Live data from Hacker News

ExpressVPN employees complain about ex-spy's top role at company

reuters.com

51–60 of 175 posts

Re: ExpressVPN employees complain about ex-spy's top role at company

#52
post #2

It's been clear for a long time that every single commercial VPN service is a waste of money. At best, you replace trusting your ISP with trusting a different group of unknown people with similar motivations. At worst, it's a government agency honeypot or someone like Facebook. If you think you want a VPN for "privacy", use Tor Browser. If you want a VPN for any other reason that "normal people" think they want a VPN…

> If you think you want a VPN for "privacy", use Tor Browser

so replace a vpn, which might be logging your traffic, for a service which absolutely is logging your traffic?

Tor is an anonymity service, not a privacy service.

Re: ExpressVPN employees complain about ex-spy's top role at company

#53
post #35
post #2

It's been clear for a long time that every single commercial VPN service is a waste of money. At best, you replace trusting your ISP with trusting a different group of unknown people with similar motivations. At worst, it's a government agency honeypot or someone like Facebook. If you think you want a VPN for "privacy", use Tor Browser. If you want a VPN for any other reason that "normal people" think they want a VPN…

Honest question: it's still a consensus that they do have value in situations such as airport Wi-Fi, correct? Separately from that, I still do wonder whether, if you subscribe to a VPN that has well-examined security practices and whose reputation depends on such practices, whether it still may have value over relying on the security over a local ISP which may not have as much expertise or reputation investment with…

> Honest question: it's still a consensus that they do have value in situations such as airport Wi-Fi, correct?

No. I don't think this was ever a consensus. When is the last time you've used a (sensitive) website that is not run over HTTPS? Unless the CAs (or the certs) are compromised, you have no reason to use a VPN when on public Wi-Fi, because it is encrypted with this so-called "military grade encryption" that VPN providers love to mention.

Edit: forgot to add, if the CAs or the certs are compromised, VPNs won't help anyway.

Re: ExpressVPN employees complain about ex-spy's top role at company

#54
post #46
post #18

Earlier quoted context omitted.

Browser fingerprinting works much better than checking IPs. With multiple devices being behind the same IP, it's necessary to distinguish between users. I'm not saying VPNs are worthless - I'm on one right now for work. Commercial VPNs, for most people who purchase them, are completely worthless. And I very much doubt that tunneling your connection through a VPN can improve ping.

> And I very much doubt that tunneling your connection through a VPN can improve ping. Surprisingly this can be the case as long as the combined link to VPN + target is better than the direct link to target. Keep in mind that the target might be geo distributed. Like driving, going over 2 highways might be fasted than going over a direct dirt road, or a longer road might be faster because the direct road is congested…

One case where I saw this was a friend who for some reason was being routed to game servers around the world when trying to connect to an Overwatch game, and a much closer server with the VPN.

Was this a bug in Overwatch? Almost certainly, but the VPN was an effective workaround.

Re: ExpressVPN employees complain about ex-spy's top role at company

#55
post #46
post #18

Earlier quoted context omitted.

Browser fingerprinting works much better than checking IPs. With multiple devices being behind the same IP, it's necessary to distinguish between users. I'm not saying VPNs are worthless - I'm on one right now for work. Commercial VPNs, for most people who purchase them, are completely worthless. And I very much doubt that tunneling your connection through a VPN can improve ping.

> And I very much doubt that tunneling your connection through a VPN can improve ping. Surprisingly this can be the case as long as the combined link to VPN + target is better than the direct link to target. Keep in mind that the target might be geo distributed. Like driving, going over 2 highways might be fasted than going over a direct dirt road, or a longer road might be faster because the direct road is congested…

> Surprisingly this can be the case as long as the combined link to VPN + target is better than the direct link to target

Is that surprising? I think that's what you would expect, and it's what the above commenter is suggesting (quite reasonably IMO) is very unlikely.

I think the issue is that you're implying the road to the target is a dirt road, but the road to the VPN is a highway, which seems a bit questionable.

Re: ExpressVPN employees complain about ex-spy's top role at company

#56
post #14

Earlier quoted context omitted.

idk mullvad seems pretty alright

It is - they know their market and they serve them well. One of the few VPNs that actually don't log traffic. That said, I've had websites flat-out refuse me because of using Mullvad (not just because it's a VPN, but a supposedly "disreputable" VPN). Meaning blackhats love it. Meaning it works.

> One of the few VPNs that actually don't log traffic.

How can one be so certain that this is the case? The only thing that's for sure is the claim they do not keep any evidence. I don't have anything against this VPN, it's really just an inherent trust problem with any provider. You take their word for it and be smart/ethical enough not to have any sketchy activity when you use it because there's a pretty good chance logs are being kept.

I don't mean to make this personal to you but it's weird seeing a tech-literate crowd like HN act naive when it comes to VPN usage, based on arguments like "oh X is shady you should use Y instead, it's 100% private!".

My point being, don't expect that doing extremely dumb shit online means any service, no matter how reputable, that may aid you do so will have your back.

Re: ExpressVPN employees complain about ex-spy's top role at company

#57
post #46
post #18

Earlier quoted context omitted.

Browser fingerprinting works much better than checking IPs. With multiple devices being behind the same IP, it's necessary to distinguish between users. I'm not saying VPNs are worthless - I'm on one right now for work. Commercial VPNs, for most people who purchase them, are completely worthless. And I very much doubt that tunneling your connection through a VPN can improve ping.

> And I very much doubt that tunneling your connection through a VPN can improve ping. Surprisingly this can be the case as long as the combined link to VPN + target is better than the direct link to target. Keep in mind that the target might be geo distributed. Like driving, going over 2 highways might be fasted than going over a direct dirt road, or a longer road might be faster because the direct road is congested…

Most of the time the end user equipment is the bottleneck rather than the internet backbone

Re: ExpressVPN employees complain about ex-spy's top role at company

#58

For any company, ask why they'd actually care about doing the right thing. Is it reputation? Integrity? Is the reasoning purely financial? Then ask whether the company operates in a way that suggests they'd do the profitable thing over the right thing if they think they might get away with it. Does that picture look realistic? As an example, look at Apple. Leaving the tangential discussion about scanning iCloud photo…

I have never in my life met anyone that has an iPhone or a Mac because Apple is processing everything on the device itself. People have iPhone and macs for 2 reasons. iMessage and because Apple is a premium brand that even that richest of richest people use. The money Apple would lose if they started mining your data like Facebook would be indistinguishable from random noise.

They're not at the level of Facebook and Google, but they still mine your data. You've gained nothing.

Re: ExpressVPN employees complain about ex-spy's top role at company

#59
post #18

Earlier quoted context omitted.

It's far from a waste of money. They help with things such as skipping geoblocking, able to deceive ISPs that send mail warning users about pirated content, can in some cases help with gaming ping, allow users to trick sites that rely on IP logging and many other applications besides cybersecurity and privacy. The main issue is that they all seem to advertise themselves as these privacy and cybersecurity services fir…

Browser fingerprinting works much better than checking IPs. With multiple devices being behind the same IP, it's necessary to distinguish between users. I'm not saying VPNs are worthless - I'm on one right now for work. Commercial VPNs, for most people who purchase them, are completely worthless. And I very much doubt that tunneling your connection through a VPN can improve ping.

Browser fingerprinting does not work for geofencing. Browser fingerprinting and IP geotags work, but fingerprinting just tells you if a user is the same person, on a different IP address. I run a website to monitor bot traffic, and really all something like a Picasso fingerprint can get you is visibility into who's spoofing their IP.

You get a hash value that's roughly unique to the browser-device configuration. You don't know from that hash where the user is located. You have to pair the hash up with geolocation services to get that info. Once you do that though, you get a decent idea of if the person is changing their IP, but there's still no way to tell what the 'real' IP is. You just end up with a unique ID that's associated with a handful of different IP addresses.

Re: ExpressVPN employees complain about ex-spy's top role at company

#60
post #35
post #2

It's been clear for a long time that every single commercial VPN service is a waste of money. At best, you replace trusting your ISP with trusting a different group of unknown people with similar motivations. At worst, it's a government agency honeypot or someone like Facebook. If you think you want a VPN for "privacy", use Tor Browser. If you want a VPN for any other reason that "normal people" think they want a VPN…

Honest question: it's still a consensus that they do have value in situations such as airport Wi-Fi, correct? Separately from that, I still do wonder whether, if you subscribe to a VPN that has well-examined security practices and whose reputation depends on such practices, whether it still may have value over relying on the security over a local ISP which may not have as much expertise or reputation investment with…

Argument is the spice of life! An argument doesn't have to be angry. But nonetheless I appreciate your earnest kindness.

It's less of an issue when every site you connect to uses https, and every app you use employs ssl/tls for its connections. That is common practice these days. Getting man-in-the-middle'd on airport Wi-Fi is less feasible these days than it was 10 years ago. The attacker would have to also install a certificate on the user's device. I welcome corrections if I'm wrong.

VPNs aren't obligated to tell you the truth. They don't have to have good security or even honor what they say on the front page. People trust marketing, not actual policy or actions - just look at Apple. Still waiting on "HMA" VPN to go out of business because they handed over users to the FBI. They're still around and claim No Logs just like everyone else, just like ProtonMail did until this month.

https://arstechnica.com/information-technology/2021/09/priva... https://hacker10.com/internet-anonymity/hma-vpn-user-arreste... https://www.theregister.com/2011/09/26/hidemyass_lulzsec_con...

Post reply on HN