Skip to content

Instantly share code, notes, and snippets.

Created March 18, 2016 18:39
Show Gist options
  • Star 0 You must be signed in to star a gist
  • Fork 0 You must be signed in to fork a gist
  • Save anonymous/03d11e15105d22d1cdb9 to your computer and use it in GitHub Desktop.
Save anonymous/03d11e15105d22d1cdb9 to your computer and use it in GitHub Desktop.
Early on, my VPN Comparison project had evoked reactions of admiration from some, and anywhere between annoyance and vitriol from others. The latter usually took the form of companies on the list who didn't like that I made evident certain policies or who noticed that they don't compare favorably. For the last couple of months, every now and again, I'll get messaged by some throwaway account with vague threats or angry rambling trying to discredit me. This has made me extra cautious as I check messages - anyone could be sending anything and (as you are probably already aware people are often not who they claim to be online).
So, onto the story:
Yesterday morning, I received some reddit mail from an individual claiming to be from a certain VPN company. The individual then proceeded to offer me a bribe - a lifetime subscription to their service (which they told me was up for negotiation), in exchange for my cooperation in recommending their service and bringing them up casually in conversation.
The original reddit mail - (https://i.imgur.com/y4cvnxe.png):
Dear That One Privacy Guy :-)
My name is [redacted] and I am the PR Manager Digital and Partnerships at Ivacy VPN. I really appreciate your hard work that goes into making a comparison sheet of VPNs. I really admire it and at times have taken references comparing VPNs.
Right now, I have something great to offer you. As a PR Manager of Ivacy, I can offer you a lifetime account of Ivacy VPN, but, I would really appreciate if in return you can create a post or mention us on your forums or threads that you create.
See, people look up to you as an authority- as an influencer, and if you mention us in any relevant discussion, that'll be a very beneficial thing.
So, I will really appreciate your positive response in this regard, or any terms that you want to put forward. We are open for negotiations.
Regards, [redacted]
My first reaction was "check the account" which confirmed the throwaway with this as its first post. Given the attention the project had recently gotten on several big tech blogs and other places, I almost dismissed is as just some troll. But then I stopped to think about it. Half of the reason I started my project was because of affiliate astroturfing, and sadly, it wouldn't be beyond the realm of possibility for this be legitimate. I owed it to the community to investigate further.
I replied to "[redacted]" that we should take the conversation to email, which I created a throwaway email account for. "[redacted]" sent me an email (https://i.imgur.com/3ZAW5q2.png) shortly after confirming that he indeed wanted to discuss further his proposed arrangement.
Dear, That One Privacy Guy,
So, I have emailed you on reddit regarding the deal. What would you like to know more. I would really appreciate your feedback.
As I'd hoped, he took the bait and I got what I wanted for confirmation - the email headers (https://i.imgur.com/hdnoyo6.png). They revealed that the email had indeed come from someone at @ivacy.com, but not from "[redacted]". the email address came from one "[redacted]" instead.
The relevant bit from all the way at the bottom:
Received: by [redacted] (Authenticated sender: [redacted]@ivacy.com, from: [redacted]@ivacy.com)
So, I started googling and looking for connections between [redacted] and Ivacy - and I found exactly what I was looking for.
Post after post by [redacted] with more of the same astroturfing I had seen on reddit earlier. This also included, but I can't post here as to not break reddit rules, a link to this individual and the company.
Let this be a lesson to the VPN companies out there who might have had the idea cross their mind. I won't be bought. By trying you will simply expose yourselves for what you are.
This experience has underscored the desperate need this industry is in for someone like me to simply shine the spotlight onto the trash heap ...and dig deeper.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment