Live data from Hacker News

Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

windscribe.com

361–370 of 456 posts

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#361

Earlier quoted context omitted.

You will have to be a lot more specific than "wasn't as good as", to get a response that is helpful to you. What are you looking for in a VPN provider?

I wanted to watch some football world cup highlights video from a japanese TV channel site, which didnt work with Proton, but did with Nord, so I have been with them since then. This was during the 2022 WC though, so maybe Proton is better nowadays.

I think they got better, I'm watching geofenced Japanese content all the time with Proton.

In the past I occasionally had to select a different server from whatever it picks by default but I've always been able to watch my content.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#362

We should really be moving towards a world of Multi-Party Relays rather than Single-Party VPN operators: https://www.privacyguides.org/articles/2024/11/17/where-are-... With Multi-Party Relays you no longer have a trust a single entity not being malicious or compromised. Disclaimer: I run obscura.net, which does exactly this with Mullvad (our partner) as the Exit Hop.

Hypothetically, could tor switch to using QUIC?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#363
post #6

Been saying it for YEARS: 95% of VPNs sell your data. It's where they make their money. It's absolutely insane the push-back I get when I say this online. I get downvoted to hell and back. Source: I bought this data from VPN companies... Hell, you can inject ads and surveys if you want!

Fun fact: I once interviewed for a company offering a free VPN, which was actually using other users as endpoints for the VPN. Some kind of P2P VPN if you will.

How did they make money? Easy: there were also selling a botnet! So if you used their "free VPN", you could be part of a botnet for DDOS or to create fake reviews/upvotes from thousands of "legit" IP addresses.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#364

Glad to see more zero trust confidential computing happening....but keep in mind its still vulnerable to attacks like Battering RAM which can fully breaks cutting-edge Intel SGX and AMD SEV-SNP confidential computing processor security technologies.

Battering RAM has been demonstrated to work well against Intel's "Scalable SGX" which is also known as SGX 2, and uses static encryption key to allow SGX to use more of the system's memory. For example at VP.NET we're using SGX 1, which uses AES-CTR for memory encryption which is not susceptible to memory reply attack, and comes with a limit of 512MB of ram. It's a lot of pain working with a very small memory allocat…

Intel TDX unfortunately suffers from the exact same vulnerability as Scalable SGX. The underlying root cause is the lack of randomized encryption; using a static-adversary encryption scheme (XTS) rather than a dynamic-adversary one. The result is that plaintext-ciphertext mappings are unchanged at a fixed memory address. While the choice of scheme might initially seem puzzling, it is due to a randomized encryption scheme requiring counters for each memory block, which has a prohibitive on-chip memory cost when scaling to hundreds of GBs of memory.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#365

Earlier quoted context omitted.

Those two are pretty big already to be honest. I guess a third one would be avoiding eavesdropping on public wi-fis.

With TLS being everywhere, and just few clicks away from having DNS over TLS, I really don't get eavesdropping on public wifi prop value.

Additionally, if ConsumerVPNs provide encryption, don't they provide encryption from the stretch between the consumer to the proxy? The stretch between the proxy to the destination would not have additional encryption, and there is no reason to believe that the second transit would be shorter.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#366

Earlier quoted context omitted.

Major issue I faced in this method is the network egress costs the cloud providers charge. I had to remind myself not to accidentally land on YouTube or some other video streaming sites. Are there any cloud providers who don’t charge for network egress?

> Major issue I faced in this method Biggest issue regular user might find with this is that basically all the VPS host' IP ranges are known, and plenty of websites give you a different (worse) experience compared to when using residential addresses, or straight up block you. Personally I found the hassle to great, compared to using existing VPN services.

Exact same experience here. In the 2010s I ran my own VPN exit node on a dirt cheap VPS so I could access streaming content in my country of birth. Worked great for years, but nowadays so many sites simply block non-residential IP ranges that I gave up ages ago now.

It's a shame because deploying WireGuard was a simple two command process: git checkout followed by a `docker compose up -d` for me etc on a fresh VPS instance.

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#367

Earlier quoted context omitted.

> I trust Mullvad more than I trust some random hotels WiFi For what exactly? All sites are HTTPS now anyway, so the only thing you're leaking is the hostnames / IPs you visit. I don't exactly see how the whole "hotel WIFI" thing is relevant at all, except as a dishonest marketing strategy by VPN salesmen

...and the IPs you connect from, which tend to correlate with where you live, work, and so on.

You connect to hotel WIFI from home and work?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#368

At this point, the VPN industry is so rife with shady dealings, suspicious ownership structures, weird exits, questionable marketing/PR practices/pushes, and rumours that waters have been muddied sufficiently for every provider out there. It might have been by design as well. Who knows. I now believe that you know your use case and use VPN only for that, and decide whether you really need to pay with parts of your ki…

A VPN is always a risk. Still, there is a difference between using Mulvad or PrivateInternetAccess. The difference between risking that the service might do bad things with your data, and having high certainty that it does. And this article gives pretty good indications which category each service belongs to

You’d put private internet access in the really bad category?

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#369

Earlier quoted context omitted.

With TLS being everywhere, and just few clicks away from having DNS over TLS, I really don't get eavesdropping on public wifi prop value.

1. example.com is not on the HSTS preload list 2. Because you normally visit example.com using an incognito window, your browser hasn't cached the redirect to SSL, or the address bar suggestion, and you haven't bookmarked the site. 3. You key in example.com, the browser connects over http, and the evil wifi MITMs your unencrypted connection - removing the redirect to SSL and messing with the page however the evildoer…

"Obviously a VPN provider can also do this, but you might hope they're less likely to."

So you have identified some marginal privacy issue, and have identified that a VPN doesn't solve it, but rather that it moves the risk to a third party actor you subjectively feel is better. Well I feel that, subjectively, introducing a third party generally decreases security.

I believe that not all privacy and security considerations can or should be solved technically, but rather we have extra-technical mechanisms like law and social norms that provide some protection on the edge cases. For example, an employee cannot lookup information for personal reasons on a system they are entrusted to in a professional capacity. I'm no expert, but you probably have first laws that prohibit that, second corporate policy that prohibits that, and thirdly social pressure that prohibits that to some extent. Are they perfect? Not necessarily which is why for the most part we rely on technical encryption and security mechanisms.

But at some point these examples become so contrived and the medicine becomes the poison, so you enter into territory that is pretty standard in other industries, what's to stop a waiter from spitting into a cup? There's no spit filter in place of McDonalds, there's other mechanisms protecting us.

On a similar note, logic and debate is not the only way to convey this phenomenon, so here's some more artistic retort to privacy schizophrenia.

https://www.youtube.com/watch?v=jf9I04Oa-hU

Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)

#370
VPNs will become illegal or backdoored, because privacy is becoming illegal.

This is not really a technology problem, it's a social and legislative one. Many of us are afraid of (other people's) privacy, so we vote for legislators that will make it illegal. The legislators stoke this fear of privacy because they want an excuse to deepen their control of discourse, and their own citizens.

So really, everybody wins!

Post reply on HN