Elektrine lite

← Feed

@thedarktangent@defcon.social

Post #3435259

2026-06-27 19:36 UTC

For #DEFCON to do private email we would want to host our own servers to avoid the 3rd party legal doctrine, and keep them secure. No problem, we have a secure location and lawyers. Back during COVID when we were investigating this it was still possible to gather some open source info on how large other private email services were. How big was the market? Could you make enough money to hire the people and buy the servers? MailFence, Proton, and others showed it was possible if you were very efficient. Great! Then I spoke with someone who worked at a white label email service provider. I realized DEF CON would never do a private email service for two reasons: CSAM: They explained they had about 10 people dedicated to responding to legal requests around CSAM, not including their lawyers and LE relationship people. SPAM: They had another room with about 30 people dealing just with spammers and the impacts of spammers. Managing their ASNs, netblocks that get lower reputation on blackhole lists, moving customers to "clean" netblocks when a shared block gets polluted by spammers, etc. Conclusion? If you are very successful you can look forward to having a room of 40 people dealing with LE, SPAM, CSAM, Networking, and that's before you add on customer service. That doesn't seem fun or very DEF CON Hacker anymore. Next up, VPN.

Replies (1)

  • Next up, a #DEFCON #VPN service sounds awesome. Like with email there is plenty of expertise on how to build VPNs. Technically it is a realistic goal, so let's investigate! To be attractive to a large customer base you need to offer a lot of locations with an ever changing pool of addresses for when some get blocked by someone in the world. Those two things mean you need a pool of providers and great automation playbooks where you can easily spin up and provision "secure" VPN gateways all over the world. Because of the reliance on 3rd parties, unlike with email, you now have to worry about the legal concept of the 3rd party doctrine, so have some more lawyers ready to do battle. Then two things happened, I spoke with two different people with experience in the VPN game. First someone who served as a CTO to a large VPN provider. They spent all their time trying to save money, automate more, and respond to non-stop customer complaints from over seas business people. Chine would block some VPN addresses and they could no longer connect to their company back home and they needed to do that RIGHT NOW. So a sort of daily fire drill. The increasing VPN competition meant they had to keep spending on advertising and cost control. The second person put the final nail in the coffin. They explained as far as they could tell about half of all VPN providers had ties to intelligence services. Either as fronts or investors or super friendly "partners". Iran, Russia, China, North Korea, some Middle Eastern countries, all play in this space. This means half of the VPN providers have a different business model than the other half. Their goal is maximum people at the least cost to cast as large a monitoring net as possible, and revenue from paying customers doesn't have to actually cover your operating costs. Building a #VPN service the right way would mean we would be more expensive, in fewer locations, and support only the strongest technologies - all things that would reduce your pool of potential customers. So, like the private email idea, it was interesting to investigate, we learned a lot, and we will never enter the VPN market. Instead we run free #Tor relays and support @torproject@mastodon.social Please support Tor and other privacy technologies.

    Open ##3435255