Live data from Hacker News

Ask HN: What VPN service are you currently using?

news.ycombinator.com

241–250 of 344 posts

Re: Ask HN: What VPN service are you currently using?

#241
post #214

I apologise if this is unhelpful: but none. I trust the (more than not at all) regulated space of ISPs in my country more than I do the unregulated space of people running VPNs out of their basements. It's important to be clear: you're just moving trust from one entity (your ISP) to another (the company / human who runs the VPN). It's not clear to me why the VPN people are more trustworthy than ISPs.

> It's not clear to me why the VPN people are more trustworthy than ISPs.

Surely it's because it is their business model.

ISP's have been proven to snoop and inject into traffic. They sell your data to those that have money. This is a breach of your privacy.

On the other hand if a VPN provider were caught doing that, it would be abandoned by it's customers overnight. It is the primary risk to the business.

With VPN services I have a choice, but with an ISP they hold most of the cards (I can leave them once my contract is up). ISP's take your trust and abuse it, VPN's have to earn it.

Re: Ask HN: What VPN service are you currently using?

#242

Earlier quoted context omitted.

> you will bottleneck at ~300Mbit\s. Any idea where the bottleneck was there? CPU use? Protocol latency? I'd be interested to see some test results around that if you know of any that have been published. A little anecdotal information: some years ago I did a CPU-load test with OpenVPN on a diminutive Atom-based netbook as the client, and it maxed out at around 95mbit/s on a 100mbit/s network (actually a gbit network…

You could start here: https://community.openvpn.net/openvpn/wiki/Gigabit_Networks_... >It is easily possible to saturate a 100 Mbps network using an OpenVPN tunnel. The throughput of the tunnel will be very close to the throughput of regular network interface. On gigabit networks and faster this is not so easy to achieve. This page explains how to increase the throughput of a VPN tunnel to near-linespeed for a 1 Gbps…

Have you read the code? It's woefully unparallelisable and is written to support more platforms rather than work better on any single one of them.

Re: Ask HN: What VPN service are you currently using?

#243

I use NordVPN, largely because they were recommended by a friend. But I only really use them to reach sites blocked by my ISP. So I find it really useful to use their Firefox plugin which doesn't affect other applications I'm running at the same time.

I switched to Nord from Private Internet Access because their apps looked nicer. I regret it entirely. NordVPN has been noticeably less stable, slower, and their apps aren't actually that nice to use, and can be slow and buggy. PIA looks a bit "programmer art" but it's far better.

Re: Ask HN: What VPN service are you currently using?

#244

I use Algo[1] on a variety of VPS providers. It supports IPSec, but I only use Wireguard through it. Supporting OpenVPN is an explicit anti-goal for Algo[2]. I generally strongly recommend against using VPN providers on false advertisement grounds -- VPNs fundamentally cannot provide strong anonymity properties, but that doesn't stop many providers from listing anonymity as a selling point. In terms of the property V…

> you don't want to be tied to someone else's weak cipher or insecure protocol choices. That's not part of the threat model for 99.999999% of VPN users though. Tracing back the usage of the VPN to them is their main worry and what they have to fight against.

> That's not part of the threat model for 99.999999% of VPN users though.

You're right, and that's why it's not my primary objection. At the end of the day, the majority of VPN providers are still advertising themselves as anonymity services. This is patently false and dangerous to consumers.

Re: Ask HN: What VPN service are you currently using?

#245

I use Algo[1] on a variety of VPS providers. It supports IPSec, but I only use Wireguard through it. Supporting OpenVPN is an explicit anti-goal for Algo[2]. I generally strongly recommend against using VPN providers on false advertisement grounds -- VPNs fundamentally cannot provide strong anonymity properties, but that doesn't stop many providers from listing anonymity as a selling point. In terms of the property V…

I just ran into a case where I needed a VPN for a short lived task. Ally bank blocks creation of time deposit accounts while in a foreign country, despite me already having an account with them. Takes less than 10 minutes to setup a VPN with algo on DO and I just shut it down after my task was done. Cost me $0.02. The support for Wireguard + OSX Wireguard App is perfect and super easy. Please tell your coworkers, tha…

Will do! I'm glad to hear that it worked well for you.

Re: Ask HN: What VPN service are you currently using?

#246
post #214

I apologise if this is unhelpful: but none. I trust the (more than not at all) regulated space of ISPs in my country more than I do the unregulated space of people running VPNs out of their basements. It's important to be clear: you're just moving trust from one entity (your ISP) to another (the company / human who runs the VPN). It's not clear to me why the VPN people are more trustworthy than ISPs.

> It's not clear to me why the VPN people are more trustworthy than ISPs.

In my country, the UK, ISPs are legally required to retain logs of customer activity for 12 months. A VPN has no such legal requirement.

So while I can't be 100% sure that my VPN is monitoring me, I can be 100% sure my ISP is. Additionally, my VPN has a financial incentive not to log customer data, or at the very least, not to be caught doing it.

(I'm currently using IVPN (https://www.ivpn.net/). It's on the more expensive side, though that isn't necessarily a bad thing, and it supports multihop over OpenVPN, and the experimental Wireguard protocol.)

Re: Ask HN: What VPN service are you currently using?

#247
post #41

The first question you should ask is why you want a VPN. Because I believe many people newer ask this question and have some vague idea about "it somehow improves security and/or privacy". In most situations this likely isn't true. You add an additional attack vector and you centralize your communication to a single point.

On reason personally is when a public or work WiFi bans a particular website. My workspace ban GitHub for some reason. Is it secure to setup your own VPN?

Re: Ask HN: What VPN service are you currently using?

#249
post #214

I apologise if this is unhelpful: but none. I trust the (more than not at all) regulated space of ISPs in my country more than I do the unregulated space of people running VPNs out of their basements. It's important to be clear: you're just moving trust from one entity (your ISP) to another (the company / human who runs the VPN). It's not clear to me why the VPN people are more trustworthy than ISPs.

> It's not clear to me why the VPN people are more trustworthy than ISPs. In my country, the UK, ISPs are legally required to retain logs of customer activity for 12 months. A VPN has no such legal requirement. So while I can't be 100% sure that my VPN is monitoring me, I can be 100% sure my ISP is. Additionally, my VPN has a financial incentive not to log customer data, or at the very least, not to be caught doing i…

Plus, in the UK the VPNs do not block certain websites which ISPs are legally required to block.

Re: Ask HN: What VPN service are you currently using?

#250

PIA (Private Internet Access) and am a happy customer for 3rd year running. Why do I choose them? Besides the ease of use over multiple platforms, they are the only VPN (I am aware of) that has held up in court that they do not store any logs when asked to handover personal information. Sources: [1] https://torrentfreak.com/private-internet-access-no-logging-... [2] https://www.scribd.com/doc/303226103/Fake-bomb-thre…

PIA's offer and their policy on retention might be good, but they're still a US company and they still tried to smear several other VPN companies (including ProtonVPN). Their clients are also messy memoryleaky electron apps with outdated chromium embedded.

There are new apps that are not based on chromium [1].

[1] https://www.privateinternetaccess.com/pages/download

Post reply on HN