India Orders VPN Companies to Collect and Hand Over User Data

  • Thread starter Thread starter minuteman
  • Start date Start date
  • Replies Replies 182
  • Views Views 17,408
Kyc requirement is much better and easier for govt than banning it completely which will be difficult.

@Chip if you want better privacy use a VPN like mullvad, with multiple hops.

Though most vpn companies use same provider m247 for providing services in Europe.

If not mandated to keep logs most vpn providers claim to use ram or something so there is minimal or no log at all which can be provided if requested. Ofcourse if you irk the govt too much they will find a solution to identify you.
 
Last edited:
VPN is only a part of security, albeit a huge one. There is browser fingerprinting too which can be used to identify an individual. I am pretty sure if the state wants to get you, VPNs aren't coming in the way. A competent actor will just infect the computer with malware, and wait for it to call back once the VPN is disconnected.
 
Is it even practical to have VPN's store user data? VPN operators only have a RAM at their nodes, now they want them to have them add storage as well to save user data? This would complicate the matter for them. There still is 2 months for implementation of this stupid law, and VPN companies are weighing their options. I would set up a my own VPN server on Vultr servers in Singapore. That should be a big enough middle finger to the government.
 
You are missing the point. Any VPN that store user activity logs no longer remains a private network. Any service complying with this requirement would essentially stop being a VPN service provider. It does not matter if it is expensive to comply or not. Your entire business model basically goes out of the window if you comply. You would get so much bad PR all over the web that you would have to shut down your service.

Vultr has presence in India which means they would comply with local laws. While they are not a VPN service provider but using their servers for VPN purposes does not provide you with any privacy. Best to find a company that has no presence in India.
 
@Sushubh Yeah you are right. I was thinking Vultr dint have a presence in India. They might have opened their data centre only just recently.
 
with vps services... servers are operated by site owners so they have to comply with any government regulation. if i delete the logs, i doubt, vps companies keep their own logs. a lot of vps companies use this excuse to refuse to take action on abuse reports. they just forward your complaints to clients.

what i can imagine would happen is that isps would be asked to monitor traffic on their platform. if a user is consistently using a few ips for most of his online activity, they would tag him as a VPN user and might go after the service provider for logs. so yeah, i do believe that web hosts would become involved in these new regulations eventually.
 
Web hosts globally? Kind of hard to achieve that. Even China has tried to do that and failed. But I do agree with the other thing you said, they'd require AWS, or Azure to keep KYC details of people who have active running VPS. Logging how the leased infrastructure is utilised is entirely out of the purview of the current legal framework. Maybe in due course.
 
Back