HACKER Q&A
📣 itubaj

Could Brazil's Supreme Court IT team track VPN usage on X?


It's more of a technical question and maybe is a really noob one. Although the restriction on VPN apps in general was dropped, the fine for VPN usage on X is still up.

Many people point out that this type of tracking would only be possible if VPN companies handled logs to the Supreme Court, others say that patterns on the VPN connections could be detected and then the access to X be uncovered, at least partially (technically they only need to know you used X on a VPN, not what you saw on X or anything else). Others say that, besides logs, it is impossible to know if a citizen Y used X.

If you were, let's say, in the Supreme Court IT team and needed to detect who is using X through a VPN, how would you do it (besides asking the companies for the logs).


  👤 talldayo Accepted Answer ✓
> how would you do it

Subpeona the ISP for a list of users that have consistently connected to a range of known VPN provider IP ranges. Then they can filter by other heuristics like amount of data transferred and histograms that show when/how they used it. Unless the VPN provider is implementing advanced antitracking techniques or multihop gateways, it should be pretty easy to get that info since most ISPs are very much at the beck and call of the government.


👤 diegoholiveira
The restrictions apply to X, so you can use your vpn to anything else. I use it daily on my job (it’s being hard to resist the temptation of take a look on X).

Also, I saw many people saying that a read only access is fine, but posting could be more problematic.


👤 toomuchtodo
DNS leakage and query logs