Live data from Hacker News

Firefox partners with ProtonVPN

premium.firefox.com

41–50 of 129 posts

Re: Firefox partners with ProtonVPN

#41
post #28

I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…

So if I understand correctly, you would want to know the details of how Mozilla audited ProtonVPN, is that it?

Re: Firefox partners with ProtonVPN

#42
I trust Mozilla, and if this helps Mozilla (and Firefox) further, I'm all for it. From a different angle though, I'd prefer more decentralized solutions than centralized ones like a single VPN provider. That could be in the form of more Tor infrastructure coming up to make the Tor network faster (I myself am not capable of setting up and running nodes).

My other concern with centralized VPN is that Cloudflare, with its appetite seemingly focused on being the biggest pipe (by a large measure) for Internet traffic, might soon come up with a free VPN service and kill most others. I'm certainly not a fan of large companies becoming large enough and entrenched enough to put up insurmountable barriers against disruption (this could end up being a futile hope).

Re: Firefox partners with ProtonVPN

#43

Earlier quoted context omitted.

Maybe we need a light fork which removes all those problematic parts on each release?

Some of this problematic points are historical and resolved, like the Mr. Robot advert.

The fact that there are so many points just means we all have to sit and wait to see what the Mozilla Corporation does next. It does not matter if they resolve every grave transgression they do, I already have 0 trust placed on them.

Re: Firefox partners with ProtonVPN

#44
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

>- Pocket, as a service being added to the default home/newtab page

Firefox now shows you ads on your home page by default. It's diabolical.

I trust a well-configured Chrome (and with that I mean using the options dialog, not the cryptic about:config) more than Firefox. Even after having a well configured about:config, they managed to remotely install the Mr. Robot advertisement addon on my computer. I freaked out when I saw it.

The Mozilla Corporation would do very well with a big change of leadership.

Re: Firefox partners with ProtonVPN

#45
post #29
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

Well, unsigned addons are banned in the branded release browser. If you use the developer edition, nightly or compile Firefox yourself then you can install unsigned addons into Firefox. The last option also enables you to turn of Pocket and a variety of other services.

I use to use nightly, then I found out they spy on you a lot more if you use nightly. I suspect the same applies to developer edition.

[0] https://utcc.utoronto.ca/~cks/space/blog/web/FirefoxNoNightl...

[1] https://lobste.rs/s/ri4kny/you_probably_don_t_want_run_firef...

Re: Firefox partners with ProtonVPN

#46
post #19

Earlier quoted context omitted.

Apparently not, since the opening comment complains about an optional VPN offering and a service integration you can turn off.

You can already opt into Proton VPN. See, it's right here: https://protonvpn.com/ So that's the point; don't bake features into my browser that point me to one company when the whole purpose of a browser in the first place is to be able to visit web pages... like https://protonvpn.com/ . This is about only one thing: money (affiliate sales).

While I'm sure some money exchanged hands, this is obviously not just a marketing move.

We live in a world where VPN are a must if you want to have any expectation of privacy. Giving people easier access to these services is not a bad thing. Mozilla has a privacy-minded vision for the internet. Regardless if you agree with their vision, they are at least following it.

Also, if it's true that Mozilla is auditing ProtonVPN, that is a huge benefit to everyone. The biggest issue with VPNs are you're forced to trust this new company that they'll do as they say with your data (namely that they don't harvest or store any of it). To me, that's a huge thing.

Re: Firefox partners with ProtonVPN

#47

Earlier quoted context omitted.

Maybe we need a light fork which removes all those problematic parts on each release?

Some of this problematic points are historical and resolved, like the Mr. Robot advert.

Maybe with a user-orientated fork the ability which allowed the Mr. Robot-thing would be gone too. As I remember it's a sketchy part which is not neccessary for the basic functionality.

Re: Firefox partners with ProtonVPN

#48
post #41
post #28

I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…

So if I understand correctly, you would want to know the details of how Mozilla audited ProtonVPN, is that it?

Right -- I'm looking for a white-paper level of detail somewhere behind the landing-page level of detail. What threats (internal and external) did you consider, what evidence convinced you they were addressed, and what acceptable risks remain? What would you as an engineer want to be told by another engineer who did the audit, for you to say "great, that's what I would have done, sounds like you did your due diligence, I'll use that"?

The white paper won't be read by everybody and shouldn't be targeted at everybody, but it will be read by the most knowledgeable folks and be a source of confidence that filters out to everyone else.

This all depends on there actually being an audit -- so far the landing page doesn't even say that! From the text on the page there's no way to tell if Mozilla just read the published policies for a bunch of VPNs and made a recommendation, or has an employee embedded in ProtonVPN's security team and a seat on the board, or somewhere in between. Without knowing the details, it's hard for me to say whether I'm looking for more documentation of the audit that already happened, or a stronger actual relationship behind the endorsement.

Re: Firefox partners with ProtonVPN

#49
post #41
post #28

I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…

So if I understand correctly, you would want to know the details of how Mozilla audited ProtonVPN, is that it?

Everyone in Vilnius, Lithuania knows, that both, NordVPN and ProtonVPN, are being developed here by the people related to Tesonet, which has been recently sued in Texas Eastern District Court for the patent infringement in "Large-scale web data extraction products and services with residential proxy network ( https://oxylabs.io/ )"[1] by Luminati Networks, an Israeli data mining company behind HolaVPN[2].

The section from the "About" page of Tesonet (26 Apr 2018)[3], which was suddenly removed in June 2018 after the connection between ProtonVPN and Tesonet was made public by the co-founder of PIA[4]:

"For the latest project, Tesonet is working together with an international brand from Switzerland to create a security product that helps users protect their network traffic. As part of this technical partnership, we are collaborating on datacenter and network infrastructure that can easily supply 10 Gbps worth of bandwidth to users around the world. The product is developed using the latest authentication encryption methods and the best practices in the security world."

As late as September 2018, NordVPN and ProtonVPN still become affected by the same extremely rare Windows security bugs at the same time[5], even though the CTO of ProtonMail claimed here on Hacker News, that they used Tesonet, a data mining company, for developing ProtonVPN, a free VPN service, only as "an office space provider"[6].

[1] http://litigation.maxval-ip.com/Litigation/DetailView?CaseID...

[2] http://fortune.com/2015/05/29/hola-luminati-vpn/

[3] https://web.archive.org/web/20180426161609/https://tesonet.c...

[4] https://news.ycombinator.com/item?id=17258203

[5] https://www.pcmag.com/news/363619/protonvpn-and-nordvpn-bugs...

[6] https://news.ycombinator.com/item?id=17258538

Post reply on HN