Live data from Hacker News

FrootVPN – Surf anonymously on the Internet

frootvpn.com

21–30 of 65 posts

Re: FrootVPN – Surf anonymously on the Internet

#21

Earlier quoted context omitted.

This phrase refers to stuff free as in free beer.

And Whisper Systems, TOR, tox are free as in free beer. What's your point?

TOR isn't free. The support and development is paid for by donations and funding, the bandwidth (currently over 12000 MiB/s) is paid for by lot's of volunteers. I get your point though. The question isn't whether something is free to use, it's who's paying for incurring costs.

Re: FrootVPN – Surf anonymously on the Internet

#23
post #6

received email with password in plaintext after registration

Not sure if it's relevant here, but I want to point out that just because you received it in plaintext doesn't mean they store it in plaintext.

So if you change it immediately to something more secure, and it might not be a security risk after all.

Re: FrootVPN – Surf anonymously on the Internet

#24

Earlier quoted context omitted.

This phrase refers to stuff free as in free beer.

And Whisper Systems, TOR, tox are free as in free beer. What's your point?

Probably a better disambiguation would be "services" that are free. Open-source projects can always be validated to make sure that they are not monetizing their user-base.

Tor is a service but by reading the source code, you can see (if you understand the code) that nothing monetizable leaves your computer.

I don't have as much confidence in Tox just because it hasn't been around as long (and I haven't read the source).

Re: FrootVPN – Surf anonymously on the Internet

#25

Free product, free support, no logs. They're either lying or trying to turn this into a freemium product at some point in the future. Everything else just seems unlikely. Furthermore, their domain is protected by WhoisGuard (Panama). If they (the people involved, not the servers) were sitting in Sweden this would be unnecessary (compare IPredator). The IP address behind the website points to the same Swedish datacent…

I can't tell you how happy I am to see this as the top comment.

Free is a con.

If you want a cheap VPN that you control (and that's faster than Tor), set up an endpoint on something that takes Bitcoin payment and pay with Bitcoins obtained via an anonymous route. This list might be helpful.

https://www.exoticvps.com

Re: FrootVPN – Surf anonymously on the Internet

#26
post #6

received email with password in plaintext after registration

Not sure if it's relevant here, but I want to point out that just because you received it in plaintext doesn't mean they store it in plaintext. So if you change it immediately to something more secure, and it might not be a security risk after all.

That isn't the point, if they can send it in plaintext then they have it in a recoverable form. They shouldn't be storing your password at all. They should be storing a hash of your password.

And on top of all that, sending it plaintext via email, itself a largely open format, means they've broadcast it to all kinds of other potentially bad actors.

Plus it indicates (to me) a questionable grasp of security, not a great sign for a VPN provider.

Its just wrong.

Re: FrootVPN – Surf anonymously on the Internet

#28
post #26

Earlier quoted context omitted.

Not sure if it's relevant here, but I want to point out that just because you received it in plaintext doesn't mean they store it in plaintext. So if you change it immediately to something more secure, and it might not be a security risk after all.

That isn't the point, if they can send it in plaintext then they have it in a recoverable form. They shouldn't be storing your password at all . They should be storing a hash of your password. And on top of all that, sending it plaintext via email, itself a largely open format, means they've broadcast it to all kinds of other potentially bad actors. Plus it indicates (to me) a questionable grasp of security, not a gr…

It could very well just mean that the email is sent before any hashing occurs (as part of the registration controller, in other words) - but yeah, you're right, considering that email's physical equivalent is a postcard, it shows a tremendous lack of respect for the user. Kiss of death for a supposedly privacy focused operation like a VPN provider.

Re: FrootVPN – Surf anonymously on the Internet

#29
post #25

Free product, free support, no logs. They're either lying or trying to turn this into a freemium product at some point in the future. Everything else just seems unlikely. Furthermore, their domain is protected by WhoisGuard (Panama). If they (the people involved, not the servers) were sitting in Sweden this would be unnecessary (compare IPredator). The IP address behind the website points to the same Swedish datacent…

I can't tell you how happy I am to see this as the top comment. Free is a con. If you want a cheap VPN that you control (and that's faster than Tor), set up an endpoint on something that takes Bitcoin payment and pay with Bitcoins obtained via an anonymous route. This list might be helpful. https://www.exoticvps.com

Depending on your needs, you can just roll your own with Amazon EC2. I use it for an SSH tunnel, mostly to use while at work. Not that I'm doing any weird browsing, I just don't like the thought of my employer keeping a log of what I am doing on my free time (https://xkcd.com/303/).

I wrote a script to spin up a new instance when I need it, and to terminate it when I don't. It should cost less than $10/mo, and I only pay for what I use.

Re: FrootVPN – Surf anonymously on the Internet

#30
post #6

received email with password in plaintext after registration

Not sure if it's relevant here, but I want to point out that just because you received it in plaintext doesn't mean they store it in plaintext. So if you change it immediately to something more secure, and it might not be a security risk after all.

Looks like you set the password originally, then they send THAT password plaintext.

It'd be acceptable if it was a random password generated for email-auth reasons. Not acceptable if you're setting the password.

Post reply on HN