersecurity agency, has advised people to make use of VPNs in order to remain safe online. However, it appears that the US government is now trying to promote laws that will inhibit the use of VPNs.

The states of Wisconsin and Michigan have introduced bills that require websites to prohibit the use of VPNs as a part of the rules on age verification. The websites do not have the capacity to identify whether a user is present in Milwaukee or in Mumbai while connected to a VPN. As a result, the websites can either block every VPN connection or stop functioning in the states.

This is similar to a fire department suggesting people to buy and install smoke detectors while other agencies attempt to make these devices illegal since someone could use them as an opportunity to smoke.

To be frank, it is only the people who are using a VPN to get around the rules who benefit from these attempts. The laws have negative impacts on journalists and people who are victims of domestic abuse.

one hand hands you the lock, the other hand tries to outlaw locks.

reddit.com
u/RecordingSingle9064 — 10 days ago

La Liga is mad FIFA sponsored a VPN. yes, that La Liga.

The announcement made by FIFA stated that ExpressVPN will be the official sponsor for the World Cup in 2026. This prompted a number of complaints from La Liga and French broadcasting networks like Canal+ and beIN Sports. They viewed this decision as “shocking” and as an assault on their efforts against torrents and other piracy-related crimes.

La Liga’s chief Javier Tebas has devised strong VPN-blocking path around the world, thanks to which more than 500,000 legal websites were blocked earlier this year. Currently, he is asking FIFA to stop associating with the tool that millions of people are using for various legal activities including doing their banking, working for media, and ensuring proper data security. This has been requested just because some people are using it to watch pirated football.

According to FIFA, they have checked everything and they don’t think the sponsorship is against anybody’s rights since ExpressVPN doesn’t enable piracy.

It seems that the organization that blocked half a million innocent sites is aiming to avoid the use of the proper privacy tool (ExpressVPN) in order to achieve its ends.

reddit.com
u/RecordingSingle9064 — 12 days ago

So the screen Act wants your ID before you look at anything? Cool, cool, cool

The federal bill that is currently in the Senate aims to gather proof of age before allowing an individual to access sites that might contain sexual content. By this, I mean that all of us will have to provide documents or biometrics so that we can be allowed to open whatever site's page. That is no longer a filter; that sounds like the whole system tracking your activity on the Internet.

It is like having a bouncer at the entrance to the Internet, requesting one’s ID anytime a person wanders in that direction.

But let’s get down to the point, “protecting kids” is not what the document even suggests. According to the wording of the bill, there are no restrictions related to what the majority of the content on the site should consist of. Hence, even platforms with minimal amount of sexual content should demand a legal proof of age from anyone wishing to visit their pages without us violating privacy.

This is a surveillance bill wearing a child-safety costume, and it almost slipped through committee with barely anyone watching.

reddit.com
u/RecordingSingle9064 — 14 days ago

CISA's official advice: stop using your personal VPN

America's own cyber protection agency repeated its memorable message for iPhone and Android users: "avoid using a personal VPN." Originally published one year ago, now the agency is delivering this message again because more users are opting for VPN technology.

CISA's real reasoning is that VPNs do not eliminate risk but change its location: instead of being seen by the internet provider, your data is now visible to VPN provider. The agency further explains that "most commercial and free VPN providers are not very secure or trustworthy."

This is true, but it looks like it is spoken by an official source. Many people do not know the value of a good VPN or do not realize that finding a good VPN all the time is better than accessing the net through an unprotected public Wi-Fi.

The analysis of CISA is that it was not accurate when it said that one should not use a VPN but rather that it is crucial to make a choice wisely.

However, did anyone change their attitude towards their personal VPNs after reading this warning?

reddit.com
u/RecordingSingle9064 — 16 days ago

Russia drops VPN tax but continues Its broader crackdown on VPN services.

This month, Russia's Ministry of Digital Development has confirmed that it has completely abandoned the initiative to impose fees on VPN users for using international internet traffic of 150 rubles for every gigabyte consumed beyond the cap of 15 gigabytes of traffic. The announcement was officially made by the Deputy Minister, Ivan Lebedev.

However, there is no reason to celebrate. The cancellation of the initiative did not happen because of any principles; it was just ineffective. The telecommunications firms stated that they have no way of identifying "international" traffic, plus some Russian firms use foreign IP addresses, and some foreign CDNs localize their servers in addition to Russian servers; thus, such a tax is not possible to implement.

Moreover, Roskomnadzor made a similar announcement regarding its plans to block 92% of VСP applications by 2030, which shows that the authorities are going to continue with their strategy.

Therefore, a small victory but no success whatsoever.

reddit.com
u/RecordingSingle9064 — 17 days ago

Hacker claims NordVPN creach, but company says leaked data was part of a vendor trial.

On January 4, a hacker named "1011" posted on the BreachForums that their reasoning was that they had successfully compromised a misconfigured NordVPN development server and acquired Salesforce API keys, JIRA tokens, as well as that of 10-plus databases. The company quickly responded, leading to findings by experts that no active systems were compromised and that the unauthorized information is from a vendor test that took place six months earlier at the time, where NordVPN was testing a product for operations but failed to adopt.

On the other hand, it should be noted that while the hacker makes an interesting point in their disclosure, it was stated, "internal salesforce and dev data" which does not imply that any customers' information was involved. Additionally, NordVPN makes a valid argument that its RAM-based operations mean that no logs were created on the hard drives that could be perhaps accessed via a possible breach.

For now, there are no user emails, passwords, IP addresses, or payment information involved. it will be interesting to see if that remains the case as the investigations get underway, rather than accepting the claims made by either party as final.

Has anyone in this community investigated the leaked data on their own, or just relying on announcements made by the relevant parties?

reddit.com
u/RecordingSingle9064 — 18 days ago

U.S. senator pushes to eliminate legacy VPNs across the federal government within two years.

Ron Wyden wrote a letter to CISA, OMB, and NIST on Monday that is not a request for evaluation but rather an action plan spanning three agencies. The request itself includes a binding CISA directive which gives civilian agencies two years to step away from the use of public VPN hardware, a directive from the NSA that will apply to military and intelligence operations, a set of technical standards from NIST to facilitate replacement and a government rule that prohibits any vendor from selling its network equipment if it hasn't proven that the equipment meets zero-trust criteria.

Wyden's tone is straightforward: "the federal Government finds itself stuck in a never-ending cycle of playing whack-a-mole." He emphasizes the fact that CISA has been issuing emergency proclamations to protect the VPN hardware that has already been exploited by the cybercriminals, with vendors like Fortinet, Ivanti, and Citrix suffering the same consequences of having their vulnerabilities exploited by the cybercriminals who are infiltrating the hardware literally without any limitations.

It is important to understand what this is at this point: a letter and not a law. Wyden does not have the power to constrain CISA, OMB, or NIST in any way. The three agencies in question have not taken a stance. However, should the proposal be accepted, the mechanism will be effective. The procurement procedures work this way in case of defense contractors. Once there is a requirement for certification, the vendors follow the procedure or cease to operate on the federal market.

This instance is about the federal infrastructure of remote access and not about the VPN app, which makes things clear. That said, this letter is undoubtedly indicative of where the VPN industry is going. Are there people in charge of IT in the government sector who are ready for the bipolar transition?

reddit.com
u/RecordingSingle9064 — 21 days ago

X’s VPN Crackdown: It’s about more than just stopping bots.

X has introduced a feature called "About this account", which indicates where the account is located. Additionally, it identifies whether the user is disguising their location using VPN or proxy and marks the profile saying: "country or region may not be accurate". According to head of product Nikita Bier, it is intended to counter bots and foreign influences.

And it does work. Accounts which pretended to be American, for example "MAG Nation" and "America First", turned out to be based in Eastern Europe and Bangladesh. This can be regarded a proper victory and transparency regarding accounts doing activities that are false.

However, the same technology, which reveals a troll farm, is flagging journalists and activists who hide their location for legitimate reasons. Surfshark and NordVPN raised this issue: once a platform makes a statement that "this one hides the location", it stops being a simple anti-bot solution.

It didn't help much regarding accuracy. The Canadian Liberal party, the NDP, was marked as located in the USA. So were CBC accounts. According to Bier, the data was "not 100% accurate for old accounts".

As a result, the company mislabels the real accounts while successfully exposing those who use VPNs. Anyone here checked their own "about this account" page yet?

reddit.com
u/RecordingSingle9064 — 22 days ago

ExpressVPN's "214 locations" isn't quite what it sounds like.

This month, ExpressVPN announced that it has expanded its network to reach 214 locations that you can select among. While this may appear to be a major increase, the reality is that, according to independent tests, the actual number of different locations is 196. The reason for the discrepancy is that the company counts every area from where you can connect to its service in the same city as a separate location.

Now here is something that's more interesting: ExpressVPN has launched its service for China but there are no servers in the country; the actual location is Singapore while the IP address is Chinese. The company does clarify this information but this is not the first time it has launched something like this as many companies tend to inflate their numbers when it comes to such things as locations.

So in case you need a Chinese IP for your business, you may consider using it, however, what you should remember is that the situation is very often similar across different companies since they define their servers and locations in different ways.

reddit.com
u/RecordingSingle9064 — 23 days ago

Best VPN for 2027: where things are actually headed, not just where they are now.

Most "best VPN" lists are just a snapshot of right now. Better question: who's actually building toward 2027, not just winning this year's speed test.

Same five names as always: Proton VPN, NordVPN, Mullvad, Surfshark, ExpressVPN. Here's the actual trajectory.

Proton VPN is my pick for 2027. Widest server footprint of any major provider, 145 countries, ahead of Nord's 135 and Express's 108, still expanding into places most VPNs ignore, Gabon, Kyrgyzstan, Papua New Guinea. Swiss, outside 14 Eyes, no-logs claim held up under real legal pressure, not just a paid audit. And it just shipped a new WireGuard codebase in beta, built to bring post-quantum encryption without killing speed. Building the next few years in public instead of running victory laps on this year's numbers.

NordVPN wins today on speed and streaming. Fully quantum-resistant already, 100+ Tbps capacity. Best pick if you need that right now. But its country growth has stalled while Proton keeps expanding.

Mullvad for OPSEC, no email, cash accepted, best obfuscation around.

Surfshark budget/unlimited devices.

ExpressVPN zero setup friction.

Bottom line:

  • trajectory → Proton.
  • speed now → Nord.
  • anonymity → Mullvad.
  • budget → Surfshark.

Anyone seeing a provider that changes this picture, or does this order hold through next year?

reddit.com
u/RecordingSingle9064 — 25 days ago

NordVPN's now been sued five times for the same thing.

On April another file was submitted in Virginia connecting the same firm with similar accusations where the “dark patterns” were mentioned as being responsible for trapping people into auto-renewing subscription.

From 2024, five class actions have been filed now, with California, North Carolina, Colorado, New York, Massachusetts and Virginia all claiming six allegations including unclear sign up conditions, absence of renewal information on receipts, debit charges two weeks in advance, difficulties canceling the subscription, inadequate notifications about auto-renewal and the presence of “30-days money-back guarantee”, which is effective starting from the date of the debit, not the cancellation date.

One of the plaintiffs claims that he was charged $119 for a service, which he did not intend to subscribe to for a duration of a year. Another tells that NordVPN withheld $131 refund from him unless he specifically made the request.

The law firm that serves as the main representative of the clients, Wittels McInturff Palikovic did already receive $400 million from similar cases. Nevertheless, it is important to note that the problem with the dark patterns of auto-renewal affects many companies in the industry and not only NordVPN.

If you're subscribed anywhere, screenshot your renewal date and set a calendar reminder. Anyone here actually gone through a NordVPN cancellation lately? How'd it go?

reddit.com
u/RecordingSingle9064 — 26 days ago

Nordvpn quietly killed Openvpn for obfuscated servers and didn't really tell anyone.

The obfuscated servers section which is utilized by individuals from places like China, Russia, and Iran to disguise their connection as standard https instead of recognizable VPN traffic is now operating on nordwhisper rather than openvpn tcp/udp. Since the release of version 8.7.2.0, users were already informed about the change in the in-app notes before the public windows changelog was updated on their website.

Nordwhisper is the company’s proprietary protocol that was created in early 2025 and has been designed specifically to disguise VPN traffic as traditional web traffic. According to Marijus Briedis, the company’s CTO, users will enjoy better performance by applying this new protocol because of the speed of connections and expanded variety of servers.

This simply means that the technology gains are exactly on paper as obfuscated connections have always been slow due to the additional layer the technology applies to shield the connection.

However, I do have my complaint regarding "who actually benefits." OpenVPN is open-source. Anyone can go through the code, audit it, and confirm that Nord isn't bypassing any protocols while NordWhisper being proprietary. One must accept the word of Nord regarding security being of the same quality and there are no audits done by some independent party as is the case with OpenVPN. This makes a difference for users depending on the technology in very strict environments.

It is the same with the lack of a proper announcement. There was no blog post, or any other kind of fanfare, the feature just appeared in release notes even before they managed to update the changelog. When you rely on obfuscated servers to be safe on the network, it is bizarre to hear about the changes in the used technologies through patch notes rather than in any other news from the company.

I'm not saying that it shouldn't be used. I'm just indicating that asserting "our technology is safe" isn't a sufficient argument when it comes to the importance of people's ability to work online without being flagged for any activities.

Is there anyone testing the NordWhisper obfuscated server yet? I'm eager to know if the speed claims are indeed justified.

reddit.com
u/RecordingSingle9064 — 28 days ago

The us just sanctioned a "no-log" vpn for laundering ransomware traffic.

On July 14, the financial arm of the U.S. Treasury called OFAC, imposed sanctions on a service named First VPN (1VPNS), its administrator, and a 45-year-old Ukrainian named Dmytro Rashevskyi, along with a Belarusian named Yegeniy Silayev who created "cryptors," instruments that can process malicious programs without getting them identified by anti-virus applications. In fact, First VPN had already been taken down back in May as a result of a joint operation by the U.S. and its European allies and this action is actually of a financial nature.

The slogan promoted by First VPN since 2014 must sound familiar: no records, no cooperation with law enforcement, etc. However, according to the U.S. Treasury, ransomware organizations purchased numerous servers from this provider based on this promise and then used the servers to mask the origin of the attacks against U.S. hospitals, banks, and municipal offices. Reportedly, Rashevskyi used a series of fake names like Maksim Sorin to keep purchasing servers from providers who would have never sold them to him if they had known who he was in real life.

It is significant that Mullvad and Proton are known for their no-logs policies because they've proven their capabilities of ensuring compliance with their promises even when their servers were subject to police raids and confiscation with no incriminating data to turn over. In contrast, the message that VPN providers present to customers claiming the adherence to the no-logs policy initially meant being "untouchable" for crime outfits or simply a bulletproof hosting service.

Thus, the customers purchasing VPN services do not know how to distinguish between those two types of companies when reading their promotional materials. The wording used by Mullvad and by VPN providers that function as sanctuaries for criminals is sufficiently similar to mislead potential customers in most cases, leading to confusion.

At this point, it is necessary to remind that this news appeared just when the UK and the EU sanctioned 24 Russian firms/individuals allegedly associated with the cyberactivities of the FSB/GUR and the FBI issued its warning regarding the 16th center of the FSB of Russia for the competition of improperly configured routers.

Does this affect how any of you evaluate a vendor before using their service or is “who is the parent company, where is it located, and has it survived a server seizure” already taken into account when deciding on a VPN service provided?

reddit.com
u/RecordingSingle9064 — 29 days ago

Why are VPNs launching TV apps that can't secure your TV?

This month, VPN Super introduced beta applications for both Apple TV and Android TV, meaning that viewers can just connect from the comfort of their homes instead of going through their router all the time. The huge focus is on ACR, which means Automatic Content Recognition, the technology that can recognize what is being watched on a TV. This is something that is present in many smart TVs and works several times per second, sending data to the manufacturers and their partners on that. It is interesting that the FBI even reminded people to consider all pros and cons before buying a smart TV.

What is essential to keep in mind here is that while VPNs do protect data that is transmitted from your smart TV, they do not interfere in ACR technology. VPN Super makes it clear in the promotional materials that they put out, but the idea given to the customers may seem different since marketing still pushes the idea of protecting a smart TV.

So two events transpire together: a tangible feature of a product, which is VPN availability without the need to configure the router, combined with a guarantee of privacy with regard to which only half of the actual problem is being solved. If you want ACR to disappear, it is done via a setting that is hidden in the menu of your TV, and no application of any kind can do that instead of you.

Moreover, there is a bonus of a sports alibi that is about easier access to soccer and tennis games which perhaps sells the product more than the privacy aspect.

Is there anybody who is using this VPN service with it's smart TV? Did you have to go digging through the ACR settings or did you rely on VPN to resolve it for you?

reddit.com
u/RecordingSingle9064 — 1 month ago

A $2,000 Telegram kit turns any phone into total surveillance.

According to a report by security experts from iVerify, ZeroDayRAT has been sold in the Telegram channel since February, and available in five languages. It requires no technical knowledge to operate. The cost is $2,000 and provides access to a web dashboard that can remotely control Android devices (versions 5 to 16) and iPhones, has access to the phone’s microphone and camera, allows tracking the GPS location, and intercepting SMS messages.

The delivery of ZeroDayRAT is unique. It is a text message that calls for urgent action and tricks victims into installing a malware disguised as a regular mobile application. The dashboard will allow the hacker to see everything that happens with the device, including social media accounts and banking applications.

The researchers also noted that it is possible to change the wallet's address in the victim's clipboard, which means that the transaction that the victim is planning to conduct is directed to the hacker's cryptocurrency account.

We have to mention two important details here: this malware isn't coming from a nation-state and also it's not just random spamming either. This pricing of $2,000 must have been done purposely; this is still cost-effective for abusive partners and stalkers who want to keep accessing the person they're stalking. In this particular case, two researchers have pointed out that this program could be considered a stalkerware since it does not even try to disguise itself as "parental control" software.

However, the good thing is that the vulnerability in this particular case is human, rather than technical; the victim must have clicked the link which they shouldn't have clicked in the first place.

reddit.com
u/RecordingSingle9064 — 1 month ago

The "privacy" VPN extension that was secretly selling your AI chats.

Urban VPN Proxy was available on the Chrome Web Store with a rating of 4.7 stars and a "Featured" badge from Google and more than six million installs as the free solution for private browsing. But Koi Security discovered that after the recent update in July 2025, it had been involved in stealing and selling the entire conversations from ChatGPT, Claude, Gemini, Copilot, Perplexity, DeepSeek, Grok, and Meta AI, amounting to around eight million users on Chrome and Edge.

How it worked: the extension used special scripts that got injected into every AI website with names like chatgpt.js and claude.js, overriding the network functions of a web browser to capture prompts before they were seen on the screen. Koi’s researchers were candid when it came to the worst aspect: "the extension warns about providing your email on ChatGPT while at the same time allowing the extension to steal the entire conversation".

Here’s something that makes it go from bad to comedically absurd: the harvesting continued even when the VPN was turned off, and even when the extension’s own ‘protection’ option was activated. While it did allow people to use the VPN, there was no option to refuse the AI harvesting, therefore resulting in an all-or-nothing consent message. Interestingly, that same link was found in 7 other extensions made by the same company, including an ad blocker and a ‘browser protector’ that all used a common surveillance engine. That means if the user did install these extensions for completely different purposes, it would still be yes to harvesting Claude’s chats.

The difference here is that it is the opposite of a two-track situation; in fact, it is a one-track one: the company has built a full product family around the false promise of a protective measure. Whatever medical questions or financial info the users typed, Koi commented that it was all sold for ‘marketing analytics.’

Anyone here checked their installed extensions against this list yet, or is this the first you're hearing Urban VPN was ever on anyone's radar?

reddit.com
u/RecordingSingle9064 — 1 month ago