Live data from Hacker News

VPN Report – Reviews of the top VPNs

vpnreport.org

61–70 of 235 posts

Re: VPN Report – Reviews of the top VPNs

#61
As someone living in China, a VPN provider that doesn't provide direct download links to their Android client is completely useless. The only way for me to install an app from Google Play store is to flash a custom ROM and install the Google Play Store, install another VPN (?!!) to access the Play Store, and then download the app in question.

Furthermore, the fact that Apple has just pulled VPN apps from its App Store and the unfortunate fact that you can't sideload apps makes iOS an untenable OS choice.

Re: VPN Report – Reviews of the top VPNs

#62
post #6

To steal (and paraphrase) what is basically the perfect summary of this from @SwiftOnSecurity: Commercial VPNs: for when you want all the security of Ukrainian coffee-house wifi from the comfort of your own home. Taylor Swift isn't wrong about this. Use something like Algo to run your own VPN if you have to. If you must use a commercial VPN to get to Netflix or whatever, do it from inside a virtual machine that you u…

I heard VPNs don't work on netflix anymore.

It's a game of whack-a-mole, to be sure, but I have a high success rate with NordVPN. FWIW.

Re: VPN Report – Reviews of the top VPNs

#63
lololol. Half of these VPN vendors show up on Kenn White's VPN Hall of Shame for offering unsafe configurations:

https://gist.github.com/kennwhite/1f3bc4d889b02b35d8aa

For anything actually sensitive, you're better off not using a VPN than using a VPN which provides an unsafe configuration.

If you'd rather not do your own pager duty for something like Algo, here's a recommendation I put together a while ago:

https://free-dissociation.com/blog/posts/2017/03/quick-and-d...

Re: VPN Report – Reviews of the top VPNs

#64
post #37

Both iOS and macOS (I don't know about windows, I havent used it recently) have built-in VPN clients so what would be the advantage to using a client from the VPN provider?

The built-in VPN clients support old broken insecure protocols (PPTP) and expensive, hard to implement and hard to deploy protocols (IPSEC-LLTP), whereas public vpn providers tend to use simple, secure, easy(er) OpenVPN for the bulk of their connections. So you need a addon client to use them for their best features.

Thanks. I've only ever used VPNs to access corporate networks. I'm not going to pretend to be knowledgeable in this area.

Re: VPN Report – Reviews of the top VPNs

#65

As someone living in China, a VPN provider that doesn't provide direct download links to their Android client is completely useless. The only way for me to install an app from Google Play store is to flash a custom ROM and install the Google Play Store, install another VPN (?!!) to access the Play Store, and then download the app in question. Furthermore, the fact that Apple has just pulled VPN apps from its App Stor…

> ... Apple has just pulled VPN apps from its App Store and > ...you can't sideload apps makes iOS an untenable OS choice.

I'm pretty sure you can still install VPN apps (e.g. Potatso 2) from the iOS App Store, although perhaps they're not available if you're logged in with a China iTunes account. iOS allows you to install apps from multiple iTunes accounts on the same device, though, so this doesn't seem like much of a limitation.

(Not sure if they're also blocking by IP address.)

Re: VPN Report – Reviews of the top VPNs

#66
From the one line summaries, OP seems to prefer native apps vs. open protocols (e.g. OpenVPN/L2TP/etc.), why is that?

I looked at the Chrome extension of TunnelBear and it requires some ridiculous permissions [1], much more than just "change your proxy settings". This doesn't seem right.

[1] http://imgur.com/3PuH0tE

Re: VPN Report – Reviews of the top VPNs

#67
post #6

To steal (and paraphrase) what is basically the perfect summary of this from @SwiftOnSecurity: Commercial VPNs: for when you want all the security of Ukrainian coffee-house wifi from the comfort of your own home. Taylor Swift isn't wrong about this. Use something like Algo to run your own VPN if you have to. If you must use a commercial VPN to get to Netflix or whatever, do it from inside a virtual machine that you u…

> Use something like Algo to run your own VPN if you have to.

This might be good advice for tech-savvy people, but too hard for most folks.

Also, Algo is targeted at only security/privacy, and not censorship resistant. The last time I checked, it didn't offer any protocols that work well behind GFW.

Also, where are you going to run your VPN? Assuming you don't have your own hosting infrastructure (or domestic broadband connection in another country), then you're renting a server from someone else. Perhaps your assumption is that a random VPS provider is more trustworthy than a random VPN provider?

> If you must use a commercial VPN to get to Netflix or whatever, > do it from inside a virtual machine that you use for nothing but that.

Again, good advice for tech-savvy people, but not practical for most folks, particularly for the times when they're on mobile devices.

I don't disagree with your overall sentiment (I don't use commercial VPN providers for the same reasons), but for many folks these serve a useful purpose, and there are no practical alternatives.

Re: VPN Report – Reviews of the top VPNs

#68
post #63

lololol. Half of these VPN vendors show up on Kenn White's VPN Hall of Shame for offering unsafe configurations: https://gist.github.com/kennwhite/1f3bc4d889b02b35d8aa For anything actually sensitive, you're better off not using a VPN than using a VPN which provides an unsafe configuration. If you'd rather not do your own pager duty for something like Algo, here's a recommendation I put together a while ago: https://…

Regarding the blog post you shared [0]

> In general, US persons today on residential broadband are safest not using a VPN.

> Only connect to US-based VPN servers while in the US. Even if your VPN provider offers servers outside the US.

What? No reasons given. Smells like FUD.

[0] https://free-dissociation.com/blog/posts/2017/03/quick-and-d...

Re: VPN Report – Reviews of the top VPNs

#69
post #22

Regardless of how you feel about _why_ PIA sponsor the organisations they do, it is surprising to see someone claiming they "perhaps put [their money] to better use" given their record of supporting foss and digital/online rights [1]. Additionally, the characterization as being extremely focused on the tech illiterate I feel isn't really the case either, they have lots of docs about how to use OpenVPN [2]. Thirdly, w…

PIA actually scores as one of the highest on the objective measures. The star count is just a subjective impression and experience with getting it set up. They connect over HTTP on startup instead of HTTPS (which is unacceptable for a privacy company). They then ping almost a hundred servers on startup (no other app does this, at least not to this extent).

Hi mobitar. Thanks for the highest score in regard to the objective measures. Regarding the subjective impression and experience, I'd like to let you know what's going on. If you feel that this changes your impression, it would be great to update accordingly!

The HTTP connection upon startup is for the region data request which is signed and verified upon receipt. It's tamper proof, but you can read it. It's something that anyone with the client can read, and the client is free to download.

Arguably, it's more secure to entrust the communication from PIA to the client software itself than to blindly entrust it to HTTPS which has provably been compromised due to bad actors in the past.

We're in #privateinternetaccess on irc.freenode.net to discuss anytime as well!

Thanks for everything mobitar and for taking the time to produce this report.

Re: VPN Report – Reviews of the top VPNs

#70

Earlier quoted context omitted.

If you use TOPS and simply choose the provider with the most green, you'll have made a terrible mistake.

I never said anything about picking "the most green". The columns are labelled and described in detail on a separate page.

Neither, I suspect, did you read my post. We can probably end here. :-)
Post reply on HN