Live data from Hacker News

ProtonVPN

protonvpn.com

131–140 of 205 posts

Re: ProtonVPN

#131

Earlier quoted context omitted.

No VPN can reliably anonymize you against government agents so I think the con is a non-issue. VPNs are only really useful when the local network is hostile and/or you want some degree of privacy from the sites you visit. Anyone with sigint capability is going to figure out who you are with a VPN. (i.e. Government agents)

This isn't about pretending to be James Bond, and "hostile" networks with "government agents" and all their "sigint" coming for your secrets. In the real world, VPN are mostly used to download copyrighted material. They have a pretty much perfect track record in that regard. Running a cloud VPS, on the other hand, is no more secure than your ISP: they have records, and will share them when ordered to do so.

Just as far as everybody knows, that doesn't mean that it's necessarily true.

There can be a distinct difference between what is believed to be true and what's actually true.

There might very well be entities that has the information, but it's sitting on it for later use.

Re: ProtonVPN

#132
post #123

Earlier quoted context omitted.

I don't know anyone working in the field who believes Wireguard is likely to be less secure than StrongSwan or OpenVPN, and Wireguard is something that gets talked about a lot . It's early days for Wireguard, to be sure, but it's one of the most promising security projects there is right now.

I work in the field and anybody that says that a piece of software is secure before it has even had a security evaluation by a third party does not know what they are talking about. I think what you have seen is security people saying that the design of Wireguard seems to be equal or better than other, current, options, that doesn't mean that the implementation is just yet.

I've spent my career doing third-party software security evaluations --- among other things, I founded the NCC Cryptography Services practice --- and I will tell you right now that the Wireguard security story is far more compelling than any third-party audit.

It's not simply the protocol design, which is superior in pretty much every conceivable way to IKE or TLS, but also the code, which is carefully written to minimize attack surface and increase reviewability.

Choosing OpenVPN or StrongSWAN over WireGuard to minimize exposure to vulnerabilities would be a dumb bet. Sometimes dumb bets pay off, but it's still dumb to make them.

Re: ProtonVPN

#133
post #76

Earlier quoted context omitted.

So an installer was trying to set up autoruns, and the outbound connection IP's were on some list? The first part seems like expected behavior, the second sounds like your list of bad IP's included several that one of the most popular VPN providers use.

This was before the client even connected for the first time. And the IPs were well known C&C servers used for collecting keystrokes and screenshots of your O.S

Checking if their various servers exist on install seems likely. And well known C&C servers probably hide their actual IP, they'd be fairly easy to shut down if they didn't.

Re: ProtonVPN

#134

Earlier quoted context omitted.

A satellite in geosync orbit? Sure, much smaller but definitely harder to reach.

Good idea, but any government that can launch satellites can also shoot them down. It's actually much easier to shoot one down than it is to launch one in the first place.

blowing up a satellite in orbit is a massive escalation over even something like a commando raid -- i believe it would qualify as a violation of outer space treaty as well. a great deal of 'space junk' was generated by china's (one, individual) test of an antisatellite missile in 2011, and it caught a lot of critical international attention over it because it puts other satellites in danger -- thousands of tiny pieces zipping around like a 3d minefield. this hazard would potentially apply to US military satellites as well.

besides this: there are many, many ways to spy on satellites. the US is believed to have at least one satellite that sits 'above' a major middle eastern comms satellite with a football field-sized antenna, passively snooping everything shot at it. you can encrypt it, sure, but do you have high enough trust in your crypto implementations to deal with an adversary like that?

what i'm getting at is, i don't think they would shoot down the satellite.

Re: ProtonVPN

#135

Earlier quoted context omitted.

Yes, but it's fairly trivial to drop a "Seal Team 6" in and physically seize whatever they want, or just sabotage your equipment. Also, they could pressure your mainland circuit provider, or simply cut your cable every time you repaired it, which would put you out of business fairly quickly. I'm not sure a data haven works unless you have a sovereign military that can defend itself against the rest of the world (good…

A satellite in geosync orbit? Sure, much smaller but definitely harder to reach.

It's still a rather bad trade-off. If you base your operation in a country with strong privacy laws then these at least protect you from that domestic government.

If you base your operation in international waters/outer space then there's literally no privacy law protecting you from anybody, you are fair game for every government out there.

Re: ProtonVPN

#136
post #56

Using public commercial VPN providers for serious security/privacy is a very bad idea. Get someone to set up Trail of Bits "Algo" for you (or do it yourself, if you're comfortable with Ansible).

Algo's pretty easy, but if you want to use a cheap service like Vultr, which isn't yet supported by Algo, I wrote a post on the necessary steps recently: http://modulolotus.net/posts/2017-03-28-setting-up-algo

Re: ProtonVPN

#137
post #56

Using public commercial VPN providers for serious security/privacy is a very bad idea. Get someone to set up Trail of Bits "Algo" for you (or do it yourself, if you're comfortable with Ansible).

What would people think of a VPN service that builds it for you, then hands over control when done? E.g., it walks you through setting up a DO droplet, uses keys to install a VPN, then prompts you to change the keys so it can't access the server? Think there's a market for that?

Re: ProtonVPN

#138
post #56

Using public commercial VPN providers for serious security/privacy is a very bad idea. Get someone to set up Trail of Bits "Algo" for you (or do it yourself, if you're comfortable with Ansible).

What would people think of a VPN service that builds it for you, then hands over control when done? E.g., it walks you through setting up a DO droplet, uses keys to install a VPN, then prompts you to change the keys so it can't access the server? Think there's a market for that?

That's essentially what Algo does.

Re: ProtonVPN

#139

Earlier quoted context omitted.

Wait. Do you mean they actually inspect traffic and tear down the connection if they see an SSH handshake on any port other than tcp/22?

They whitelist ports, I believe. That's the reason torrents don't work, for example.

Yeah, my understanding is they whitelist standard ports, and everything else is blocked. They say it's because of BitTorrent, but it prevented me from accessing a server on a non-standard port, so I didn't buy.

Re: ProtonVPN

#140

what a dreadful buggy site, failed to signup. gives up as does not auger well for the reliability of the service. is it some pointless phishing thing?

Their reputation is well established. Possible the site is under heavy load.

hmm ok benefit of doubt given - refused every possible username and does not say what is wrong with them, did not appear to work, then did unexpectedly, then tried username recovery but got 404s. Genuinely I'd never heard of them before now so I was like - 'wait what is there something else going on? like some shell thing posted to hackernews'...

I just tried again and it completed and is working okay now - bit of a fiddly registration process but actual vpn seems to pretty good and there are lots of endpoints, so great too.

Post reply on HN