Live data from Hacker News

Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

windscribe.com

141–150 of 456 posts

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#141

Earlier quoted context omitted.

The original use for a VPN - getting access to private resources - is still very much in play. I don't just mean being able to access some private web interface you have on a private server in your at home, I mean connecting a satellite office to the main corporate office. But for all of these consumer marketed VPNs, I think your list has 90%+ covered...

Interesting that we use the same word to describe both technologies, but semantically and technically they are very different. Perhaps we use the same word to describe them because initially they did use the same technologies, but they have branched out ever since? Maybe IPSec would be a common tech used. But the algorithms are not the same anymore since they serve different purposes (Personal privacy vs corporate/sy…

> Interesting that we use the same word to describe both technologies, but semantically and technically they are very different.

That's where my head was at. When i hear my colleagues talk about a VPN, i'm thinking about an IPSEC tunnel and an afternoon of swearing at ios on some outdated ASA. When I hear regular people talking about a VPN, my mind immediately goes to "oh, so you want to watch rick and morty on netflix and don't know anybody hosting a jellyfin/plex server".

When do we coin a new term? Or do we? Does "vpn" turn into a word like "truck" where it's only the context that tells you if we're talking about a 2 axle pickup truck in a home depot parking lot or something pulling a 40ft container unit?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#142

Is there any other real world usecases for VPN nowadays other than: 1. Getting access to geolocked data 2. Torrenting "Linux ISOs" ?

Another one is getting around content filters / service-specific throttling (think college dorms and campuses, hotels, public hotspots etc).

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#143
post #50

Earlier quoted context omitted.

A ton of ISPs use deep packet inspection for various kinds of filtering (and other shenanigans). When they get it wrong it manifests to the user as certain websites or access patterns being inaccessible and the ISPs customer support agreeing that you should have access and being able to do fuck all to fix it. A VPN in the middle usually solves the issue.

Wait, I think an ISP cannot inspect the content of packets that are encrypted, say, with HTTPs. In order to inspect TLS encrypted packets you need access to the end-device, controlling the end-router is not sufficient since you would not have access to the device certificates. If you can prove that an ISP can inspect packets, it would be major news.

They may not need the contents, seeing you're connecting to a netflix IP and having a lot of data transfer may be a good reason to throttle, for example.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#145
post #6

Been saying it for YEARS: 95% of VPNs sell your data. It's where they make their money. It's absolutely insane the push-back I get when I say this online. I get downvoted to hell and back. Source: I bought this data from VPN companies... Hell, you can inject ads and surveys if you want!

> 95% of VPNs sell your data. It's where they make their money. It's absolutely insane the push-back I get when I say this online.

People love to stick to what they irrationally believe in. I would give you push back as well by saying 95% is a very conservative number. I would say 98-99%

But hey, they say they don't sell my data isn't it?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#146

Earlier quoted context omitted.

[flagged]

Calling out Israeli conspiracy isn't Jew hating. This is the whole issue. No one can question what Israel is doing for fear of anti semitimtism. If everyone is "anti-semitic" then you allow real antisemitism to foster unabated.

> No one can question what Israel is doing

I literally said "it certainly should be allowed"

but it goes both ways. no one can question what Jew haters are doing for fear of anti-anti-semitism. If no one is a "Jew hater" then you allow real antisemitism to foster unabated.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#147
post #103

Earlier quoted context omitted.

Doesn't pretty much every Starbucks location in the United States use a nationwide provider? Despite the randomized Mac address, you can still fingerprint devices using all the usual tricks when they connect to the authentication and authorization page before you allow them to access the broader internet. If the receipt had a passcode on it, you've got a link between all of your browser fingerprint, radio fingerprint…

>Despite the randomized Mac address, you can still fingerprint devices using all the usual tricks when they connect to the authentication and authorization page before you allow them to access the broader internet. Fingerprinting is overrated given that every iPhone 17 is identical to any other iPhone 17. If you leave system settings at stock, which most people do, there's very little to fingerprint. >Doesn't pretty…

> Those are diverse enough that it's tough to build a complete profile.

Debatable; i promise you that somebody out there is willing to buy the info and will attempt to combine it with $otherInfo such that it becomes valuable enough for somebody else to buy. Lots of adtech/survalence-tech operates with thin margins at _massive scale_.

> I don't think I ever saw a place that was that guarded about their wifi.

It's rare; i'd run into it only a few times a year. Typically PoS systems and WiFi are not integrated. I also haven't really been paying attention since LTE is good now :).

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#148
post #87

Earlier quoted context omitted.

It’s not Tesonet, Proton is wholly self-owned and managed. Proton VPN was briefly sharing employees with Tesonet during initial app bringup, and that partnership is long over. Naturally due to competition and the huge importance of privacy in this space, people still bring this up, but Proton VPN does not and never will sell or share your data with anyone. Source: I am a Proton VPN employee.

So, why were the employees shared? EDIT: I'm not saying being related to Tesonet is bad, but it is a fact that you cannot run away from.

> Proton VPN was briefly sharing employees with Tesonet during initial app bringup

I assume they needed the experience in how to run a VPN company, so that initial partnership was needed.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#149
post #50

Earlier quoted context omitted.

A ton of ISPs use deep packet inspection for various kinds of filtering (and other shenanigans). When they get it wrong it manifests to the user as certain websites or access patterns being inaccessible and the ISPs customer support agreeing that you should have access and being able to do fuck all to fix it. A VPN in the middle usually solves the issue.

Wait, I think an ISP cannot inspect the content of packets that are encrypted, say, with HTTPs. In order to inspect TLS encrypted packets you need access to the end-device, controlling the end-router is not sufficient since you would not have access to the device certificates. If you can prove that an ISP can inspect packets, it would be major news.

* Russia

* Kazakhstan

* China

* Belarus

* Iran

* Mayanmar

- list of countries that are known or suspected to MITM traffic, including SSL

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#150
post #50

Earlier quoted context omitted.

A ton of ISPs use deep packet inspection for various kinds of filtering (and other shenanigans). When they get it wrong it manifests to the user as certain websites or access patterns being inaccessible and the ISPs customer support agreeing that you should have access and being able to do fuck all to fix it. A VPN in the middle usually solves the issue.

Wait, I think an ISP cannot inspect the content of packets that are encrypted, say, with HTTPs. In order to inspect TLS encrypted packets you need access to the end-device, controlling the end-router is not sufficient since you would not have access to the device certificates. If you can prove that an ISP can inspect packets, it would be major news.

You don't need fully broken encryption to gain useful information. Knowing how much data is transferred, to which servers, and when (especially with details like how various endpoints will inadvertently chunk up HTTPS requests based on the details about the content or how interactive sessions will have certain back-and-forth transmit patterns) is sufficent to generate a traffic "fingerprint" which you can correlate to other users, to automated traces crawling those same servers, and otherwise get a very good sense of what a user is up to online even above and beyond just knowing which IP is being queried.

Toss that into any sort of "anomaly detection" or other such nonsense, and it's easy to create rare edge cases at an ISP level.

It's somewhat analogous to how you can sometimes "reverse" hashes like SHA256. E.g., suppose the thing you're hashing is an IPV4 address. There are only 4 billion of those, so a pre-image attack just iterating through all of them and checking the forward direction of the hash is extremely effective. TLS makes that a little more complicated since the content itself is actually hidden, but time and space side-channels give you a lot of stochastic information. You might not be able to deduce somebody's bank password, but you can probably figure out where in the bank's login flow they are and approximately what they did once they logged in.

Post reply on HN