# Why is VPN providers like Cryptostorm or OVPN not recommended

**URL:** https://discuss.privacyguides.net/t/why-is-vpn-providers-like-cryptostorm-or-ovpn-not-recommended/13061
**Category:** General
**Created:** 2023-07-02T14:57:18Z
**Posts:** 16

## Post 1 by @KredesX — 2023-07-02T14:57:18Z

Pretty much title. Both providers seem to be very privacy focused etc, and trusted.. at least OVPN. Cryptostorm seems to have been through some controversy, with one of their “staff” members or whatever, and accusations of being a honeypot, even though i can’t seem to find any proof on that.

---

## Post 2 by @dngray — 2023-07-02T16:48:59Z

> [@KredesX](#):
>
> and trusted

By whom, they don’t have any infrastructure audits audits, and ovpn has no source code for their clients.

---

## Post 3 by @moonwriting — 2023-07-02T17:01:54Z

Here is one good reason.

> **[Next chapter for OVPN](https://www.ovpn.com/en/blog/next-chapter-for-ovpn)**
>
> It is with great pleasure that we can open our doors and take our first step on a new and exciting journey. One filled with new experiences and opportunities.

---

## Post 4 by @dngray — 2023-07-02T17:27:25Z

That blog post literally looks like marketing fluff.

---

## Post 5 by @KredesX — 2023-07-02T17:43:20Z

That’s a good point.

---

## Post 6 by @moonwriting — 2023-07-02T19:39:48Z

Yes you’re right, but my point was mainly to point out that OVPN has been acquired by Pango, a company who owns other, not very trustworthy VPN companies and thus, it adds another reason why OVPN should not be listed.

---

## Post 7 by @root — 2023-07-03T07:52:18Z

Pango is the owner of Hotspot Shield (VPN), [Identity Defense](https://identitydefense.com/) (data aggregation service/broker), VPN 360, Ultra VPN, etc.

Sounds like they buy honeypots.

I want to provide proof, to back up my claims, so here it is. Black and white.

- Owns Hotspot Shield VPN (AnchorFree) - [https://www.corporationwiki.com/California/Sunnyvale/pango-inc/44270431.aspx](https://www.corporationwiki.com/California/Sunnyvale/pango-inc/44270431.aspx)

- He has lectured to government contractors at the Technical Training Centre, Chennai Chengalpattu (Tamil Nadu, India) - [https://in.linkedin.com/in/ravichandran-g-a8a1a391](https://in.linkedin.com/in/ravichandran-g-a8a1a391)

- “Hari Ravichandran … is CEO and Founder of Jump Ventures, a scalability infusion firm … and also the CEO and Founder of Aura a technology company dedicated to simplifying digital security … Hari has founded successful businesses focused on technology-enabled services and web security …” — funded by Indian and US government-owned property manufacturers. - [About Hari Ravichandran - Hari Ravichandran](https://hariravichandran.com/about-hari-ravichandran/)

- “AnchorFree, the company that makes the popular Hotspot Shield virtual private network (VPN) software, on Wednesday announced that it raised $295 million in a new funding round.” — [https://www.securityweek.com/vpn-company-anchorfree-raises-295-million/](https://www.securityweek.com/vpn-company-anchorfree-raises-295-million/)

- The CSO /Co-founder Eugene Malobrodsky was engineer at SimulTrans which facilitates localization of and testing of government materials

- Partnered w/ Sujay Jaswa, (silent investments and known investments)

- Sujay is one of Silicon Valley’s leading business innovators, and oversees WndrCo’s investment and operating activities. [https://www.wndrco.com/partner/sujay-jaswa](https://www.wndrco.com/partner/sujay-jaswa) He makes Ventures and Growth investments, and creates companies through Venture Buyouts. He serves as Chairman of Aura, Twingate, and Super Unlimited, and led WndrCo’s investments in Figma, 1Password, Databricks, Pango, Pilot, Rally, Zagat / The Infatuation, etc.

- “AnchorFree was accused last year by the Center for Democracy & Technology (CDT), a nonprofit technology advocacy organization, of collecting user data through Hotspot Shield and sharing it with advertisers.”

- “Earlier this year, a researcher disclosed the details of a vulnerability that exposed the names and locations of Hotspot Shield users. The expert made his findings public after claiming that the vendor ignored his attempts to report the flaw. A patch was released a few days later.”

At the very least, this means both Hari and Sujay have partnered with venture business capitalists whom purchase businesses, and either flip them, or build them into other venture business capitals. They buy companioes and use them to either purchase other companies or sell them to make seed money for other projects, which all seem to have the WORST privacy policies, facilitating stealing and selling user data, up to and including browsing history, ad preferences, location data, names and addresses, phone numbers, usual PII. They have a LONG history of buying from weird companies that are paid for in seed funding rounds by shady companies that also have bad track records of selling user data, just like them.

It’s clear that they have incompetent partners, as well as staff, because despite being a comp sci major, Hari seems to hire ex-contractors for governments of both India and the US, who have little experience in their fields.

---

## Post 8 by @Ganther — 2023-07-03T21:09:54Z

OVPN was sued a few years ago and proved in a Swedish court that they don’t and can’t store any logs.

> **[Swedish Court rules OVPN doesn't have to hand over logs](https://proprivacy.com/privacy-news/privacy-victory-ovpn-no-logs-policies)**
>
> A Swedish court has ruled in favor of OVPN, ruling that the VPN provider doesn't have to supply logs of a user believed to be involved with The Pirate Bay.

But as mentioned above I find it odd that they focus heavily on transparency and then… They don’t open source their apps.

---

## Post 9 by @dngray — 2023-07-04T07:49:10Z

> [@Ganther](#):
>
> few years ago

Or maybe they said they didn’t who really knows, either way an infrastructure audit also checks security related stuff, for example against infiltration and exfiltration of data from the company.

In any case, being to court and saying you can’t provide something isn’t the same thing as attestation from a third party.

---

## Post 10 by @Ganther — 2023-07-04T08:17:23Z

Indeed, but IMO it makes the company stick out compared to the countless of other corporations that run a VPN that has neither open source nor a court order to back up their no-logging policy.

I also think there’s a bit more to it than OVPN simply claiming that’s the case:

> **[OVPN wins court order](https://www.ovpn.com/en/blog/ovpn-wins-court-order)**
>
> We took the case incredibly serious as it sets a precedent in terms of logging requirements on Swedish VPN services. Today, the Court reached a decision.

> To summarize the verdict, the Rights Alliance and their security experts have not been able prove any weaknesses in OVPN’s systems that could mean that logs are stored. OVPN therefore wins the information injunction as our statements and evidence regarding our no log VPN policy have not been disproven. The movie companies also need to pay OVPN’s legal fees which amounts to 108 000 SEK (roughly $12300 at current exchange rate).

I’d still recommend Mullvad over this.

---

## Post 11 by @viktorivpn — 2023-07-05T19:50:18Z

I would add that any court case, criminal investigation documents and server seizures (see Express in Turkey in 2017) should be treated similarly to “no-logs audits” when considering it as a trust signal. It can be useful, especially it’s a recent one. However, conditions can change the next day - I’d argue it’s specifically relevant notion if the company got acquired after the fact, which is true for both Express and OVPN.

---

## Post 12 by @Regime6045 — 2024-05-23T16:36:14Z

Any opinions on Crypto Storm? I just found out about them and at first glance they look good. Cross-platform (Wireguard & OpenVPN), port forwarding support, can pay with Monero, claim to have no logs…

---

## Post 13 by @moonwriting — 2024-05-23T18:38:45Z

- The website is buggy, which doesn’t give a good first impression. I tested this with both Firefox and Brave.
- They don’t want to tell their users where they’re located, nor is there any information about the people behind it.
- No audits.
- No apps, you have to use Wireguard or OpenVPN clients.

There were some good things I noticed, but I don’t see any reason to recommend them over the options that Privacy Guides currently has. The fact that we don’t know anything about the people behind it is a big red flag, as well as their unwillingness to say where they are located. They say they do this to prevent themselves from being shut down, but this only creates more questions and makes me wonder why they see this as a potential concern. So no, I would not recommend them.

---

## Post 14 by @d3c1oak3d — 2024-05-23T21:04:32Z

For starters.

Cryptostorm seemingly has had associations with certain people potentially accused of criminal acts in the past.

A few years ago they installed an IDS on their VPN servers to intercept plain-text HTTP traffic with the justification of deterrence from using them for cyberattacks.

It is true that Cryptostorm was a pioneer in token based payments to avoid collecting information about their users. But they are not the only provider that practices information minimization of their users. You can’t disclose what you don’t have.

Some of this was discussed [on the forum](https://airvpn.org/forums/topic/17010-cryptostorm/) of AirVPN.

Given the alternatives. I do not see conducting business with them as necessary.

---

## Post 15 by @Regime6045 — 2024-05-24T15:47:55Z

> [@d3c1oak3d](#):
>
> Some of this was discussed [on the forum](https://airvpn.org/forums/topic/17010-cryptostorm/) of AirVPN.

That discussion actually brought forward some interesting arguments in favour of Crypto Storm. The token system you mentioned (but which is not unique anymore) is one. I particularly noticed that if you connect to their VPN their DNS allows you to resolve .onion and .i2p domains in the normal browser. Not best practice due to browser fingerprinting I assume, but I still like it.

> [@d3c1oak3d](#):
>
> Cryptostorm seemingly has had associations with certain people potentially accused of criminal acts in the past.

Yes I agree that was pretty disgusting to find out (bestiality)

> [@moonwriting](#):
>
> The fact that we don’t know anything about the people behind it is a big red flag, as well as their unwillingness to say where they are located.

That doesn’t have to be a bad thing. We also don’t know who created Bitcoin or Monero.

---

## Post 16 by @moonwriting — 2024-05-24T17:43:50Z

> [@Regime6045](#):
>
> That doesn’t have to be a bad thing. We also don’t know who created Bitcoin or Monero.

You can’t compare a VPN provider and cryptocurrencies such as Monero this way because, with VPN providers, you are placing trust in a company, which means that I have no idea who I am trusting my data with Cryptostorm, and that isn’t a good thing. I would suggest that you read [this](https://www.ivpn.net/blog/who-owns-your-vpn-you-should-find-out/) excellent article by IVPN that talks about this.

On the other hand, it doesn’t matter that we don’t know who is behind Monero because we don’t have to trust them. We only need to trust the protocol that is publicly available for auditing.
