This Chinese VPN exposes 5.7 billion pieces of personal information


Maxime Alder

August 24, 2022 at 9:30 a.m.

15

Personal data privacy © Shutterstock

© Shutterstock

The information was relayed on July 7 by a researcher from cyber news : a 626 GB ElasticSearch instance was opened on a free virtual private network (vpn) Chinese. The latter contains a database of nearly 5.7 billion entries, including user IDs and IP addresses.

This data leak is not without risk since it could allow the Chinese regime to prosecute users of Airplane Accelerates, the VPN in question. Virtual private networks are especially popular in a country like China where internet browsing is controlled.

A VPN with several gray areas

This discovery prompted the team of researchers to continue their investigation of Airplane Accelerates, and what they found will not reassure the main parties concerned by this leak. The VPN is actually said to be from an Australian-based parent company by the name of AP Network PTY Ltd.

The application would use the HTTPS protocol, a protocol that generates its share of problems, as Aras Nazarovas, head of research on the software, points out: “ Depending on how it is implemented, the app might only encrypt web traffic, not traffic from the operating system (OS) or other apps. “.

This VPN would have, if we are to believe the opinions left on the application page, several thousand, even hundreds of thousands of users. This leak can therefore have serious repercussions.

Fuzzy data management from this Australian company

By pushing a little more research into the legal aspects of the application, cyber news found practices that were suspicious to say the least, such as requesting access to the photo and video sensor of its users, reading its contacts or even recording audio. Unjustified requests for a VPN.

A behavior that is confusing, especially since the application does not have its own privacy policy, the link redirecting to the latter being empty. There is indeed one on the parent company’s website, but the turns of phrase can confuse the services concerned.

Dubious methods that do not protect Airplane Accelerates users from sharing their data. Despite all these flaws, the VPN did not respond to contacts from the research team, which therefore decided to reveal the case to the general public.

Source : cyber news

Best VPN, the 2022 comparison

How to choose the best VPN? Clubic has tested and compared the performance and level of security of the best providers to establish this VPN comparison
Read more



Source link -99