Live data from Hacker News

Mozilla VPN

blog.mozilla.org

311–320 of 531 posts

Re: Mozilla VPN

#311

Every time someone mentions a VPN provider in my techie social circles, the "A VPN doesn't protect you" crowd piles in, usually with links to something like: https://gist.github.com/joepie91/5a9909939e6ce7d09e29 I don't understand this argument, but would like to. I run https://everytwoyears.org , a political non-profit focused on ending the warrantless metadata collection of U.S. citizens' communications. From every…

A VPN is just a tunnel from one point to another. You'd have to establish why the remote end is more trustworthy than the local end. Being located in a hostile jurisdiction may be somewhat protective, but it would also seem likely that compromising foreign VPN services is within the NSA's wheelhouse.

> compromising foreign VPN services is within the NSA's wheelhouse

This is the explicit danger of VPN providers. Even if the provider is not complicit (which I believe applies to the likes of Mozilla), it still creates a centralized aggregation site for collection.

I'm not even sure a US-based VPN provider is safe. GCHQ just conducts the interception and would share the data with NSA. At that point, you are at the mercy of the NSAs locators being good enough to flag your tunneled traffic as "reasonably a US person" so it gets excluded.

Re: Mozilla VPN

#312
post #305

Earlier quoted context omitted.

Not sure why I would switch to another chat, email, file, sync just because it’s from Mozilla

Privacy

I don't think it's a good idea to give any company a monopoly on your data even if you trust them.

Re: Mozilla VPN

#313
post #197

Forget the VPN--I already have a VPN provider and I have no interest in changing. Offer a paid e-mail service, on the other hand, and I'd sign on up Day 1.

I've heard good things from HEY[1]; I've been thinking about using their trial [1] https://hey.com/

Unfortunately it's invite-only, at least for now.

Re: Mozilla VPN

#314
post #141

Come on Mozilla, hurry up! I want to give you money for goods and services (I also donate monthly [1]), but I'm not that interested in a VPN (I can and do also pay Mullvad). Give me that real internet stuff - email, calendar, file sync, chat(?) - give me Firefox Premium. Bundle in the Lockwise password manager. I'd pay good money to see a company fill the void of paid, privacy first essential internet services and I…

Let them stay in the Niche maybe? I'd rather have a really great safe browser than half a dozen half baked products from the same company.

The problem is the revenue source. Currently Mozilla gets most of their income from their biggest competitor, Google, which is pretty fragile and all-eggs-in-one-basket. Diversifying their revenue stream by slightly diversifying their product would make them more likely to survive.

Re: Mozilla VPN

#315
post #292

Earlier quoted context omitted.

If nothing else, it significantly reduces the entropy of your IP when websites are fingerprinting you, especially if your ISP assigns you a static IP. Even if you don't have a static IP, I suspect the entropy of your /24 (IPv4) is also a lot smaller when over VPN.

Do you understand the words you're using?

I thought I did? The condescending attitude is unnecessary. Happy to clarify my point if my initial comment was confusing:

Websites such as http://panopticlick.eff.org/ showcase how fingerprinting works. They tell you how many bits of information they can extract from various datapoints they get out of you when visiting their site, such as User-Agent.

Panopticlick does not use your IP address as a datapoint, but actual trackers most likely do. If not your IP directly, then a prefix thereof (such as your /24), to account for ISPs w/ dynamic IP allocation.

If you have a static IP, there's a lot of bits of entropy in it, i.e. it's great for fingerprinting. It's basically sufficient, by itself, to uniquely identify your home. The handful of devices in your home can then likely be distinguished by the User-Agent.

If you're part of your ISP's small dynamic IP pool (e.g. a /24), there's probably still a lot of entropy in there. How many people in your neighborhood are also on Linux and have the same set of fonts installed? Probably just you.

Your VPN's dynamic IP subnets, OTOH, can be a lot larger, and the members of the pool are not geographically close to one another, so there's probably a lot less fingerprinting entropy in your IP in that case.

Re: Mozilla VPN

#316
Really smart from Mozilla; they leverage trust in their brand with a product for which trust is the most important feature. Making a VPN is a non-trivial technology project, but it's pretty straightforward how to do it well.

Re: Mozilla VPN

#317

Public VPN services should not be trusted blindly. Online anonymity is very hard. However, you can still create your own VPN server on cloud providers for at least have some privacy while you are on an untrusted network. Because of this reason, I created https://zudvpn.com - It is a free and open-source mobile application that's used to deploy a private VPN server on major Cloud Providers! Github repo: https://github…

But doing this will give you a static IP which will make you even less anonymous.

You cannot connect to the internet without an IP address. However, ZudVPN servers are disposable. This means that you can always destroy the server and create another VPN with completely new IP address that is assigned by cloud providers.

Re: Mozilla VPN

#318

Earlier quoted context omitted.

Totally understood for those countries, but it’s still hugely popular in the US. That’s what I’m wondering about.

Many ISPs in the US perform DPI, sell anonymized data to marketing companies, slowdown YouTube/Netflix when the backend pipes are congested, etc. If you want your ISP to provide you with a dumb pipe and not interfere with your traffic, a VPN is an easy solution.

In practice, you’re almost certainly not getting faster netflix or youtube by adding an extra VPN into the congestion path. There are some weird edge cases where particular peering agreements and anycast routing quirks leave some exceptions to that, but I highly doubt a non-negligible amount of users are actually seeing a consistent speed increase on a VPN, and the vast majority would definitely see a decrease. That VPN is doing more to interfere with traffic than an ISP is.

As for tracking you and selling your data, I trust my ISP to behave better in that regard than I do some shady VPN provider. And I don’t even trust my IP that much.

Re: Mozilla VPN

#319

Earlier quoted context omitted.

How about FastMail? They have a stellar email service. They also offer contacts and calendars, though I don't personally use those (I use iCloud for that).

I’ve used Fastmail for years now on a work account. It’s best feature is that it’s not Google. First, no phone support. Hardly acceptable when even Google has this. Second, no collaboration suite like Drive/Docs. Third, no addons I’m accustomed to having in my daily driver email suite. Things I miss include schedule to send later, default reply all, and no priority inbox. Im stuck using Google for email and maps. I h…

« First, no phone support. Hardly acceptable when even Google has this. »

...you can reach Google over the phone?

Re: Mozilla VPN

#320
post #249

Earlier quoted context omitted.

I want to migrate from Gmail but I have my Gmail address tied up to so many things. How do you make the move ?

Here are the steps I've been following: 1) Sign up for Fastmail. 2) Sync all mail from GMail account to Fastmail (via the Fastmail web UI; you grant FM access to your GMail data through OAuth - once sync is complete you can revoke this access). 3) Set up an auto-forward rule in GMail for all incoming mail to go to your Fastmail address. 4) Set up a rule in Fastmail to put all incoming mail sent to your GMail address…

And most importantly:

0) Get your own domain and set up MX record to fastmail servers

This way if you ever migrate again, you will not need to do it all over again. One word of advice - keep your registrar login and emails associated with the domains _not_ on your domain, otherwise it is going to present a problem should you ever need to fix anything related to domains.

Post reply on HN