Live data from Hacker News

Who Owns, Operates, and Develops Your VPN Matters

opentech.fund

201–203 of 203 posts

Re: Who Owns, Operates, and Develops Your VPN Matters

#201
post #142

Earlier quoted context omitted.

Mullvad is rather principled on privacy. You can't even make a real account, you can only generate an account number that you can charge, and I assume they do some sort of clever tricks to keep themselves as blind as possible to who uses the account number. Firefox Relay is also just whitelabeled Mullvad, so they have Mozilla's stamp of approval. Of the big VPNs, the only one's that have ever felt shady to me are Nor…

>Mullvad is rather principled on privacy. no their not. protonvpn spends money to offer free account as form of advertisment. mullvd spend money on weird billboards. protonvpn provide free privacy even for those from 3rld world country. you can create proton email anonymousley thats also protonvpn account protonvpn is principled on privacy.

ProtonVPN is so principled they use a company providing datamining services (Tesonet) to run their VPN.

That doesn't mean they're datamining their customers, but it is terrible optics.

Proton is great, and in many ways they're doing great stuff. But in this case I wouldn't call them principled.

Re: Who Owns, Operates, and Develops Your VPN Matters

#202

Earlier quoted context omitted.

What about (3) "bypass government censorship"? UK and China are examples of where this is desirable. This is different from (1) because it's broader than just streaming shows and is about authoritarian rather than capitalist restrictions.

I think the general discussion is conflating censorship with age restrictions. Lumping the UK with China is very disingenuous. The UK law is stipulating adult content can only be viewed if you are provably over 18. They are putting all of that responsibility onto the websites/platforms to enforce that. If a child goes to a shop and tries to buy a pornographic magazine and they are denied, is that censorship? If a chi…

In practice the UK law is covering far more than explicit porn, but rather anything even slightly taboo or that acknowledges sex. Furthermore, many adults won't hand over government ID to the Internet like that. Taking these together, you get de-facto censorship.

Re: Who Owns, Operates, and Develops Your VPN Matters

#203
post #186

Earlier quoted context omitted.

> a DYI VPN may hide my home IP but it does not hide my identity unless the server i route through is not owned by me. Again, threat model matters – hide your identity from whom? You certainly won't hide it from someone who can seize payment records. You will struggle to hide it from someone who has control of enough of the internet to correlate data across sites, like Google or Cloudflare. But if you're looking to b…

sure, threat model matters. no protection is 100%, but more is better. using my own hosted proxy means that my identity is out in public. it's not even hidden. no need to even seize payment records. anyone can look up the ip address and eventually figure out who owns the server. i might hide it somewhat if i use that proxy only for this purpose, not point any DNS records at it, not reveal any public data, never use i…

> sure, threat model matters. no protection is 100%, but more is better.

You can't just say "threat model matters" and then treat security as an absolute gradient (poset?). That means you don't have a real threat model.

> using my own hosted proxy means that my identity is out in public. it's not even hidden. no need to even seize payment records. anyone can look up the ip address and eventually figure out who owns the server.

Bold claim – you've gotta show your work for this one.

> there is no threat model where your own hosted proxy could ever provide better protection than any VPN.

"no threat model [em-bee can imagine]", maybe :)

Here's one for you: how do you know your VPN provider doesn't log usage? You SSHed in and looked at /etc/syslog lately? Went to their hosting provider and opened door 641A?[0]

You sell a VPN and accept US cash? You are interacting with the US financial system and are open to all sorts of laws and enforcement levers that get to be pulled against the company that sold you that service & pinky swore they didn't log.

How sure are you about that "no log" claim if your VPN provider had a visit from a friendly FinCEN CI and some HSI folks who explained what a "US nexus" is?

All this said, I don't necessarily disagree with you: my personal threat model is that bigger fish exist than me, and a paid VPN provider fits the risks I take. Yours might be the same. But I don't see how you reasoned your way there.

[0]https://en.wikipedia.org/wiki/Room_641A

Post reply on HN