Thursday, December 24, 2020

TorrentFreak's Latest News

christmascatvpn
 

FBI and Europol Shut Down 'Bulletproof' VPN Service That Helped Criminals
Ernesto Van der Sar, 24 Dec 06:26 PM

insorgMillions of Internet users around the world use a VPN to protect their privacy online.

Another key benefit is that VPNs hide users' true IP-addresses, making them more anonymous. This prevents third-party monitoring outfits from carrying out unwanted snooping.

While there are good reasons to remain 'relatively' anonymous these services can also be abused by criminals. That can present problems, as most good VPN providers keep no identifiable logs, which makes the job of law enforcement agencies harder.

Operation Nova

This week, the FBI and Europol shut down "Safe-Inet," a VPN service that went to extreme lengths to keep its customers hidden. The enforcement effort, dubbed "Operation Nova," was coordinated by the German Reutlingen Police Headquarters with help from many international partners.

According to Europol, Safe-Inet was used by some of the biggest cybercriminals including ransomware operators that held hundreds of companies hostage. With help from the VPN service, the criminals were able to avoid detection.

"This VPN service was sold at a high price to the criminal underworld as one of the best tools available to avoid law enforcement interception, offering up to 5 layers of anonymous VPN connections," Europol notes.

"Law enforcement were able to identify some 250 companies worldwide which were being spied on by the criminals using this VPN. These companies were subsequently warned of an imminent ransomware attack against their systems, allowing them to take measures to protect themselves against such an attack."

Servers and Domains Seized

The operation targeted several servers and domains of the VPN service, which also offered bulletproof hosting. U.S. authorities also seized several servers and have assumed control over three associated domain names: INSORG.ORG, SAFE-INET.COM and SAFE-INET.NET.

The domain names all show a seizure banner now complete with the badges of the various enforcement agencies that contributed to the operation. A screenshot copy (via) of the working INSORG site shows that it offered various VPN, proxy and anonymizer options.

operation nova

At first sight, it's quite an unprecedented move to take down a company that does what every good VPN is supposed to. That is, protecting the privacy of its users. However, it appears that Safe-Inet went further than that.

"Designed to Support Crime"

Commenting on the matter, the US Department of Justice notes that so-called "bulletproof" services are "intentionally designed" to provide hosting or VPN services to criminals.

"These services are designed to facilitate uninterrupted online criminal activities and to allow customers to operate while evading detections by law enforcement. Many of these services are advertised on online forums dedicated to discussing criminal activity.

"A bulletproof hoster's activities may include ignoring or fabricating excuses in response to abuse complaints made by their customer's victims; moving their customer accounts and/or data from one IP address, server, or country to another to help them evade detection; and not maintaining logs."

The Justice Department says that by acting in this manner, these companies knowingly aid and support the criminal activities of their customers, which makes them liable as well.

Needless to say, this enforcement action and the comments that come with it will create a lot of uncertainty among VPN providers. There are dozens if not hundreds of VPN companies that don't keep logs, and some of these are undoubtedly used by criminals as well.

Advertising in Shady Places

While further details about the investigation have not been revealed, we expect that Safe-Inet was not just any regular VPN provider. The Justice Department claims that it was actively helping and advertising to criminals. That changes things.

When we searched through a few forums where stolen credit cards are traded, Safe-Inet and associated names indeed showed up to market its services.

"We are happy to announce you about our elite level of service for high anonymity in the Internet network from insorg.org company, on advert reads, with another one mentioning that they don't record logs and never show the real IP-address.

insord ad

Needless to say, Operation Nova comes as a shock to the VPN industry, but regular VPNs don't advertise in these places.

The i2Coalition, which includes several prominent VPN services among its members, says it supports the law enforcement action. While many of its members don't keep any logs, they do what they can to deter criminal abuse.

"Any technology can be misused, and the overwhelming majority of VPN usage is for legal and legitimate purposes, and millions of consumers and businesses rely on VPNs for essential online protection," i2Coalition notes.

VPN services won't be rendered illegal anytime soon, but those who advertise their services on criminal platforms or knowingly help dodgy customers could be in trouble. The problem is, however, that it's not entirely clear where the line is drawn.

From: TF, for the latest news on copyright battles, piracy and more. We have some good VPN deals here for the holidays.

EU Opinion: Abusive BitTorrent Copyright Trolls Should Be Denied Access to Subscriber Data
Andy Maxwell, 24 Dec 09:49 AM

EU CopyrightThe term 'copyright troll' is regularly used to describe companies and entities, largely in the video entertainment industries, that target alleged file-sharers for cash settlements.

In the main, these companies prefer not to enter into adversarial legal action for various reasons, mostly related to the profits to be made from additional sources of relatively easy settlement revenue.

However, their often complicated business structures have the potential to undermine their own schemes, as an ongoing case involving a well-known troll illustrates.

Mircom Background

Cyprus-based Mircom International Content Management & Consulting (Mircom) is a well-known entity in the world of copyright trolling. Acting as a middle-man between rightsholders and legal action against alleged pirates, the company is no stranger to obtaining cash settlements while simultaneously causing legal controversy.

In the summer of 2019, the High Court in the UK threw out its efforts to obtain the identities of Virgin Media customers and as reported this week, the company is now under fierce scrutiny in Denmark after filing cases that it had absolutely no right to.

However, it's a separate matter in Belgium that now has the company under considerable pressure, one that has the potential to cause even wider disruption to the troll business model.

ISP Pushes Back Against Mircom Demands For Subscriber Data

In 2019, Mircom demanded that Telenet, the largest provider of cable broadband in Belgium, should hand over the personal details of subscribers behind thousands of IP address alleged to have downloaded pornographic movies using BitTorrent.

At the Antwerp Business Court (Ondernemingsrechtbank Antwerpen) Telenet, along with ISPs Proximus and Scarlet Belgium which received similar demands from Mircom, fought back in an effort to protect their customers.

As part of that process, several questions were referred by the local court to the EU Court of Justice for clarification.

These included questions over the nature of BitTorrent, which enables users to download and upload pieces of files, essentially fragments of a copyright work, which in non-complete form are unusable. Does this constitute communication to the public within the meaning of Article 3(1) of Directive 2001/29, (1) and if so, is there a minimum threshold?

Second, if users are unaware that they are automatically seeding full copies after downloading, is that relevant?

Finally, does an entity that is a contractual holder of a copyright (licensee) but does not exploit those rights other than to benefit from piracy by collecting money from settlements, have the same rights as rightsholders who utilize copyright protections in the normal way? If so, how can they have suffered 'prejudice' as a result of infringement?

EU Advocate General Szpunar Publishes Opinion

More than a year after the referral, the 62-page opinion of Advocate General Szpunar had now been published and is notable for both its impressive detail and the immediate labeling of Mircom's conduct as the classic behavior of a "copyright troll". Szpunar then goes on to demonstrate an impressive knowledge of BitTorrent before dealing with the concept of "making available" under EU law.

BitTorrent-Specific Questions

"The arguments raised by Telenet, Proximus and Scarlet Belgium that the pieces exchanged on peer-to-peer networks are not parts of works which enjoy copyright protection are…unfounded," Szpunar writes.

"Those pieces are not parts of works, but parts of files containing those works. Those parts are merely the mechanism for transmitting those files under the BitTorrent protocol. However the fact that the pieces which are transmitted are unusable in themselves is irrelevant since what is made available is the file containing the work, that is to say the work in digital format."

On the question of whether it's relevant that users may be unaware that they are seeding/uploading, Szpunar says that specific know-how is required to configure torrent clients, information that is widely available via Internet tutorials. He's not convinced that users are unaware of the uploading component but whether they are or not, downloading unlicensed content is also illegal.

In any event, full knowledge of how things work is not required for there to be an act of unlicensed making available.

"Accordingly, by offering the possibility to download pieces of files containing copyright-protected works from their computers, whether at the time that those files are downloaded or independently of that download, the users of peer-to-peer networks make those works available to the public within the meaning of Article 3 of Directive 2001/29," Szunar notes.

"I therefore propose that the answer to the first question referred for a preliminary ruling should be that Article 3 of Directive 2001/29 must be interpreted as meaning that the act of making pieces of a file containing a protected work available for download within the context of a peer-to-peer network, even before the user concerned has himself downloaded that file in its entirety, falls within the scope of the right to make works available to the public in accordance with that article, and that user's knowledge of the facts is not decisive."

Mircom's Standing As a Copyright Troll

In dealing with Mircom, Advocate General Szpunar begins by noting that the company is not a copyright holder but claims to have obtained licenses to communicate certain copyright works on P2P networks. However, Mircom does not exploit those licenses in a way a regular rightsholder usually does.

"It therefore appears that Mircom's conduct does indeed correspond to that of a copyright troll. However, that concept is unknown in EU law. Moreover, Mircom's conduct is not illegal per se," Szpunar writes.

Nevertheless, that doesn't necessarily mean that its current business model is acceptable.

"The EU legislature's aim was to give licensees an instrument to protect the normal exploitation of their licenses, whereas Mircom's aim is solely to punish infringements of the copyright and related rights and to obtain a financial advantage from them. That conduct would therefore fall under the definition of an abuse of rights which is prohibited under EU law.

To determine whether abusive conduct exists, national courts in the EU must carry out an assessment of the relevant facts on a case-by-case basis, Szpunar says.

"If [a court] were to find that Mircom is effectively trying to misuse its licensee status in order to benefit from the measures, procedures and remedies provided for in the provisions adopted in the transposition of Directive 2004/48, that court should then refuse to grant it the benefit of those measures, procedures and remedies in so far as that benefit is based on licensee status," he adds.

In other words, courts all around Europe need to take much closer interest in these cases to ensure that entities like Mircom really do have the rights to obtain the details of Internet subscribers.

While Mircom's shortcomings in the UK were exposed by Virgin Media and are now under the microscope thanks to Belgian ISPs, Danish courts were initially all too quick to rubberstamp the company's applications for personal data. As a result, large numbers of people paid cash to settle cases that should have never been brought.

The big question now is whether courts elsewhere in the EU will look again at the activities of Mircom and similar companies to determine whether abusive conduct led to unlawful disclosure of customer data and, if so, how things may be put right.

The Advocate General's opinion is not binding but in most cases the EU Court of Justice adopts such recommendations in its final decision.

From: TF, for the latest news on copyright battles, piracy and more. We have some good VPN deals here for the holidays.

 
 
Powered by Mad Mimi®A GoDaddy® company

No comments: