I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…
Today I received promotional e-mails from Mozilla to my Firefox Account address. That really annoyed me, dipping into a privacy-sensitive database just to send marketing spam. How can marketing people even get access to that DB? No Mozilla, I don't want to watch your seasonal streaming music concerts. I want you to get on with building a better browser and stop undermining my trust. Sadly the top management think the…
Firefox partners with ProtonVPN
121–129 of 129 posts
Re: Firefox partners with ProtonVPN
#122Earlier quoted context omitted.
You missed a few things: - They have telemetry turned as the default - They are experimenting with TLS over HTTPS and use beloved Cloudflare to handle every DNS request - They are always in the headlines about some shady 'addon' or 'extension' been sold off and taken over by shady actors - The TorBundle which is a fork of FF ESR is always in the headlines as been unsecure and way behind FF mainline release
Could you elaborate about the tor browser?
Currently Tor is behind mainline Firefox in terms of security because it's a fork of Firefox ESR[1]. Pay attention to this part[2]:
> Unlike other release channels, ESRs are not updated with new features every six weeks. They are instead supported for more than a year, updating with major security or stability fixes.
[1] https://www.mozilla.org/en-US/firefox/organizations/
[2] https://developer.mozilla.org/en-US/docs/Mozilla/Firefox/Fir...
Re: Firefox partners with ProtonVPN
#123I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…
Mozilla Foundation is non-profit but Mozilla Corporation is for profit. I don't know how that would affect your opinion but it certainly did when I found that that out recently when I wanted to know how much they were paid by search engines.
Re: Firefox partners with ProtonVPN
#124I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…
> I trust Mozilla more than to just about anybody: they're nonprofit, Mozilla Foundation is non-profit but Mozilla Corporation is for profit. I don't know how that would affect your opinion but it certainly did when I found that that out recently when I wanted to know how much they were paid by search engines.
Re: Firefox partners with ProtonVPN
#125I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…
> I'm excited because VPNs are all about shifting trust I agree overall about the benefits of getting more reliable auditing for VPNs, I think that's important and I'd like to see Mozilla release more details. But I strongly disagree with the "shifting trust" explanation that people use when they talk about VPNs. People bring up this point all the time, that if you can't guarantee trustworthiness, there's no benefit.…
As opposed to leaking your VPN's IP address, which is about as meaningful.
> You're also trusting any other networks that you connect to when you open up your laptop in a coffee shop or hotel room not to have a sniffer sitting on them.
True. Which is why a personal VPN to your home network is useful.
> You're trusting tons of faceless organizations across the entire chain of you to the website you visit to be safe with your data.
The connection from the VPN provider still goes through a similar chain.
It's true that the chain will be substantially different if you, say, connect to a service in the US from the UK via an Australian VPN service. On the other hand, the chain will be way longer if you use that Australian VPN to look up your local pizza place's menu.
Re: Firefox partners with ProtonVPN
#126Earlier quoted context omitted.
Apparently not, since the opening comment complains about an optional VPN offering and a service integration you can turn off.
Yeah, in the about:config, which you are told not to meddle with by the browser. I agree, it's better than nothing. But it might as well be missing for the average user.
Re: Firefox partners with ProtonVPN
#127Earlier quoted context omitted.
> I'm excited because VPNs are all about shifting trust I agree overall about the benefits of getting more reliable auditing for VPNs, I think that's important and I'd like to see Mozilla release more details. But I strongly disagree with the "shifting trust" explanation that people use when they talk about VPNs. People bring up this point all the time, that if you can't guarantee trustworthiness, there's no benefit.…
> You're also leaking your IP address to any website you visit. As opposed to leaking your VPN's IP address, which is about as meaningful. > You're also trusting any other networks that you connect to when you open up your laptop in a coffee shop or hotel room not to have a sniffer sitting on them. True. Which is why a personal VPN to your home network is useful. > You're trusting tons of faceless organizations acros…
Unless you're very lucky with providers, your local IP address is good enough for me to get at least your zip code, and if you're particularly unlucky with your provider/network setup there are theoretical attacks that can be used to get even closer to your physical location[0].
By comparison, the closest VPN address to my physical location is in a different state. That really matters if you care about privacy -- without a VPN you are broadcasting your current town to literally every single site you visit.
> The connection from the VPN provider still goes through a similar chain.
But when it goes through that chain, the request is sent from the VPN provider, not from your own IP address, which is significantly more unique and easier to track, even if you've taken steps to block browser fingerprinting. Request aggregation is by no means a perfect defense against tracking, but it is significantly better than not aggregating requests.
> Which is why a personal VPN to your home network is useful.
Granted. If you've set up a personal VPN to your home network and you're maintaining your own server to make that work, that'll protect you when you browse at a coffee shop. It's also a lot more work for the average user (it's certainly not a viable substitute for what Firefox is doing here), and if done incorrectly a home VPN can make your network vulnerable to attacks because it forces you to open ports.
So my suggestion if you're going down that route would be to buy a 3rd-party server on something like Linode and set up your VPN there. That way a poorly configured server won't make your home network vulnerable. That will also protect you from at least the geolocation attacks I mentioned above. You won't have the advantage of sharing an IP with other people, but I can see that being an acceptable tradeoff for people who want more control.
At that point though, you've basically just rolled your own private VPN provider. You can debate whether or not it's better to roll your own provider or use an existing provider, but in either case, you're still using a VPN. Because VPNs are strict upgrade to network security for most people.
[0]: https://arstechnica.com/tech-policy/2011/04/getting-warmer-a...
Re: Firefox partners with ProtonVPN
#128Earlier quoted context omitted.
> I want a browser that is reliable, high quality, respects my privacy, and nothing else. I don't want addons baked into it. I don't want to be spied on. I recommend that you look into what you're getting with software freedom -- the single most important aspect that makes Firefox different from Google Chrome, Microsoft's web browsers, Opera, or Apple Safari. All of the items on your list can be changed by using your…
I know how to program. I've contributed to Mozilla projects. Including minor contributions to components of Firefox. I do not have the time or the money to personally develop a secure web browser for the rest of the world, nor does any other individual. Your demand is unreasonable. Moreover, I'm not demanding that Mozilla do something. I'm explaining what would have to change for me to be able to promote Firefox and…
Apparently some people do, that's why we have Firefox derivatives like the Tor browser and GNUZilla, among others. Also, I made a recommendation not a demand. I continue to recommend that you consider what software freedom grants you in light of what you say you want other programmers to do for you.
Re: Firefox partners with ProtonVPN
#129Earlier quoted context omitted.
So if I understand correctly, you would want to know the details of how Mozilla audited ProtonVPN, is that it?
Everyone in Vilnius, Lithuania knows, that both, NordVPN and ProtonVPN, are being developed here by the people related to Tesonet, which has been recently sued in Texas Eastern District Court for the patent infringement in "Large-scale web data extraction products and services with residential proxy network ( https://oxylabs.io/ )"[1] by Luminati Networks, an Israeli data mining company behind HolaVPN[2]. The section…
> Everyone in Vilnius, Lithuania knows, that both, NordVPN and ProtonVPN, are being developed here by the people related to Tesonet
This is not true. Proton has staff in Geneva, Zurich, Skopje, Vilnius, and San Francisco. Years ago, we did sublease office space from Tesonet (one of the biggest IT firms in Vilnius) as alleged above, but there is no connection today.
ProtonVPN is fully developed (and owned) by Proton Technologies AG, the Swiss company that also operates ProtonMail. This can be verified in the Swiss commercial registry, which also lists all our directors: http://ge.ch/hrcintapp/externalCompanyReport.action?companyO...