Live data from Hacker News

Show HN: SmokeVPN – All-in-One WireGuard VPN Hub – Switch Exits in Realtime

smokevpn.com

11–15 of 15 posts

Re: Show HN: SmokeVPN – All-in-One WireGuard VPN Hub – Switch Exits in Realtime

#11
post #7
post #6

Earlier quoted context omitted.

yeah the account number is basically the mullvad model, 16 digits, no email no password. its a tradeoff, i know some people hate it. login is rate limited server side so you cant just sit there hammering numbers at it. is it weaker than a long passphrase? probably yeah. the flip side is theres no personal info sitting in a database for someone to leak, or for someone to show up with a subpoena for. on the local netwo…

The difference is that Mullvad doesn't enable any east/west connectivity at all. If somebody guesses a user's Mullvad 16 digit number, they can use Mullvad's services as that user. If somebody gets a SmokeVPN users's 16 digit number, they can connect to that user's other devices. How would you take any action with an abuse report and no logs? You'd get a report or subpoena or similar that listed an egress IP and a ti…

[deleted]

Re: Show HN: SmokeVPN – All-in-One WireGuard VPN Hub – Switch Exits in Realtime

#12
post #7
post #6

Earlier quoted context omitted.

yeah the account number is basically the mullvad model, 16 digits, no email no password. its a tradeoff, i know some people hate it. login is rate limited server side so you cant just sit there hammering numbers at it. is it weaker than a long passphrase? probably yeah. the flip side is theres no personal info sitting in a database for someone to leak, or for someone to show up with a subpoena for. on the local netwo…

The difference is that Mullvad doesn't enable any east/west connectivity at all. If somebody guesses a user's Mullvad 16 digit number, they can use Mullvad's services as that user. If somebody gets a SmokeVPN users's 16 digit number, they can connect to that user's other devices. How would you take any action with an abuse report and no logs? You'd get a report or subpoena or similar that listed an egress IP and a ti…

[deleted]

Re: Show HN: SmokeVPN – All-in-One WireGuard VPN Hub – Switch Exits in Realtime

#13
post #7
post #6

Earlier quoted context omitted.

yeah the account number is basically the mullvad model, 16 digits, no email no password. its a tradeoff, i know some people hate it. login is rate limited server side so you cant just sit there hammering numbers at it. is it weaker than a long passphrase? probably yeah. the flip side is theres no personal info sitting in a database for someone to leak, or for someone to show up with a subpoena for. on the local netwo…

The difference is that Mullvad doesn't enable any east/west connectivity at all. If somebody guesses a user's Mullvad 16 digit number, they can use Mullvad's services as that user. If somebody gets a SmokeVPN users's 16 digit number, they can connect to that user's other devices. How would you take any action with an abuse report and no logs? You'd get a report or subpoena or similar that listed an egress IP and a ti…

[deleted]

Re: Show HN: SmokeVPN – All-in-One WireGuard VPN Hub – Switch Exits in Realtime

#14
post #7
post #6

Earlier quoted context omitted.

yeah the account number is basically the mullvad model, 16 digits, no email no password. its a tradeoff, i know some people hate it. login is rate limited server side so you cant just sit there hammering numbers at it. is it weaker than a long passphrase? probably yeah. the flip side is theres no personal info sitting in a database for someone to leak, or for someone to show up with a subpoena for. on the local netwo…

The difference is that Mullvad doesn't enable any east/west connectivity at all. If somebody guesses a user's Mullvad 16 digit number, they can use Mullvad's services as that user. If somebody gets a SmokeVPN users's 16 digit number, they can connect to that user's other devices. How would you take any action with an abuse report and no logs? You'd get a report or subpoena or similar that listed an egress IP and a ti…

You're right on both counts.

My Mullvad comparison was focused on the credential, not on the LAN model. Brute forcing the account was never the issue, I missed the point about device-to-device was the real threat, fair point. I'm starting implementing LAN connections as opt-in, not default.

Second point, you're also right, because I was mixing prevent and identify, preventions shouldn't need logs, we can't take an IP address and a timestamp and attach a user to it, and the AUP imply something else, I'll rephrase this.

Re: Show HN: SmokeVPN – All-in-One WireGuard VPN Hub – Switch Exits in Realtime

#15
post #7
post #6

Earlier quoted context omitted.

yeah the account number is basically the mullvad model, 16 digits, no email no password. its a tradeoff, i know some people hate it. login is rate limited server side so you cant just sit there hammering numbers at it. is it weaker than a long passphrase? probably yeah. the flip side is theres no personal info sitting in a database for someone to leak, or for someone to show up with a subpoena for. on the local netwo…

The difference is that Mullvad doesn't enable any east/west connectivity at all. If somebody guesses a user's Mullvad 16 digit number, they can use Mullvad's services as that user. If somebody gets a SmokeVPN users's 16 digit number, they can connect to that user's other devices. How would you take any action with an abuse report and no logs? You'd get a report or subpoena or similar that listed an egress IP and a ti…

For completion, I decided to make device to device connections an opt-in feature that requires 2fa enabled to log into the account. AUP was also rephrased to make a clear distinction between prevention and identification.
Post reply on HN