Live data from Hacker News

OpenPGPjs has passed an independent security audit

protonmail.com

121–128 of 128 posts

Re: OpenPGPjs has passed an independent security audit

#121
post #120
post #111

Earlier quoted context omitted.

ProtonVPN is no competitor to Private Internet Access in terms of the size and the number of users. If you were a co-founder of PIA, would you risk your reputation by publicly providing false accusations against a company 1/100 of the size of yours?

No but there's incentive to provide many small half-truths out of context to shape the narrative into one beneficial for yourself want.

That's the problem. I haven't found any of his statements, that would be only half-true. I even discovered a conference held in Lithuania in 2017, where one of the speakers was presented as the head of B2B sales at Tesonet, working on Oxylabs[1]. It is very unlikely, that ProtonMail was not aware of who it was partnering with on a free VPN service.

[1] https://web.archive.org/web/20170909183904/https://salesclub...

Re: OpenPGPjs has passed an independent security audit

#122
post #121
post #120

Earlier quoted context omitted.

No but there's incentive to provide many small half-truths out of context to shape the narrative into one beneficial for yourself want.

That's the problem. I haven't found any of his statements, that would be only half-true. I even discovered a conference held in Lithuania in 2017, where one of the speakers was presented as the head of B2B sales at Tesonet, working on Oxylabs[1]. It is very unlikely, that ProtonMail was not aware of who it was partnering with on a free VPN service. [1] https://web.archive.org/web/20170909183904/https://salesclub...

Furthermore, after it was pointed out by the co-founder of PIA, that the CEO of Tesonet is the director of ProtonVPN UAB, the company was renamed multiple times in two months[1], with its director now hidden from the public view.

[1] https://web.archive.org/web/20180818102535/https://rekvizita...

Re: OpenPGPjs has passed an independent security audit

#123
post #122
post #121

Earlier quoted context omitted.

That's the problem. I haven't found any of his statements, that would be only half-true. I even discovered a conference held in Lithuania in 2017, where one of the speakers was presented as the head of B2B sales at Tesonet, working on Oxylabs[1]. It is very unlikely, that ProtonMail was not aware of who it was partnering with on a free VPN service. [1] https://web.archive.org/web/20170909183904/https://salesclub...

Furthermore, after it was pointed out by the co-founder of PIA, that the CEO of Tesonet is the director of ProtonVPN UAB, the company was renamed multiple times in two months[1], with its director now hidden from the public view. [1] https://web.archive.org/web/20180818102535/https://rekvizita...

Finally, the IP blocks, which belonged to Tesonet and were used by ProtonVPN just a few months ago – despite the co-founders of ProtonMail publicly denying any technical partnership between the two[1] – now belong to ProtonVPN[2].

[1] https://news.ycombinator.com/item?id=17260847

[2] https://web.archive.org/web/20180818104256/https://bgpview.i...

Re: OpenPGPjs has passed an independent security audit

#124
post #123
post #122

Earlier quoted context omitted.

Furthermore, after it was pointed out by the co-founder of PIA, that the CEO of Tesonet is the director of ProtonVPN UAB, the company was renamed multiple times in two months[1], with its director now hidden from the public view. [1] https://web.archive.org/web/20180818102535/https://rekvizita...

Finally, the IP blocks, which belonged to Tesonet and were used by ProtonVPN just a few months ago – despite the co-founders of ProtonMail publicly denying any technical partnership between the two[1] – now belong to ProtonVPN[2]. [1] https://news.ycombinator.com/item?id=17260847 [2] https://web.archive.org/web/20180818104256/https://bgpview.i...

ProtonMail's response is here: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn...

Re: OpenPGPjs has passed an independent security audit

#125
post #123

Earlier quoted context omitted.

Finally, the IP blocks, which belonged to Tesonet and were used by ProtonVPN just a few months ago – despite the co-founders of ProtonMail publicly denying any technical partnership between the two[1] – now belong to ProtonVPN[2]. [1] https://news.ycombinator.com/item?id=17260847 [2] https://web.archive.org/web/20180818104256/https://bgpview.i...

ProtonMail's response is here: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn...

> These stories were first fabricated by Private Internet Access, a competitor who has been feeling pressure from ProtonVPN lately.

This is a lie. Private Internet Access is probably the largest paid VPN provider in the world, and ProtonVPN (by Tesonet?) belongs to a short list of free VPN providers, such as Onavo VPN by Facebook[1] and Hola VPN by Luminati[2], most of which are subsidized by data mining companies. These are two completely different markets.

> We used the same legal address and nominee directors as our local partners because we still did not have our own office yet. For contractual reasons, these moves took some time. For example, ProtonLabs Skopje, our newest entity, only moved in November 2017.

ProtonVPN UAB has been founded in July 2016, and was still operated from Tesonet HQ in June 2018, when this fact was made public by the co-founder of PIA. The current ProtonVPN legal address in Vilnius, Lithuania can be used by any company, which agrees to pay for 1 work-place without any long-term obligations[3]. This means, that ProtonVPN might as well be still operating from Tesonet HQ.

> ProtonVPN/ProtonMail does not, and has never used any IPs or servers from Tesonet (this can be publicly verified)

This is a lie. ProtonMail admitted to using Tesonet IPs, when presented with Whois results in June 2018[4]. Those IP blocks were later assigned to ProtonVPN.

> Proton does not share any employees (or company directors) with Tesonet. This is also a verifiable fact.

This is a lie. It is no longer possible to verify, who is the director of ProtonVPN, because the company made the public record unavailable after changing its name multiple times in the last two months[5]. The last public record listed the CEO of Tesonet as the director of ProtonVPN[6], which was still true in early June 2018, when the co-founder of PIA made the fact public.

> There is little actual evidence that Tesonet does data-mining (in any case we have never used infrastructure from them).

This is a lie. There is plenty of actual evidence, that Tesonet is running a data mining company, called Oxylabs[7][8], which sells access to "10+ Million Mobile IPs in Every Country and Every City in the World".

[1] https://fossbytes.com/facebook-onavo-protect-feature-vpn-tra...

[2] https://www.techtimes.com/articles/56706/20150530/if-you-are...

[3] http://bc2000.lt/en/#ofisas

[4] https://news.ycombinator.com/item?id=17261243

[5] https://web.archive.org/web/20180818102535/https://rekvizita...

[6] https://web.archive.org/web/20171017093924/http://rekvizitai...

[7] https://web.archive.org/web/20180426151621/http://oxylabs.io...

[8] https://web.archive.org/web/20170909183904/https://salesclub...

Re: OpenPGPjs has passed an independent security audit

#126
post #76
post #36

Earlier quoted context omitted.

There is nothing wrong with data mining itself. It's completely neutral technology. You are just thrwoing shade with link flooding (those who read the links find out that they don't credibly confirm what you say). Tesonet provides all kinds of services, like hosting, software development and cybersecurity for it's customers.

> There is nothing wrong with data mining itself. It's completely neutral technology. Tesonet's Oxylabs offers "10+ Million Mobile IPs in Every Country and Every City in the World"[1], which might explain why ProtonVPN, whose Android app is signed by Tesonet[2], is a free service. This is how Luminati, Tesonet's largest competitor in Residential Proxies, operates: it provides a free VPN service, Hola VPN, and then co…

It turns out, that Luminati Networks Ltd sued UAB Tesonet over patent infringement in "Large-scale web data extraction products and services with residential proxy network (oxylabs.io)"[1] in July 2018.

[1] http://litigation.maxval-ip.com/Litigation/DetailView?CaseID...

Re: OpenPGPjs has passed an independent security audit

#127

Earlier quoted context omitted.

I stand by that statement.

Those types of comments (yours and the general back-and-forth with ProtonMail) make the VPN industry look like it's full of sharks. It's hurting all of you. It makes you look unprofessional. Before seeing this I had a favourable impression of PIA, but not anymore. EDIT: I'm sure the competition is intense and I'm not sure I would be able to rise above it myself but I think you need to be aware of what it looks like.

It may be full of sharks. Specifically, though, my issues are with the two companies who pretend they are privacy companies and aren’t.

They bring shame to our industry, and further, shame to our cause.

I will stand up against them everyday regardless of what kind of repercussions come to me. That’s what it means to protect people’s privacy.

Cheers!

Re: OpenPGPjs has passed an independent security audit

#128
post #118
post #87

Earlier quoted context omitted.

This also means you can't use another computer or that your key is lost if you clear browser data. Unless you'd do backups but I doubt this is standard procedure of ProtonMail users.

That's true assuming that the browser doesn't offer any way to manage that using e.g. Chrome/Firefox Sync. What PGP really needs is a modern security model so you'd have many device keys registered to an identity rather than requiring the risk of spreading copies around. I think I have IIRC 8 GPG subkeys currently (6 of them being Yubikeys) and every aspect of that toolchain is unacceptable in the modern era.

I've got the same setup with subkeys per Yubikey (though I had to rotate due to Infineon).

What do you mean by "device keys"? Something like forward secrecy keys for initial session setup as used by e.g. Signal? This could be done with some effort... actually Rust OpenPGP library Sequoia developers already work on making this use case easier.

Another set of patches circulating on the ML adds support for TPM bound keys, that are non extractable.

Post reply on HN