Live data from Hacker News

Who Owns, Operates, and Develops Your VPN Matters

opentech.fund

41–50 of 203 posts

Re: Who Owns, Operates, and Develops Your VPN Matters

#41
How realistic is possibility that some VPN providers use clients (computers of person who installed VPN) to just be able to crawl (or rent crawl infra) sites and make it look like regular residential traffic? (This is speculation i heard somewhere)

Like reverse VPN :) on one side makes client look like he's accessing internet from VPN exit location, and on the other end allowing for money someone to pretend that he's a residential client.

Re: Who Owns, Operates, and Develops Your VPN Matters

#42

Earlier quoted context omitted.

And shitposting here in germany has become slightly more dangerous. If you use a vpn to call your local politician an idiot, you are much less likely to get into legal trouble.

Here in the United States, I don't know that I could trust the vpn to protect me from that. I remember an incident from a few years ago, some idiot at Harvard emailed in a bomb threat to get out of finals. They arrested him only a few hours later. It's possible he misused the vpn, but I suspect that they merely contacted the vpn provider, got a shortlist of people going through that endpoint, and eliminated all of th…

[deleted]

Re: Who Owns, Operates, and Develops Your VPN Matters

#43
post #8

Earlier quoted context omitted.

Commercial VPNs do indeed vaguely promise to protect your data, access, etc. For those of us that are technical but unschooled, what resources would you recommend we learn from?

You can operate your own VPN (algovpn, openvpn, etc). There's low utility to doing so, but it's fairly straightforward these days. Or run Tailscale (and a self-hosted DERP relay).

> You can operate your own VPN

On what infra? Can you trust that one? Doesn't that solution just move the problem down one level?

Re: Who Owns, Operates, and Develops Your VPN Matters

#44
post #7

Commercial VPNs will go down as one of the greatest money-making schemes of the last decade. Outside of a few specific use cases their sales often rely on leveraging non-technical users' fear of what they don't fully understand. I have non-technical friends and relatives that have fully bought into this and when I asked why they use a VPN I got non-specific answers like "you need it for security", "to prevent identit…

Long ago, in the era of Firesheep and exploding prevalence of coffee-shop Wi-Fi, consumer VPN services were definitely valuable. But that was long ago. Now, HTTPS is the norm. The only use cases for consumer VPNs today seem to be (1) "pretend I'm in a different geography so I can stream that show I wanted to see" and (2) "torrent with slightly greater impunity". I live in Seattle and Mullvad VPN seems to have bought…

Also (3) work around overbroad restrictions on public Wi-Fi, which still sometimes do things like block Reddit or HN or SSH. But I guess more typical consumers than those of us here are less likely to experience those obstacles.

Re: Who Owns, Operates, and Develops Your VPN Matters

#45
post #33

MullvadVPN seem to be pretty decent at the moment, but it looks like they're laying down a worldwide VPN infrastructure of sorts that other VPN companies can rent (similar to phone networks) This makes me feel a little uneasy of their unstated longterm goals (corner the entire market), but I do think they are the most trustworthy out there right now

I think Mullvad's market share is still pretty low compared to NordVPN, which actually cornered the market thanks to their suspiciously large advertising budget.

Of the two im more suspicious that NordVPN is a CIA honeypot in the style of Crypto AG.

Re: Who Owns, Operates, and Develops Your VPN Matters

#46
post #7

Commercial VPNs will go down as one of the greatest money-making schemes of the last decade. Outside of a few specific use cases their sales often rely on leveraging non-technical users' fear of what they don't fully understand. I have non-technical friends and relatives that have fully bought into this and when I asked why they use a VPN I got non-specific answers like "you need it for security", "to prevent identit…

This is my feeling too. I also don't think these people realize how none of these groups can refuse a subpoena so the scenario of "the government coming after me," doesn't get addressed either. Worse, some of these are tied to foreign nation state intelligence, who are now analyzing your data when before they couldn't because they didnt have a relationship with your ISP. Domestically, I wouldnt be surprised if all of…

Many major VPN providers claim to keep no logs, and some have had third party audits supporting that claim. Subpeonas don't do anything if the company doesn't keep logs.

Re: Who Owns, Operates, and Develops Your VPN Matters

#47
i’m not sure what this list is, why investigate vpn companies yet dont even look at nordvpn, pia, express, or others that are wildly popular yet still shady af with their real world origins?

i mean, those companies are so popular they’re almost normie household names. the couple i looked at from the papers list have a small fraction of downloads compared to the above.

i agree that we absolutely need a deeper dive and a lot more transparency on who owns these companies but i’m curious why they chose to avoid the elephants in the room.

Re: Who Owns, Operates, and Develops Your VPN Matters

#48

Earlier quoted context omitted.

You can operate your own VPN (algovpn, openvpn, etc). There's low utility to doing so, but it's fairly straightforward these days. Or run Tailscale (and a self-hosted DERP relay).

> You can operate your own VPN On what infra? Can you trust that one? Doesn't that solution just move the problem down one level?

The answer is always "maybe" until you bring your threat model to the table.

I use a VPN to watch IPTV & download torrents without my ISP sending me nasty letters. Mullvad is great for that.

I would trust it in conjunction with Tor to protect me from low-level crimes. I wouldn't run trust either it or Tor, alone or in combination, to run a marketplace the DEA would become interested in.

If your threat model is obscuring your home IP to hide your IP from above board HTTPS sites, a DIY VPN probably is great. If it's to do low level crime, a cheap VPN is probably enough. Anything else, good luck.

Re: Who Owns, Operates, and Develops Your VPN Matters

#49
post #35
post #30

Earlier quoted context omitted.

Port forwarding is really easy with PIA's client. I had to switch to them because Mullvad doesn't offer port forwarding anymore unfortunately.

Damn! I was thinking about switching to Mullvad from PIA, but now I guess I won't.

Yeah, PIA is great. You can even use regular wireguard with it if you don't want to use their client. Been a happy use for many years

Re: Who Owns, Operates, and Develops Your VPN Matters

#50
Do people here trust their ISPs more than their VPN providers? That’s the question!

On the other hand, as far as privacy from the end point is concerned, users can be identified regardless of IP addresses. Visit fingerprint.com, you will get an identifier, then connect to a privacy VPN and change servers once in a while. The website will identify you, tell you are the same user visited last week from such location, and the number of times you visited.

Browsers (except Tor) send so much data that accurate identification is possible without IP address. And services could refuse to work if users don’t provide the required information, although that info could be randomized.

Post reply on HN