Live data from Hacker News

ProtonVPN

protonvpn.com

61–70 of 205 posts

Re: ProtonVPN

#61
post #17

I saw that they use OpenVPN protocol[1], then I stopped reading other things. Although the encrypted connections can not be decrypted, the OpenVPN protocol is easy to be detected and banned in some highly censored network. I recommends the shadowsocks protocol[2] which I used in the censored network, which is hard to be detected and decrypted. [1] https://protonvpn.com/secure-vpn [2] https://github.com/shadowsocks

> the OpenVPN protocol is easy to be detected and banned in some highly censored network.

Tunnelbear are one of the few VPN providers that use a thing called obfsproxy to circumvent this kind of censorship. They call it 'Ghostbear'[0] but really it's just an obfsproxy bundling which uses the domain fronting technique.

[0] https://help.tunnelbear.com/customer/en/portal/articles/2435...

[1] https://en.wikipedia.org/wiki/Domain_fronting

Re: ProtonVPN

#63
post #28

Earlier quoted context omitted.

Except for the fact that PIA has been subpoenaed by the FBI and state police multiple times and PIA could give them dick all. Yes, their servers could be compromised illicitly, but if the NSA or GCHQ is willing to go to that much trouble just to monitor you, you have bigger problems.

>[...] but if the NSA or GCHQ is willing to go to that much trouble just to monitor you, you have bigger problems. This type of argument contains the assumption that it would be too much trouble for them/not worth it to monitor an affluent anarchist or semi- anti-authortitarian with an above-average IQ. We've seen that A) their resources are as virtually unlimited as their paranoia B) tech developments have driven do…

It also embeds an assumption that someone is targeting you instead of people like you. Compromising the servers of a VPN provider makes plenty of sense in the service of full-take or person-of-interest collection.

We've already seen that the NSA actively targets people searching for privacy tools (e.g. Tails, Tor). The act of using a VPN is mildly interest-provoking, so it's far from crazy to suspect that someone might try to scrape everything happening there in case some of it is interesting.

Re: ProtonVPN

#64
post #25

How does this compare to TunnelBear [1]? - TunnelBear is a bit more expensive (4.99$/mo, paid annually vs 4$/mo). - TunnelBear supports up to 5 connections per account vs 2. I use TunnelBear regularly for my browser and phone. Both works great. My subscription is going to expire soon and I'll be open to try other VPN providers, not that there is anything wrong with TunnelBear. Any recommendations? This site [2] has f…

HN gets regular "what VPN should I use?" questions and my answer is always the same: Algo [1]. It is designed to be simple to set up, simple to tear down, and usable with numerous cloud providers or your own Linux server. [1] https://github.com/trailofbits/algo

I strongly agree with this, with the one caveat that right now algo doesn't provide seamless integrated support yet for a VPS provider that offers a flat bandwidth cap (like OVH or Scaleway) vs a high burstable data cap oriented offering like DigitalOcean. The flat bandwidth (generally 100 Mbps on the cheap plans) tends to come at the expense of burst/cpu/disk storage, but none of those matter in VPN vs reliability and not having to ever think about going over limits, even if you want to let family members for example use it. While for a lot of general projects I'd definitely agree with their current easy cloud choices, for this particular application, for most people, I think the likes of OVH or Scaleway or similar would be a far better fit, though I realize the major holdup is Ansible support. Of course, it can still be setup wherever, just without the same ease of use for someone only mildly technically oriented which is how it truly excels right now.

Still, I think it creams every general public offering. I agree with fictioncircle above that the "anonymity" thing is a total red herring. VPNs in this application are fundamentally about creating a hack to let individuals change their Internet access from a natural monopoly situation to a strongly competitive and customer oriented market situation via virtual end point shifting. That's "it", though it's a big deal. But "anonymity" is a far, far trickier problem, requiring not just extensive infosec but also significant opsec. At a bare minimum most people would need to use something like the Tor browser, not just for the "tor" part but for the hardening they put into the browser to make it somewhat harder to get tracked anyway regardless of IP address. I think a lot of the "anonymity" marketing claims some public VPNs make verge on not merely disingenuous but outright dangerous to the extent they can create a totally false sense of security.

Re: ProtonVPN

#65

Earlier quoted context omitted.

They say theres nothing to give, but how do you really know for sure?

If they have your data but won't give it to the authorities, the result is the same, isn't it? Unless you're suggesting the authorities aren't fooled, and will pry it out of them? That hasn't been the case so far.

They're asking how do you know they didn't hand the data over but just publicly say they didn't? Or that they agreed to give it to the FBI if the FBI would treat it as a confidential source.

Re: ProtonVPN

#66
post #31

Earlier quoted context omitted.

Another two I heard TheGrugq mention in one of his talks are Mullvad and PRQ https://www.mullvad.net https://prq.se/?intl=1

Those prices are… pricey! At least the ones at PRQ.

Yes but then they give you a tunnel with a static IP you can host things on, so it's not really comparable to proton VPN.

Re: ProtonVPN

#67
post #9

I have mixed feelings about protonmail. On the one hand, they tend to be on the right side of political / legal issues, and this transparency report is nice: https://protonmail.com/blog/transparency-report/ On the other hand, they recently reduced the level of detail in the transparency report. There is also the fact that they are Swiss, and their privacy laws were severely weakened by a recent referendum. In particu…

The Reddit discussion thread has a response indicating the BÜPF doesn't apply to their VPN service, with an official blog post upcoming:

https://www.reddit.com/r/ProtonMail/comments/6id4lw/protonvp...

Re: ProtonVPN

#68
post #3

Great that there's more options out there. Will there be an option to signup over TOR, and pay with ETH or BTC? I run free privacy/security classes for journalists, and some of them have said that their sources can't use paid VPNs because they're afraid of the purchase showing up on their credit card statement. TOR is great, but doesn't yet work for things like video chat (yes i tell them not to use Skype...)

What would be good for video chat?

Re: ProtonVPN

#69
post #56

Using public commercial VPN providers for serious security/privacy is a very bad idea. Get someone to set up Trail of Bits "Algo" for you (or do it yourself, if you're comfortable with Ansible).

Isn't one of the main benefits of VPNs sharing the IP with many other people?

Re: ProtonVPN

#70
post #33
post #25

Earlier quoted context omitted.

HN gets regular "what VPN should I use?" questions and my answer is always the same: Algo [1]. It is designed to be simple to set up, simple to tear down, and usable with numerous cloud providers or your own Linux server. [1] https://github.com/trailofbits/algo

In terms of privacy, doesn't it kind of let the cat out of the bag if you host your own VPN server? It's not your home address, but it's still just as much an address associated with you, isn't it?

Indeed it doesn't provide anonymity against the sites you visit - quite the opposite, it makes it even easier to correlate your browsing regardless of device/location.

But many (the undersigned for example) use VPNs for many other purposes:

Unencrypted WiFi (airport, hotel, etc)

Secure connectivity but provided by someone you aren't willing to trust (your employer?)

Fooling Geo-IP based restrictions (hello Netflix/BBC)

Not having your VoIP traffic mangled by a shitty carrier who's trying to extort protection money from you in the form of some "VoIP-optimized" expensive plan

Etc etc

Post reply on HN