Live data from Hacker News

Who Owns, Operates, and Develops Your VPN Matters

opentech.fund

131–140 of 203 posts

Re: Who Owns, Operates, and Develops Your VPN Matters

#131
post #37

Earlier quoted context omitted.

Do you have a source that shows that popular VPN providers such as Mullvad or NordVPN actually sell your residential internet to third parties? That's a bold claim, but pretty scary if true.

yes, search for NordVPN vs Luminatti (guys behind Holla VPN) scandal: "nordvpn luminati lawsuit patent". Basically Luminatti, now known as bright data, reached out to NordVPN in order to utilise their user's internet as residential proxy nodes. NordVPN thought otherwise and created their own network instead (Oxylabs if I'm not mistaken). They are still in patent wars I believe. I don't know anything bad about Mullvad…

> That being said I, as a small business owner in this space, will not use any of them, ever. I know it sounds like a "yeah right" because I sell the services but I know better.

If you weren't you, would you trust your service?

Re: Who Owns, Operates, and Develops Your VPN Matters

#132
post #128

MullvadVPN seem to be pretty decent at the moment, but it looks like they're laying down a worldwide VPN infrastructure of sorts that other VPN companies can rent (similar to phone networks) This makes me feel a little uneasy of their unstated longterm goals (corner the entire market), but I do think they are the most trustworthy out there right now

We have a few partners who use our infrastructure (e.g. Mozilla), but we're not trying to dominate as a white-label solution. In fact, we've said no to a few well-known brands who wanted to white-label our infrastructure. As for our long term goals, take a look at our owner's directive: https://mullvad.net/en/blog/ownership-and-future-mullvad-vpn We want to make online mass surveillance and censorship ineffective. Mu…

I really like the "to plant trees in the shade of which we will never sit" statement. My pessimism only comes from watching trusted giants like Google and Cloudflare turn into critical infrastructure that in turn dictates the web.

May you continue to be the beacon of trustworthiness and hope that we all need right now

Re: Who Owns, Operates, and Develops Your VPN Matters

#133

Shameless plug: VP.NET [1] runs in a trusted execution environment (enclave) so you can verify it is doing what it is supposed to do and not anything else! [1] https://vp.net/l/en-US/blog/Don%27t-Trust-Verify

no you can't... you can verify what something is doing, but there's no guarantee it's the same code routing your VPN requests, or that nothing else on the network/server is listening/forwarding your traffic elsewhere.

Re: Who Owns, Operates, and Develops Your VPN Matters

#134

Earlier quoted context omitted.

Long ago, in the era of Firesheep and exploding prevalence of coffee-shop Wi-Fi, consumer VPN services were definitely valuable. But that was long ago. Now, HTTPS is the norm. The only use cases for consumer VPNs today seem to be (1) "pretend I'm in a different geography so I can stream that show I wanted to see" and (2) "torrent with slightly greater impunity". I live in Seattle and Mullvad VPN seems to have bought…

Times Square at one point was practically half full of Mullvad ads. I already distrusted it but the sheer amount of money they spent to do that made it shadier to me

I feel like other VPNs sponsoring YouTubers or others to talk wonders about them while not really using their product makes me trust them less, especially if they are based in some opaque jurisdiction like NordVPN (Panama) or ExpressVPN (British Virgin Islands) among others

Re: Who Owns, Operates, and Develops Your VPN Matters

#135
post #56

That's why we sell only the service [1] and point our users to the default app install (Wireguard in our case). Ever since Holla VPN and the entire Brightdata/Luminati clusterf~ VPNs are a risky business for users. Most of them are proxy nodes underneath, they rent you datacenter IPs while they sell your residential internet to third parties. [1] https://www.anonymous-proxies.net/products/

> We offer highly secure, /.../Residential /.../ Proxies. Where do you get residential proxies? I ask because I'm always reminded of https://sponsor.ajay.app/emails/ .

brightdata but it will cost several hundred USD per month

Re: Who Owns, Operates, and Develops Your VPN Matters

#136
post #98

Earlier quoted context omitted.

HSTS solves this to some extent. If you've visited the domain in the past (or the site operator submitted to the HSTS preload list), a different certificate presented would be flagged by your browser.

Not a different certificate, but one signed by an untrusted authority. HSTS won't let you bypass it. There used to be a Firefox addon that could warn you if the actual certificate changed, but it died with manifest addons.

It isn't too useful nowadays, is it? With most websites' certificates being from Let's Encrypt or similar CAs automated via ACME and up to 90-day certs; and this getting reduced in the future to only 47 days. Every month you'd need to accept any website's new certificate.

Also, does HSTS have something to do with the authority? AFAIK it only forces the browser to use HTTPS and never plain HTTP for that domain, but if you switch from a legit Let's Encrypt to a legit ZeroSSL cert, HSTS won't care about it; only the browser if you have a not-trusted certificate from another CA (or self-signed).

Re: Who Owns, Operates, and Develops Your VPN Matters

#137
post #50

Do people here trust their ISPs more than their VPN providers? That’s the question! On the other hand, as far as privacy from the end point is concerned, users can be identified regardless of IP addresses. Visit fingerprint.com, you will get an identifier, then connect to a privacy VPN and change servers once in a while. The website will identify you, tell you are the same user visited last week from such location, a…

I use a VPN because it does NAT and shared public IP. My residential connection’s public IP and timestamp uniquely identifies my physical residence.

Also ISPs are shady and will sniff your DNS and SNI and they know your name, address, and phone number, and will sell it all as a bundle.

Re: Who Owns, Operates, and Develops Your VPN Matters

#138

I use tailscale with an exit node. I just need location control. Wireguard gives me that.

Wireguard doesn't give you exit nodes, it's just the encrypted L3 stack. Whomever is responsible for your exit nodes actually gives you this functionality. If it's tailscale itself then they use mullvad nodes as exit nodes which I welcome very much.

> Wireguard doesn't give you exit nodes, it's just the encrypted L3 stack.

That's why I said tailscale lol. But I understand, I guess I said it in a confusing manner.

> If it's tailscale itself then they use mullvad nodes as exit nodes which I welcome very much.

You can also set on of your devices as an exit node for your Tailscale network. Kind of cool.

Re: Who Owns, Operates, and Develops Your VPN Matters

#139

Earlier quoted context omitted.

> You can operate your own VPN On what infra? Can you trust that one? Doesn't that solution just move the problem down one level?

The answer is always "maybe" until you bring your threat model to the table. I use a VPN to watch IPTV & download torrents without my ISP sending me nasty letters. Mullvad is great for that. I would trust it in conjunction with Tor to protect me from low-level crimes. I wouldn't run trust either it or Tor, alone or in combination, to run a marketplace the DEA would become interested in. If your threat model is obscur…

a DYI VPN may hide my home IP but it does not hide my identity unless the server i route through is not owned by me. also any server that i can use is likely blocked by wikipedia, youtube, reddit, and others because they detect and block hosting services.

Re: Who Owns, Operates, and Develops Your VPN Matters

#140
post #123

Earlier quoted context omitted.

Long ago, in the era of Firesheep and exploding prevalence of coffee-shop Wi-Fi, consumer VPN services were definitely valuable. But that was long ago. Now, HTTPS is the norm. The only use cases for consumer VPNs today seem to be (1) "pretend I'm in a different geography so I can stream that show I wanted to see" and (2) "torrent with slightly greater impunity". I live in Seattle and Mullvad VPN seems to have bought…

The way I see it there's four use cases: - protecting your privacy from your local ISP, WiFi, school, government etc - protecting your privacy from some forms of online tracking - circumventing censorship - circumventing geographical restrictions If you combine masking of your IP address with a web browser that protects you from various types of browser-based fingerprinting, you are more in control of your privacy on…

Hi! Thanks for your deeply non-silly reply; it's nice to (virtually) meet a cofounder.

If you have time, I'd love to hear your thoughts on Mullvad's campaign here in Seattle.

For what it's worth, I suppose my perspective boils down to: the first three issues aren't issues here in town, or can be addressed in more direct ways (we have a wide choice of providers; 1st party browsers and services cover the gamut of tracking concerns; etc). Circumventing geographical restrictions is useful, but -- perhaps understandably! -- doesn't appear to be what Mullvad is advertising on the trains I ride.

Post reply on HN