I only ever use a VPN to access region blocked content and the occasional "linux iso" torrent..I tried Mullvad first, but they just don't play the game of cat and mouse with the streaming providers and all their IPs are pretty much blocked. I have about a 95% success rate with NordVPN (except for Amazon Prime video which have some sort of wizardry and always are able to detect VPNs). It's a shame because Mullvad has…
But you can connect any machine to any vpn and have it be a tailscale exit node?
Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
451–456 of 456 posts
Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
#452Earlier quoted context omitted.
> If an attacker knows the WPA2 password, they can intercept traffic. Oh yes, of course, this is not unlike the capacity of computers in my LAN being able to see my packets, for example if my roommate was a hacker, they would be able to intercept packets while on their way to the router. Now an interesting thing I've seen in public networks like say Starbucks or McDonalds, they usually don't rely on WPA2 password def…
It's like your roommate being able to splice into your cable without touching it, which seems to me silly to allow, but basically yeah. WPA3 uses a better calculation where listening in doesn't tell you the key.
At least from a blue team perspective that's what I assume can happen. The power lines outside my home have the network cables all spliced together anyways, it's not like you'd have to make a new connection.
Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
#453Earlier quoted context omitted.
You don't need fully broken encryption to gain useful information. Knowing how much data is transferred, to which servers, and when (especially with details like how various endpoints will inadvertently chunk up HTTPS requests based on the details about the content or how interactive sessions will have certain back-and-forth transmit patterns) is sufficent to generate a traffic "fingerprint" which you can correlate t…
ip addresses are not encrypted, they are part of the header, not the body. The mailman needs to know the address.
Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
#454Earlier quoted context omitted.
> How are all Russians in Lithuania or Estonia responsible for the deeds of the Russian government? Or Russians in England? It's not about Russian people, you assumed that. There are well known connections between any company doing business in or with Russia who are basically extorted to hand over all information about customers or financials to the government. This is no secret. If any company is working from or wit…
> It's not about Russian people, you assumed that. I assumed that because it's what has been said. >> ... but they're lovely people that would 100% walk out if there were some real Russian ties involved. > If any company is working from or with Russian ties, you can assume the government will have access to that data. Given the sensitive nature of VPN's, antivirus software, deployed software in general, its completel…
We're talking business connections here not personal friendships. Russian businesses and business people are not to be trusted as Kremlin retains full control over them and Kremlin is an enemy of Lithuania. It's basic safety and risk assestment to not integrate compromised systems and every russian system is compromised. Same applies to any other actor but guess what, no other actor is threatening invasion of Lithuania so the math adds up here, no?
Re: Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
#455Earlier quoted context omitted.
Including the US right? And I don't mean in a conspiratorial sense. Just in the sense that they wouldn't deny it because it's their home country (Say Windows certs or Google certs), and at the very least they can issue warrants, gag orders, or triple letter agency bypasses. Now it only sounds weird when a country exherts their national sovereignity because the US doesn't need to perform any additional steps to instal…
> Including the US right? And I don't mean in a conspiratorial sense. Just in the sense that they wouldn't deny it because it's their home country (Say Windows certs or Google certs), and at the very least they can issue warrants, gag orders, or triple letter agency bypasses. Yeah. I don't think the US explicitly requires it but they don't have to, there are more than enough US-based entities with root certificates w…