Live data from Hacker News

NordVPN disables features when you turn off auto-renew

reddit.com

201–210 of 238 posts

Re: NordVPN disables features when you turn off auto-renew

#201

Earlier quoted context omitted.

I am not sure using your own is a good idea. Every time I was in China for the last 3 years they would quickly find and block my small startups VPN. I was able to send an email and ask someone to move it to a new IP. Now imaging you have your own setup and they block it, as well as access to the provider you used to create the VM that runs it. Using something like Nord or the like at least you know that they will kee…

I guess if you really wanted to be clever you could set up a number of IP addresses and if your VPN doesn't see you login for, say, a day, switch to another IP. Or just give your VM 14 addresses and rotate them as you need. For a 2 week trip/14 addresses this would cost you about $26 on AWS.

Digital Ocean will let you use their Floating IPs to do this for no charge (I have an Algo VM I'm paying them to host).

1: https://www.digitalocean.com/docs/networking/floating-ips/

Re: NordVPN disables features when you turn off auto-renew

#202
post #134
post #55

Earlier quoted context omitted.

I totally understand using a VPN service if you're trying to access the internet from another location, e.g. to get past the China firewall or get access to content from a different copyright jurisdiction. However, I don't fully understand the privacy argument. It would seem to be that instead of handing over your entire DNS query history and unencrypted HTTP history to your own corporate IT department or the Starbuc…

Could you elaborate on this? How do you create your own VPN on aws (or any other server)?

Makes for a fun little project.

https://www.digitalocean.com/community/tutorials/how-to-set-...

Re: NordVPN disables features when you turn off auto-renew

#203
post #161

Earlier quoted context omitted.

"Honestly, nothing holds up to ... (VPN provider)" If you're serious you send a machine, that you own, to a colo provider and you register for service with a corporate entity that you created for just that purpose. Your name exists nowhere and ... regulatory inquiries are directed to your corporate contact email. Or, if you feel like that's a heavy burden and you don't attach any value to the physical machine (some o…

If you're serious , you use tor. If just you want to torrent the last season of game of thrones (why would you?) then a reasonably reputable no-log vpn service will probably do a perfectly fine job. If you want to access non-https websites from coffee shops, buy a $5/mo vps from amazon/prgmr/digitalocean/whomever and tunnel through it. I don't see a situation in which the dedicated colocated hardware is the right cho…

I find tor is usually just fine for coffee shop browsing. I went to a couple that blocked it someway or other though. Most are no issue.

Re: NordVPN disables features when you turn off auto-renew

#204
post #67

Earlier quoted context omitted.

Nowadays its probably best to set up your own VPN server for that. Back when I lived there, most VPNs got occationally blocked, then they would get new IPs and work fine again. But from what I heard, it got way worse since Winnie the Pooh took over.

Agree. I always use my own VPN for this. Most VPN services get blocked eventually and then play cat-and-mouse to get themselves back up, so the service is overall unreliable. The China firewall also does some "intelligent" blocking of common VPN protocols by fingerprinting their traffic patterns, handshakes, ports, and other things. If you set up own server, it helps to modify the protocol or wrap it in a proxy that…

So you'd be exchanging cat pictures million times a day? That'll stand out well.

Re: NordVPN disables features when you turn off auto-renew

#205

Earlier quoted context omitted.

I used to use Mullvad but got sick of having to pay them via Bitcoin (or Bitcoin Cash, lol). I emailed them about accepting Monero directly and they said something like "we would like to but it's too much work." Ended up switching to IVPN, which actually costs more but is worth it for me not to have to deal with those shitcoins.

I really love paying with Monero as well. Fast, super cheap and anonymous. It's definitely my favorite coin to use (since I don't like speculation). I just wish it were more widespread as a payment option.

Government pressure is getting those anonymous coins to be delisted from exchanges.

Re: NordVPN disables features when you turn off auto-renew

#206
post #5

Honestly, nothing holds up to Mullvad [1]. They don't even take an email address while creating accounts, and you can pay easily with Bitcoin or even with cash mailed to them. I'm not affiliated, just a very happy customer. Mullvad is also who Mozilla trusts for the Mozilla VPN [2]. You can sign up with that if you'd like Mozilla to get a cut. [1]: https://mullvad.net/ [2]: https://vpn.mozilla.org/

Who runs Mullvad? Am I supposed to just blindly trust these people with my entire internet activity?

I'd assume Mozilla did the due diligence and it may count for something.

Re: NordVPN disables features when you turn off auto-renew

#207

Earlier quoted context omitted.

I really love paying with Monero as well. Fast, super cheap and anonymous. It's definitely my favorite coin to use (since I don't like speculation). I just wish it were more widespread as a payment option.

Government pressure is getting those anonymous coins to be delisted from exchanges.

Which exchanges? I'm only aware of Bittrex, whose Monero volume was insignificant to begin with. And what evidence is there that government pressure had anything to do with it?

Re: NordVPN disables features when you turn off auto-renew

#208

Earlier quoted context omitted.

Current BTC fee seems to be just over $1, not $20. I don't think MorphToken would work because as far as I can tell, they have no way to set a fixed amount of the destination currency. Other providers like ChangeNOW do offer that but they have much higher minimums, something like .003 BTC, which is obviously not useful for a $5 payment.

> Current BTC fee seems to be just over $1, not $20. Really? My Ledger app says 112 sat/byte, which comes out to $8 for me, and I'm pretty sure they were higher a few weeks ago, when I checked. Am I way overpaying? > I don't think MorphToken would work because as far as I can tell, they have no way to set a fixed amount of the destination currency. That's too bad, XMR.to was really useful for this...

> Really? My Ledger app says 112 sat/byte, which comes out to $8 for me, and I'm pretty sure they were higher a few weeks ago, when I checked. Am I way overpaying?

Hm, maybe? I think those clients usually just use the average fee paid in recent transactions, which will result in overpayment if everyone else is doing it too.

The real question, "how low can I set the fee and still have my tx confirmed," is given an attempt at an answer by https://fees.watch, which is what I checked -- it showed less than $2 for every speed at the time.

To be honest I don't actually use Bitcoin, but I do use Ethereum regularly and I use this fees.watch site for that. My transactions almost always get confirmed exactly when expected, and it's almost always cheaper than whatever the wallet suggests.

Re: NordVPN disables features when you turn off auto-renew

#209
post #55

Earlier quoted context omitted.

I totally understand using a VPN service if you're trying to access the internet from another location, e.g. to get past the China firewall or get access to content from a different copyright jurisdiction. However, I don't fully understand the privacy argument. It would seem to be that instead of handing over your entire DNS query history and unencrypted HTTP history to your own corporate IT department or the Starbuc…

> I don't fully understand the privacy argument It's mostly moot. In the days of HTTPS and DoH, they're essentially selling snake oil. It was a lot more useful in 2010.

Torrents and related traffic is still good send over a VPN.

Also getting around some geoblocking.

Re: NordVPN disables features when you turn off auto-renew

#210

Earlier quoted context omitted.

For practical purposes the only people who can penetrate a simple vpn service are potentially a government order to start recording your traffic that is legal based on jurisdiction or a dedicated hacker. It looks to me that NEITHER would be prevented by you using a colocated machine. It's not like your colocation provider is incapable of compromising you and probably would if ordered to do so in a jurisdiction where…

The problem is more that a commercial VPN changes the threat model from an individual one to a collective one. Very likely, no one cares about me enough to put effort towards specifically monitoring or hijacking my internet traffic. However, someone puts out a shingle as NordVPN or Mullvad or whatever else, and starts advertising VPN services to the world. That VPN provider has a finite number of endpoints / egress n…

I think the analogy fails because thats valuable isn't a good that it is simply retained or lost. If your vpn usage for example is downloading movies the fact that bob the hacker knows you downloaded inception isn't very worrisome. Likewise with keeping your personal traffic personal instead of having it show up on your bosses network who cares if bob has it.

If the vpn provider doesn't keep any logs your total exposure is that they may start collecting logs of traffic for the duration during which they are compromised. If they are attentive and competent this either will never happen or it will be for a short duration. Again this breaks the example of valuables in storage.

In fact a VPS or indeed any host actually has the same problem you describe in that a host is a bigger target than you and therefore more valuable.

On the other hand for most people the differential between know how between you and professionals is probably sufficiently useful that you are less likely to get hacked with them than on your own. After all nobody has to actually target you in particular they can look for vulnerable hosts in an automated fashion.

I don't think you have provided any substantial argument for most commercial vpn users to switch. I feel like for most threat models its a more than acceptable tool.

Post reply on HN