Live data from Hacker News

Mozilla VPN

blog.mozilla.org

321–330 of 531 posts

Re: Mozilla VPN

#321

Earlier quoted context omitted.

I want to migrate from Gmail but I have my Gmail address tied up to so many things. How do you make the move ?

Get your own domain, use it for all your email, and in five or so years gmail will be nothing but spam, basically.

which ironically, is the 5yrs it take for gmail/yahoo to not threat your domain outgoing email as spam.

Re: Mozilla VPN

#322
post #204

Every time the VPN service industry is discussed on HN there is a barrage of comments that use keywords like “honeypot”, “snake oil”, and “shady”. I’m not denying that the industry has problems, but in this thread I’d like to focus on how we can improve it. Please tell me - What makes a VPN provider trustworthy, and how do you _know_? Personally I believe a trustworthy provider is _characterized_ by consistent action…

Block all plaintext traffic. Only allow TLS. Be transparent about what you log and what you don't. Publish results of third party audits.

Re: Mozilla VPN

#323

Earlier quoted context omitted.

I used to work at an ISP, and once a month I would stuff envelopes with DMCA letters. I can assure you, that the only thing your ISP is doing with this letters is laughing at whatever porn you downloaded. They're just a scare tactic, and if you get one, you can almost certainly ignore it.

I've had a connection shut off because of three letters. Spectrum.

Spectrum is a joke. They constantly call me and expect me to provide them my address and payment details like it is a sane thing to ask.

Which is sad because their pricing model is less stupid than most of the competition.

Re: Mozilla VPN

#324

Earlier quoted context omitted.

I’ve used Fastmail for years now on a work account. It’s best feature is that it’s not Google. First, no phone support. Hardly acceptable when even Google has this. Second, no collaboration suite like Drive/Docs. Third, no addons I’m accustomed to having in my daily driver email suite. Things I miss include schedule to send later, default reply all, and no priority inbox. Im stuck using Google for email and maps. I h…

« First, no phone support. Hardly acceptable when even Google has this. » ...you can reach Google over the phone?

[deleted]

Re: Mozilla VPN

#325

Earlier quoted context omitted.

I used to work at an ISP, and once a month I would stuff envelopes with DMCA letters. I can assure you, that the only thing your ISP is doing with this letters is laughing at whatever porn you downloaded. They're just a scare tactic, and if you get one, you can almost certainly ignore it.

Didn't Cox recently lose a big lawsuit for not actually doing anything to punish repeat DMCA offenders? I'd be cautious about assuming those letters are still harmless today.

No.

They got a $1bi shakedown in a local court because they successfully fought the RIA in 2015 and won (it was $25mi then).

This time, Cox legal team tried to simply stand behind the DMCA safe-harbor (just like google does) and somehow lost.

it will appeal and win (or likely settle out of court as RIAA already got what it wanted, a hole in safe-harbor)

Re: Mozilla VPN

#326
post #36

Earlier quoted context omitted.

Are DMCA letters still a thing? It seems like Torrenting died out significantly over the last 5 years.

i torrent from home, i also work from home. i just never wanted my job to hire some dumb IT consulting firm to do some cross between IPs on a swam and IPs VPNing in as a "threat analysis" and my dumb name getting dragged into an office. I know it's far fetched, but $40 a year of PIA keeps my mind at ease.

if you work from home and your company provided computer do not talk exclusively to a VPN tunnel into their network, I doubt they will pay a threat analysis.

Re: Mozilla VPN

#327
post #249

Earlier quoted context omitted.

Here are the steps I've been following: 1) Sign up for Fastmail. 2) Sync all mail from GMail account to Fastmail (via the Fastmail web UI; you grant FM access to your GMail data through OAuth - once sync is complete you can revoke this access). 3) Set up an auto-forward rule in GMail for all incoming mail to go to your Fastmail address. 4) Set up a rule in Fastmail to put all incoming mail sent to your GMail address…

And most importantly: 0) Get your own domain and set up MX record to fastmail servers This way if you ever migrate again, you will not need to do it all over again. One word of advice - keep your registrar login and emails associated with the domains _not_ on your domain, otherwise it is going to present a problem should you ever need to fix anything related to domains.

Then you are pushing the problem to someone else to manage the domains right? How do you set this up?

Re: Mozilla VPN

#328

Every time someone mentions a VPN provider in my techie social circles, the "A VPN doesn't protect you" crowd piles in, usually with links to something like: https://gist.github.com/joepie91/5a9909939e6ce7d09e29 I don't understand this argument, but would like to. I run https://everytwoyears.org , a political non-profit focused on ending the warrantless metadata collection of U.S. citizens' communications. From every…

Most people use a VPN because it lets them have a different geolocation (to watch Netflix in a different country, access thepiratebay, etc.) If you do use a VPN to mask your traffic, there are two questions to ask yourself: 1. who are you masking your traffic from? 2. can you trust the VPN network more? In general, you cannot trust a VPN network more, and HTTPS is the solution as it provides end-to-end encryption wit…

HTTPS protects content. Content requires a warrant in the united states.

The bulk metadata programs, as far as we know, only collect metadata. Which two IP addresses communicated, the routes they took, the size of the payloads, etc. are all "metadata".

HTTPS, AFAIK, does not solve this.

Re: Mozilla VPN

#329
post #147

Earlier quoted context omitted.

Only Mozilla can make me pay for Google services like Email/Calendar etc. I think I subconsciously trust the brand more than most internet companies out there.

How about FastMail? They have a stellar email service. They also offer contacts and calendars, though I don't personally use those (I use iCloud for that).

Been using Fastmail for years. Not one glitch, love em’

Re: Mozilla VPN

#330
post #311

Earlier quoted context omitted.

A VPN is just a tunnel from one point to another. You'd have to establish why the remote end is more trustworthy than the local end. Being located in a hostile jurisdiction may be somewhat protective, but it would also seem likely that compromising foreign VPN services is within the NSA's wheelhouse.

> compromising foreign VPN services is within the NSA's wheelhouse This is the explicit danger of VPN providers. Even if the provider is not complicit (which I believe applies to the likes of Mozilla), it still creates a centralized aggregation site for collection. I'm not even sure a US-based VPN provider is safe. GCHQ just conducts the interception and would share the data with NSA. At that point, you are at the me…

> I'm not even sure a US-based VPN provider is safe.

Oh, I am sure that it is not safe, thanks to the PATRIOT Act. Even if they were not storing any metadata, VPN providers can be compelled to 1) share all data about their subscribers, which will include you, then 2) silently wiretap and decrypt everything. US courts will rubber-stamp, as they've consistently done in the past, and "that's all, folks".

Sadly it's not like you'll be much safer elsewhere: as soon as you step outside of the US, one of the strongest cybersec agencies on the planet (NSA) will have free reign on your traffic. But you can resist the legal attack (in some countries) and at least try to make it challenging on a technical level.

I hope Mozilla want to bring some innovation to the table that will make VPNs somehow more resistant to legal attack (not just in the US) but I doubt it.

Post reply on HN