Live data from Hacker News

A privacy VPN you can verify

vp.net

101–110 of 160 posts

Re: A privacy VPN you can verify

#101

I have no relationship with OVPN but after watching their server deployment on YouTube I have to say I do like their approach to security / privacy. Servers that don't log and can't without hard drives, ports physically glued shut. https://www.ovpn.com/en/security

Ah, but how can you tell that you’re connecting to a server that was actually configured that way? Answer: no you can’t, you still have to trust them. At the end of the day, you always just have to trust the provider, somewhere.

OVPN successfully evaded Hollywood(through pressure on Swedish institutions) 5 years ago when they were up ThePirateBays ass again.

You still have to trust them, you're not wrong but at some point I'll fall back to the common question security people(not me) tell paranoid doubters: Whats your threat model?

If you're running a global child-abusing ring through Mullvad or OVPN(offers static IPv4 for inbound traffic) I don't know what they'd do but they've proved themselves over and over to be organisations you can trust.

OVPN turns around about 1.2M$ with 0.8M$ profit (0), Mullvad turns around significantly more money but with less profit margin (1) (probably funneling profits to a tax haven) so the risk of someone buying out OVPN is there, but "you" are probably not worth it if the ones targeting TPB didn't figure out how to get through.

You can still run TOR over their VPNs as another layer if you're uncertain their reputation is trustworthy enough for your usecase but don't want TOR traffic originating from your IP.

https://claude.ai/share/a47c19f7-8782-4a9f-ae26-2d2adb52eaed

0: https://www.allabolag.se/foretag/ovpn-integritet-ab/-/konsul... 1: https://www.allabolag.se/foretag/mullvad-vpn-ab/g%C3%B6tebor...

You can look up any Swedish company through sites like allabolag or merinfo if you're curious... until they grow into tax-evading evil megacorps :)

Re: A privacy VPN you can verify

#102
post #98

> No trust required. You also have to trust that SGX isn't compromised. But even without that, you can log what goes into SGX and what comes out of SGX. That seems pretty important, given that the packets flowing in and out need to be internet-routable and necessarily have IP headers. Their ISP could log the traffic, even if they don't. > Packet Buffering and Timing Protection: A 10ms flush interval batches packets t…

Taking a look at their code I see a rather concerning comment:

    func (om *ObfuscationManager) ProcessOutgoingPacket(
    ...
    // TODO where is the obfuscation here?
https://github.com/vpdotnet/vpnetd-sgx/blob/bc63e3b8efe41120...

While I do see the impl of the 10ms flush interval, I don't see any randomisation within batches. So iiuc, packets are still flushed in their original order.

Re: A privacy VPN you can verify

#103
post #97
post #68

I'm a huge fan of the technical basis for this. I want services to attest themselves to me so I can verify that they're running the source code I can inspect. And, well, the combination of founders here? Good fucking lord. I'm really fascinated to see whether we can generate enough trust in the code to be able to overcome the complete lack of trust that these people deserve. I can't imagine a better way to troll me o…

>the complete lack of trust that these people deserve Yeah, I took one look at that and laughed. CEO of mt gox teaming up with the guy who sold his last VPN to an Israeli spyware company sounds like the start of a joke.

I didn’t sell PIA. It was a merger to create a publicly owned privacy company and, unfortunately, the terms of the merger did not come to fruition.

I left the company on principle by relinquishing my shares at a mere fraction (about 1/3) the value. I walked away from millions of dollars, and I am happy with my decision.

Given what happened, we built VP so that trust is no longer required.

Re: A privacy VPN you can verify

#104
post #73

The chief privacy officer of the company is the moron that destroyed Freenode. Of course, Libera lives on, but it is a transition we could’ve done without.

This has been debunked.

Freenode was sold to me by Christel, the previous owner. I did not even offer to purchase it and simply assumed I was doing what I had been doing for a decade for freenode and many other FOSS projects - keeping them alive. It was my funds that did so the whole time for freenode (and a number of other projects which I stopped funding thereafter given the death threats I was receiving which led to the end of many of them unfortunately).

The Libera staff [1] attempted to steal the domain because they wanted control. None of the staff were developers at the time and complained they couldn’t even write their own irc client. Think of Mozilla. The people who run it aren’t the coders. Same thing.

Here are the receipts for every statement I just made:

http://techrights.org/wp-content/uploads/2021/05/lee-side.pd...

PS: Freenode seems more active then Libera where everyone is just idle (bots?) but that is another point. See for yourself with the client I wrote: IRC.com.

[1] By Libera staff I mean the former freenode staffers who left to form Libera. These are the same people I spent a lot of money helping to protect legally from the allegations made by “OldCoder”

Re: A privacy VPN you can verify

#105
post #91
post #52

Earlier quoted context omitted.

Pray tell how a black box peer can validate its not had its private keys cloned?

Because the code doesn't have any code to clone private keys. The trust chain ends with you trusting Intel to only make CPUs that do what they say they do, so that if the code doesn't say to clone a private key, it won't. (You also have to trust the owners to not correlate your traffic from outside the enclave, which is the same as every VPN, so this adds nothing)

The first part is definitely true.

The second part in terms of correlations is untrue since we include a number of techniques to frustrate timing attacks among other things.

Re: A privacy VPN you can verify

#106
post #68

I'm a huge fan of the technical basis for this. I want services to attest themselves to me so I can verify that they're running the source code I can inspect. And, well, the combination of founders here? Good fucking lord. I'm really fascinated to see whether we can generate enough trust in the code to be able to overcome the complete lack of trust that these people deserve. I can't imagine a better way to troll me o…

> I'm a huge fan of the technical basis for this

Trusting random internet people is actually the biggest “troll” of the internet.

Any VPN that asks you to trust their guarantees and not the guarantees of code is selling you snake oil and should not be trusted.

Trust is not a feature in security. Thus, we removed and replaced it with code based guarantees.

Re: A privacy VPN you can verify

#107

Cute idea. Bit worried about the owners here; rasengan doesn't have a stellar reputation after what happened with Freenode. The idea itself is sound: if there are no SGX bypasses (hardware keys dumped, enclaves violated, CPU bugs exploited, etc.), and the SGX code is sound (doesn't leak the private keys by writing them to any non-confidential storage, isn't vulnerable to timing-based attacks, etc.), and you get a val…

The whole point here is you don’t have to trust us - we don’t want you to. We want you to trust code, period.

That said, the freenode issue was debunked and you can see receipts here: http://techrights.org/wp-content/uploads/2021/05/lee-side.pd...

I funded freenode since 2011 so any narrative that makes it seem I just appeared out of nowhere is factually untrue. Also, I was handed it because Christel felt I was a good custodian thereof. Instead, former staff who I protected from allegations made by OldCoder for years, went on to form Libera, tried to steal the domain for a developers irc network when they themselves shockingly couldn’t even code a simple irc client, and then made up a false narrative.

The state of open source generally isn’t what you think and you would do well for yourself to read Lunduke’s Journal among other things. The developers don’t actually run most of the projects these days. Look at Mozilla.

Re: A privacy VPN you can verify

#108
post #98

> No trust required. You also have to trust that SGX isn't compromised. But even without that, you can log what goes into SGX and what comes out of SGX. That seems pretty important, given that the packets flowing in and out need to be internet-routable and necessarily have IP headers. Their ISP could log the traffic, even if they don't. > Packet Buffering and Timing Protection: A 10ms flush interval batches packets t…

Taking a look at their code I see a rather concerning comment: func (om *ObfuscationManager) ProcessOutgoingPacket( ... // TODO where is the obfuscation here? https://github.com/vpdotnet/vpnetd-sgx/blob/bc63e3b8efe41120... While I do see the impl of the 10ms flush interval, I don't see any randomisation within batches. So iiuc, packets are still flushed in their original order.

The comment was added before the implementation of the IPC buffer & shuffling and was left there, sorry about that.

In an older version packets were sent back in sequence to their original connection to the host, as it was faster.

We since then implemented a system where nproc (16+) buffers receiving packets running at differed intervals, meaning that while packets are processed "in order" the fact this runs in multiple threads, reading packets even from the same client will cause these to be put in queues that will be flushed at different timings.

We have performed many tests and implementing a more straightforward randomized queue (by allocating memory, handling array of pointers of buffers, shuffling these, and sending these shuffled) did not make much of a difference in terms of randomization but resulted a huge loss in performance due to the limitations of the SGX environment.

As we implement other trusted environments (TEE) we will be implementing other strategies and obfuscation methods.

Re: A privacy VPN you can verify

#109
post #56

One of the many reasons I love Mullvad (been using it for 4 years now) is their simple pricing—$5/month whether you subscribe monthly, yearly, or even 10 years out. I wanted to give your product a try, but the gap between the 1-month and 2-year plans is so big that a single month feels like a rip-off, while I’m not ready to commit to 2 years either. On payments: for a privacy-focused product, Monero isn’t just a luxu…

I don't know what payment methods this VPN supports (it requires sign-in), but on Mullvad you also can send cash in an envelope.

Re: A privacy VPN you can verify

#110
post #56

One of the many reasons I love Mullvad (been using it for 4 years now) is their simple pricing—$5/month whether you subscribe monthly, yearly, or even 10 years out. I wanted to give your product a try, but the gap between the 1-month and 2-year plans is so big that a single month feels like a rip-off, while I’m not ready to commit to 2 years either. On payments: for a privacy-focused product, Monero isn’t just a luxu…

Which are the other reasons, and which other providers have you evaluated? Asking because I might soon be in the market.
Post reply on HN