Live data from Hacker News

ExpressVPN employees complain about ex-spy's top role at company

reuters.com

161–170 of 175 posts

Re: ExpressVPN employees complain about ex-spy's top role at company

#161
post #93

Earlier quoted context omitted.

> you replace trusting your ISP with trusting a different group of unknown people with similar motivations I've always seen this argument but it's never made sense to me. For starters I absolutely don't trust my ISP. I know they are collecting, storing, likely selling my data and that they are 100% going to comply with any government requests from my government (I don't even trust that they would only respond to lega…

Use an alternative DNS server, Firefox/Brave/Ungoogled Chromium, uBlock Origin, and disable JavaScript everywhere you can possibly help it. As far as reclaiming some privacy from routine surveillance, this is probably better advice than "Pay Unknown Company X $9/mo to maybe be slightly better than your ISP in terms of privacy".

But wouldn't the measures you mentioned make routine surveillance easier due to the much more unique fingerprint?

Re: ExpressVPN employees complain about ex-spy's top role at company

#162
post #41
post #18

Earlier quoted context omitted.

Browser fingerprinting works much better than checking IPs. With multiple devices being behind the same IP, it's necessary to distinguish between users. I'm not saying VPNs are worthless - I'm on one right now for work. Commercial VPNs, for most people who purchase them, are completely worthless. And I very much doubt that tunneling your connection through a VPN can improve ping.

> And I very much doubt that tunneling your connection through a VPN can improve ping. Yea... as someone who used to play a lot of online games, this was always a surefire way to increase ping time lol. "Crap, my VPN is still on... brb"

This is actually a thing outside of the US mostly. For example in many Asian countries routing is utterly fucked if it's not incumbent to incumbent.

Re: ExpressVPN employees complain about ex-spy's top role at company

#163
post #93

Earlier quoted context omitted.

Use an alternative DNS server, Firefox/Brave/Ungoogled Chromium, uBlock Origin, and disable JavaScript everywhere you can possibly help it. As far as reclaiming some privacy from routine surveillance, this is probably better advice than "Pay Unknown Company X $9/mo to maybe be slightly better than your ISP in terms of privacy".

But wouldn't the measures you mentioned make routine surveillance easier due to the much more unique fingerprint?

The fingerprint fails to run with JS disabled.

Re: ExpressVPN employees complain about ex-spy's top role at company

#164
post #120

Earlier quoted context omitted.

I have no idea and wasn't even aware of its existence. I have no affiliation with either dVPN Alliance, Mysterium or Sentinel but I have used both of the latter two as well as Privatix. Mysterium is my go to choice but there's an issue with split tunneling which prevents me from using it right now.

FWIW, I do not believe that either Sentinel nor Mysterium (though I don't bother looking at their product often; I am very confident about this for Sentinel, though) currently have any support for "multiple hops" through VPNs, and so for the complaints people are talking about here I would consider them "somewhat actively dangerous". (To be fair, Orchid has for some reason decided to hide multiple hops behind an adva…

The machine I tend to use for connecting runs headless and a recent change in Mysterium has made it so that once I connect to their network I'm disconnected from that machine on the local network. Not sure if it's a feature of split tunneling that normally allows this behaviour. I might have my terminology wrong.

Re: ExpressVPN employees complain about ex-spy's top role at company

#165
post #120

Earlier quoted context omitted.

FWIW, I do not believe that either Sentinel nor Mysterium (though I don't bother looking at their product often; I am very confident about this for Sentinel, though) currently have any support for "multiple hops" through VPNs, and so for the complaints people are talking about here I would consider them "somewhat actively dangerous". (To be fair, Orchid has for some reason decided to hide multiple hops behind an adva…

The machine I tend to use for connecting runs headless and a recent change in Mysterium has made it so that once I connect to their network I'm disconnected from that machine on the local network. Not sure if it's a feature of split tunneling that normally allows this behaviour. I might have my terminology wrong.

Ah ha! Ok, I wouldn't have called that split tunneling myself (but maybe I should have: I am totally willing to believe that I should). (That sane issue happens with Orchid's tooling by default--on a desktop it is somewhat easy to fix with another manual route, which you can probably also use with Mysterium, but on mobile as a user you don't have many options. I was actually going to be fixing that for our next update because one of our key people told me they don't run it on their phone because of this; in his case, it disconnects his phone from his baby monitor.)

Re: ExpressVPN employees complain about ex-spy's top role at company

#166
post #163

Earlier quoted context omitted.

But wouldn't the measures you mentioned make routine surveillance easier due to the much more unique fingerprint?

The fingerprint fails to run with JS disabled.

Well, except that disabling js doesn't prevent you from having a browser fingerprint. In fact, it will make it even more unique and therefore easier to trace. So not sure what you are referring to

Re: ExpressVPN employees complain about ex-spy's top role at company

#167
post #55
post #46

Earlier quoted context omitted.

> And I very much doubt that tunneling your connection through a VPN can improve ping. Surprisingly this can be the case as long as the combined link to VPN + target is better than the direct link to target. Keep in mind that the target might be geo distributed. Like driving, going over 2 highways might be fasted than going over a direct dirt road, or a longer road might be faster because the direct road is congested…

> Surprisingly this can be the case as long as the combined link to VPN + target is better than the direct link to target Is that surprising? I think that's what you would expect, and it's what the above commenter is suggesting (quite reasonably IMO) is very unlikely. I think the issue is that you're implying the road to the target is a dirt road, but the road to the VPN is a highway, which seems a bit questionable.

I've seen it happen. Blizzard is quite notorious for having some weird network links, where a VPN is known to be a workaround. Example [1], and I've heard the same from WoW players.

[1] https://eu.forums.blizzard.com/en/overwatch/t/lower-ping-whe...

Re: ExpressVPN employees complain about ex-spy's top role at company

#168
post #2

It's been clear for a long time that every single commercial VPN service is a waste of money. At best, you replace trusting your ISP with trusting a different group of unknown people with similar motivations. At worst, it's a government agency honeypot or someone like Facebook. If you think you want a VPN for "privacy", use Tor Browser. If you want a VPN for any other reason that "normal people" think they want a VPN…

It depends on your risk model.

We use a commercial VPN at our company because it provides a mechanism for traffic encryption for employees who might be connecting from insecure networks. Sure most sites use HTTPS but there is still some unencrypted traffic like CDN or similar.

It’s not a cure all or some privacy guarantee, it’s just that for us, the risk of our employees browser history being stolen by that VPN for some nefarious purpose is just less than the risk of information leaking via insecure network.

Re: ExpressVPN employees complain about ex-spy's top role at company

#169
post #61

Earlier quoted context omitted.

What traffic does it log exactly, and who logs it? As I understand Tor: - the exit node knows the second-to-last node, the cleartext data and the destination, - each intermediate node knows the previous and next nodes, - the entry node knows the sender and the second node. And using HTTPS prevents the exit node from knowing the cleartext data. This doesn't enable any individual node to know who sent what to whom, ass…

Everything you mentioned goes back to my point that it's an anonymity service, not a privacy service. Tor exit nodes don't know who sent traffic, but they do see all the traffic that passes through them. HTTPS can mitigate some of that, just like it can for VPNs, but the site you're going to is still very much visible. Don't get me wrong, Tor is a very useful service if anonymity is your goal, but it requires a solid…

> HTTPS can mitigate some of that, just like it can for VPNs, but the site you're going to is still very much visible.

Not in a sense that defeats privacy, since the exit node doesn't know the sender.

With Tor and HTTPS, no Tor node sees the cleartext data, and no node can associate me with the server I'm contacting. That sounds very much private to me.

> https://support.torproject.org/faq/staying-anonymous/

I've read these warnings, but I don't see anything that would defeat privacy if Tor is used correctly.

Re: ExpressVPN employees complain about ex-spy's top role at company

#170
post #2

It's been clear for a long time that every single commercial VPN service is a waste of money. At best, you replace trusting your ISP with trusting a different group of unknown people with similar motivations. At worst, it's a government agency honeypot or someone like Facebook. If you think you want a VPN for "privacy", use Tor Browser. If you want a VPN for any other reason that "normal people" think they want a VPN…

> At best, you replace trusting your ISP with trusting a different group of unknown people with similar motivations. I'm not sure what country you live in, but in the US, all the big ISPs might as well be run by the government, at least when talking about privacy. Private VPN companies are far more trustworthy, all else being equal.

> Private VPN companies are far more trustworthy, all else being equal.

How? I don't see how being a VPN company as opposed to an ISP makes a difference in regards government seizure or request of logs.

Post reply on HN