Live data from Hacker News

Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

windscribe.com

101–110 of 456 posts

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#101
post #56
post #19

Are we allowed to discuss (edit: if it's not too political?) if Kape Technologies has any connections to Israeli security services, given the nature of VPNs and given the amount of data that can be trivially collected, and: "Being from Israel, Teddy Sagi had connections with the Israeli military intelligence sphere and was able to procure himself a real-life cyber spy [his co-founder] from the famed Unit 8200 (kinda…

>Teddy Sagi had connections with the Israeli military intelligence sphere Does this mean much given that israel has mandatory military service? Unlike in the US where you have to make a conscious choice (eg. patriotism or desperation) to join the CIA/NSA/military, that's not really the case in israel. "has ties to unit 8200" might as well mean "has ties to stanford/MIT/caltech" or "has ties to big tech".

[deleted]

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#103
post #55

Earlier quoted context omitted.

>but there are still metadata that can be collected. That logic is questionable given how poorly "spying on public wifi users" scales. You either need to put a bunch of eavesdropping radios in a bunch of public places or somehow convince a bunch of small businesses to use your "free wifi" solution. Even if you do have access, it's hard to monetize the data, given that nearly every device does MAC randomization (so yo…

Doesn't pretty much every Starbucks location in the United States use a nationwide provider? Despite the randomized Mac address, you can still fingerprint devices using all the usual tricks when they connect to the authentication and authorization page before you allow them to access the broader internet. If the receipt had a passcode on it, you've got a link between all of your browser fingerprint, radio fingerprint…

>Despite the randomized Mac address, you can still fingerprint devices using all the usual tricks when they connect to the authentication and authorization page before you allow them to access the broader internet.

Fingerprinting is overrated given that every iPhone 17 is identical to any other iPhone 17. If you leave system settings at stock, which most people do, there's very little to fingerprint.

>Doesn't pretty much every Starbucks location in the United States use a nationwide provider?

True, although mobile data is cheap and plentiful enough that I rarely bother using wifi at cafes or fast food places. The only time I use public wifi is if I'm staying long term, which basically only encompasses trains, airports, and hotels. Those are diverse enough that it's tough to build a complete profile.

>If the receipt had a passcode on it, you've got a link between all of your browser fingerprint, radio fingerprint and payment detail fingerprint and possibly customer loyalty provided at time of payment.

I don't think I ever saw a place that was that guarded about their wifi. The closest I've seen is hotels requiring your room/last name, which would allow them to identify you, but at the same time I'm not sure how much information they can glean, other than that I'm logging into gmail or airbnb. Persistent monitoring that ISPs can do is far more useful.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#104

Earlier quoted context omitted.

It does if you do DNS over TLS or HTTPS, although I guess that information would still be knowable to your DNS provider if they terminate your TLS behind the scenes

Not quite. In order to make TLS certs work on a per-site basis, requests sent over HTTPS also include a virtual host indicator in cleartext that shows the hostname of the site you’re trying to connect to, so if the IP on the other end is hosting multiple domains it can find the right cert. For this reason some people feel that DNS over TLS is pretty pointless as a privacy measure.

SNI leakage is what encrypted client hello (ECH) tries to solve: https://blog.cloudflare.com/announcing-encrypted-client-hell...

It's still not perfect since you're still leaking information about the privacy set implied by the outer ClientHello, but this possibly isn't much worse than the destination IP address you're leaking anyway.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#105
post #87

Earlier quoted context omitted.

Idk what's the official status, but it's Tesonet. Some fake debunking in the comments of this thread that is factually almost correct: https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/protonvpn... EDIT: ProtonVPN app was "accidentally" signet by Tesonet. How do you think this could happen?

It’s not Tesonet, Proton is wholly self-owned and managed. Proton VPN was briefly sharing employees with Tesonet during initial app bringup, and that partnership is long over. Naturally due to competition and the huge importance of privacy in this space, people still bring this up, but Proton VPN does not and never will sell or share your data with anyone. Source: I am a Proton VPN employee.

So, why were the employees shared?

EDIT: I'm not saying being related to Tesonet is bad, but it is a fact that you cannot run away from.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#108
post #19

Are we allowed to discuss (edit: if it's not too political?) if Kape Technologies has any connections to Israeli security services, given the nature of VPNs and given the amount of data that can be trivially collected, and: "Being from Israel, Teddy Sagi had connections with the Israeli military intelligence sphere and was able to procure himself a real-life cyber spy [his co-founder] from the famed Unit 8200 (kinda…

I think VPNs are one of the clearest cases of tech/politics intersection, it's not just OT for tech but also for hacker culture.

What do you think @dang ?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#109

Note that all of these companies are also under the umbrella of Tesonet, a Lithuanian VC firm also headed by Tomas Okmanas (Tom Okman in TFA). Their flagship investments are Nord Security, Hostinger, Oxylabs, Surfshark, Decodo, Mediatech, and nexos.ai - all closely related business models around proxying. They don't seem to have Russian ties: "In 2022, CyberCare opened an office in Lviv, Ukraine. Although planning fo…

Don't forget ProtonVPN links to Tesonet, which they're trying hard to "debunk" (though no clue why, I have nothing against Tesonet). They only shared employees and accidentally signed apps with the same certificates, but are "totally unrelated". Their PR people are already on this thread.

If they didn't try so hard to fight it, people might care less.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#110

Is there any other real world usecases for VPN nowadays other than: 1. Getting access to geolocked data 2. Torrenting "Linux ISOs" ?

Sharing corporate info with your employees and not everyone else. You know, the "go to work" thing some people do.
Post reply on HN