Live data from Hacker News

Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

windscribe.com

331–340 of 456 posts

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#331

Earlier quoted context omitted.

what makes your vpn verifiable? can i verify you run specific oss on your servers? secure enclave is just management's idea of implementing crypto. everyone out here knows that it is highly flawed and intel with their management engine bullshit can't be trusted at all.

You might find this helpful: https://youtu.be/sz7NAe0G1_Y?si=focPEWli8xv7NCDi Re verifiability: the point isn’t trust us, it’s that you don’t have to. We built it so anyone can independently confirm what’s running. 1. All server and client code is published. 2. Builds are reproducible. 3. Each node provides cryptographic attestations of its runtime and routing identity. 4. Enclaves are used for verifiable isolation.…

It looks like this boils down to 'check the magic number in the code against the magic number our server gives you. It matches!!!'

Is there some indication the user has that your server isn't simply hard coded to return the right magic number? I don't understand how this provides any assurance of anything.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#332

Earlier quoted context omitted.

Proton explains this here: https://redlib.catsarch.com/r/ProtonVPN/comments/8ww4h2/prot... I suppose you're free not to believe them, but I'm unsure what exactly you believe is happening here and what exactly Proton is lying about. Tesonet secretly owns them and has been running a decades-long misinformation campaign to trick you into thinking they don't? To what end? It's not like Tesonet is some nefarious company w…

[flagged]

>You're devoting a lot of emotional energy

You're on the Internet. How are you surprised that someone is repeatedly responding in a thread about a very obscure topic, especially when people are posting conspiracy theories?

It's interesting to have these discussions. But it is funny that people's conspiratorial thinking now makes me a part of the conspiracy merely for pointing out easily verifiable facts.

>What is your relationship to either company?

I subscribe to Proton's services, so I was originally interested in finding out what actually happened. Now I'm interested in pointing out people's flawed reasoning because I think Proton is doing something valuable, and I don't want these attacks against them to go unanswered.

Since we're now part of this thread, as the attack on Proton was orchestrated initially by a competitor and seemed to use bot accounts on Twitter, how much do they pay you to try to discredit me?

Just kidding, see above. You and I, we are the same. We do it because it is interesting.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#333

Earlier quoted context omitted.

Back when I was running PIA, they threatened me a significant amount just for pointing these facts out. Now that I launched a verifiable VPN, they are once again sending legal threats [1]. [1] https://vp.net/l/en-US/blog/Verified-Privacy-vs-Trust

The same PIA which is now part of Kape Technologies which under its former name of Crossrider was known for malware? https://cyberinsider.com/private-internet-access-kape-crossr...

If you cant trust VPNs sold to dodgy Israeli spyware firms who can you trust?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#334
I only ever use a VPN to access region blocked content and the occasional "linux iso" torrent..I tried Mullvad first, but they just don't play the game of cat and mouse with the streaming providers and all their IPs are pretty much blocked. I have about a 95% success rate with NordVPN (except for Amazon Prime video which have some sort of wizardry and always are able to detect VPNs).

It's a shame because Mullvad has a deal with Tailscale where you can sign up for Mullvad through Tailscale and use any of their servers as a Tailscale exit node. It's super slick and nice since Tailscale has really decent apps for nearly everything (even Apple TV, etc) and I already have a decently sized Tailnet of all my devices / ssh accessible things.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#335

Earlier quoted context omitted.

Proton explains this here: https://redlib.catsarch.com/r/ProtonVPN/comments/8ww4h2/prot... I suppose you're free not to believe them, but I'm unsure what exactly you believe is happening here and what exactly Proton is lying about. Tesonet secretly owns them and has been running a decades-long misinformation campaign to trick you into thinking they don't? To what end? It's not like Tesonet is some nefarious company w…

My comment still applies regardless of any level of “explaining” [1]: 1. Either Nord/Teso are loose with keys (horrible) Or 2. Proton isn’t being truthful. I don’t think it’s a conspiracy or anything that it is Tesonet/Nord. Rather, the problem is you cannot trust someone with your privacy if they can’t even manage their own keys. [1] The explanation is poor at best and doesn’t explain why they worked so hard to try…

The people who couldn't handle their keys were at Nord. The people you trust are at Proton.

> worked so hard to try to delete all of the evidence

The cert is still there. Apparently, they didn't work nearly hard enough.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#336

I only ever use a VPN to access region blocked content and the occasional "linux iso" torrent..I tried Mullvad first, but they just don't play the game of cat and mouse with the streaming providers and all their IPs are pretty much blocked. I have about a 95% success rate with NordVPN (except for Amazon Prime video which have some sort of wizardry and always are able to detect VPNs). It's a shame because Mullvad has…

But you can connect any machine to any vpn and have it be a tailscale exit node?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#338

Earlier quoted context omitted.

You might find this helpful: https://youtu.be/sz7NAe0G1_Y?si=focPEWli8xv7NCDi Re verifiability: the point isn’t trust us, it’s that you don’t have to. We built it so anyone can independently confirm what’s running. 1. All server and client code is published. 2. Builds are reproducible. 3. Each node provides cryptographic attestations of its runtime and routing identity. 4. Enclaves are used for verifiable isolation.…

It looks like this boils down to 'check the magic number in the code against the magic number our server gives you. It matches!!!' Is there some indication the user has that your server isn't simply hard coded to return the right magic number? I don't understand how this provides any assurance of anything.

The SGX certificate is signed by intel and includes a certification of the hash of the code loaded in the secure enclave ("MRENCLAVE").

When the client connects to the server, the server presents a tls certificate that includes an attestation (with OID 1.3.6.1.4.1.311.105.1) which certifies a number of things:

- the TLS certificate's own public key (to make sure the connection is secure) - The enclave hash

It is signed by Intel with a chain of custody going to intel's CA root. It's not "just a magic number" but "a magic number certified by Intel", of course it's up to you to choose to trust Intel or not, but it goes a much longer way than any other VPN.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#339

At this point, the VPN industry is so rife with shady dealings, suspicious ownership structures, weird exits, questionable marketing/PR practices/pushes, and rumours that waters have been muddied sufficiently for every provider out there. It might have been by design as well. Who knows. I now believe that you know your use case and use VPN only for that, and decide whether you really need to pay with parts of your ki…

Not saying that this is what I do, but a VPN is useful for things that are illegal but not serious.

For example, France is spying torrent downloads of copyrighted content but they only look at the domestic consumer ISP IP addresses. They ignore all foreign IPs, so if you're using a VPN it doesn't matter if the VPN keeps all the logs they won't bother.

Of course if you're doing things that will get you personally targeted by the police, like cyber-bullying or CSAM, a VPN won't protect you.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#340

Glad to see more zero trust confidential computing happening....but keep in mind its still vulnerable to attacks like Battering RAM which can fully breaks cutting-edge Intel SGX and AMD SEV-SNP confidential computing processor security technologies.

Battering RAM has been demonstrated to work well against Intel's "Scalable SGX" which is also known as SGX 2, and uses static encryption key to allow SGX to use more of the system's memory.

For example at VP.NET we're using SGX 1, which uses AES-CTR for memory encryption which is not susceptible to memory reply attack, and comes with a limit of 512MB of ram. It's a lot of pain working with a very small memory allocation (especially nowadays where most machines come with 128GB+). batteringram.eu calls that "Client SGX" with a checkmark on "Read", but reading the actual paper it only mentions being able to know which areas of memory were written to (see 7.1). There might be applications where memory access pattern gives detail on the underlying work performed, but this is likely coarse (encryption is likely per page) and unlikely to yield to anything useful.

This said we are also exploring other TEEs including Intel TDX, and having a wider array of options will give us the ability to instantly disable any technology for which we know security has been compromised.

Post reply on HN