Live data from Hacker News

FreePN: Open-source peer-to-peer VPN service

freepn.org

111–120 of 136 posts

Re: FreePN: Open-source peer-to-peer VPN service

#111

Earlier quoted context omitted.

Hello, Ian "Every user is exit node" concept in addition to legal question raises more practical questions. What are you going to do if majority for your users (and when you call something "free" the chance increases) will be from countries like China, Russia, Iran and other where government controls and blocks a lot of the websites and services? And I'm talking not about surveillance but about actual block of the IP…

Semantics. It's not FreeVPN (the organisation) who are throttling or bottlenecking you, it's the node you're connected to.

While the distinction between these two concepts is purely semantic to tech folks, the choice by this company to exploit that purely semantic difference by tacitly implying a falsehood in marketing to non-tech-tolks is significant.

Re: FreePN: Open-source peer-to-peer VPN service

#112
post #102
post #2

If its P2P it means it uses other peoples' nodes as your exit node, sort of like Tor but without the onions. That's risky. What happens to me if someone does something illegal via my connection? How could I prove it wasn't me? Maybe I could win in court by citing my use of something like this, but I really don't want to be dragged into court in the first place even if I end up walking out.

This seems like a decent tool to use in an oppressed, non-free country. Except Tor (or Whonix or Tails), WireGuard, or ZeroTier are a better option. All of these allow better management (and therefore control) of routes. There is a very good reason Usenet does not require uploading, and P2P protocols like BitTorrent are used with a VPN. It provides a reasonable enough protection against a civil actor such as RIAA and…

This actually uses ZeroTier under the hood. It uses ZT as the transport, encryption, and network virtualization layer and then does P2P exit node stuff on top of that.

ZT would be useful for this from an oppressed country because it is used by a ton of businesses. You would just look like you were accessing a corporate ZeroTier DVPN from home, which is pretty common these days.

That's better in some ways than Tor. The problem with Tor is if you use it naked then it can be obvious that you're using Tor. Even in countries like the USA I've always been concerned that using Tor might put you in some kind of database. In a very non-free country I'd be really worried about using Tor naked, meaning without running it over something more mundane looking like ZT or Wireguard.

Re: FreePN: Open-source peer-to-peer VPN service

#113

Earlier quoted context omitted.

To be fair, ZeroTier isn't just "some tool". It has a solid reputation. The founder (api) is actually here in the thread.

What about Zerotier 2.0 btw? Was supposed to surface before summer, but seems to have stalled. Might actually be relevant as more people are working from home now.

2.0 is still in the works, but took far longer than we hoped. We have back-ported some of its features to the 1.x branch and have a 1.6.0 beta (tagged 1.5.0) out now. 1.6.0 should be late this month. We are pushing for 2.0 by EOY.

2.0 is a major re-architecting for performance and versatility with a rewrite of the CLI and service layer (not core protocol). If we had 100% of our time to dedicate only to engineering we could have shipped it by now, but biz and other things got in the way.

Re: FreePN: Open-source peer-to-peer VPN service

#114
post #48
post #16

Earlier quoted context omitted.

> I can't imagine many of the owners of those IPs know what they're being used for. They don’t. For instance, Luminati, possibly the best known player in this market, uses HolaVPN users as exit nodes.[1] [1] https://www.trendmicro.com/vinfo/hk-en/security/news/cybercr...

I was approached by Luminati on Twitter to turn my browser extensions into exit nodes, they are enticing developers to exploit users. https://i.imgur.com/EbT96an.png

Auto-update of extensions and apps should be set to off by default. There would be less reason for extensions to be bought by other developers for their installed user base.

Secondly, how come there is no regulation about selling chrome extensions and apps?

Re: FreePN: Open-source peer-to-peer VPN service

#115
post #24

Hmm. Dont see any white paper or design docs on their website. Did i miss it. At a glance sounds like a reinvention of Tor, but less secure.

> At a glance sounds like a reinvention of Tor, but less secure. ...and with every client also acting as an exit node, which is kinda a big deal.

Its not just that though. There are lots of privacy attacks on this kind of system that you have to be careful to avoid.

How easy is it in this system to force a specific user to use you as their exit node during a targeted attack? Given the state of their website, i am going to guess pretty easy.

Re: FreePN: Open-source peer-to-peer VPN service

#117
post #70

Earlier quoted context omitted.

Some other sketchy bits, from a very quick perusal: * Shelling out[1] to some tool that may be responsible for all of the heavy networking bits[2] * Falling back on a non-monotonic clock but calling it monotonic[3] * Another sketchy shellout[4] that calls a bunch of scripts with trivial interpolation/injection bugs[5]. It's not clear if the arguments passed to those scripts are remotely controllable, but it's sketchy…

Hi! Link [4] is missing.

Whoops. I can't edit the parent anymore, but here is the intended link: https://github.com/freepn/fpnd/blob/e14e4b0cda7e7d851c1823bf...

Re: FreePN: Open-source peer-to-peer VPN service

#118
post #113

Earlier quoted context omitted.

What about Zerotier 2.0 btw? Was supposed to surface before summer, but seems to have stalled. Might actually be relevant as more people are working from home now.

2.0 is still in the works, but took far longer than we hoped. We have back-ported some of its features to the 1.x branch and have a 1.6.0 beta (tagged 1.5.0) out now. 1.6.0 should be late this month. We are pushing for 2.0 by EOY. 2.0 is a major re-architecting for performance and versatility with a rewrite of the CLI and service layer (not core protocol). If we had 100% of our time to dedicate only to engineering we…

Thanks for the update and thank you for working on this! Looking forward to the upcoming releases!

Re: FreePN: Open-source peer-to-peer VPN service

#119

Earlier quoted context omitted.

SEO companies are big customers of products like this. Scraping Google at scale requires a huge budget for proxies and IP blocks, and I believe they apply ML to detect people abusing their service.

I can confirm that, scraping Google instantly needs huge effort and money. In our best we can scrape 2500 SERP per IP. But i must say using proxy services and other things did not helped us much. Because most of them were banned before we use.

Yeah, and then you recycle the IP back into the pool for the next guy to work with. An operation I know of was getting 6+ million SERPs a day, budget for proxies was hundreds of thousands a year.

Re: FreePN: Open-source peer-to-peer VPN service

#120
post #101

Earlier quoted context omitted.

I can confirm that, scraping Google instantly needs huge effort and money. In our best we can scrape 2500 SERP per IP. But i must say using proxy services and other things did not helped us much. Because most of them were banned before we use.

How does it wotk out for IPv6?

IPv6 is just not widely used, so when you do use it, you stick out like a sore thumb. Think like a bayesian: for Google, it's easy to just block whole /32s of IPv6 space.
Post reply on HN