I compiled the messages as texts, not screenshots. I organized them to be clear and easy to understand, without any beating around the bush.
The most interesting thing, within Nym’s own sphere of influence, is that the administrator started attacking me. What did I do? I used his own arguments against him and at the same time pointed out that he was contradicting the word “guaranteed,” which Nym itself claims to uphold.
Arguments.
Is no one going to answer my legitimate questions?
I don’t speak Spanish but I can guess. In effect, there are no 100 percent guarantees in security and anonymity, but due to adding fake traffic and mixing traffic Nym is the only VPN that protects against a global adversary like the NSA or Palatir. To use that, you must use 5 hop mode.
Why guess? Use a translator like I do; it’s the only way I can understand anything in other languages.
If it’s the only way, do you have irrefutable proof based on real facts?
Translators are not 100% accurate; have you had the chance to read through the whitepaper? Everything the mixnet does is explained pretty thoroughly here:
https://nym.com/nym-whitepaper.pdf
Section 4 fyi
I know it’s not 100%, so why is the website multilingual? It’s strange.
The white paper doesn’t help me; it’s not irrefutable proof. What I’m looking for is based on the “guaranteed” privacy, as argued on Nym’s official website as irrefutable proof of how well it actually protects users in real-world situations.
Based on real-world experiences is what I need, and after searching the official website to a certain extent, I haven’t found it.
If you have it, could you share it with me?
That’s why it’s important to understand the questions I posted earlier in Spanish, unless the company has people who can translate accurately into English.
I think the privacy and anonymity aspect, same as with Tor, comes to the point if you use it with the right software clients and Nym components properly. This is not much discussed, because the Nym team focuses primarily on the Network infrastructure and NymVPN app and there are no use cases or tutorials from them availabe how to properly protect Nym users, from various threats.
Real-world protection can’t be absolute (same as it’d be for any other VPNs). It depends on what you’re up against, your device’s security, and some factors outside Nym’s control, like @Ch1ffr3punk said. If you’re looking for case studies, those simply don’t exist but do let us know if you come across any other VPNs you that have published content like this.
What Nym does guarantee is strong technicals. Anonymous mode(Mixnet+cover traffic+timed delays) is designed to resist traffic analysis in ways a standard VPN cannot. The code is open source, and backed by academic research. All papers and audits are available on the trust centre: Trust Center | Nym
So, if they “guarantee” it, as you’ve said, how do they back up that argument in real-life situations of harassment on both sides: in real life and online?
Because, for example, does someone who genuinely needs a VPN tool in an emergency “guarantee” it?
I like to make a little proposal. Maybe the (external)
Advisors, like Chelsea, DJB etc. can in the future show us some protection examples, when it comes to Online Privacy/Anonymity, similar to what EFF and others do with their tutorials.
It’d depend on the particular cases - there are n number of possibilities regarding how your anonymity could be compromised. For example, Nym or any other VPNs can’t protect you from a compromised device, logging into websites that already know who you’re, browser fingerprinting etc. the protection is for the network layer only and nowhere on the website/the documentation do we claim otherwise
I’m aware of the example you gave, so here’s my recommendation for Nym:
If you don’t have real proof, replace the word “guaranteed” with something you can actually demonstrate.
Be humble and honest, then.
Remember that there are threats like APTs (Advanced Persistent Threats), etc.
Furthermore, it would be interesting if you published a document explaining how Nym protects legitimate users (if any exist) of your service against infiltrations using “sham” nodes—in other words, veteran hackers, organized crime, etc.—who infiltrate to carry out their activities silently.
Your comments sound increasingly hostile for what wasn’t a false claim to begin with. Network level privacy is what Nym is for. Nowhere on the website is it advertised as a one-button magic solution that makes you anonymous instantly.
It does look like you’ve made up your mind/just want to spread FUD here as I saw your thread of privacy guides too (Lots of them commenters tried to explain it to you, and we’d be happy to respond there but you’ve closed the thread since
)
Analysis of Nym VPN and its "guaranteed" privacy
that said, this
does sound like a cool idea to give nymsters guides for good privacy practices/setups in general
Regarding this, Nym’s research does not assume all nodes are honest. and there’s plenty of theoritical proof to support that a full-scale compromise of the network can’t be accomplished under real work circumstances.
If you’d like to read through the documentation that supports these claims, you can read through the papers from our research team here. Listing some sections below that’ll be relevant:
-
Nym whitepaper (section 4, 6)
-
Reward Sharing for Mixnets: pg 16 sybil resilience discussion
-
The Loopix Anonymity System: 3.2 Format, Paths and Cover Traffic
-
The Loopix Anonymity System: 4.2 Active-attack Resistance
-
(Yo) :
Who are you afraid of? It’s not what you’re accusing me of, and it’s strange that someone with the title of administrator would behave this way.
Go ahead, if you’re willing to respond in the forum, I won’t stop you. But what is clear is that an administrator has accused me of something I haven’t claimed.
I never said anything about being “magical.” You yourself are demonstrating in your messages that they contradict the word “guarantee” and the company that claims to offer it. Whether you’re doing so consciously or unconsciously.
So, if it’s “theoretical,” it means it’s “luck,” and in the argument in session 2 of the PDF security file, you use the word “probabilities.”
File mentioned:
Are continuous stop-and-go mixnets provably secure?
Published: Proceedings on Privacy Enhancing Technologies (PoPETs)
Date: 2024
Authors: Debajyoti Das, Claudia Diaz, Aggelos Kiayias, Thomas Zacharias
To use the word “guaranteed,” regardless of the industry—privacy, security, food, etc.—requires irrefutable proof based on real-world facts, not laboratory experiments or paperwork.
Therefore, if there is no real proof, then, as I stated in the thread you shared, it’s “luck,” and the more luck, the lower the “probabilities.”
I offered my recommendation; if the company decides to accept it, great, but if not, it’s already mentioned in the forum thread.
Furthermore, the server can be attacked by an APT from within or without. If the server is hacked and the attacker can see the work being done—for example, just one instance—the “guarantee” is false, and it’s not the fault of the legitimate user.
That concludes my message. My questions remain unanswered; if the Nym team decides to respond, great.
- Silence. No more answers.
The company has to make a decision; I’ve already done my part.
Those who decide to buy the service and stay, I won’t stop them, but they need to know something fundamental:
→ I completely reject the system Nym uses for cryptocurrencies (and cryptocurrencies in general), and I don’t trust the company at all. Why and how? I don’t like the aforementioned system; I prefer simplicity, and it’s not a suitable tool for me. I’ve already mentioned this throughout the report (above) and here (below).
Beware of pretty words.
And if the company ever decides to answer my questions… then I could see their arguments and make a decision.