Live data from Hacker News

TunnelBear VPN app

tunnelbear.com

41–48 of 48 posts

Re: TunnelBear VPN app

#41
post #24
post #16

I'll be sticking with iPredator, and here's why: I don't care what my VPN client looks like -- I care about how secure it is. I have immense trust for Peter Sunde & Friends. They are not in this business to Get Rich Quick™. They are in it for deeply held moral, social reasons; reasons, so deeply held, they have put their own personal safety and freedom at risk. I feel very safe knowing they will NEVER comply with NSA…

Hi, I'm Ivan Sergeyenko, also known as iBear. I am one of the engineers on the TunnelBear team. We all hold deep respect for Peter Sunde and his team. iPredator is definitely one of the most trustworthy VPN services out there. Our goal, however, is different. We aim to bring VPN/privacy protection to people who have never heard of VPN (notice that we don't have "VPN" anywhere on our site, except for in a quote from T…

"We aim to bring VPN/privacy protection to people who have never heard of VPN"

Will such people understand the subtle ways in which using a VPN will make your communications less secure, though?

Re: TunnelBear VPN app

#42
post #27

Earlier quoted context omitted.

They claim that they keep no logs. http://help.tunnelbear.com/customer/portal/articles/1469449-...

Yes this is correct. I am sorry that this is not made more apparent on our site.

Hi Ivan,

I wonder how it is possible that you keep no logs of customer IP addresses. It seems that, from a technical standpoint, you must log some IPs for troubleshooting connection issues and being sure that your system is not being used for nefarious purposes (i.e., ones that cause harm to your own system, not necessarily copyright infringement or spam). Furthermore, wouldn't you need to log IPs to track how much data one user transfers? Or even to determine who has an account and who doesn't? This data must reside somewhere on your system.

Re: TunnelBear VPN app

#43
post #16

I'll be sticking with iPredator, and here's why: I don't care what my VPN client looks like -- I care about how secure it is. I have immense trust for Peter Sunde & Friends. They are not in this business to Get Rich Quick™. They are in it for deeply held moral, social reasons; reasons, so deeply held, they have put their own personal safety and freedom at risk. I feel very safe knowing they will NEVER comply with NSA…

Unfortunately, it doesn't matter what beliefs the owners of a Swedish VPN have. The FRA law [0] means that any data which goes over Swedish links will be logged. One can only assume that the iPredator service is heavily monitored by the IC, just on principle.

If you are concerned about your privacy and want to use a VPN, then I would recommend using cryptostorm [1]. Firstly because it is run by people passionate about privacy, who have devoted considerable time and effort into creating a service that is both "safe" and fast. Secondly because those efforts have been directed at solving the right problems: unlinking, best practices crypto, and fast links.

The primary strength of cryptostorm is their decoupling of the VPN service provider and account management. You don't buy VPN service, you buy a token that is redeemable for VPN service.

Their banking is handled by a First Nation's bank (so effectively a country), and the financial transaction is between you and a 3rd party (not cryptostorm the VPN service provider).

So while some companies claim "we don't log account access", cryptostorm literally has nothing that they can log. They do not have access to any personal information at all. It is all handled by other people. Even if cryptostorm was compromised, or they lie about not logging, or they are forced to log due to court order - they are unable to provide any personal information.

So they solved the important problem: you are anonymous to your VPN service provider.

Their openvpn config is heavily tweaked to ensure that it uses only the most robust crypto (no RC4, thank you very much).

Of course, a VPN isn't really much use against a nation state level actor, but at least it can provide protection against local miscreants on an open wifi.

(Full disclosure: I've spoken with the cryptostorm guys about privacy and security, I respect their skills and knowledge. I might be biased for that reason [I also know anakata, teimo and peter sunde, and no disrespect to them but the cryptostorm guys did it correctly])

[0]: http://en.wikipedia.org/wiki/FRA_law

[1]: http://cryptostorm.is

Re: TunnelBear VPN app

#44
post #43
post #16

I'll be sticking with iPredator, and here's why: I don't care what my VPN client looks like -- I care about how secure it is. I have immense trust for Peter Sunde & Friends. They are not in this business to Get Rich Quick™. They are in it for deeply held moral, social reasons; reasons, so deeply held, they have put their own personal safety and freedom at risk. I feel very safe knowing they will NEVER comply with NSA…

Unfortunately, it doesn't matter what beliefs the owners of a Swedish VPN have. The FRA law [0] means that any data which goes over Swedish links will be logged. One can only assume that the iPredator service is heavily monitored by the IC, just on principle. If you are concerned about your privacy and want to use a VPN, then I would recommend using cryptostorm [1]. Firstly because it is run by people passionate abou…

2 questions:

1) cryptostorm would still have the ip the isp assigned a user. mapping this ip to a real name is trivial. right?

2) The cryptostorm team decided to remain 'pseudoanonymous' at this point. The points they outline (privacy activists get constantly hassled and threatened) make sense but don't help me verify the integrity of the service. You saying that you spoke to them and that they are trustful doesn't do much either. Why should i trust them? I know in the end i should trust no one, but your argument boils down to cryptostorm being outside of FRA jurisdiction?

You could argue that iPredator is not a real crypto/security vpn service in the first place. I think they are using 128bit encryption which can be cracked if enough effort is put into it. They are just making it more difficult, eliminating 'drive by snooping'.

Lastly: no offense, but that website is not very trust-inducing. i know it shouldnt matter but still....

Re: TunnelBear VPN app

#45
post #24
post #16

I'll be sticking with iPredator, and here's why: I don't care what my VPN client looks like -- I care about how secure it is. I have immense trust for Peter Sunde & Friends. They are not in this business to Get Rich Quick™. They are in it for deeply held moral, social reasons; reasons, so deeply held, they have put their own personal safety and freedom at risk. I feel very safe knowing they will NEVER comply with NSA…

Hi, I'm Ivan Sergeyenko, also known as iBear. I am one of the engineers on the TunnelBear team. We all hold deep respect for Peter Sunde and his team. iPredator is definitely one of the most trustworthy VPN services out there. Our goal, however, is different. We aim to bring VPN/privacy protection to people who have never heard of VPN (notice that we don't have "VPN" anywhere on our site, except for in a quote from T…

Hey svintus, I think your friend Gita was just telling me about you a few weeks ago :) Do you quit your job to work on tunnelbear, huh? People like you belong on my hero-bookcase

I'm trying to avoid proprietary OS's now -- I don't suppose I could get into the linux beta you mention here: http://help.tunnelbear.com/customer/portal/articles/824779-i...

Re: TunnelBear VPN app

#46
post #43

Earlier quoted context omitted.

Unfortunately, it doesn't matter what beliefs the owners of a Swedish VPN have. The FRA law [0] means that any data which goes over Swedish links will be logged. One can only assume that the iPredator service is heavily monitored by the IC, just on principle. If you are concerned about your privacy and want to use a VPN, then I would recommend using cryptostorm [1]. Firstly because it is run by people passionate abou…

2 questions: 1) cryptostorm would still have the ip the isp assigned a user. mapping this ip to a real name is trivial. right? 2) The cryptostorm team decided to remain 'pseudoanonymous' at this point. The points they outline (privacy activists get constantly hassled and threatened) make sense but don't help me verify the integrity of the service. You saying that you spoke to them and that they are trustful doesn't d…

No, my argument boils down to "cryptostorm doesn't know who you are". They isolated their accounting (the part that has to collect money and ties an individual to an account) from their VPN service. They compartmented their operations from their business. So their customers are anonymous to them.

You purchase an access token (time limited from first use) from a third party (cryptostorm offers bulk rates for resellers). The entity which sells the tokens is based in a First Nation in Canada, meaning it has reduced legal attack surface. This entity is distinct and separate from cryptostorm.is the VPN service provider. They are compartmented and share no information. Neither one has sufficient information to link a specific individual to any activity.

That's the beauty of what they've done, they've made it so that you don't have to trust them. As I said, they could be compromised and log everything, it doesn't matter. They cannot tie an account to an individual. That's the problem that they solved. They removed trust from the equation.

Now, indeed, you should not use a VPN for anonymity. That is not what they are designed for and that is not what they are capable of providing. However, given that the cryptostorm VPN service can only know:

* you originating IP,

* your (anonymous) token ID, and

* the packet stream that exits their servers...

You can easily ensure a level of anonymity to your internet usage by accessing the VPN from an IP that is not associated with you (eg public library, coffee shop, etc). Provided you maintain discipline and never access it from an IP "owned" by you, they cannot know who you are.

I've spoken and written before about how VPNs are not tools for anonymity. A recent example is a "no logs" VPN used to catch a kid sending bomb threats to his school [0]. A VPN service is essentially just a proxy, and no single hop proxy is going to deter a nation state level actor. VPNs are tools for privacy, circumventing stupid IP restrictions, and evading (some) network access controls. They're not safe for robust clandestine activity.

I've spoken with them and they are competent, have been doing VPNs for years, and are passionate about privacy and security. That doesn't mean I trust them. The beauty of their architecture is that I don't have to.

[0]: http://grugq.tumblr.com/post/73393664323/no-logs-earthvpn-us...

Re: TunnelBear VPN app

#47
post #24
post #16

I'll be sticking with iPredator, and here's why: I don't care what my VPN client looks like -- I care about how secure it is. I have immense trust for Peter Sunde & Friends. They are not in this business to Get Rich Quick™. They are in it for deeply held moral, social reasons; reasons, so deeply held, they have put their own personal safety and freedom at risk. I feel very safe knowing they will NEVER comply with NSA…

Hi, I'm Ivan Sergeyenko, also known as iBear. I am one of the engineers on the TunnelBear team. We all hold deep respect for Peter Sunde and his team. iPredator is definitely one of the most trustworthy VPN services out there. Our goal, however, is different. We aim to bring VPN/privacy protection to people who have never heard of VPN (notice that we don't have "VPN" anywhere on our site, except for in a quote from T…

Hey, Ivan, have you folks fixed the security hole yet where your tunnel can potentially drop and the connection simply reverts to clear without the user knowing it? Have you yet included a function similar to VPNCheck which blocks traffic in that event?

Unfortunately, because TunnleBear uses it's own client rather than the standard Windows VPN mechanism VPNCheck can't be used with it. While I love your company and the generous touch of humor and whimsy you bring to a normally somber market, I can't live with a product with that gaping a security hole. If and when that's fixed and if the performance is about an order of magnitude better than it was when I tested it a year or so ago I'll be on board in a heartbeat.

Re: TunnelBear VPN app

#48
post #41
post #24

Earlier quoted context omitted.

Hi, I'm Ivan Sergeyenko, also known as iBear. I am one of the engineers on the TunnelBear team. We all hold deep respect for Peter Sunde and his team. iPredator is definitely one of the most trustworthy VPN services out there. Our goal, however, is different. We aim to bring VPN/privacy protection to people who have never heard of VPN (notice that we don't have "VPN" anywhere on our site, except for in a quote from T…

"We aim to bring VPN/privacy protection to people who have never heard of VPN" Will such people understand the subtle ways in which using a VPN will make your communications less secure, though?

How about giving us a clue rather than just being cryptic.
Post reply on HN