Live data from Hacker News

ProtonVPN

protonvpn.com

161–170 of 205 posts

Re: ProtonVPN

#161
post #25

Earlier quoted context omitted.

HN gets regular "what VPN should I use?" questions and my answer is always the same: Algo [1]. It is designed to be simple to set up, simple to tear down, and usable with numerous cloud providers or your own Linux server. [1] https://github.com/trailofbits/algo

I'm really interested in trying this but nervous with how much a cloud service will cost. Is there a free option for a cloud hosting service that I can start with?

$5/month with DigitalOcean will be enough - or try your luck with the AWS free tier: http://lifehacker.com/how-to-set-up-your-own-completely-free...

Re: ProtonVPN

#163
post #152

Earlier quoted context omitted.

>it might be time for space satellite hosting companies. Uhm that would probably backfire and make you an open target for every security service on the planet. German BND did bulk-collection on satellite communications, even tho German law does not allow for something like that. So BND reasoned "Satellites are in space, German Grundgesetz does not apply in space!", dubbing it the "Weltraumtheorie" (Spacetheory) Germa…

What if you can't control it once it's gone? and anyone can access the read-only data that is stored on-board.

Afaik this whole "satellite/international water" scenario was suggested to prevent government agencies from forcing access to sensitive data trough legal means. If your data is so insensitive, that you can have it just sitting there accessible by anybody, then you might as well just put the data on regular public servers and not bother with the effort of building a "space server".

Re: ProtonVPN

#164

Earlier quoted context omitted.

See now, this is the part I don't get. Assuming that you don't encrypt your email with pgp (reasonable, if you're emailing someone who isn't very techy) and aren't emailing someone else who also uses protonmail, there's nothing stopping them from making an unencrypted copy of every email they receive.

I was trying to do some research to refute this claim, and my ignorance of email standards has once again reared its ugly head. I thought DKIM was for encryption, but it's apparently just for verification? Email is still primarily sent in the clear ? I'm at a loss. What a mess.

Domain Keys Identified Mail. ;)

Re: ProtonVPN

#165

Earlier quoted context omitted.

If customers are paying a premium why would Amazon drop the region? Were the privacy laws too complex for them?

Sidenote, this is an example of a contronym, a word that means one thing and the opposite.

[deleted]

Re: ProtonVPN

#166
post #33

Earlier quoted context omitted.

In terms of privacy, doesn't it kind of let the cat out of the bag if you host your own VPN server? It's not your home address, but it's still just as much an address associated with you, isn't it?

It's less private for some forms of traffic, but for me, my main goal is to avoid ISP tracking and provide encryption on potentially malicious networks, which it works well enough for.

Your ISP in the DC, the DC itself, whoever owns the box your VPS is on or your fellow tenants could be malicious.

Re: ProtonVPN

#167

Earlier quoted context omitted.

No VPN can reliably anonymize you against government agents so I think the con is a non-issue. VPNs are only really useful when the local network is hostile and/or you want some degree of privacy from the sites you visit. Anyone with sigint capability is going to figure out who you are with a VPN. (i.e. Government agents)

This isn't about pretending to be James Bond, and "hostile" networks with "government agents" and all their "sigint" coming for your secrets. In the real world, VPN are mostly used to download copyrighted material. They have a pretty much perfect track record in that regard. Running a cloud VPS, on the other hand, is no more secure than your ISP: they have records, and will share them when ordered to do so.

This isn't remotely true. Pretty much every journalist uses a commercial VPN.

Re: ProtonVPN

#168
Does anyone know why they require existing ProtonMail users to enter their account's password AND the decryption password? Fair enough, they're linking my account, they require the account password. But the key that encrypts the email data too?

Re: ProtonVPN

#169

Does anyone know why they require existing ProtonMail users to enter their account's password AND the decryption password? Fair enough, they're linking my account, they require the account password. But the key that encrypts the email data too?

Your access token to the service is encrypted with your primary public key as an extra security measure, thus your client needs to decrypt it to use it.

Re: ProtonVPN

#170

Would you trust a service that knowingly pays ransoms to protect your personal data when it really counts? https://arstechnica.com/security/2015/11/crypto-e-mail-servi...

That was a mistake and we own it.
Post reply on HN