Live data from Hacker News

Ask HN: Which VPN?

news.ycombinator.com

31–40 of 69 posts

Re: Ask HN: Which VPN?

#32
To answer "Which VPN?" you first need to answer "Why VPN?" because there are a lot of different reasons for using a VPN.

If it's just privacy from snooping, you'll be fine with setting up your own VPS with OpenVPN. It's simple enough that any technical person can do it in a few minutes (or hours).

Re: Ask HN: Which VPN?

#34
post #4

I haven't used it extensively, but so far MullvadVPN has worked well for me and they are one of thatoneprivacysite's top recommendations

I use Mullvad when traveling, with wireguard app just to avoid public wifi security issue. It's cheaper than rolling your own Digital Ocean droplet

Re: Ask HN: Which VPN?

#35
post #24
post #23

Earlier quoted context omitted.

I'm using Mullvad. On the plus side, their servers are the most reliable I have seen, and they provide IPv6 addresses (behind NAT, which is reasonable for privacy). On the minus side, since November 2017 they intercept DNS queries and answer them themselves (hence you can not use DNS service of your choice), unless you connect to a specific undocumented OpenVPN port (1400 or 1401) available on a small but diverse sub…

Interesting. Good info to know. Have they specified a reason for intercepting DNS?

I believe I can quote the response to my support request:

«We added iptables rules to hijack all DNS requests on port 53 going via the VPN tunnel, this is to protect users having set a DNS server unknowingly (or by malware). We are aware that not all users want this behaviour, and we intend to add an extra port that OpenVPN listens on, where DNS hijacking will not happen.»

Some VPN providers (including Mullvad) have a client-side feature called DNS leak protection that configures the system to use the provider's DNS server. I don't know how Mullvad decided that this was not enough, and they are justified to intercept DNS. (Note that for the server-side intervention to work, the client side must be configured not to use ISP DNS, hence the client-side DNS leak protection is a prerequisite.)

Re: Ask HN: Which VPN?

#39
post #21

IVPN (Gribaltar), Mullvad (Sweden) or PIA (U.S.) are the best bet for most users IMO. They are all fast, no logging, and have good apps. IVPN, Mullvad are not in U.S. jurisdiction if you are concerned about that. Most people are not and just want a VPN to hide shit from ISP, etc... Although PIA is U.S. based, they keep no logs and then they have their famous "FBI" case which they did not provide anything to them. I m…

Cannot agree with this enough. When I first started looking for a VPN, the only source of information I found were these disingenuous websites that based their reviews off how much vpns were paying them, with every off-site link being a referral. thatoneprivacysite is by a landslide most unbiased source of information I found on VPNs.

Re: Ask HN: Which VPN?

#40
post #21

IVPN (Gribaltar), Mullvad (Sweden) or PIA (U.S.) are the best bet for most users IMO. They are all fast, no logging, and have good apps. IVPN, Mullvad are not in U.S. jurisdiction if you are concerned about that. Most people are not and just want a VPN to hide shit from ISP, etc... Although PIA is U.S. based, they keep no logs and then they have their famous "FBI" case which they did not provide anything to them. I m…

[deleted]
Post reply on HN