Live data from Hacker News

Firefox partners with ProtonVPN

premium.firefox.com

81–90 of 129 posts

Re: Firefox partners with ProtonVPN

#81

Earlier quoted context omitted.

How can one subscribe to this?

By using a VPN :)

It's prolly me that I am dumb and don't get it but I am already a Proton VPN paid user. On top of that I have to pay $10? What the fucking fuck?

Re: Firefox partners with ProtonVPN

#82
post #29
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

Well, unsigned addons are banned in the branded release browser. If you use the developer edition, nightly or compile Firefox yourself then you can install unsigned addons into Firefox. The last option also enables you to turn of Pocket and a variety of other services.

That's exactly how it should be! The developer version isn't behind any barriers - it's trivially easy to find and install - and it keep the majority of people from installing some of the most malicious extensions.

Re: Firefox partners with ProtonVPN

#83
post #64

Earlier quoted context omitted.

> false allegations These are nothing but facts backed by sources anyone can verify by himself.

Why is there an article about Hola in there?

To show that Luminati Networks, which sued Tesonet for patent infringements, has publicly admitted using HolaVPN as a residential proxy network for data mining operations.

Re: Firefox partners with ProtonVPN

#84

when considering different VPN services based on privacy criteria, this site is helpful: https://thatoneprivacysite.net/vpn-comparison-chart/ for example, i can see the ProtonVPN is hosted in Switzerland, and that Switzerland cooperates with Five-Eyes countries (according to Privacy International) by sharing intelligence information regarding citizens of Five-Eyes countries (including the US). this is a relatively mi…

That being said, you don't need to provide your real identity to sign up; in fact, you're encouraged not to. So, it's a lot harder to identify a particular user.

Switzerland has _extremely_ good banking privacy laws so they can't be required to disclose credit card details, so that's an identifying link not available to Five-Eyes. Plus, you can pay in BTC.

I'm not sure about what's required for a company in Switzerland to be compelled to share information with Five-Eyes but I expect they would have to be ordered to by the Federal government; a hard feat given how privacy friendly they are, and how the Cantonal government of Geneva have additional privacy laws.

Re: Firefox partners with ProtonVPN

#85

There are multiple extensions and VPN products out there (some better and some worse), so why are they choosing who wins or loses here. I know it is because of $, but I hate the direction they have been taking lately.

That money has to come from somewhere; I'd happily pay for Firefox but most people wouldn't and it's not cheap developing a browser.

Their outreach, web literacy, and STEM education work is also not cheap and is doing amazing work.

It would be nice for them to list two or three VPNs they've audited though. Their endorsement goes a long way for many people and we would still have a choice then.

Re: Firefox partners with ProtonVPN

#86
post #28

I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town…

I fully understand. If you can't trust Proton then you don't _actually_ benefit from anything. If it helps however, ProtonVPN is by the people behind ProtonMail, the security-first email provider. They started in CERN as a mission to provide email to scientists that wouldn't be subject to censorship. Their entire business - email and VPN both - embodies the same philosophy that Mozilla does. It's rare that I trust an…

> Their entire business - email and VPN both - embodies the same philosophy that Mozilla does.

ProtonMail doesn't report security vulnerabilities to the users, when researchers discover them[1]. It has also publicly boasted about hacking a phishing site, when claimed the journalist's report was based on "unsubstantiated rumors"[2]. I really hope that it has nothing to do with the philosophy Mozilla embodies.

[1] https://www.theregister.co.uk/2014/07/07/protonmail_fail_jav...

[2] https://motherboard.vice.com/en_us/article/qvvke7/email-prov...

Re: Firefox partners with ProtonVPN

#87
post #16

I only use firefox. But I don't feel like I can strongly recommend it because of the long list of bad decisions. - Google analytics baked into about:addons - Sending data to Cliqz - Pocket, as a service being added to the topbar - Pocket, as a service being added to the default home/newtab page - Firefox hello - Completely banning unsigned addons - Mr. Robot advert - And now probably this I want a browser that is rel…

I would add: - Public search for sources of other people's breached personal data via monitor.firefox.com (eg, you can enter anyone's email and see results, and not just your own, as there's no verification that you own the email until you sign up for continuous alerting) That said, I love Firefox itself and think Mozilla usually try to do the right thing. Someone just lost the security vs usability debate there I gu…

Isn't that just what haveibeenpwned does? In fact, I wouldn't be surprised if monitor.firefox were using hibp internally.

Re: Firefox partners with ProtonVPN

#88
post #76
post #67

Earlier quoted context omitted.

The modern aversion to "lesser of two evils" is a thinly-disguised post-hoc rationalization for apathy (or worse, nihilism). It's not even false equivalence, because that would suggest trying to paint both "evils" as equal; no, this is simply saying that, when presented with two choices where one is better than the other, we might as well make the worse choice, because who cares?

Disagreed. You should personally should choose the lesser of two evils when those are your only choices. Promoting the lesser evil is not such an easy call though. From a practical standpoint, promoting an evil, even if it's a lesser evil, has the potential for harming your own reputation as a reliable source. It is also fundamentally morally questionable, of course what is morally right and wrong is a matter of much…

Alternatively, you can lobby for a different choice, or pressure the 'lesser evil' to improve themselves. Rarely do folks bother to do this though after they've made their choice.

Re: Firefox partners with ProtonVPN

#89
post #55

Earlier quoted context omitted.

First question: yes, they provide a virtual private network between you and the service endpoint. Second question: no, it's not a general-purpose VPN. It's purely for cloaking traffic to and from anywhere on the internet.

Is there a service that can do the second?

Typically if you're trying to provide VPN access to your own private network, you would run your own VPN server on that network.

Re: Firefox partners with ProtonVPN

#90
post #49
post #41

Earlier quoted context omitted.

So if I understand correctly, you would want to know the details of how Mozilla audited ProtonVPN, is that it?

Everyone in Vilnius, Lithuania knows, that both, NordVPN and ProtonVPN, are being developed here by the people related to Tesonet, which has been recently sued in Texas Eastern District Court for the patent infringement in "Large-scale web data extraction products and services with residential proxy network ( https://oxylabs.io/ )"[1] by Luminati Networks, an Israeli data mining company behind HolaVPN[2]. The section…

1 only shows Tesonet being sued and does not prove that both Nord and Proton services are being developed by Tesonet people, and even if they were Tesonet-adjacent people, further proof would be needed to link these services directly to Tesonet the entity. 2 is contingent on 1.

3 and 4 are the only things I can see with any weight to them, yet they were brought up by a competitor (red flag), and vague enough not to be considered "evidence".

5 and 6 prove absolutely nothing. Both of these products use OpenVPN, which is what the vulnerability was in.

The vulnerability has nothing to do with Tesonet and I have not seen proof otherwise. Presumably other VPN services that also use OpenVPN could have encountered the same vulnerabilities. What makes you think that both having the same bug, because they use the same open-source system, is any kind of "proof"?

It's interesting how one can seem to provide a huge body of quotes and evidence for something- yet the majority of it easily deflates when viewed directly. We're gonna need more than this, much more. I'm not willing to 100% disbelieve you or dismiss your concerns outright- but if you're trying to convince people, this is a pretty weak effort.

You've made these claims before, you say ProtonMail's response is inadequate- could you elaborate on why? I thought it was relatively thorough and convincing, but am willing to see any holes poked in it

Post reply on HN