Live data from Hacker News

Firefox partners with ProtonVPN

premium.firefox.com

101–110 of 129 posts

Re: Firefox partners with ProtonVPN

#101
post #96

Earlier quoted context omitted.

Why didn't you invite Mozilla to the real office in Vilnius, Lithuania where ProtonVPN was actually being developed?

Because the senior team members who developed the ProtonVPN partnership with Mozilla were all in our Geneva HQ, because that's where we're actually based...

Could you post some pictures from your office in Vilnius, Lithuania, where ProtonVPN UAB with 19 technical(?) employees is currently based? Are they still working from Tesonet's HQ, just like they did in 2017, and for the most of 2018?

Is Tesonet's CEO still the director of ProtonVPN UAB, more than 2 years after the incorporation in July 2016? I can no longer check it myself, because the public record is now hidden. But it was still true in June 2018.

And how do you feel about partnering on a free VPN service with a company, which has been sued for multiple patent infringements in "Large-scale web data extraction products and services with residential proxy network" by the founders of another free VPN service, HolaVPN, who have publicly admitted to using it for exactly that?

Re: Firefox partners with ProtonVPN

#102
post #28

I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…

I've been toying around with ProtonMail premium service, so this isn't a direct reflection on ProtonVPN the product. However ProtonMail's support is abysmal. For me that hasn't been a direct reflection of the product, however getting anyone from ProtonMail to engage in a cognizant support conversation is next to impossible and takes days to get an answer. They don't seem to treat paying customers any different than t…

I switched to ProtonMail about 6 weeks ago and have had nothing but prompt, positive experiences with their support team. Going so far as releasing new import-export tools which specifically address issues I came across when migrating my mail over.

Re: Firefox partners with ProtonVPN

#103

Earlier quoted context omitted.

I would add: - Public search for sources of other people's breached personal data via monitor.firefox.com (eg, you can enter anyone's email and see results, and not just your own, as there's no verification that you own the email until you sign up for continuous alerting) That said, I love Firefox itself and think Mozilla usually try to do the right thing. Someone just lost the security vs usability debate there I gu…

> Public search for sources of other people's breached personal data via monitor.firefox.com That page is powered by haveibeenpwned.com. Mozilla just made a fantastic security tool available to user who don't know about Troy's site. > you can enter anyone's email and see results This data is all very easily available online anyway. It's just aggregating leaks that already public, and neither HIBP or the Mozilla page…

In other words, they have publicized the existing tool to make it available to a broader audience without adding anything on top to improve its security. They're both in the wrong on this.

The argument of "Others are being irresponsible, so we should be irresponsible as well" does not stand up very well.

The only valid use case for providing this information is for when a user no longer has access to the email address in question.

In this case, they should still require it to be sent via email, and they should still send a notification to the email address being requested which includes details about the request like the IP it is made from and the email it would forward to, perhaps with a delay-and-prevent option so that someone who still owns the email can prevent the exfiltration by responding to the notice quickly.

Otherwise, this enables anyone to solicit unauthorized PII data about basically anyone else from Mozilla.

Even HIBP somewhat acknowledge the potential damage this can do, from the way they censor some results like the Ashley Madison data breach. They've made the decision that some personal information linked to a person's email address is more worthy of protection than other bits of personal information, which really shouldn't be up to them.

They get away with it because of weak data protection laws and the fact that this caters to individual users who are more likely to opt themselves out if they become aware of it than to file a lawsuit or otherwise apply pressure to make them change.

Re: Firefox partners with ProtonVPN

#104

Earlier quoted context omitted.

I would add: - Public search for sources of other people's breached personal data via monitor.firefox.com (eg, you can enter anyone's email and see results, and not just your own, as there's no verification that you own the email until you sign up for continuous alerting) That said, I love Firefox itself and think Mozilla usually try to do the right thing. Someone just lost the security vs usability debate there I gu…

Isn't that just what haveibeenpwned does? In fact, I wouldn't be surprised if monitor.firefox were using hibp internally.

Yes, it's the same, FF Monitor calls HIBP on the backend. Firefox Monitor is basically branding, to get the information out to more users (and more stalkers) because they are more recognizable.

Re: Firefox partners with ProtonVPN

#105

I started using ProtonVPN in the last few weeks. If you run Little Snitch, you can see they're sending data to Google Crashlytics. Doesn't inspire confidence. https://www.dropbox.com/s/t5ciujv55g7l2dj/ProtonVPN-Google-C...

They confirmed this [0]. I don't like it, but I don't think it's the worst thing in the world if there's no user data being sent.

[0] https://www.reddit.com/r/ProtonVPN/comments/a0qiuu/protonvpn...

Re: Firefox partners with ProtonVPN

#106

I started using ProtonVPN in the last few weeks. If you run Little Snitch, you can see they're sending data to Google Crashlytics. Doesn't inspire confidence. https://www.dropbox.com/s/t5ciujv55g7l2dj/ProtonVPN-Google-C...

I've heard good things about Mulvad but have yet to try it out. https://www.mullvad.net/en/

Nord was pretty good but I got rid of them when they removed the ability to see the distances to the servers in their app.

Re: Firefox partners with ProtonVPN

#107

Earlier quoted context omitted.

> But the service isn't fully baked yet for me, because they're not explaining how they're enforcing the trustworthiness of ProtonVPN. I have no idea if ProtonVPN is as trustworthy as Mozilla -- maybe it is, but I don't want to learn and stay on top of that. Instead I want premium.firefox.com/vpn/ to convince me that, if I use Mozilla's service, I'm fully benefiting from their trustworthiness. I'm also interested in…

You can find details about this on Mozilla's blog post on this topic, which also describes what they did to audit ProtonVPN: https://blog.mozilla.org/futurereleases/2018/10/22/testing-n...

To be fair, that's not very detailed. While I trust Mozilla, I agree that it would be interesting to have more details.

Re: Firefox partners with ProtonVPN

#108
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

Today I received promotional e-mails from Mozilla to my Firefox Account address. That really annoyed me, dipping into a privacy-sensitive database just to send marketing spam. How can marketing people even get access to that DB?

No Mozilla, I don't want to watch your seasonal streaming music concerts. I want you to get on with building a better browser and stop undermining my trust. Sadly the top management think they're running a social experiment.

Re: Firefox partners with ProtonVPN

#109

Earlier quoted context omitted.

I've been toying around with ProtonMail premium service, so this isn't a direct reflection on ProtonVPN the product. However ProtonMail's support is abysmal. For me that hasn't been a direct reflection of the product, however getting anyone from ProtonMail to engage in a cognizant support conversation is next to impossible and takes days to get an answer. They don't seem to treat paying customers any different than t…

I switched to ProtonMail about 6 weeks ago and have had nothing but prompt, positive experiences with their support team. Going so far as releasing new import-export tools which specifically address issues I came across when migrating my mail over.

Bridge has been in development for while. I'm guessing that's the tool you're referring to. I've asked them about a few more complex scenarios with regard to sharing of mailboxes and group send-as features. My questions were well defined and not answered in their existing FAQ. The problem I experienced was that they gave me non-answers to my questions. Sure, I did receive a response (days later) but the response didn't address my questions. Since your issue seems to have been well defined I'm not all that surprised you had a more positive experience.

Re: Firefox partners with ProtonVPN

#110

I started using ProtonVPN in the last few weeks. If you run Little Snitch, you can see they're sending data to Google Crashlytics. Doesn't inspire confidence. https://www.dropbox.com/s/t5ciujv55g7l2dj/ProtonVPN-Google-C...

They confirmed this [0]. I don't like it, but I don't think it's the worst thing in the world if there's no user data being sent. [0] https://www.reddit.com/r/ProtonVPN/comments/a0qiuu/protonvpn...

In particular it's in the todo list to migrate to Sentry on premise.
Post reply on HN