Live data from Hacker News

ProtonVPN

protonvpn.com

141–150 of 205 posts

Re: ProtonVPN

#141
post #72

Earlier quoted context omitted.

Looking at Algo ( https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-th... ), it seems like it provides an easy way to setup a (secure) VPN on a piece of hardware you own or one of the supported public clouds. In that respect, I'm not sure if it gives a lot of privacy. As you're the only one using that VPN, the traffic may not be too hard to trace back to you.

Algo isn't that much better than any other VPN - arguably it's slightly better security wise, though I'd argue Wireguard tops it by far on cipher choices and security margins. Ultimately VPNs just aren't for hiding anything that could cause you significant problems. If you want that, Tor, i2p, or piles of hacked boxes are your only options really if you must interact with the clearnet.

The only problem I have with Algo is that it isn't compatible with Little Snitch :(

Re: ProtonVPN

#142

Earlier quoted context omitted.

>ProtonMail fought the referendum, but hasn't updated this "Why Switzerland?" page: https://protonmail.com/blog/switzerland/" Agreed, and that referendum was back in September of 2016. That's almost 9 months ago. This seems really disingenuous. And the referendum didn't just eek by but it passed by 65%. So if the Swiss domicile doesn't offer the protections it once did, why would I choose this provider over any of th…

Because they still can't read your email, nobody can, even thought it is on their servers and crossing Swiss borders.

[deleted]

Re: ProtonVPN

#143

Earlier quoted context omitted.

What would people think of a VPN service that builds it for you, then hands over control when done? E.g., it walks you through setting up a DO droplet, uses keys to install a VPN, then prompts you to change the keys so it can't access the server? Think there's a market for that?

That's essentially what Algo does.

Oh, I know; I wrote a blog post on using Algo.

To be clear, I was thinking about the less-technically-sophisticated-than-HN crowd. E.g., is there a market for the people who would typically purchase VPN services, don't want to trust a VPN company, but don't know how to setup a cloud server?

Re: ProtonVPN

#144

Earlier quoted context omitted.

I think he means "dropped" as in "the rapper dropped his mixtape today", not as in "the service provider dropped their service due to lack of profitability".

Well that's confusing :) Given your example is out of context and counter-example is perfectly in context.

[deleted]

Re: ProtonVPN

#145
post #103

Earlier quoted context omitted.

Germany has very strong privacy laws which is one of the reasons Amazon dropped an AWS region there. Customers are paying a premium for the jurisdiction.

If customers are paying a premium why would Amazon drop the region? Were the privacy laws too complex for them?

Think "drop a pin" like in Google maps parlance. To "drop something" is to release something. In that context it's really American hip-hop slang. Although its used widely by the music press when discussing a new release from any type of artist.

A band or artist might be "getting ready to drop something new" - a new single, a new album, video etc.

Re: ProtonVPN

#146
post #81
post #79

ProtonMail is doing what I expected Mozilla would do. I expected Mozilla to promote online privacy with their browser and Tor nodes and more...

Mozilla's made a couple of bet-the-company decisions in the last couple years, including Firefox OS and the phone. Given the results of those, it's a miracle of luck and effective management that they're still in business. But that would be another bet-the-company prospect, and I don't see them likely to try that for a couple years.

Their non-profit model probably helped.

Re: ProtonVPN

#147
Too bad they're focused on new and shiny at the expense of real (paying) email users. After a year of Visionary, I finally went back to Google. PM just isn't designed for large mailboxes, real search, or navigation. Plus they still have not provided any way for you to export your emails out. They're locked up forever, unless you want to forward each one, one at a time.

Re: ProtonVPN

#148

Earlier quoted context omitted.

Switzerland was one place people use the name of as the hallmark of their service being free from surveillance while still residing in a developed country. So which will be that new country now, since apparently Swizterland isn't that option anymore? And what if that new country does something similar? Then next? And then? I don't think there will be many countries left to go to in that case. Or any, after some time?…

Swiss being a bastion of privacy for anything other than banking should be taken with a pinch of salt. They've been up to their neck in crypto cooperation with the NSA since at least the Crypto AG scandal if not longer.

>"Swiss being a bastion of privacy for anything other than banking ..."

The secrecy of Swiss banking actually ended a couple of years ago:

http://money.cnn.com/2015/03/19/news/switzerland-tax-evasion...

Re: ProtonVPN

#149

Earlier quoted context omitted.

>ProtonMail fought the referendum, but hasn't updated this "Why Switzerland?" page: https://protonmail.com/blog/switzerland/" Agreed, and that referendum was back in September of 2016. That's almost 9 months ago. This seems really disingenuous. And the referendum didn't just eek by but it passed by 65%. So if the Swiss domicile doesn't offer the protections it once did, why would I choose this provider over any of th…

Because they still can't read your email, nobody can, even thought it is on their servers and crossing Swiss borders.

I was asking why I would choose them as a VPN provider over any of the others.

Re: ProtonVPN

#150
post #123

Earlier quoted context omitted.

I work in the field and anybody that says that a piece of software is secure before it has even had a security evaluation by a third party does not know what they are talking about. I think what you have seen is security people saying that the design of Wireguard seems to be equal or better than other, current, options, that doesn't mean that the implementation is just yet.

I've spent my career doing third-party software security evaluations --- among other things, I founded the NCC Cryptography Services practice --- and I will tell you right now that the Wireguard security story is far more compelling than any third-party audit. It's not simply the protocol design, which is superior in pretty much every conceivable way to IKE or TLS, but also the code, which is carefully written to min…

Could you unpack your statement about the careful code writing, or link to an explanation? We would usually expect a formal third-party audit to substantiate such a claim, but if there is other good evidence for their code's secure implementation I'd love to see it.
Post reply on HN