Live data from Hacker News

ProtonVPN

protonvpn.com

111–120 of 205 posts

Re: ProtonVPN

#111
post #20

How does this compare to TunnelBear [1]? - TunnelBear is a bit more expensive (4.99$/mo, paid annually vs 4$/mo). - TunnelBear supports up to 5 connections per account vs 2. I use TunnelBear regularly for my browser and phone. Both works great. My subscription is going to expire soon and I'll be open to try other VPN providers, not that there is anything wrong with TunnelBear. Any recommendations? This site [2] has f…

I use VyprVPN [1] which I've found to be good and fast. It's a bit of a tough area to research well. I might give TunnelBear a try. [1]: https://www.goldenfrog.com/vyprvpn

VyprVPN do store logs. I used to use them and wasn't aware of it. Just to let you know.

Re: ProtonVPN

#112
post #78

Looks the time has come for a small country to create a data haven like the fictional Sultanate of Kinakuta . I believe that the idea will attract foreign investment quickly.

It doesn't need to be a country. Just get some container ships, sail to international waters dragging a fiber cable with you and bam, data haven. You could also operate as a secure key storage. No worries about governments requesting keys as there is no government.

Yes, but it's fairly trivial to drop a "Seal Team 6" in and physically seize whatever they want, or just sabotage your equipment. Also, they could pressure your mainland circuit provider, or simply cut your cable every time you repaired it, which would put you out of business fairly quickly.

I'm not sure a data haven works unless you have a sovereign military that can defend itself against the rest of the world (good luck!)...

Re: ProtonVPN

#113
post #33
post #25

Earlier quoted context omitted.

HN gets regular "what VPN should I use?" questions and my answer is always the same: Algo [1]. It is designed to be simple to set up, simple to tear down, and usable with numerous cloud providers or your own Linux server. [1] https://github.com/trailofbits/algo

In terms of privacy, doesn't it kind of let the cat out of the bag if you host your own VPN server? It's not your home address, but it's still just as much an address associated with you, isn't it?

It just shifts your traffic egress location to a cloud provider, but this is valuable because all of the last mile Internet providers in the US colluded with the government to get permission to use your internet traffic to sell ads, so if you care about privacy, and not allowing your ISP to inspect your traffic, it's a huge benefit.

AWS will make no secondary use of customer data. The ISPs have told us they will, and the FCC gave them permission to do so. Which one will you trust? I know I would trust AWS any day over the ISPs...

Re: ProtonVPN

#114
post #72
post #56

Using public commercial VPN providers for serious security/privacy is a very bad idea. Get someone to set up Trail of Bits "Algo" for you (or do it yourself, if you're comfortable with Ansible).

Looking at Algo ( https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-th... ), it seems like it provides an easy way to setup a (secure) VPN on a piece of hardware you own or one of the supported public clouds. In that respect, I'm not sure if it gives a lot of privacy. As you're the only one using that VPN, the traffic may not be too hard to trace back to you.

Algo isn't that much better than any other VPN - arguably it's slightly better security wise, though I'd argue Wireguard tops it by far on cipher choices and security margins.

Ultimately VPNs just aren't for hiding anything that could cause you significant problems. If you want that, Tor, i2p, or piles of hacked boxes are your only options really if you must interact with the clearnet.

Re: ProtonVPN

#115
post #72

Earlier quoted context omitted.

Looking at Algo ( https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-th... ), it seems like it provides an easy way to setup a (secure) VPN on a piece of hardware you own or one of the supported public clouds. In that respect, I'm not sure if it gives a lot of privacy. As you're the only one using that VPN, the traffic may not be too hard to trace back to you.

Algo isn't that much better than any other VPN - arguably it's slightly better security wise, though I'd argue Wireguard tops it by far on cipher choices and security margins. Ultimately VPNs just aren't for hiding anything that could cause you significant problems. If you want that, Tor, i2p, or piles of hacked boxes are your only options really if you must interact with the clearnet.

The security of Wireguard is completely unknown. Sure, it might be more secure after a formal release and a security evaluation.

They even state themselves that they should not be used if security is required.

Re: ProtonVPN

#116
post #33
post #25

Earlier quoted context omitted.

HN gets regular "what VPN should I use?" questions and my answer is always the same: Algo [1]. It is designed to be simple to set up, simple to tear down, and usable with numerous cloud providers or your own Linux server. [1] https://github.com/trailofbits/algo

In terms of privacy, doesn't it kind of let the cat out of the bag if you host your own VPN server? It's not your home address, but it's still just as much an address associated with you, isn't it?

I think you misunderstand the reason for using a VPN. Privacy is not the same as anonymity.

Let me try to explain. You use a VPN to protect your connection from MiM attacks, for example if you connect to a public wifi-hotspot, or even when you are connected from home. It also gives you some privacy, because nobody can sniff your traffic, but it does not give you anonymity, well it can, but you'll not be able to verify that it does.

Sure, you hide from your ISP, but you can't verify that your VPN-provider is more trustworthy than your ISP. They might actually log everything and send it on to a third party and you'll never know. Hell, they might even be funded by the NSA...

Use Tor if you want anonymity, even though that's not 100 % sure either.

Re: ProtonVPN

#117

Earlier quoted context omitted.

It doesn't need to be a country. Just get some container ships, sail to international waters dragging a fiber cable with you and bam, data haven. You could also operate as a secure key storage. No worries about governments requesting keys as there is no government.

Yes, but it's fairly trivial to drop a "Seal Team 6" in and physically seize whatever they want, or just sabotage your equipment. Also, they could pressure your mainland circuit provider, or simply cut your cable every time you repaired it, which would put you out of business fairly quickly. I'm not sure a data haven works unless you have a sovereign military that can defend itself against the rest of the world (good…

A satellite in geosync orbit? Sure, much smaller but definitely harder to reach.

Re: ProtonVPN

#118
post #115

Earlier quoted context omitted.

Algo isn't that much better than any other VPN - arguably it's slightly better security wise, though I'd argue Wireguard tops it by far on cipher choices and security margins. Ultimately VPNs just aren't for hiding anything that could cause you significant problems. If you want that, Tor, i2p, or piles of hacked boxes are your only options really if you must interact with the clearnet.

The security of Wireguard is completely unknown. Sure, it might be more secure after a formal release and a security evaluation. They even state themselves that they should not be used if security is required.

I don't know anyone working in the field who believes Wireguard is likely to be less secure than StrongSwan or OpenVPN, and Wireguard is something that gets talked about a lot.

It's early days for Wireguard, to be sure, but it's one of the most promising security projects there is right now.

Re: ProtonVPN

#119
post #56

Using public commercial VPN providers for serious security/privacy is a very bad idea. Get someone to set up Trail of Bits "Algo" for you (or do it yourself, if you're comfortable with Ansible).

Why use algo over ssh tunneling? ssh -ND 8080 user@host

Re: ProtonVPN

#120
post #28
post #18

Earlier quoted context omitted.

I think it's prudent to assume (even if not accurate in every case) that any VPN provider that reaches PIA scale has already been compromised by the relevant State Actor working its jurisdiction. It's the tragedy of success in the privacy industry.

Except for the fact that PIA has been subpoenaed by the FBI and state police multiple times and PIA could give them dick all. Yes, their servers could be compromised illicitly, but if the NSA or GCHQ is willing to go to that much trouble just to monitor you, you have bigger problems.

PIA might actually log everything and send to the FBI as a regular part of their operation, hell, they might even be funded by the FBI and you would never know.

You should not trust what people tell you over the internet.

Post reply on HN