Live data from Hacker News

VPN Encryption

privateinternetaccess.com

11–20 of 46 posts

Re: VPN Encryption

#11
While I've heard good things about PIA, you're still trusting someone else with your data. Whether you trust them or not is entirely up to you, but it's not that hard to set up your own VPN tunnel. We posted about it a few weeks ago here: https://www.tinfoilsecurity.com/blog/dont-get-pwned-on-publi..., and there was some good HN discussion on it here: https://news.ycombinator.com/item?id=6285458

Re: VPN Encryption

#12
post #4

I've been a happy PIA subscriber since the Snowden controversy. However every time I see them becoming more popular (at least 4 of my friends have signed up with them in the past few weeks) and earnestly trying to make themselves more secure, I also realize that someone, somewhere within the NSA (and yes, other intelligence agencies around the world) is elevating them on a list of VPNs to break.

Doesn't their business location in the US negate the need to be cracked?

Based on their sites, I believe they're UK-based company (and US endpoints are just endpoints, in case someone wants to have US-located exit to access US-only services), so it makes somehow reasonably harder (but not impossible) to correlate between the client and their traffic.

Still, I don't see any significant difference between NSA and GHCQ, except that we have (thanks to Snowden) some details of former's operations leaked, but the latter's remain secret (or I didn't pay enough attention to the news, maybe).

Re: VPN Encryption

#13
post #4

I've been a happy PIA subscriber since the Snowden controversy. However every time I see them becoming more popular (at least 4 of my friends have signed up with them in the past few weeks) and earnestly trying to make themselves more secure, I also realize that someone, somewhere within the NSA (and yes, other intelligence agencies around the world) is elevating them on a list of VPNs to break.

Doesn't their business location in the US negate the need to be cracked?

They don't store any user logs (I have no reason to suspect they'd lie about that). So there's not much stored data to break. Which means the focus will be on breaking their traffic encryption protocols.

Re: VPN Encryption

#14
I use this service, and have been thrilled with it for a long time. They do no logging whatsoever, and their encryption and endpoint options are great.

they are also by far the cheapest truly secure option in this space - $40/year

Re: VPN Encryption

#15
post #3

FYI, this is the info page for our new (beta) OpenVPN based client which supports multiple encryption options: https://www.privateinternetaccess.com/forum/index.php?p=/dis...

I love PIA but I was too afraid to use it at Black Hat / DEFCON this year. If you use L2TP (required for iOS, handy for OS X because there is a native client) there is no certificate to prevent a MITM. Is there any way to address this? Can you use a certificate instead of a pre-shared key?

nitpick: There is a native OpenVPN client for iOS in the AppStore. I don't know how they managed to, but it's plugging into the native iOS VPN functionality and it works perfectly well.

Re: VPN Encryption

#16
post #11

While I've heard good things about PIA, you're still trusting someone else with your data. Whether you trust them or not is entirely up to you, but it's not that hard to set up your own VPN tunnel. We posted about it a few weeks ago here: https://www.tinfoilsecurity.com/blog/dont-get-pwned-on-publi... , and there was some good HN discussion on it here: https://news.ycombinator.com/item?id=6285458

You still have to trust somebody to host your VPN endpoint.

(Although, it's probably less risky to use some relatively obscure VPS/dedicated/colocation ISP than major VPN service which certainly attracts some attention of TLAs)

Re: VPN Encryption

#17
Pretty bogus preset choices, what is this? If the provider isn't providing the expertise to ensure a safe connection for every customer, what the hell are they doing?

Re: VPN Encryption

#18
post #11

While I've heard good things about PIA, you're still trusting someone else with your data. Whether you trust them or not is entirely up to you, but it's not that hard to set up your own VPN tunnel. We posted about it a few weeks ago here: https://www.tinfoilsecurity.com/blog/dont-get-pwned-on-publi... , and there was some good HN discussion on it here: https://news.ycombinator.com/item?id=6285458

You still have to trust somebody to host your VPN endpoint. (Although, it's probably less risky to use some relatively obscure VPS/dedicated/colocation ISP than major VPN service which certainly attracts some attention of TLAs)

Fair point, but your personal VPN is also a lot less likely to attract scrutiny and be attractive to snooping than PIA. It's just a much bigger surface area, more popular, and potentially has a lot more useful data than your single box.

Re: VPN Encryption

#19
post #11

While I've heard good things about PIA, you're still trusting someone else with your data. Whether you trust them or not is entirely up to you, but it's not that hard to set up your own VPN tunnel. We posted about it a few weeks ago here: https://www.tinfoilsecurity.com/blog/dont-get-pwned-on-publi... , and there was some good HN discussion on it here: https://news.ycombinator.com/item?id=6285458

> Whether you trust them or not is entirely up to you, but it's not that hard to set up your own VPN tunnel.

While I agree that trust is a _giant_ issue, speed and price (due bandwidth needed/used) is also a major concern if you're one looking for an always-on VPN solution.

I personally used PIA for a few months mostly due to cost and it is at or near my speed cap at all times. I have also rolled my own VPN using a VPS at the same price point, however, considering that bandwidth would be limited and speeds were not as stable, it's hard for me to choose that route for my use cases.

Sure, if I need absolute security I wouldn't use PIA and I'd reconsider using a VPN on any VPS on US soil. But then, one would have to consider if it will be worth it.

Post reply on HN