Live data from Hacker News

TunnelBear Publishes Security Audit

tunnelbear.com

31–40 of 61 posts

Re: TunnelBear Publishes Security Audit

#31
post #18

Can official binaries be independently reproduced from published sources by members of the public? If no, then an audit has little to no value as it still implies trusting the vendor not to fudge the binaries or, more broadly, be malicious.

The trouble with VPN providers is that even with reproducible client builds, it's much easier for them to intercept the traffic on their side. Plus there is a near-zero chance of detection, unlike on the client side where the binary can be decompiled.

I work for an ISP and believe deeply in online privacy. I've had the idea of offering up an as-private-as-I-can-make-it VPN service a few times, but I always end up at the same point: wondering how I could prove that the service wasn't doing anything malicious or nefarious -- "taps", Netflow data, etc. would all be easily available to me.

What would it take to convince you that a VPN service was trustworthy?

Re: TunnelBear Publishes Security Audit

#32
post #21

Earlier quoted context omitted.

I still have issues with a VPN provider who insists on using their VPN client.

Are there any nice free VPN Clients out there? I haven't been very lucky in finding any in the OS X realm

I was hesitant to buy Viscosity, but it has been well worth the money.

Re: TunnelBear Publishes Security Audit

#33
post #21

Earlier quoted context omitted.

I still have issues with a VPN provider who insists on using their VPN client.

Are there any nice free VPN Clients out there? I haven't been very lucky in finding any in the OS X realm

Fruho is a decent VPN GUI on Linux

Re: TunnelBear Publishes Security Audit

#34
post #21

Earlier quoted context omitted.

I still have issues with a VPN provider who insists on using their VPN client.

Are there any nice free VPN Clients out there? I haven't been very lucky in finding any in the OS X realm

NetworkManager is pretty much the default GUI for most distros and DEs, and has built-in support for OpenVPN, PPTP, L2TP, IPsec, SSH, etc... And it also integrates well with the Wifi setup, so you can easily set it up to automatically connect to the VPN when you connect to certain networks.

Re: TunnelBear Publishes Security Audit

#35
post #21

Earlier quoted context omitted.

Are there any nice free VPN Clients out there? I haven't been very lucky in finding any in the OS X realm

You can use the MacOS Network settings to connect to most types of VPN (hit "+" and fill in the forms to add a new connection). For free, open-source clients, Tunnelblick is very common.

macOS and iOS don't support OpenVPN with the built-in client. You can use strongSwan-based VPNs (e.g., as would be deployed through Algo) or Cisco, but for OpenVPN you'll need a custom client which, unfortunately, very likely brings along its own .kext.

Re: TunnelBear Publishes Security Audit

#36
Never trust a 3rd party VPN for anything sensitive ever, period. Words of assurance and "security audits" are completely meaningless. HTTPS interception and forwarding is a trivial thing to do. For the public who are unable to setup their own VPN, they will have to accept that everything they do is being monitored by a random internet company rather than their ISP now.

There can be some use for these services if you are very careful with everything you do while connected. But the risk of transmitting usernames, emails, passwords, and CC numbers accidentally while still connected is too great IMO.

Re: TunnelBear Publishes Security Audit

#37
post #21

Earlier quoted context omitted.

I still have issues with a VPN provider who insists on using their VPN client.

Are there any nice free VPN Clients out there? I haven't been very lucky in finding any in the OS X realm

Secure Pipes.

Re: TunnelBear Publishes Security Audit

#38

Never trust a 3rd party VPN for anything sensitive ever, period. Words of assurance and "security audits" are completely meaningless. HTTPS interception and forwarding is a trivial thing to do. For the public who are unable to setup their own VPN, they will have to accept that everything they do is being monitored by a random internet company rather than their ISP now. There can be some use for these services if you…

I'd rather give my internet traffic to a company that doesn't sell my info versus my ISP, which almost certainly would sell my info.

Re: TunnelBear Publishes Security Audit

#39
post #18

Earlier quoted context omitted.

The trouble with VPN providers is that even with reproducible client builds, it's much easier for them to intercept the traffic on their side. Plus there is a near-zero chance of detection, unlike on the client side where the binary can be decompiled.

I work for an ISP and believe deeply in online privacy. I've had the idea of offering up an as-private-as-I-can-make-it VPN service a few times, but I always end up at the same point: wondering how I could prove that the service wasn't doing anything malicious or nefarious -- "taps", Netflow data, etc. would all be easily available to me. What would it take to convince you that a VPN service was trustworthy?

I feel like people who complain about this are people who wouldn't be satisfied with anything unless they rolled it themselves. Of course, you could purchase your own server, use OpenVPN, etc. But anything that you haven't touched yourself is just one more thing that's potentially malicious.

Re: TunnelBear Publishes Security Audit

#40

Never trust a 3rd party VPN for anything sensitive ever, period. Words of assurance and "security audits" are completely meaningless. HTTPS interception and forwarding is a trivial thing to do. For the public who are unable to setup their own VPN, they will have to accept that everything they do is being monitored by a random internet company rather than their ISP now. There can be some use for these services if you…

If you aren't using their software, you will notice HTTPS intercepts. If your installing their client, they could slip a certificate into your chain, but someone would eventually notice.

I stick to openvpn providers and use my own software.

Post reply on HN