:KLOHLWVHHPVWKDWXVLQJWKHVWROHQLQIRUPDWLRQ
ZRXOGKDYHEHHQGL̇FXOWIRUWKHDWWDFNHUDQGLW¶V
LQWHUHVWLQJWKDW1RUG931DQGLWVFRPSHWLWRU
7RU*XDUG931DJUHHRQWKLVSRLQW,DP
GLVWXUEHGE\WKHSRVVLELOLW\WKDWWUḊFFRXOGKDYH
EHHQREVHUYHGE\WKHDWWDFNHU7KHJRRGQHZVLV
WKDW+7736LVPRUHFRPPRQWRGD\WKDQHYHU
before, which would greatly limit what the
DWWDFNHUFRXOGKDYHREVHUYHG,W¶VDOVRDUHOLHIWKDW
WKHDWWDFNHUZRXOGQRWKDYHEHHQDEOHWRDWWULEXWH
WKHWUḊFREVHUYHGWRVSHFL¿FXVHUVFRQQHFWHG
ZLWKWKHVHUYHU%XWWKDW¶VVWLOOFROGFRPIRUWDVLW
UHSUHVHQWVDFRPSOHWHIDLOXUHRIZKDWD931
FRPSDQ\LVVXSSRVHGWRGRLQWKH¿UVWSODFH
,DOVRUHDFKHGRXWWR7RU*XDUG931WRVHHLIWKH
DWWDFNHUFRXOGKDYHREVHUYHGWUḊFZKLOH
FRQQHFWHGWRLWVVHUYHUV7KHUHSUHVHQWDWLYHVDLGLW
ZDVQRWSRVVLEOHEHFDXVHWKHFRPSDQ\XVHV
VHFXUH3XEOLF.H\LQIUDVWUXFWXUH3.,
PDQDJHPHQWWRSURWHFWLWVHQFU\SWLRQNH\V$
UHSUHVHQWDWLYHZURWH
“No, that would be impossible in TorGuard’s
case. [...] TorGuard’s >FHUWL¿FDWHDXWKRULW\@
CA private key is never stored on any VPN
server, so it would not be possible for an
DWWDFNHUWRGHFU\SWSDFNHWVÀRZLQJWKURXJK
WKH931:KHQ931WUDI¿FOHDYHVWKHHQG
user’s computer through the VPN adapter, it
is fully encrypted. Once the packet arrives at
the VPN provider, the only way to see
activity is to decrypt the packet with the VPN
provider’s private key. In theory, the
DWWDFNHUFRXOGWKHQORJWUDI¿FRUIXUWKHU
examine it for exploitation.”
M
a
x
E
d
d
y
That’s cold com-
fort, as it repre-
sents a com-
plete failure of
what a VPN
company is sup-
posed to do in
the first place.