Earlier quoted context omitted.
With RavenDB, you cannot setup a unsecured server unless you are _really_ trying. And we worked on getting secured setup to be a click through process with under 10 minutes to setup a whole cluster. You can see it here: https://www.youtube.com/watch?v=K-2iZ_lJVag That was done explicitly because of issues like that. Security isn't a feature, and the fact that your product keep leaking details is not the fault of the…
This is completely unrelated, but I remember your blog about dotnet development. I followed it about 10 years ago and remember when you started with RavenDb. I haven't done any dotnet development in about 7 years, but you taught me a lot about programming properly. Thanks. I'm glad RavenDb is still going well.
UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
211–220 of 240 posts
Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#212Earlier quoted context omitted.
I use a VPN to keep Comcast from logging and selling my data to third parties. The client is always on and running on my PC.
I do the same, but again using remote AWS (free) servers. Which is funny sometimes, I realize that some website are suddenly in german because I am using my Berlin server, instead of my US one.
Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#213Earlier quoted context omitted.
Saw an article a while back (years) saying NSA/FBI is able to track TOR connections and won’t say how even if it means they’d forfeit some cases.. anyone remember this? Edit to add: Also, it’s public knowledge that TOR is funded by the DoD, it seems extremely feasible that they privately control a sizable chunk of nodes. Based on what I know of American 3 letter agencies, I don’t think one could resist designing a “s…
Most Tor nodes are actually in Germany. You can see a map of them https://tormap.void.gr/ The design of the system is resilient to some nodes being under hostile control, too.
Some nodes can be under hostile control, but as the number increases the likelihood increases that they can link entry to exit based on timings. I consider it quite likely that the us govt can say “hey Germany/UK/Fance/etc., we have this batch of exit times, do any of your nodes correspond on entry?” or vice virce.
Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#214Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#215Earlier quoted context omitted.
As it should? You're on a call. You lock the phone. You expect the call to continue right? This bug is in their new browser. Its in a very early stage. So these bugs are expected
No, I dont expect the camera to stay ON (even for a video call) if I lock the phone.
Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#216Earlier quoted context omitted.
I wouldn't trust PIA for anything. The whole company is shrouded in secrecy. After speaking at length with an ex-employee of PIA who now maintains this open-source iOS VPN client: https://passepartoutvpn.app/ many (most?) employees and contractors at PIA have no idea of the identify of their direct managers. Imagine working for a company and not knowing your manager's real name. Now imagine trusting that company with…
Disgruntled employees aren't necessarily the least biased sources one can find
Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#217Unsecured Elasticsearch, once again. ( https://www.theregister.com/2020/07/17/ufo_vpn_database/ ) So ES has insecure defaults, I get that and it's been discussed to death. But who the heck, in this day and age, exposes clusters directly to internet traffic? I don't care what the defaults or security measures you have. DONT EXPOSE SERVERS. Place them inside a VPC, preferably a private one(in AWS parlance, behind a NAT…
What's the difference between a VPC and iptables? I agree that you shouldn't expose insecure services. But why do I need to introduce an entire private address space and cloud-managed SDN services to achieve that goal? If it weren't industry status quo, I'd almost call you a shill for the union of ops teams working to secure jobs for years to come. Almost.. (;
VPC is more akin to a glorified virtual switch/bridge.
Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#218Earlier quoted context omitted.
FoxyProxy posted one of their Secret Service subpoenas along with their reply. TLDR; they said they have nothing to give: https://blog.getfoxyproxy.org/2017/11/04/secret-service-subp... As for PrivateInternetAccesss / PIA, I would not trust them at all. No one knows who the founders and executives are. After speaking at length with an ex-employee of PIA who now maintains this open-source iOS VPN client, https://passe…
So the company is run by people who enjoy privacy? It seems weird to frame that alone as an argument against a company which deals in Virtual PRIVATE Networks.
It should be a red flag to you that if a founder or executive won’t reveal his identity, there is a possibility those people represent a nation state or other organization (not necessarily governmental) that you would not give your private data to if you knew their identity up-front.
Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#219Earlier quoted context omitted.
it's good for things like public wifi and other untrusted networks since your data is encrypted from your machine to the vpn server
it's 2020. if you're still relying on vpn connection to provide encryption, you are doing it wrong. (I understand there are certain cases you have to deal with unencrypted traffic, but those should be really rare now).
Re: UFO VPN claims zero-logs policy, leaks 20M user logs [resolved]
#220Earlier quoted context omitted.
Never buy a VPN with these kinda names. You can tell they are shady from their names and websites. UFO, Secure, Pure VPN, etc
Which name is better in your opinion? PIA? Nord? Express? All their web sites look alike as well.
But, there are few reasons to actually use a VPN nowadays, there was a discussion on HN a few days back, but I cannot seem to find it at the moment.
Edit: Found it: https://news.ycombinator.com/item?id=23566390