Live data from Hacker News

ProtonVPN

protonvpn.com

121–130 of 205 posts

Re: ProtonVPN

#121
post #25

How does this compare to TunnelBear [1]? - TunnelBear is a bit more expensive (4.99$/mo, paid annually vs 4$/mo). - TunnelBear supports up to 5 connections per account vs 2. I use TunnelBear regularly for my browser and phone. Both works great. My subscription is going to expire soon and I'll be open to try other VPN providers, not that there is anything wrong with TunnelBear. Any recommendations? This site [2] has f…

HN gets regular "what VPN should I use?" questions and my answer is always the same: Algo [1]. It is designed to be simple to set up, simple to tear down, and usable with numerous cloud providers or your own Linux server. [1] https://github.com/trailofbits/algo

There are a few main purposes for a commercial VPN:

- accessing non-encrypted stuff on an untrusted network

- firewall bypassing

- Torrenting

- IP ban bypassing (pretty popular for people writing scrapers or trolling)

Anonymous anything is garbage - many of them log and all can be logged by government agencies or datacenter owners ahead of you. Tor or similar is the best option there. Running something like Algo on your own server is pretty bad for both torrenting and IP ban bypassing as you only have a single IP and many cloud providers will accept DMCA and abuse reports.

All in all if you're looking for either torrenting or IP ban bypassing a commercial VPN solution is going to be a better bet. More IPs for cheaper and with lower risks.

Re: ProtonVPN

#122

Earlier quoted context omitted.

Yes, but it's fairly trivial to drop a "Seal Team 6" in and physically seize whatever they want, or just sabotage your equipment. Also, they could pressure your mainland circuit provider, or simply cut your cable every time you repaired it, which would put you out of business fairly quickly. I'm not sure a data haven works unless you have a sovereign military that can defend itself against the rest of the world (good…

A satellite in geosync orbit? Sure, much smaller but definitely harder to reach.

Good idea, but any government that can launch satellites can also shoot them down. It's actually much easier to shoot one down than it is to launch one in the first place.

Re: ProtonVPN

#123
post #115

Earlier quoted context omitted.

The security of Wireguard is completely unknown. Sure, it might be more secure after a formal release and a security evaluation. They even state themselves that they should not be used if security is required.

I don't know anyone working in the field who believes Wireguard is likely to be less secure than StrongSwan or OpenVPN, and Wireguard is something that gets talked about a lot . It's early days for Wireguard, to be sure, but it's one of the most promising security projects there is right now.

I work in the field and anybody that says that a piece of software is secure before it has even had a security evaluation by a third party does not know what they are talking about.

I think what you have seen is security people saying that the design of Wireguard seems to be equal or better than other, current, options, that doesn't mean that the implementation is just yet.

Re: ProtonVPN

#124
post #9

I have mixed feelings about protonmail. On the one hand, they tend to be on the right side of political / legal issues, and this transparency report is nice: https://protonmail.com/blog/transparency-report/ On the other hand, they recently reduced the level of detail in the transparency report. There is also the fact that they are Swiss, and their privacy laws were severely weakened by a recent referendum. In particu…

ProtonMail has pretty much stagnated and flat out refuses to cooperate with the community to implement new features of the OpenPGP email standards. Their Reddit guy is also pretty terrible, he pretty much insulted me in a comment after I criticized them.

Re: ProtonVPN

#125
post #56

Using public commercial VPN providers for serious security/privacy is a very bad idea. Get someone to set up Trail of Bits "Algo" for you (or do it yourself, if you're comfortable with Ansible).

Why use algo over ssh tunneling? ssh -ND 8080 user@host

Mobile use, for one.

Re: ProtonVPN

#126
post #98

Earlier quoted context omitted.

What would be a good jurisdiction for them?

it might be time for space satellite hosting companies... or maybe once SpaceX reduces the cost of used rockets.

>it might be time for space satellite hosting companies.

Uhm that would probably backfire and make you an open target for every security service on the planet.

German BND did bulk-collection on satellite communications, even tho German law does not allow for something like that. So BND reasoned "Satellites are in space, German Grundgesetz does not apply in space!", dubbing it the "Weltraumtheorie" (Spacetheory)

German source: https://www.heise.de/newsticker/meldung/Geheimakte-BND-NSA-B...

Re: ProtonVPN

#127

Earlier quoted context omitted.

A satellite in geosync orbit? Sure, much smaller but definitely harder to reach.

Good idea, but any government that can launch satellites can also shoot them down. It's actually much easier to shoot one down than it is to launch one in the first place.

Try that with the moon.

Re: ProtonVPN

#128
I'm currently using hide.me under Linux and even though the speed is great, I have issues all the time. Will try this during this month to see how it compares.

Re: ProtonVPN

#129
post #35

I would be interested in hearing what the security pros think about this..tptacek, grugq, dguido, idlewords. At this point, these are the guys I trust with security advice. Worth mentioning their VPN recommendations: algo by trailofbits and freedome. There is another paid service they recommend but I can't recall the name.

I have a few concerns about the cryptosystem. First of all, there does not appear to be a whitepaper available that describes the security architecture in any detail. This is an immediate red flag. Second, they do have a "Security Features" page which is rather light on the details; it mentions that ProtonVPN uses AES-256 (encryption), RSA 2048 (key exchange) and HMAC-SHA256 (auth). I'll start with RSA: the fact that…

If you download the ovpn config file you can see what crypto they employ. According to the ovpn config file for Android it's AES-256-CBC and auth is done with SHA512 hope this helps.

Re: ProtonVPN

#130

Earlier quoted context omitted.

I think he means "dropped" as in "the rapper dropped his mixtape today", not as in "the service provider dropped their service due to lack of profitability".

Well that's confusing :) Given your example is out of context and counter-example is perfectly in context.

Yes, because I agreed with you that it was perhaps a poor time for a colloquial usage of "dropped" considering that, in the context, it was fairly likely to be interpreted as my counter-example, or your initial interpretation.

I'd like to think my wording was completely unambiguous to make up for any context-switching your brain might have tried to pull on you, and if not I apologize.

Post reply on HN