A Legal and Technical Analysis of VP.net’s Zero-Trust VPN Architecture

By Robert Z. Cashman, attorney and owner of the Cashman Law Firm, PLLC and the TorrentLawyer.com blog.


Introduction

Every few years, a new VPN provider enters the market claiming to have solved the privacy problems that plague the industry. Most of those claims amount to little more than another “no logs” policy, another jurisdiction with favorable privacy laws, or another promise that customers can simply trust the company operating the servers.

This time might be different.

A recent article by Ernesto Van der Sar on TorrentFreak introduced a new VPN provider, VP.net, whose design departs from the traditional trust model that has defined commercial VPN services for decades. Rather than asking customers to believe that the company chooses not to monitor or retain browsing activity, VP.net attempts to engineer that capability out of its own infrastructure by using Intel Software Guard Extensions (SGX), hardware-backed trusted execution environments, open-source software, and cryptographic remote attestation.

Whether VP.net ultimately succeeds remains to be seen. Like any new security architecture, its design will need to withstand scrutiny from security researchers, cryptographers, and the broader privacy community. Hardware vulnerabilities are discovered. Software contains bugs. Security claims are (at best) met with skepticism until they have been tested over time.

Even so, I believe VP.net represents one of the most interesting developments in consumer Internet privacy in years because it attacks the central weakness that has existed in virtually every commercial VPN service since the industry’s inception: trust.

As an attorney whose practice has included representing individuals in BitTorrent copyright litigation lawsuits, I find another implication equally fascinating.

For well over a decade, thousands of copyright infringement lawsuits have followed essentially the same pattern. A copyright holder or its investigator identifies an IP address participating in a BitTorrent swarm. A lawsuit is filed against a John Doe defendant. The plaintiff obtains early discovery, subpoenas the subscriber’s Internet Service Provider, and uses subscriber records to identify the individual associated with that IP address at a particular date and time.

The legal theories have evolved. The plaintiffs have changed. The technology used to monitor BitTorrent swarms has become increasingly sophisticated. Yet the underlying assumption has remained remarkably consistent:

An IP address can be associated with a particular subscriber, and that association can serve as the starting point for litigation.

That assumption has shaped an entire category of copyright enforcement.

This article is not about encouraging copyright infringement, nor is it intended as an endorsement of any particular VPN provider. Copyright owners possess legitimate rights under federal law, and technological advances do not eliminate those rights or excuse unlawful conduct. At the same time, Internet users also possess legitimate privacy interests. The question worth examining is whether advances in privacy engineering can reduce unnecessary collection of identifying information while preserving the ordinary operation of the Internet.

From this perspective, let us turn our attention to VP.net.

If its architecture performs as described, its significance extends well beyond providing one more commercial VPN service to compete with all the others. This new kind of VPN technology raises broader questions about the future of online privacy, putting into question the reliability of IP-address attribution, and it challenges current internet service providers to ask whether future Internet infrastructure can be designed so that service providers themselves possess less information about their users.

For those of us who have spent years watching litigation built upon IP-address identification, such an architecture is difficult to ignore.


Why VPN Architecture Is More Important Than VPN Marketing or VPN Company Reputation

VPN advertising has become remarkably predictable.

One provider promises military-grade encryption; another advertises thousands of servers across dozens of countries, while another emphasizes streaming performance and stealth against streaming companies like Netflix, Disney, or Amazon Prime (which prevent their own paid users from accessing their legitimate and paid online content when using a VPN).

Nearly all VPN companies promise that they keep “no logs.”

For many consumers, these claims are sufficient. Encrypting traffic between a user’s computer and a VPN server provides meaningful protection against monitoring by Internet Service Providers, public Wi-Fi operators, and others positioned between the user and the VPN provider. Even websites such as TorrentFreak provide an annual article evaluating “which VPN providers take privacy seriously.

For any of the VPN providers, the difficulty begins after the encrypted tunnel reaches the VPN server.

At that point, the VPN must decrypt traffic before forwarding it to its destination. Technically speaking, the VPN provider occupies one of the most privileged positions on the entire Internet path. Although reputable providers generally state that they do not retain browsing logs, customers must ultimately trust that those statements are accurate, consistently implemented, and maintained over time.

That trust-based model has always represented the industry’s greatest weakness.

The issue with reputable VPN companies is not that they are inherently untrustworthy. Many have invested substantial resources in independent audits, open-source software, transparency reports, and carefully engineered logging policies. These efforts should only continue to boost their recognition.

The larger point is architectural.

Whenever privacy depends primarily upon a company’s promises rather than technical limitations, its customers remain dependent upon the continued integrity of the organization itself. But employees change; company ownership changes; corporate policies evolve. Governments issue lawful process with which the company must comply. Technology eventually becomes outdated, and infrastructure is modified, all of these without the cautious user being aware. None of these possibilities necessarily indicate wrongdoing, but they illustrate why security engineers generally prefer systems that minimize trust wherever practical.

Trust is precisely the problem VP.net is attempting to solve.

Instead of asking customers to believe that the company chooses not to correlate subscriber identities with browsing activity, VP.net’s design attempts to make that correlation technically unavailable to the customer itself.

If successful, this represents more than a strong privacy policy on a website, or placing the burden on the end users to sue the company if and when it violates that privacy policy.

A reliance on technology represents a fundamentally different trust model.

In the upcoming series articles that I will write over the coming days and weeks, I’ll examine how that new VPN architecture works, where it appears genuinely innovative, where healthy skepticism remains appropriate, and why these developments may ultimately have implications extending well beyond VPN technology — including the future of IP-address-based copyright litigation itself.

Next Article: Understanding the Problem VP.net Is Trying to Solve

DISCLAIMER: While the author is an attorney, this content is not to be taken as legal advice to act or not act in any way. The author is also not encouraging the use of VPNs, or condoning or encouraging any illegal or unlawful acts. Any references to the VP.net company or service is not an endorsement; the author is merely analyzing this new approach to online privacy which the company is offering.

Could Hardware-Enforced VPNs End IP-Address-Based Copyright Litigation? is a post from Innovation Unleashed: Exploring Patents, AI, and Deep Learning – A Cashman Law Firm blog exploring Patents, AI, and Deep Learning… “where technology, law, and transformative ideas converge.”