Live data from Hacker News

Show HN: A small bootstrapped independent VPN company in the Netherlands

wifimask.com

51–60 of 111 posts

Re: Show HN: A small bootstrapped independent VPN company in the Netherlands

#52

In the macOS app I cannot copy paste my password into the textfield to login.

I have seen this throughout macOS lately with other apps too, a rightclick will show you the paste option btw. Meanwhile I will investigate this, thanks!

Re: Show HN: A small bootstrapped independent VPN company in the Netherlands

#53
post #42

Already posted in 2016? https://news.ycombinator.com/item?id=11366537 So not just launched as I’d expected

We preferably launch once in a while. ;-) This is not really a launch btw, although it's getting a launch with upvotes on HN this time. But I just wanted to show the current state of WifiMask, it took some time to work on it more and there is still a lot of work to do, like Android and Windows apps.

Re: Show HN: A small bootstrapped independent VPN company in the Netherlands

#54
post #44

Earlier quoted context omitted.

As a counterpoint: any VPN service that claims that they will ignore the authorities legal requests is lying. No matter what, as soon as it is a business, has a registered address and a nominal director it can be put under pressure.

I think this is true. We want to be as honest and open as possible, that includes being honest about the laws we have to comply too. On the other hand, we have a strict no log policy, we have nothing to hand over to authorities accept for the registered email address, a hashed password and the last 4 numbers of a creditcard. Authorities will need to find different ways to get the information they want.

A 'no log policy' is a hard one, it may be true but you can't really prove a negative. So it is as good as your word and your reputation, which in this case may be very good but it may not be enough to reduce skepticism.

FWIW I do tech DD for a living and I've seen several places that had 'no log' policies on the outside and yet they would occasionally - or even structurally - log data in order to comply with the law.

The 'WBT' (Retenion duty for Telecommunicationsdata) has been disbanded, which should work to your advantage, but the GDPR makes explicit room for the accomodation of legal and regulatory requirements and this in turn may transcend your 'no log' policy. Please make sure you have appropriate legal advice on the subject, it is complex and getting it wrong can really bite you.

Best of luck with your company!

Re: Show HN: A small bootstrapped independent VPN company in the Netherlands

#56
post #41

As a minor nitpick, I dislike the term "Holland" when referring to the Netherlands. Additionally, you're based in Den Bosch, which is not even in Holland. (you say "made in Holland" in your logo)

You can blame the Dutch Tourism board for that, they unilaterally declared 'The Netherlands' to be too complicated for marketing purposes and decided on Holland.

https://www.nbtc.nl/

So, from on high: Den Bosch is now also in Holland, as are Maastricht, Enschede, Middelburg and Groningen, to great chagrin of those living there. It's been a major point of contention between the NBTC and almost all of the rest of the country but 'Made in Holland' has displaced 'Made in The Netherlands' for quite a while now.

Re: Show HN: A small bootstrapped independent VPN company in the Netherlands

#57
post #49
post #12

Earlier quoted context omitted.

Many thanks for your feedback! Much appreciated. The missing newlines and subresource integrity are now fixed. The Privacy Policy is now updated with information on how to opt-out. WifiMask uses OpenVPN for the macOS app and IKEv2/IPSec for iOS. Examples of OpenVPN config files can be found at https://www.wifimask.com/contact#androidwindows which allows you to use the WifiMask service on every OpenVPN capable device.…

No 2FA other than mandatory phone number? This is a really, really bad thing. (+ forcing proprietary app?) Can't find list of hostnames to use with OVPN, seemingly

The optional 2FA used is Authy, you activate Authy with your phonenumber only once, after that you use Authy to login to your account. So 2FA is not done through SMS text messages for example, where hijacking could be a problem.

Good one with the list of hostnames, I will prepare one, for now you can take a look at this JSON file:

https://vpnserver.wifimask.net/vpnservers.json

Re: Show HN: A small bootstrapped independent VPN company in the Netherlands

#58
post #31

very reasonably priced, if I had a mac I'd be trying it out. what I want is a vpn that the BBC that fools the bbc into thinking I'm in the UK. They're wise to my current one, pia.

Unfortunately BBC iPlayer is also not unblocked with WifiMask since a few weeks. It looks like they bought some anti-VPN algorithms from Netflix.

Re: Show HN: A small bootstrapped independent VPN company in the Netherlands

#59
post #11

I'm not sure I agree with pushing responsibilities on customers. If you miss some security item or if you make my account a super admin on signup I shouldn't have some responsibility to help you fix it. What we need our customers to do: - Use responsible disclosure in the event any security vulnerabilities occur in our website, software or infrastructure.

I will rephrase it, the intention is not to push responsibilities, we are merely asking our customers to let us know if they ever find a vulnerability. Thanks for the feedback!

Re: Show HN: A small bootstrapped independent VPN company in the Netherlands

#60
post #57
post #49

Earlier quoted context omitted.

No 2FA other than mandatory phone number? This is a really, really bad thing. (+ forcing proprietary app?) Can't find list of hostnames to use with OVPN, seemingly

The optional 2FA used is Authy, you activate Authy with your phonenumber only once, after that you use Authy to login to your account. So 2FA is not done through SMS text messages for example, where hijacking could be a problem. Good one with the list of hostnames, I will prepare one, for now you can take a look at this JSON file: https://vpnserver.wifimask.net/vpnservers.json

Yeah, this is really not a good thing on the Authy part. You should not need to activate it with a phone number.
Post reply on HN