I've been a happy PIA subscriber since the Snowden controversy. However every time I see them becoming more popular (at least 4 of my friends have signed up with them in the past few weeks) and earnestly trying to make themselves more secure, I also realize that someone, somewhere within the NSA (and yes, other intelligence agencies around the world) is elevating them on a list of VPNs to break.
I've said this before, but PIA and other similar VPN providers are great security against most drive-by hackers. I am a happy customer for this reason. But if your threat model includes "NSA/CIA/FBI/DEA", you are going to have to spend more than $4 a month to remain secure.
VPN Encryption
31–40 of 46 posts
Re: VPN Encryption
#32I've been a happy PIA subscriber since the Snowden controversy. However every time I see them becoming more popular (at least 4 of my friends have signed up with them in the past few weeks) and earnestly trying to make themselves more secure, I also realize that someone, somewhere within the NSA (and yes, other intelligence agencies around the world) is elevating them on a list of VPNs to break.
I've said this before, but PIA and other similar VPN providers are great security against most drive-by hackers. I am a happy customer for this reason. But if your threat model includes "NSA/CIA/FBI/DEA", you are going to have to spend more than $4 a month to remain secure.
Re: VPN Encryption
#33FYI, this is the info page for our new (beta) OpenVPN based client which supports multiple encryption options: https://www.privateinternetaccess.com/forum/index.php?p=/dis...
I love PIA but I was too afraid to use it at Black Hat / DEFCON this year. If you use L2TP (required for iOS, handy for OS X because there is a native client) there is no certificate to prevent a MITM. Is there any way to address this? Can you use a certificate instead of a pre-shared key?
https://www.privateinternetaccess.com/forum/index.php?p=/dis...
Re: VPN Encryption
#34Earlier quoted context omitted.
I love PIA but I was too afraid to use it at Black Hat / DEFCON this year. If you use L2TP (required for iOS, handy for OS X because there is a native client) there is no certificate to prevent a MITM. Is there any way to address this? Can you use a certificate instead of a pre-shared key?
nitpick: There is a native OpenVPN client for iOS in the AppStore. I don't know how they managed to, but it's plugging into the native iOS VPN functionality and it works perfectly well.
Re: VPN Encryption
#35Earlier quoted context omitted.
I've said this before, but PIA and other similar VPN providers are great security against most drive-by hackers. I am a happy customer for this reason. But if your threat model includes "NSA/CIA/FBI/DEA", you are going to have to spend more than $4 a month to remain secure.
Yes. In fact, I'm not aware of a failsafe method to guard against digital surveillance at any price save not using computers.
Re: VPN Encryption
#36Earlier quoted context omitted.
Yes. In fact, I'm not aware of a failsafe method to guard against digital surveillance at any price save not using computers.
"Failsafe" is unnecessary. Come on, we call ourselves engineers here, right? A cardinal rule of engineering is to not let "perfect" get in the way of "good enough".
Re: VPN Encryption
#37Re: VPN Encryption
#38Earlier quoted context omitted.
Doesn't their business location in the US negate the need to be cracked?
They don't store any user logs (I have no reason to suspect they'd lie about that). So there's not much stored data to break. Which means the focus will be on breaking their traffic encryption protocols.
Re: VPN Encryption
#39I've been a happy PIA subscriber since the Snowden controversy. However every time I see them becoming more popular (at least 4 of my friends have signed up with them in the past few weeks) and earnestly trying to make themselves more secure, I also realize that someone, somewhere within the NSA (and yes, other intelligence agencies around the world) is elevating them on a list of VPNs to break.
I've said this before, but PIA and other similar VPN providers are great security against most drive-by hackers. I am a happy customer for this reason. But if your threat model includes "NSA/CIA/FBI/DEA", you are going to have to spend more than $4 a month to remain secure.
I think there are two vastly different threat model within that - (a) large-scale and indiscriminate vacuuming up of the average citizen's Internet usage data to fill up datacenters and do analytics, and (b) active targeting of a specific subject.
I'm hoping a VPN will insulate me against (a) too. But for (b), I don't think I stand much of a chance even if I spent $400 a month.
Re: VPN Encryption
#40Earlier quoted context omitted.
They don't store any user logs (I have no reason to suspect they'd lie about that). So there's not much stored data to break. Which means the focus will be on breaking their traffic encryption protocols.
Not necessarily. There's no need to break the encryption or have logs if the NSA can monitor all the traffic going in and out of the proxy server. They just have to correlate your incoming encrypted connection with the outgoing unencrypted data to remove the layer of anonymity. I'd frankly be a little surprised if they weren't doing this or something like it. I would guess that using PIA makes you less secure against…
So you're saying not using encryption and VPN services is a safer choice as regards Internet usage today? You seem to be going against the grain of most of what's been discussed around privacy & Internet surveillance on HN recently.