Live data from Hacker News

NordVPN library and client code open-sourced

github.com

241–250 of 276 posts

Re: NordVPN library and client code open-sourced

#241
post #117

Earlier quoted context omitted.

I ran into a situation where I left a VPN on my phone on and the Target app (US store Target) would pop up an alert "true". I assume someone was detecting if you were using a VPN and testing and it somehow made it into production. I emailed them and never heard back. Granted ... I get why a retailer with financial activity going on might want to know if a VPN was used to possibly apply extra scrutiny to the purchase.

Target now also has a world class incident response and forensics team setup after their big breach and being nearly every security vendors topic du jour for years. It's entirely reasonable they do this to add to malicious detection signal, or fraud.

Yes, Best Buy and many others I'm sure do this as well.

Re: NordVPN library and client code open-sourced

#242

Earlier quoted context omitted.

There’s many ways Netflix could detect VPN use, especially on mobile devices. It’s not obvious at all. Netflix could be doing something as simple as checking the IPs or could be actually checking the use of VPN at a system level. Both are equally valid readings of the GP comment.

seems like torrenting is still easier (and safer) than using netflix and co

I find this "easier" argument amusing.

Any solution that requires me to reach behind my TV and plug in my laptop is already not easy.

With Netflix you just punch your password into your smart TV and you're watching content.

Re: NordVPN library and client code open-sourced

#243

Earlier quoted context omitted.

seems like torrenting is still easier (and safer) than using netflix and co

I find this "easier" argument amusing. Any solution that requires me to reach behind my TV and plug in my laptop is already not easy. With Netflix you just punch your password into your smart TV and you're watching content.

i can stream torrents from my phone to tv without hassle

Re: NordVPN library and client code open-sourced

#244
post #158
post #87

Earlier quoted context omitted.

Do you know for sure that Mullvad sells DNS data? They claim to not log anything, including DNS.

Mulvad is the only VPN I trust (almost) completely. Private Internet Access and ProtonVPN both have tenuous relations to shady stuff. Private Internet Access got purchased by the same company that made Cyberghost (malware), but so far nothing bad has come of it. AFAIK they're also the only VPN that has been truly court-tested. ProtonVPN has some really weird circumstantial stuff related to TesoNet. Any other VPN I wo…

There are others, like OVPN that are A tier, but yea you need to vet carefully.

Re: NordVPN library and client code open-sourced

#245
post #122

Earlier quoted context omitted.

Perfect Privacy. VPN chaining, setting so your IP address always changes to be the one closest to the server, no logs (audited), stored in ramdisk, unlimited connections and bandwidth because they don't even know who's connecting. Cons: it can be slow and have issues with disconnects sometimes.

Perfect privacy was at least in the past run by austrian neonazis: https://www.zeit.de/gesellschaft/zeitgeschehen/2012-09/neona...

I didn't know that, but it almost makes me trust their service more. While I don't share their views, I do think technologically capable extremists are probably who I'd most want behind a service that I use as a layer for anonymity and privacy from everyone including government agencies.

Re: NordVPN library and client code open-sourced

#246
post #211

Earlier quoted context omitted.

I don't believe Mullvad sells DNS data, largely in part to their much higher pricing model when compared to Nord/Express/et. al Their FAQ confirms this, assuming you trust them. https://mullvad.net/en/help/no-logging-data-policy/#no-logs

A higher price point isn't proof of anything. If a provider can sell a VPN for $1/month as a loss leader and make $5/user after selling all data, what keeps a $10/month VPN from making >$15 doing the exact same thing?

My point was that they charge more for the subscription to avoid putting themselves in a situation where they feel pressure to sell user data to make up for a bad quarter of sales.

Re: NordVPN library and client code open-sourced

#247

Earlier quoted context omitted.

> terrible attitude towards privacy A VPN is inherently not a privacy tool. It is perceived that way because of the acronym Virtual 'Private' Network but privacy is not in the design specs at all. It's just for tunneling over untrusted networks like Starbucks Wi-Fi and spoofing your geo-location. That's it. You can't verify the no-logs claims by providers unless you're physically in their building and auditing the se…

> A VPN is inherently not a privacy tool. Maybe not, but NordVPN and similar services do heavily market themselves as essential privacy tools.

And some, like MullvadVPN, don't even ask for common PII. No usernames, no email addresses, no passwords, no persistent billing information.

They could claw some information from certain payment providers (like if you used Stripe to top off your account) if they wanted, but you can pay your bill by putting cash in an envelope and mailing it, if you wanted to.

Re: NordVPN library and client code open-sourced

#248

Earlier quoted context omitted.

seems like torrenting is still easier (and safer) than using netflix and co

I find this "easier" argument amusing. Any solution that requires me to reach behind my TV and plug in my laptop is already not easy. With Netflix you just punch your password into your smart TV and you're watching content.

You don't have to, I can use my Android TV to stream torrents in a Netflix-like GUI using public torrents. My father uses it and he's not very "techy".

It even syncs progress across devices, works on all my devices (doesn't work in the Apple ecosystem).

Re: NordVPN library and client code open-sourced

#249

Earlier quoted context omitted.

I was wondering the same thing. How would my ISP even know that I am using a site like z-library if everything is over HTTPS?

They still likely get your DNS info, and also they know you are connected to x ip address which is likely y service. All HTTPS does is make sure they can’t see what you are transferring. There is still meta data to whom. Why do you think google runs 8.8.8.8? It’s not out of kindness.

Do I care that can see metadata? If they don’t know what was transferred, how is that useful to them? Data-mining?

Re: NordVPN library and client code open-sourced

#250
post #27

So, should we, or should we not use a VPN? If most sites nowadays are on HTTPS, is vpn still needed for daily use I think the only reason now to use a vpn, is to login to a site as if from a different location, if the site blocks your region, or sensor some of its content Any other good reason to use a vpn

Torrenting without a VPN gets you a nasty letter pretty quickly. Someone at my IP address downloaded a single episode of The Last of Us with the VPN turned off, and I got an email that same day. No idea who would do such a horrible thing, but I think I saw some hacker-looking guy parked on the street stealing my wifi.

>Torrenting without a VPN gets you a nasty letter pretty quickly.

Only in some countries ;)

Post reply on HN