Live data from Hacker News

NordVPN disables features when you turn off auto-renew

reddit.com

191–200 of 238 posts

Re: NordVPN disables features when you turn off auto-renew

#191

Earlier quoted context omitted.

I used to use Mullvad but got sick of having to pay them via Bitcoin (or Bitcoin Cash, lol). I emailed them about accepting Monero directly and they said something like "we would like to but it's too much work." Ended up switching to IVPN, which actually costs more but is worth it for me not to have to deal with those shitcoins.

But you could always pay them with Monero You can pay any bitcoin invoice with Monero and people have been doing that for 6 years

When xmr.to existed, sure. Not anymore.

Re: NordVPN disables features when you turn off auto-renew

#192

Earlier quoted context omitted.

Although not entirely false, this post is a bit too defeatist. "Don't use a VPN because they may be lying about not logging connections" is the same as saying "Don't get on an airplane because the pilot may be suicidal". I'm not going to stop using vpns nor flying on airplanes because of that.

You typically get on an airplane because you have to travel someplace. With VPNs I fail to see a reason beyond circumventing geo-blocking.

https://news.ycombinator.com/item?id=26050877

TL;DR: My bank wouldn't let me use their online banking because I had run a Tor service sometime in the past.

Re: NordVPN disables features when you turn off auto-renew

#193
post #77

Earlier quoted context omitted.

Audible might be the exception, I'm very happy with it.

Very crappy if you want to cancel after you forgot to get new audiobooks for a few months. You lose all your credit, and they don’t say that during the cancellation process. I gifted 6 months of payment to Audible just because they avoided to inform me about that.

That's rough but on the scale of company bad practices that leans more towards being an oversight than truly malicious. I'm not saying it's an oversight but it's not on the same level as making cancellation take 10 clicks or having only phone support or turning off features when you turn off auto-renew.

Re: NordVPN disables features when you turn off auto-renew

#194

Earlier quoted context omitted.

They show you a BTC address and you send BTC to that address. Whatever arrives at the address is credited to your account. No "invoicing system" involved.

How do things like Morphtoken and Xmr.to handle the $20 Bitcoin transfer fee?

Current BTC fee seems to be just over $1, not $20.

I don't think MorphToken would work because as far as I can tell, they have no way to set a fixed amount of the destination currency.

Other providers like ChangeNOW do offer that but they have much higher minimums, something like .003 BTC, which is obviously not useful for a $5 payment.

Re: NordVPN disables features when you turn off auto-renew

#195

Earlier quoted context omitted.

For practical purposes the only people who can penetrate a simple vpn service are potentially a government order to start recording your traffic that is legal based on jurisdiction or a dedicated hacker. It looks to me that NEITHER would be prevented by you using a colocated machine. It's not like your colocation provider is incapable of compromising you and probably would if ordered to do so in a jurisdiction where…

These guys say they'll colo a raspberry pi for $9 a month: https://www.endoffice.com/picolo.html

That is pretty neat.

Re: NordVPN disables features when you turn off auto-renew

#196

Earlier quoted context omitted.

How do things like Morphtoken and Xmr.to handle the $20 Bitcoin transfer fee?

Current BTC fee seems to be just over $1, not $20. I don't think MorphToken would work because as far as I can tell, they have no way to set a fixed amount of the destination currency. Other providers like ChangeNOW do offer that but they have much higher minimums, something like .003 BTC, which is obviously not useful for a $5 payment.

> Current BTC fee seems to be just over $1, not $20.

Really? My Ledger app says 112 sat/byte, which comes out to $8 for me, and I'm pretty sure they were higher a few weeks ago, when I checked. Am I way overpaying?

> I don't think MorphToken would work because as far as I can tell, they have no way to set a fixed amount of the destination currency.

That's too bad, XMR.to was really useful for this...

Re: NordVPN disables features when you turn off auto-renew

#197
post #161

Earlier quoted context omitted.

"Honestly, nothing holds up to ... (VPN provider)" If you're serious you send a machine, that you own, to a colo provider and you register for service with a corporate entity that you created for just that purpose. Your name exists nowhere and ... regulatory inquiries are directed to your corporate contact email. Or, if you feel like that's a heavy burden and you don't attach any value to the physical machine (some o…

If you're serious , you use tor. If just you want to torrent the last season of game of thrones (why would you?) then a reasonably reputable no-log vpn service will probably do a perfectly fine job. If you want to access non-https websites from coffee shops, buy a $5/mo vps from amazon/prgmr/digitalocean/whomever and tunnel through it. I don't see a situation in which the dedicated colocated hardware is the right cho…

If you're super super serious, can you even trust Tor? I personally give it better than 50% chance that some consortium of goverments control the majority of tor exit points but won't reveal it for small cases so as not to reveal this trick.

Re: NordVPN disables features when you turn off auto-renew

#198
post #177
post #161

Earlier quoted context omitted.

"Honestly, nothing holds up to ... (VPN provider)" If you're serious you send a machine, that you own, to a colo provider and you register for service with a corporate entity that you created for just that purpose. Your name exists nowhere and ... regulatory inquiries are directed to your corporate contact email. Or, if you feel like that's a heavy burden and you don't attach any value to the physical machine (some o…

From a security perspective, this is equivalent to renting a dedicated server. Once it leaves your possession, it isn't really "your hardware" anymore from a data security standpoint. Also, as others have pointed out, all you have to do is sniff the traffic going in to the machine, something both the colo and ISP and upstreams are trivially able to do to obtain your residential or GSM IP, linked to your name/identity…

I think it's at least conceptually possible to pre-load a machine with software that doesn't pass any plaintext between you and it, and which the software image can't be modified without you knowing it.

I don't know about obscuring the fact of the connection between you and it though. Tor isn't enough by itself.

Re: NordVPN disables features when you turn off auto-renew

#199
post #161

Earlier quoted context omitted.

"Honestly, nothing holds up to ... (VPN provider)" If you're serious you send a machine, that you own, to a colo provider and you register for service with a corporate entity that you created for just that purpose. Your name exists nowhere and ... regulatory inquiries are directed to your corporate contact email. Or, if you feel like that's a heavy burden and you don't attach any value to the physical machine (some o…

For practical purposes the only people who can penetrate a simple vpn service are potentially a government order to start recording your traffic that is legal based on jurisdiction or a dedicated hacker. It looks to me that NEITHER would be prevented by you using a colocated machine. It's not like your colocation provider is incapable of compromising you and probably would if ordered to do so in a jurisdiction where…

The problem is more that a commercial VPN changes the threat model from an individual one to a collective one.

Very likely, no one cares about me enough to put effort towards specifically monitoring or hijacking my internet traffic.

However, someone puts out a shingle as NordVPN or Mullvad or whatever else, and starts advertising VPN services to the world.

That VPN provider has a finite number of endpoints / egress nodes, and those become a very high value target. Now my threat model has to include not just targeted attacks at me, but general attacks on the VPN provider.

An analogy would be, if you have 1 million dollars worth of real-world valuables (artwork, say), it's better to store it in a nondescript warehouse than a warehouse with a neon billboard out front that says "BOB'S HIGH-SECURITY WAREHOUSE FOR EXPENSIVE VALUABLES". The latter is painting a giant target on itself for anyone interested in stealing stuff.

Re: NordVPN disables features when you turn off auto-renew

#200
post #177

Earlier quoted context omitted.

From a security perspective, this is equivalent to renting a dedicated server. Once it leaves your possession, it isn't really "your hardware" anymore from a data security standpoint. Also, as others have pointed out, all you have to do is sniff the traffic going in to the machine, something both the colo and ISP and upstreams are trivially able to do to obtain your residential or GSM IP, linked to your name/identity…

I think it's at least conceptually possible to pre-load a machine with software that doesn't pass any plaintext between you and it, and which the software image can't be modified without you knowing it. I don't know about obscuring the fact of the connection between you and it though. Tor isn't enough by itself.

> which the software image can't be modified without you knowing it.

Nah. If you're worried about the kind of attacks that necessitate sending your own hardware, then, regardless of who owns title to the device, the firmware being replaced to snoop on or alter what is actually in RAM is in-bounds.

There are lots of ways of hiding persistence on a system, and decades of research along these lines. Once it leaves your possession, there's not much you can do to ensure that it still has unmodified code on it (assuming standard PC hardware).

Really though this isn't the threat model at all for someone who just wants to use a VPN, I only went there because the comment senselessly advised shipping your own hardware to the colo. That's the same privacy as using the colo-owned machine, which, for a VPN, is the same privacy as using a generic $5/mo VPN service, as in all cases the upstream can be trivially monitored (even in the case where it's your own, tamper-evident HSM-whatever remote attestation hardware).

Post reply on HN