Live data from Hacker News

Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

windscribe.com

261–270 of 456 posts

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#261

Note that all of these companies are also under the umbrella of Tesonet, a Lithuanian VC firm also headed by Tomas Okmanas (Tom Okman in TFA). Their flagship investments are Nord Security, Hostinger, Oxylabs, Surfshark, Decodo, Mediatech, and nexos.ai - all closely related business models around proxying. They don't seem to have Russian ties: "In 2022, CyberCare opened an office in Lviv, Ukraine. Although planning fo…

Don't forget ProtonVPN links to Tesonet, which they're trying hard to "debunk" (though no clue why, I have nothing against Tesonet). They only shared employees and accidentally signed apps with the same certificates, but are "totally unrelated". Their PR people are already on this thread. If they didn't try so hard to fight it, people might care less.

"Links to" is doing a lot of work in that sentence. ProtonVPN is owned by Proton, which has no legal ownership ties with Tesonet. During Proton's expansion into Eastern Europe, Tesonet initially assisted Proton with HR, payroll, and local regulation, so for a period of time, people working for Proton were employed by Tesonet, since Proton had no local subsidiary that could hire them. These were not "shared employees", they worked exclusively for Proton.

In 2016, Proton created its own subsidiary, and these people are now employed by Proton. But for this historical reason, the ProtonVPN keystore on Android still lists Tesonet as the organization name, even though it is fully controlled by Proton.

None of this is "debunking"; these are just the facts. You can make of them what you will, but you should be honest about what actually happened when you talk about it.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#262
post #150

Earlier quoted context omitted.

Wait, I think an ISP cannot inspect the content of packets that are encrypted, say, with HTTPs. In order to inspect TLS encrypted packets you need access to the end-device, controlling the end-router is not sufficient since you would not have access to the device certificates. If you can prove that an ISP can inspect packets, it would be major news.

You don't need fully broken encryption to gain useful information. Knowing how much data is transferred, to which servers, and when (especially with details like how various endpoints will inadvertently chunk up HTTPS requests based on the details about the content or how interactive sessions will have certain back-and-forth transmit patterns) is sufficent to generate a traffic "fingerprint" which you can correlate t…

It may have been fixed since, but I saw a decent talk about this (defcon, IIRC) using Tinder as an example.

Using timing, amounts of data, and what was being connected to, you could recreate what someone was looking at and swiping direction. (left/right sent different amounts of data)

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#263

Earlier quoted context omitted.

Don't forget ProtonVPN links to Tesonet, which they're trying hard to "debunk" (though no clue why, I have nothing against Tesonet). They only shared employees and accidentally signed apps with the same certificates, but are "totally unrelated". Their PR people are already on this thread. If they didn't try so hard to fight it, people might care less.

"Links to" is doing a lot of work in that sentence. ProtonVPN is owned by Proton, which has no legal ownership ties with Tesonet. During Proton's expansion into Eastern Europe, Tesonet initially assisted Proton with HR, payroll, and local regulation, so for a period of time, people working for Proton were employed by Tesonet, since Proton had no local subsidiary that could hire them. These were not "shared employees"…

> Tesonet initially assisted Proton with HR, payroll, and local regulation

Entirely normal behaviour for a competitor to provide “HR assistance”.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#266

Earlier quoted context omitted.

Thanks for the link. How does this work on the server side? It gets packets on 8080 and then what? The article needs to explain the server config, even if it is just how to install ssh-server. I have tried setting up OpenVPN on my own VPS and I didn't get very far with it. I have also had to use OpenVPN in the day job and I much prefer just using ssh without some extravagant OpenVPN layer. My experience of failing to…

There are very simple options to selfhost a VPN nowadays. For example, Amnezia allows you to just type your server ssh credentials into their mobile app, and it will automatically set up AmneziaWG on your server and add it to the app. You can then create Amnezia or plain WireGuard config files from extra devices right from there.

That sounds like I'm putting a lot of trust in an app. Also giving it control over my server, which I guess is not a big deal if the server is a disposable VPS

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#267

Earlier quoted context omitted.

With TLS being everywhere, and just few clicks away from having DNS over TLS, I really don't get eavesdropping on public wifi prop value.

1. example.com is not on the HSTS preload list 2. Because you normally visit example.com using an incognito window, your browser hasn't cached the redirect to SSL, or the address bar suggestion, and you haven't bookmarked the site. 3. You key in example.com, the browser connects over http, and the evil wifi MITMs your unencrypted connection - removing the redirect to SSL and messing with the page however the evildoer…

You connect to an access point, and your browser/OS tries to open one of http://detectportal.firefox.com/canonical.html, http://www.msftconnecttest.com/connecttest.txt, http://connectivitycheck.gstatic.com/generate_204, https://captive.apple.com/hotspot-detect.html and loads/displays whatever unencrypted web page is served.

Getting someone to open an unencrypted webpage is almost trivial. It's often one of the only web pages you can open on a device.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#268

Earlier quoted context omitted.

> Proton VPN was briefly sharing employees with Tesonet during initial app bringup I assume they needed the experience in how to run a VPN company, so that initial partnership was needed.

But why would tesonet spend resources to help a competitor to start? I'd be surprised if there wasn't at least an equity deal.

> But why would tesonet spend resources to help a competitor to start?

I thought tesonet is venture / seed fund?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#269

Earlier quoted context omitted.

> Now please repeat the sentence, but use Jews, Muslims, or PoC instead of Russians. Why? OP decided to use Russians, as they're free to do so. No need to bring your objections to personal feelings here.

[flagged]

You've just pissed off the entire eastern Europe and are still acting like you've any moral with this. It's the Russian state (and their elites) that's been an abuser to neighboring countries and they're still doing it. It has nothing to with race at all, Russians are slavic people as well. We don't really have a problem with them, beyond them supporting their government

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#270

Earlier quoted context omitted.

"Links to" is doing a lot of work in that sentence. ProtonVPN is owned by Proton, which has no legal ownership ties with Tesonet. During Proton's expansion into Eastern Europe, Tesonet initially assisted Proton with HR, payroll, and local regulation, so for a period of time, people working for Proton were employed by Tesonet, since Proton had no local subsidiary that could hire them. These were not "shared employees"…

> Tesonet initially assisted Proton with HR, payroll, and local regulation Entirely normal behaviour for a competitor to provide “HR assistance”.

I've been part of a European startup that added offices in Asia and the US, and we initially always partnered with local companies to do this. It's mutually beneficial. It allowed us to grow more quickly, and it allowed them to make relatively easy money (and, in our case, to dump some of their shittier employees on us without us knowing).

In Proton's case, they already knew each other because Tesonet had previously offered to provide infrastructure during a DDoS attack against Proton.

So maybe it's a conspiracy, or maybe it's just how things go. You can make up your own mind, but you should provide the facts when you make sinister insinuations.

Post reply on HN