I was looking at Metropipe.net today and they posted a Security Advisorie for the Findnot.com service.
they are saying that FindNot.com has security holes all over the place.
http://www.metropipe.net/advisories.php?id=FN15294
says:
Quote: Several vulnerabilities have been reported in Findnot.com's Microsoft PPTP VPN Service Client, which can cause intermittent immediate loss of anonymity and privacy while using the service
( Follow the link for everything else they have to say about Findnot)
and
http://www.metropipe.net/advisories.php?id=FN15398
Says:
Quote: Several vulnerabilities have been reported in Findnot.com's SSH Proxy Service which can cause all DNS requests for lookup of sites visited to be resolved using local DNS servers. Exposing the location of all sites visited to local wireless, network, sysadmin snoopers or to an ISP that is monitoring their DNS server.
( Follow the link for everything else they have to say about Findnot)
Looks like from what they are saying, at the links I posted above, all it takes is a loss of connection to their servers. or a blip in the connection and your IP is sent out.
I have been using the Metropipe Tunneler PRO for a little over 4 months and I know it dosn't have these problem.
Have any of you guys come accross this same thing with the Findnot service?
I hate to make my first post a negative one, but I've just given up on Findnot after they kept terminating my account. The final straw was when they terminated it, and then reset the password, but then terminated it again before I could log in with my new password. Apparently I was "abusing" the service without even logging into it.
Ho hum. I guess these services are all like that? I mean, if they want to terminate your account there's nothing to stop them. So what does it matter whether you're using metropipe, findnot, or whatever?
Truly bizarre. I am a very light internet user, just using the service to get around the Great Firewall of China - why they would choose me to disconnect is beyond me. The only possible explanation is that they are doing it by IP addresses, which are dynamic of course, but how can I be bumped off the system for abuse without even having logged into it?
The scam seems to be to do with the anonymity idea. Of course none of these are really anonymous services - the service provider always knows who you are - but I don't need anonymous I just need a server outside China. Surely there is a service somewhere for this?
Same EXACT thing just happened to me. I used the service for less than a week. I was actually happy with it as I only used it for simple web surfing.
Yet, they suspeneded my account for "abusing" the service, just as you mention.
Bizarre is the right word. I did nothing wrong, and they basically just stole my 30 bucks. No refunds.
Seems like a scam to me. Either that or there are some major security problems and they are being hacked.
Either way, I would stay away.
I also agree with you that none of these services are anonymous. In fact, using a service like this is probably more risky than most people realize.
If you access anything with usernames and passwords, the folks at places like findnot can see all of this. So, in your quest to be anonymous, you're actually giving away more info than you realize.
Same EXACT thing just happened to me. I used the service for less than a week. I was actually happy with it as I only used it for simple web surfing.
Yet, they suspeneded my account for "abusing" the service, just as you mention.
..........
Well we were two friends wich bought findnot.
I went on holiday for a week and they suspended the account. The nice thing is that they send to me and to my friend the same exact mail. then we answered the mail, and they sent us the same exact answer. We asked logs of our abusive (FALSE) behaviour and they simply told us that the account was closed. Then to one of us gave a new account, and without even using it, they sent me a mail 2 days ago (i wasnt using tunnel for a few days) telling that I raised again the alarm on their servers for abusive behaviour (mass mail) without even using it. I will make a lot of posting now all around the net to load **** upon them (with true experiences).