HARRY (CEO) PUBLICLY CONFESSES THAT “NO ONE CAN GUARANTEE THE ABSENCE OF LOGS”
His lethal contradictions condemn the company itself with his own words, but, at the same time, he is telling the public the reality that something serious is happening internally within the company.
What is happening? is a deep question, but I don’t have the fundamental data since I don’t have internal access to the company. Nevertheless, Harry and Alexis are two extremely contradictory individuals (both confessed publicly).
Possible strange question: Is this a game, or is what’s happening actually serious?
I’m inclined to believe it’s real.
The website has heavily inflated and highly deceptive advertising, not just in one single place called a “guarantee.”
Unfortunately, I haven’t been able to find that “person” right now who, according to Harry, was expelled, in order to get their testimony. It’s highly likely that this person doesn’t exist; it must be an excuse to make people believe in something that currently has no basis. Does a person exist or not? With so many contradictions between the Nym team and its website, suspicions are extremely high.
They kicked me out of their Telegram group; on the one hand it’s better, because it reveals more of what they say.
Casey Ford (Admin) replied to me when I responded to Harry, but I ignored him; it’s just noise now. I don’t know if he’s aware of, or oblivious to, the true knowledge of the military’s technological force regarding its advancement and what exists in private (not visible to the public).
Below are the messages between Harry and me:
- Harry (CEO Nym):
No one can guarantee zero logs and anyone that says they are “guaranteeing” zero logs and so forth is lying. A adversary can easily log information such as timing and volume WITHOUT even having to compromise a machine. Nym solves that by decentralization and adding fake traffic/timing delays (i.e. mixing). Also, for any centralized VPN, a govt. can force a backdoor (and even make it illegal to talk about it or ask a lawyer, see FISA national security letters and the Nick Merrill case).I have no idea what you mean about “new claim” but technology isn’t magic, however, we do think we do a better job than any centralized VPN or even Tor in defending our claims technically. As for word choice issues by our marketing people, we fired the guy that wrote some of it as he wasn’t very good, and @sallysundries can sift in. If anyone wants to run a node, they surely can - that’s decentralization. No one needs a license. That being said, if you don’t want to run one and aren’t comfortable with the legal risk don’t run one.
To repeat: Privacy is a holistic property. Transparency is gained by looking at source code, compiling it yourself, and so on. In terms of security, it’s always relative to an adversary, and Nym and mixnets in general are built to combat a global passive adversary that watches every packet and records it. Others may think this adversary is unrealistic. See here: https://academic.oup.com/cybersecurity/article/11/1/tyaf006/8097877
- Yo (DanielM):
Exactly, and your website says the opposite about the logs—why didn’t Casey update it at the time when he removed the rest and added new text? Read on below.
Audits won’t help you down the road, Harry; those guarantees stated on your website are the company’s downfall:
- Down the road, a zero-day exploit could emerge and compromise something—for example, security.
- An APT may or may not have been operating on your network of nodes for some time, adapting in real time.
- The NSA (as well as other authorities in other countries) is dynamic and possesses technology that neither Nym nor the public is aware of; therefore, it’s unclear whether the “mixing” is still useful, only partially effective, or, in general, just a matter of probability (luck).
- etc.
Your nodes are also vulnerable and could (if they currently exist) be compromised by sophisticated malware, and the people who connect to them could be affected. That’s the reality, Harry.
The point I’m making is that that part of the site is rife with misleading advertising (the URL cited earlier in my response). You’re speaking technically, but someone with a high level of cybersecurity expertise and knowledge of real-world facts wouldn’t say the same thing. You’re being too overconfident.
Can you tell me who that fired person is (if they even exist), or is that confidential information? I’m interested in hearing their account. What I see here is that the company itself isn’t on the same page, and the problem is obvious from the outside. Suspicions are already running high.
And my questions remain unanswered.
For the record: I’ve reported the matter to the FTC and SECO.
End of messages.
Why haven’t they answered me yet, not even question 3 (how does Nym protect people from real adversaries on its nodes) that I asked, and neither of them responded? It’s very simple: their terms of service put the blame on you:
- If an exit node logs your data or manipulates your traffic, for example: advanced phishing… It’s your fault, not the company’s.
- If a node logs your IP and sends it to an unknown destination for real-time monitoring with all data included, whether encrypted or not, it’s your fault, not the company’s.
- If the mob hires adversaries with APT (Advanced Persistent Threat) capabilities among the nodes and something happens to a genuinely innocent person within 4 weeks, it’s that person’s fault, not the company’s.
- … (continues).
Don’t trust NymVPN; if something happens to you later, they’ll blame you and the company will wash its hands of it. Of course, you have every right to report the company for fraud and public manipulation, but you need irrefutable proof of what happened to you.