Live data from Hacker News

VPN Encryption

privateinternetaccess.com

41–46 of 46 posts

Re: VPN Encryption

#41
post #15

Earlier quoted context omitted.

nitpick: There is a native OpenVPN client for iOS in the AppStore. I don't know how they managed to, but it's plugging into the native iOS VPN functionality and it works perfectly well.

To my knowledge, there are 7 companies including OpenVPN who have been granted access to private VPN APIs. I personally use the OpenVPN iOS client for "always-on" phone VPN.

I see now. I didn't know there was a private API for App Store VPN clients. Cool, I will have to switch to using OpenVPN.

Re: VPN Encryption

#42
post #40
post #25

Earlier quoted context omitted.

Not necessarily. There's no need to break the encryption or have logs if the NSA can monitor all the traffic going in and out of the proxy server. They just have to correlate your incoming encrypted connection with the outgoing unencrypted data to remove the layer of anonymity. I'd frankly be a little surprised if they weren't doing this or something like it. I would guess that using PIA makes you less secure against…

> I would guess that using PIA makes you less secure against NSA snooping since it makes you more of a target and provides weak anonymity. So you're saying not using encryption and VPN services is a safer choice as regards Internet usage today? You seem to be going against the grain of most of what's been discussed around privacy & Internet surveillance on HN recently.

I wouldn't make a blanket statement like that. Depends what VPN and how you're using it and what you're doing on the internet and (in particular) what threat you're trying to protect yourself against. PIA will do a good job of protecting the contents of your messages from someone sniffing your wifi hotspot, but is useless against someone with the ability to monitor all internet traffic. The data leaving the PIA proxy is just as unencrypted as it would be if you weren't using a VPN, except your attempt to secure it will likely draw extra attention. There's strong evidence [1] that the NSA has special rules that allow enhanced collection and analysis of encrypted traffic.

[1] "...the NSA is allowed to hold onto communications solely because you use encryption." https://www.eff.org/deeplinks/2013/06/depth-review-new-nsa-d...

Re: VPN Encryption

#45
post #23

Earlier quoted context omitted.

Based on their sites, I believe they're UK-based company (and US endpoints are just endpoints, in case someone wants to have US-located exit to access US-only services), so it makes somehow reasonably harder (but not impossible) to correlate between the client and their traffic. Still, I don't see any significant difference between NSA and GHCQ, except that we have (thanks to Snowden) some details of former's operati…

We're still talking about PIA? Definitely US-based. From https://www.privateinternetaccess.com/pages/contact-us "Q: Where are you located? A: We are located in the US. Being in the US is optimal for VPN Privacy services since the US is one of the few countries that does not have a mandatory data retention policy. Countries in the EU are forced to log, even though some claim they do not."

IPredator: "There are no traffic logs, we do not look into your traffic."

http://www.wilderssecurity.com/showthread.php?t=331316 – "Sweden - Data retention law going into effect in May 2012, but (presumably) not applicable to VPNs"

Re: VPN Encryption

#46
post #18

Earlier quoted context omitted.

You still have to trust somebody to host your VPN endpoint. (Although, it's probably less risky to use some relatively obscure VPS/dedicated/colocation ISP than major VPN service which certainly attracts some attention of TLAs)

Fair point, but your personal VPN is also a lot less likely to attract scrutiny and be attractive to snooping than PIA. It's just a much bigger surface area, more popular, and potentially has a lot more useful data than your single box.

Also, public VPN services like PIA mix the traffic, i.e. multiple VPN users' traffic is coming from one IP address.
Post reply on HN