Thursday, January 31, 2019

If you are using a free VPN,THEN YOU ARE NOT SAFE

The reason is simple – many of them simply sell your data to 3rd party advertisers.

And this defeats the whole purpose of having a VPN in the first place.

But there’s more:

1. Many free VPN services are not transparent about how they make money from you using their services; in most cases, when you’re not being sold a product you are most likely the product.

2. Most free VPNs simply sell your data to affiliated/partnered companies or to the third party who is willing to pay the most.

3. Some free VPNs have gotten caught using shady practices like injecting ads, referring affiliate traffic and more (more info can be found on the CSIRO research and FTC complaint against a free VPN).

9 Popular Free VPN Services That Can Sell Your Data

The following free VPNs can sell your data to 3rd parties (according to their privacy policy)

Hola
Betternet
Opera VPN
HotSpot Shield
Psiphon
Onavo Protect
ZPN
FinchVPN
TouchVPN
There are probably more as many free VPNs aren’t really upfront about how they make money. Below are the ones that admit selling or sharing your data (or aggregated data sets) to third parties:

1. Hola (Free VPN, 10+ Million Users)

“We may share “Anonymous” information with third parties…”
“We may share your email with our marketing partners…”
“You may be a peer for Luminati network…”

Hola VPN shares your data with 3rd parties
Unlike other free VPNs, Hola gives you unlimited data without displaying ads — no wonder 152 million people use their service. Unfortunately, like mom told you, if it sounds too good to be true, it most probably is.

A group of security researchers discovered multiple flaws in Hola and found that they aren’t as noble as they claim.

Besides the fact that Hola turns your computer into an exit node, they also sell access to your computer and network to third-parties through their commercial brand, Luminati. How do you opt out of this? There’s only one way: by subscribing to their premium subscription (proving once again that nothing good comes free).

It even gets worse: it was proven that Hola can be exploited to allow anybody to execute programs on the computers of its users.

In Hola’s defense, they were at least upfront in their privacy policy. They even made it clear that they may share your email with their marketing partners.

HOLA VPN sharing your info

They also make it clear in their TOS that by using Hola you become a peer on their paid Luminati network — in other words, access to your computer could be sold to people paying to use their services:

Hola VPN uses you as a peer

Here’s exactly how Hola makes money on you:

They share your email with their marketing partners.
They sell your traffic to users of their business arm, Luminati.
They can share your “anonymous” information with third parties.
They sell access to your computer and network – making it serve as an exit node through which other users (including people paying them) can access the Internet – although they didn’t indicate this on their website, it has been widely reported (since 2015) by reputable media publications.
2. Betternet (Free VPN, 38 Million Users)

“Advertisers may also place cookies in your browser that may allow them to collect certain information about your browsing history…”

Betternet adds advertisers cookies
If you’ve done more than a few minutes of research about free VPNs, you’ve probably come across Betternet. This VPN service recently came out of nowhere to become one of the leading free VPN service providers. They now boast over 38 million users. They make it clear that they make money by offering free sponsored apps and by displaying video and other ads. They also allow advertisers to track and log information of users of their free VPN:

Worse, the CSIRO research paper on free VPN apps found that Betternet has the highest number of tracking libraries of all free VPN services (14 in total).

Here’s exactly how Betternet makes money on you:

By allowing advertisers to track and log your data – basically giving them carte blanche access to as much of your information as they need.
By allowing advertisers to include cookies in your browser.
By displaying ads, including sponsored apps, videos, and other types of ads.
3. Opera VPN (Free VPN)

“Our services include third-party technology or code that may use the collected data. We may share anonymized data and/or aggregated sets of data with our partners…”

OperaVPN shares your data with 3rd parties
Opera’s free VPN is a free VPN service that comes embedded in the Opera browser: you install the browser and have access to the free VPN service.

On the surface, the “catch” of the free VPN seems to be simple: to drive adoption of Opera’s browser. We wish it were that simple!

Research shows that Opera’s free VPN actually engages in other practices to make money off their free VPN user. Their privacy policy makes it clear that they share your data with third-parties and allow third-party services to monitor your data.

Here’s exactly how Opera VPN makes money on you:

By sharing your data with third-parties and marketing partners.
By allowing advertisers and marketing partners to track your data.
4. HotSpot Shield (Free VPN, 500+ Million Users)

Can share your information with their “ad partners”

Hotspot shield data selling policy
With over 500 million users, Hotspot Shield is undoubtedly the most popular free VPN service.

When you have that many users, you have data that is a potential goldmine for advertisers… and Hotspot Shield is certainly not just being charitable by providing free VPN to hundreds of millions of people.

They make money off users in a lot of ways:

While Hotspot Shield makes it clear in its terms of service that it displays ads to users of its free VPN service, it is not very upfront about the fact that it makes money off users through other unscrupulous means.

Less than a year ago, The Center for Democracy and Technology issued a complaint to the FTC claiming that Hotspot Shield not only shares data of its free VPN users, but it also redirects their traffic to third-party affiliate sites.

Here’s how Hotspot Shield makes money on you:

May share your data with 3rd parties.
By redirecting your traffic to affiliate partners (FTC Complaint in 2017).
By displaying advertisements in front of apps and websites you use.
By setting you a data cap of 500Mb/day.
5. Psiphon (Free VPN, 1+ Million Users)

“We may use technology such as cookies and web beacons. Our advertising partners’ use of cookies enable them and their partners to serve ads based on your usage data…”

Psiphon data sharing policy
When it comes to the free VPN game, Psiphon is no newbie. They’ve been offering their free VPN service since 2008, which is a long time in the Internet age. However, they support their ability to offer this free VPN by sharing your data with advertisers and letting advertisers track your data usage.

While they generally defer to their advertising partners’ privacy policies, the policies of these partners show that they do use and share your data. With annual revenue estimated to be over $2.2 million, Psiphon sure seems to be making some money!

Here’s exactly how Psiphon makes money on you:

By sharing your data with their advertising partners.
By allowing their advertising partners to track your Internet usage.
By displaying ads to you.
6. Onavo Protect (Free VPN)

“We may share (or receive) information, including personally identifying information, with our Affiliates…”

Onavo Protect policy
Onavo Protect is a VPN service owned by Facebook. Facebook has been in the middle of several scandals relating to how they collect and use user data, so it won’t be surprising to find that Onavo has the same issue — they were recently in the news due to their data usage practices. Onavo makes it clear from the get-go that they do log user data and share this information with third-parties:

Here’s exactly how Onavo Protect makes money on you:

They share your information with affiliates and third-parties.
They use your information for several purposes including advertising and marketing purposes.
They display ads to you.
7. ZPN (Free VPN, 8+ Million Users)

 “May share, sell and rent your personal information with affiliated companies/people..”

How ZPN sells/shares your data
With more than 8.2 million users, ZPN is certainly not a free VPN service you can ignore. The 10GB monthly data they offer is generous compared to what is offered by other VPN services.

According to them, they won’t share your data with “non-affiliated” companies unless under conditions including…

Read that again.

What about “affiliated” companies?

According to their Privacy Policy, they seem to do that…

Here’s exactly how ZPN makes money on you:

There’s a high possibility of sharing your data with their partners.
By limiting your monthly data to 10GB per month in order to get you to upgrade to a paid plan.
By limiting your bandwidth in order to get you to upgrade to a paid plan.
By disabling P2P (and torrenting) and limiting your access to five locations in order to get you to upgrade to a paid plan.
8. FinchVPN (Free VPN)

“We may share with third parties certain pieces of aggregated information…”

FinchVPN data sharing policy

FinchVPN seems more secure than most free VPN services. They have a generous 3GB monthly data and seem to take user privacy more seriously than most free VPN services. However, they limit the number of servers you can access in order to get you to upgrade.

They may also share data of user activity with third parties.

Here’s exactly how FinchVPN makes money on you:

They may share aggregate data of users with third-parties.
They limit your monthly data to 3GB and restrict the number of servers you can access in order to get you to upgrade to a paid plan.
9. TouchVPN (Free VPN)

“We may share your “anonymous” information with third parties, for additional purposes, including marketing…”

TouchVPN data sharing policy

touchvpn marketing
TouchVPN is another shady, free VPN that adds Cookies, Pixel Tags, and Web Beacons to your browser while you use their service.

Though they are some-what upfront about sharing your “anonymous” data with third parties for marketing purposes.

Sadly, they don’t elaborate much on “anonymous data”.

10. Private Pipe VPN (Free VPN)

“We may share “personal data” and “anonymized information” with affiliated and non-affiliated third parties…”

Private Pipe VPN promises “a simple, no nonsense, VPN” that offers completely free service, unlimited data, and malware protection without requiring its users to have any technical knowledge. However, in their privacy policy, they do not hide the fact that they make money by sharing/selling user data:

privatepipevpn privacy policy 1

Now, while they claim that personal identifiers are removed in data they share/sell, another part of their privacy policy indicates that they may share “personal data” with affiliates — whatever that means!:

Privatepipevpn priacy policy 2
Image from: https://www.privatepipevpn.com/privacy-policy-us.html
Here’s exactly how Private Pipe VPN makes money on you:

By selling/sharing your data with advertisers.
By displaying targeted ads when you browse websites using their app.
11. #VPN by Apalon (Free VPN)

“We may share “aggregated information”… with third parties, including advisors, advertisers, and investors…”

With over 5,000 ratings on the Apple store, #VPN is one of the more popular free VPN services available to Apple device users. It promises multiple virtual locations and unlimited data to enable you access websites and apps privately. However, besides the fact that ads and in-app purchases are offered to users of #VPN, they also make it clear that they may share your information with third-parties:

#VPN by Apalon privacy policy

Now, while they claim they only share aggregate information, they collect so much more information that it’s worrisome. #VPN collects the following information:

your timestamp
device information
location data
service provider information
hardware device information
they may also collect your movement data.
That’s more than is necessary for a free VPN app!

Here’s exactly how #VPN makes money on you:

By sharing your information with advertisers and third-parties
By displaying ads to you
By offering in-app purchases to you
12. Tuxler (Free VPN)

“We also share “technical data” that we collect about your browsing habits and your device…”

“Here at Tuxler, your privacy is our business – not someone else’s,” Tuxler boldly states on its homepage. But really?

While Tuxler touts the fact that users of its free VPN service can choose from “millions of locations,” we had to dig deeper to see what the catch is. We didn’t have to dig too long. It’s right there on their privacy policy page: they share data about your browsing habits and your device with advertising companies in order to allow them target ads to you.

Tuxler privacy policy

Here’s exactly how Tuxler makes money on you:

By sharing your data with advertisers and third-parties.
By displaying advertisements to you.
13. GO VPN (Free VPN)

“We also cooperate with a third party in various ways to utilize data collected, processed and handled…”

If you’ve tried looking for a free VPN app on the Google Play Store before, you’ve most likely come across the GO VPN app offered by the VPN Master team. Like almost every other free VPN, this app promises unlimited data with no registration or settings. All you need to do is “install and push the ON” button.

Unfortunately, our investigation revealed that there is something sinister going on: The high number of permissions required should be the first red flag. This app requires the following permissions:

Access to your device and app history
Access to read your phone status and identity
Access to read, modify and delete your phone media
Access to read your phone status and identity
Access to check your Google play license
Access to prevent your device from sleeping
We believe that’s too much access for a VPN app, but some extra digging makes clear why: The GO VPN app is offered by Talking Data, a Chinese big data company that sells data and information to willing buyers, and their privacy policy makes it clear that when you use their apps you are giving them permission to share/sell your data to their partners, and that they will use your information to build their data database:

Talking Data privacy policy
Here’s exactly how GO VPN makes money on you:

By selling/sharing your data with third parties for marketing purposes.
By displaying advertisements to you when you use their free VPN.
14. Hexatech (Free VPN)

Hexatech promises 100 percent free unlimited VPN access to users — and with over 1 million installs there must be a catch!

Hexatech was created by Betternet, one of the major data abusers on our list. Don’t let the fancy name deceive you, though! Hexatech is governed by the same principles and privacy policies as Betternet, and the same rules apply: they allow advertisers to track and log your data and do with it whatever they please.

Here’s exactly how Hexatech makes money on you:

By allowing their advertisers to track and log your data — and to use your information however they deem fit.
By displaying ads — including sponsored apps, videos, and other types of ads.
We Don’t Recommend Using FREE VPNs

Besides the obvious, using you as a product, free VPNs often go an extra mile to get more money from you.

Despite advertising themselves as “free VPNs”, they often set a very low data cap (bandwidth) so you can only use their service a few hours a month. Common data caps are 250mb/day, 500mb/mo, 2GB/mo and 10GB/mo.

Many free VPNs like TurboVPN and Betternet also include additional ads in your browsing activity.

Last, but not least, the vast majority of free VPN servers are overwhelmed with other folks who make your browsing (or streaming) activity extremely slow.

Free VPNs also tend to leak your DNS and keep your log files.

In a nutshell, if you want to stay secure and safe, free VPNs aren’t the best option. You’d be better off relying on your ISP instead of a sketchy, money-hungry VPN provider

No comments:

Post a Comment