Live data from Hacker News

TunnelBear Publishes Security Audit

tunnelbear.com

51–60 of 61 posts

Re: TunnelBear Publishes Security Audit

#51

TunnelBear is a great product, one which I've been using for a few years, and I trust them with my business. I wish services like Netflix didn't blacklist their IPs, but it's easy enough to get content off alternative sites when I'm traveling outside the US. Thanks for the good work!

What do you do when you want to watch Netflix while traveling outside of the US?

Re: TunnelBear Publishes Security Audit

#52
The claims of transparency would be a bit more meaningful if they simply published their source code. It is hard to imagine anything too precious to disclose in the code.

Instead what we have is a pdf (4 pages long) with the title "TunnelBear Security Assessment Summary 07.2017" and an equally long web page claiming how awesome and transparent this is.

Re: TunnelBear Publishes Security Audit

#53

TunnelBear is a great product, one which I've been using for a few years, and I trust them with my business. I wish services like Netflix didn't blacklist their IPs, but it's easy enough to get content off alternative sites when I'm traveling outside the US. Thanks for the good work!

What do you do when you want to watch Netflix while traveling outside of the US?

I just used Cloak while in Poland a few weeks ago with HBO Go (don't think i watched in any netflix).

Re: TunnelBear Publishes Security Audit

#54
post #46

OFFTOPIC: Does anyone know whether TunnelBear will be available for Linux (or at least Firefox) one day?

https://www.tunnelbear.com/blog/linux_support/

Their Linux support is limited (ie no client), but it is there. You just need to do the configurations (somewhat) manually. Works pretty well when I used it a few months ago on my Mint box.

Re: TunnelBear Publishes Security Audit

#56
post #38

Earlier quoted context omitted.

I'd rather give my internet traffic to a company that doesn't sell my info versus my ISP, which almost certainly would sell my info.

A VPN provider is no different than ISP. Seriously. Both get paid and provide Internet connectivity. Both have incentives to do something to your traffic, would it have no negative consequences (financial, legal or just moral) for them. The only non-technical difference is that VPNs have a lot of competition (so free market actually works) and in some countries/areas telcos have near-monopolistic positions. That does…

Just because there are options doesn't mean there's competition n the free market sense. In order to have competition, the market requires complete information (or as complete as possible).

VPN providers are not competing on security as there is (as others have stated on this thread) no ability to validate their relative security claims. Many people are advocating for VPNs as a pure knee-jerk reaction to monitoring by traditional ISPs.

Re: TunnelBear Publishes Security Audit

#57
post #21

Earlier quoted context omitted.

I still have issues with a VPN provider who insists on using their VPN client.

Are there any nice free VPN Clients out there? I haven't been very lucky in finding any in the OS X realm

After macOS deprecated pptp I stumbled upon the flow vpn client[0]. Replace the hostname, enter your credentials and it just works!

[0]: https://www.flowvpn.com/download-mac/

Re: TunnelBear Publishes Security Audit

#58
post #21

Earlier quoted context omitted.

I still have issues with a VPN provider who insists on using their VPN client.

Are there any nice free VPN Clients out there? I haven't been very lucky in finding any in the OS X realm

Viscocity

https://www.sparklabs.com/viscosity/

Re: TunnelBear Publishes Security Audit

#60
post #18

Earlier quoted context omitted.

The trouble with VPN providers is that even with reproducible client builds, it's much easier for them to intercept the traffic on their side. Plus there is a near-zero chance of detection, unlike on the client side where the binary can be decompiled.

I work for an ISP and believe deeply in online privacy. I've had the idea of offering up an as-private-as-I-can-make-it VPN service a few times, but I always end up at the same point: wondering how I could prove that the service wasn't doing anything malicious or nefarious -- "taps", Netflow data, etc. would all be easily available to me. What would it take to convince you that a VPN service was trustworthy?

Random audits from trusted third-parties would be a nice thing. Allow people to come in at any time and check the systems. Trust is better when distributed over multiple neutral parties.

In terms of features, allow clients to regularly change IP and don't log who is using what IP. Also mix client traffic with Tor exit nodes to add noise to the traffic.

Post reply on HN