How does this compare to TunnelBear [1]? - TunnelBear is a bit more expensive (4.99$/mo, paid annually vs 4$/mo). - TunnelBear supports up to 5 connections per account vs 2. I use TunnelBear regularly for my browser and phone. Both works great. My subscription is going to expire soon and I'll be open to try other VPN providers, not that there is anything wrong with TunnelBear. Any recommendations? This site [2] has f…
private internet access appears to be good, but I do not think they are very transparent about their operation.
ProtonVPN
41–50 of 205 posts
Re: ProtonVPN
#42Earlier quoted context omitted.
I found malware in the PIA installer. Not sure if it was planted by PIA themselves or I was subjected to a MITM attack, and so I would never use any bespoke VPN software again. Best just downloading the OpenVPN config files and plug them into something like Viscosity[0] (which I trust over the more bespoke VPN clients made by the VPN providers themselves). [0]: https://www.sparklabs.com/viscosity/
What so you mean "found malware?" You checked the installer and found that some aspect was malicious or some software you are running said it found malware? As the installer seems likely to cause false positives. You're still better using independent VPN clients, but I would not trust them at all if the installer actually has malware.
Just be careful with the bespoke VPN clients as they are very juicy targets for MITM attacks. I know I would be going after VPN software if I wanted to do ex-filtration for a small subset of users trying to hide their tracks from governments and ISPs.
[0] https://technet.microsoft.com/en-us/sysinternals/bb963902.as...
Re: ProtonVPN
#43I have mixed feelings about protonmail. On the one hand, they tend to be on the right side of political / legal issues, and this transparency report is nice: https://protonmail.com/blog/transparency-report/ On the other hand, they recently reduced the level of detail in the transparency report. There is also the fact that they are Swiss, and their privacy laws were severely weakened by a recent referendum. In particu…
So which will be that new country now, since apparently Swizterland isn't that option anymore? And what if that new country does something similar? Then next? And then? I don't think there will be many countries left to go to in that case. Or any, after some time?
So, aren't user privacy and fight against surveillance running towards a wall which is the deadend?
Re: ProtonVPN
#44Earlier quoted context omitted.
I think it's prudent to assume (even if not accurate in every case) that any VPN provider that reaches PIA scale has already been compromised by the relevant State Actor working its jurisdiction. It's the tragedy of success in the privacy industry.
Except for the fact that PIA has been subpoenaed by the FBI and state police multiple times and PIA could give them dick all. Yes, their servers could be compromised illicitly, but if the NSA or GCHQ is willing to go to that much trouble just to monitor you, you have bigger problems.
Re: ProtonVPN
#45Earlier quoted context omitted.
private internet access appears to be good, but I do not think they are very transparent about their operation.
I found malware in the PIA installer. Not sure if it was planted by PIA themselves or I was subjected to a MITM attack, and so I would never use any bespoke VPN software again. Best just downloading the OpenVPN config files and plug them into something like Viscosity[0] (which I trust over the more bespoke VPN clients made by the VPN providers themselves). [0]: https://www.sparklabs.com/viscosity/
Re: ProtonVPN
#46Re: ProtonVPN
#47Earlier quoted context omitted.
Unless they've changed their policy in the last few months, TunnelBear won't let you use SSH over any port other than 22, so if you need to SSH into a server with a non-standard port you're out of luck.
Wait. Do you mean they actually inspect traffic and tear down the connection if they see an SSH handshake on any port other than tcp/22?
Re: ProtonVPN
#48Earlier quoted context omitted.
Except for the fact that PIA has been subpoenaed by the FBI and state police multiple times and PIA could give them dick all. Yes, their servers could be compromised illicitly, but if the NSA or GCHQ is willing to go to that much trouble just to monitor you, you have bigger problems.
They say theres nothing to give, but how do you really know for sure?
Re: ProtonVPN
#49Earlier quoted context omitted.
What so you mean "found malware?" You checked the installer and found that some aspect was malicious or some software you are running said it found malware? As the installer seems likely to cause false positives. You're still better using independent VPN clients, but I would not trust them at all if the installer actually has malware.
I spotted loads of malicious network traffic, and using the Sysinternals Autoruns[0] utility I was able to spot attempts at persistence. I also checked the outbound connections and they were C&C servers. I can't remember if the installer was digitally signed or not, but there was definitely malware in it. I always make sure to opt-out of any AD ware that might be bundled with an installer, but this seems to have been…
Care to provide anything substantial (e.g. net dumps or screenshots at least)?
> and they were C&C servers
How do you know that, have you MITMD your connection? Do you have anything besides generic spooky words?
Re: ProtonVPN
#50I would be interested in hearing what the security pros think about this..tptacek, grugq, dguido, idlewords. At this point, these are the guys I trust with security advice. Worth mentioning their VPN recommendations: algo by trailofbits and freedome. There is another paid service they recommend but I can't recall the name.