Live data from Hacker News

ExpressVPN employees complain about ex-spy's top role at company

reuters.com

111–120 of 175 posts

Re: ExpressVPN employees complain about ex-spy's top role at company

#111

Earlier quoted context omitted.

> One of the few VPNs that actually don't log traffic. How can one be so certain that this is the case? The only thing that's for sure is the claim they do not keep any evidence. I don't have anything against this VPN, it's really just an inherent trust problem with any provider. You take their word for it and be smart/ethical enough not to have any sketchy activity when you use it because there's a pretty good chanc…

The only ones you can trust are the ones that have actively fought court orders. That is a reasonable show of certainty that they do what they say otherwise there are real legal consequences.

You still don’t know if they’re feeding your data to an intelligence agency or data broker.

For example, why wouldn’t China run a few top VPN companies — or at least compromise them? The benefit would outweigh the costs. So they shield you from piracy lawsuits and the like, they gain data to blackmail and compromise key figures later on.

Re: ExpressVPN employees complain about ex-spy's top role at company

#112
post #91

Decentralised VPNs are the future. Edit: https://dvpnalliance.org/

Any reason Orchid isn't a part? https://www.orchid.com

Ok, so there doesn't seem to be any benefit to this "alliance", so I am personally not sure why anyone is a part of it, much less us ;P... but like, frankly, "to be real about this" for a moment, the Sentinel community is so actively hostile--in a kind of nasty "personal" way that involves stuff like them "bullying" (their term) people who work at Orchid or posting memes constantly of stuff like Sentinel users as soldiers marching through the bloody carcasses of dead Orchid defenders (somewhat hilariously to me one of their favorite images for this is a specific re-drawn painting that I can't imagine they know the origin of, as I would not want to be affiliated with those particular attackers)... and like, this is in addition to adamantly insisting false things about our project (such as that we somehow aren't open source?! we literally do all our development in public and have GitHub CI doing reproducible builds of all of our assets!)--that there is very little interest in having any involvement with them (particularly so given the lack of any real benefit to this alliance).

Re: ExpressVPN employees complain about ex-spy's top role at company

#113
post #2

It's been clear for a long time that every single commercial VPN service is a waste of money. At best, you replace trusting your ISP with trusting a different group of unknown people with similar motivations. At worst, it's a government agency honeypot or someone like Facebook. If you think you want a VPN for "privacy", use Tor Browser. If you want a VPN for any other reason that "normal people" think they want a VPN…

You are right that most people are just signing up with the same credit card and details as their isp and even if they claim they don't keep logs the vpn needs to link the use of their service to your details for billing just like your isp. That said if you live in the UK the government logs your internet history to be used against you at their convenience. Using a vpn like mullvad.net that you can buy with bitcoin a…

Accounts can be completely decoupled from the payer. As long as the account is paid for, it should work. If there are no speed or time limits imposed, then why worry about who is using the VPN? If you allow a reasonable number of connections to the account at any given time, the rest shouldn't matter.

Re: ExpressVPN employees complain about ex-spy's top role at company

#114
post #99

Earlier quoted context omitted.

this is a bad faith argument. Proton logged IPs in response to Swiss court order and handed over that data after the order was received. They do not log IPs otherwise. And bear in mind, the specific request in question here had the involvement of the French state as well.

How is this a bad faith argument? Proton's claim was they didn't log IPs and then it turns out that in certain cases they do – regardless of the reason, they reneged on their claim.

Because the way it was phrased might imply that Proton had always been logging all IPs, despite their claim, when in reality the breach was of a much smaller scope than that. They only logged IPs for a particular user after a particular legal demand was made, and not otherwise (as far as I know).

Re: ExpressVPN employees complain about ex-spy's top role at company

#115

Get a VPS, they are actually cheaper than VPNs (if you only need one country location). You will have one single IP and you won't share IP with hundreds of other people thus being flagged. I have never been blocked from a site when using my VPS, including sites that otherwise block VPNs, I think they don't care for whatever reason. Doesn't mean they can't know, they will, but they seem to not care? Some websites migh…

Popular VPS hosts like Digital Ocean, Linode, etc are all going to smack you down if you do anything remotely fishy on their networks. They have to have a pretty good idea of what's happening with their VPS systems, and I've seen them (DO/Linode) smack down everything from specific VPN connections to web scraping.

If you're going to use a VPS for anything remotely sketch you probably don't want to go with a reputable provider - they're reputable for a reason.

Re: ExpressVPN employees complain about ex-spy's top role at company

#116
post #102

Earlier quoted context omitted.

It’s funny express has you advertise as being able to watch X service considering when I used express I couldn’t watch Netflix because they throw an error saying they know I’m using a VPN. Same with Amazon prime. I’ve switched to nordvpn but they are no different I can’t even use fast.com to check the speed when the vpn is on. False advertising I’d say

Yeah Netflix is the reason I switched from ExpressVPN to NordVPN.

NordVPN unblocks services by routing through residential IPs without explicit consent: https://news.ycombinator.com/item?id=21664692

Re: ExpressVPN employees complain about ex-spy's top role at company

#117
post #2

It's been clear for a long time that every single commercial VPN service is a waste of money. At best, you replace trusting your ISP with trusting a different group of unknown people with similar motivations. At worst, it's a government agency honeypot or someone like Facebook. If you think you want a VPN for "privacy", use Tor Browser. If you want a VPN for any other reason that "normal people" think they want a VPN…

I think there’s been good criticism of your arguments so far and I don’t want to pile on; but I see _a value_ in commercial VPN companies.

I, a tech savvy person, have no issue creating an SSH proxy server in any country in seconds.

But I also make online video games, and the US sanction system means I must block people from accessing our services; even if they have a copy of the game.

They did nothing wrong, my company isn’t even US based: we just used a cloud provider and all of those are US based.

So, I encourage those users to use a vpn if one is available to them.

Re: ExpressVPN employees complain about ex-spy's top role at company

#118
post #72

Earlier quoted context omitted.

Most public wifi block all the ports necessary for VPN except 80 and 443. Even then DPI will stop most VPN protocol right in its track. I’ve never had reliable VPN working over public wifi/mobile network, unless I roll my own custom protocol that masquerades as HTTP traffic.

Interesting. I'm an ExpressVPN subscriber (maybe I won't be much longer) and haven't had any problem using it on public Wi-Fi networks.

Same here with multiple different VPN providers. Once I get through the TOS screens I can activate the VPN and have no issues. At one hotel chain (rhymes with a moldy British cheese), I have to activate my VPN first since my DNS provider won't resolve their login page.

Re: ExpressVPN employees complain about ex-spy's top role at company

#119

Earlier quoted context omitted.

Totally agree. The geoblocking is the most common reason a lot of people use VPNs, even if that isn’t always how they are directly marketed. A friend’s mom asked me a few weeks ago for VPN recommendations so she could watch British TV easier. She’s 70. Her concern isn’t about safer browsing stuff but watching GBB more easily. *Disclosure: ExpressVPN has sponsored my podcast in the past (tho I don’t handle ad sales fw…

It’s funny express has you advertise as being able to watch X service considering when I used express I couldn’t watch Netflix because they throw an error saying they know I’m using a VPN. Same with Amazon prime. I’ve switched to nordvpn but they are no different I can’t even use fast.com to check the speed when the vpn is on. False advertising I’d say

Netflix has been particularly vigilant as of late to combat VPN usage so it is a cat and mouse game. I haven’t had an ad from them in months but last time I did, it worked with the services I’ve used without a problem. For all VPN services, the geoblock stuff is a moving target so what works one day or week, won’t necessarily work the next. It’s unfortunate but it is what it is.

Re: ExpressVPN employees complain about ex-spy's top role at company

#120
post #91

Earlier quoted context omitted.

Any reason Orchid isn't a part? https://www.orchid.com

I have no idea and wasn't even aware of its existence. I have no affiliation with either dVPN Alliance, Mysterium or Sentinel but I have used both of the latter two as well as Privatix. Mysterium is my go to choice but there's an issue with split tunneling which prevents me from using it right now.

FWIW, I do not believe that either Sentinel nor Mysterium (though I don't bother looking at their product often; I am very confident about this for Sentinel, though) currently have any support for "multiple hops" through VPNs, and so for the complaints people are talking about here I would consider them "somewhat actively dangerous".

(To be fair, Orchid has for some reason decided to hide multiple hops behind an advanced settings panel currently; I feel like this must have been some kind of miscommunication internally, and I annoyingly-to-me don't directly do the development on the front-end app; but it is supported, if slow.)

Like, if you want to, right now, you can run a Sentinel node... and then you just get to "be the spy" and collect all of the information about the users who select your node. They claim this isn't possible, but that makes no sense and I can tell you from first-hand experience that it is... they seriously seem to think that because their code is distributed using a docker container that no one can either edit its behavior or add logging around it? It is really awkward, actually :(.

And, worse, part of the goal of these "decentralized VPN" projects is to let you not care so much about which node you are using... which means that, over time, you are likely to eventually use an attacker as your exit node (which is actually somewhat intrinsically "dangerous" anyway, even with multiple hops, as, if you allow any non-authenticated--in the cryptographic sense of that term--traffic to go through your tunnel, as even with multiple hops the final node can edit the traffic).

(I am very curious, BTW, what your specific use case is with split tunneling that isn't being supported currently by Mysterium.)

Post reply on HN