Live data from Hacker News

Who Owns, Operates, and Develops Your VPN Matters

opentech.fund

81–90 of 203 posts

Re: Who Owns, Operates, and Develops Your VPN Matters

#81
post #7

Commercial VPNs will go down as one of the greatest money-making schemes of the last decade. Outside of a few specific use cases their sales often rely on leveraging non-technical users' fear of what they don't fully understand. I have non-technical friends and relatives that have fully bought into this and when I asked why they use a VPN I got non-specific answers like "you need it for security", "to prevent identit…

Most non-technical people I know that have VPNs simply have it for streaming media from platforms that geo-restrict. It's a cat and mouse game as the provider bans servers/providers.

Re: Who Owns, Operates, and Develops Your VPN Matters

#83
post #45
post #33

Earlier quoted context omitted.

I think Mullvad's market share is still pretty low compared to NordVPN, which actually cornered the market thanks to their suspiciously large advertising budget.

Of the two im more suspicious that NordVPN is a CIA honeypot in the style of Crypto AG.

I also think this is the scandal waiting to emerge in this space; with what we know from Snowden/CryptoAG/Encrypted message app sting operations etc it is borderline impossible for me to believe not one of the major players is owned by a State level intelligence service.

Re: Who Owns, Operates, and Develops Your VPN Matters

#84
post #7

Commercial VPNs will go down as one of the greatest money-making schemes of the last decade. Outside of a few specific use cases their sales often rely on leveraging non-technical users' fear of what they don't fully understand. I have non-technical friends and relatives that have fully bought into this and when I asked why they use a VPN I got non-specific answers like "you need it for security", "to prevent identit…

I pay to route my traffic through a barely known intermediary to obscure its origin. It all depends on your threat model for that traffic. If the traffic itself is not sensitive (or already encrypted) but you want to obscure the origin from the destination, or the destination from your ISP, it works.

Re: Who Owns, Operates, and Develops Your VPN Matters

#85
post #50

Do people here trust their ISPs more than their VPN providers? That’s the question! On the other hand, as far as privacy from the end point is concerned, users can be identified regardless of IP addresses. Visit fingerprint.com, you will get an identifier, then connect to a privacy VPN and change servers once in a while. The website will identify you, tell you are the same user visited last week from such location, a…

I do trust my ISP more than any foreign VPN service providers because I have the option to take my ISP to court if they violate my rights. I stopped caring about anonymity on political subjects when I realised not being anonymous made me more civil online, and more mindful of what I want to talk about. (Ofcourse, I can think like this because I have the privilege of living a democracy).

If you lived in a place like Germany or the UK, you could get arrested for posting online that you don't like what Israel is doing in Gaza or that you think Elon Musk is a Nazi (among other things you could get arrested for saying). In this case, routing your traffic through an unknown intermediary makes sense.

You said you have to be mindful of what you say and how you say it, in order to comply with the law. In other words, your legitimate speech is being chilled. Why do you think that's okay?

Re: Who Owns, Operates, and Develops Your VPN Matters

#86
post #35

Earlier quoted context omitted.

Damn! I was thinking about switching to Mullvad from PIA, but now I guess I won't.

Yeah, PIA is great. You can even use regular wireguard with it if you don't want to use their client. Been a happy use for many years

Being able to use wg-quick to create a tunnel is also something mullvad supports, just fyi

Re: Who Owns, Operates, and Develops Your VPN Matters

#87

How realistic is possibility that some VPN providers use clients (computers of person who installed VPN) to just be able to crawl (or rent crawl infra) sites and make it look like regular residential traffic? (This is speculation i heard somewhere) Like reverse VPN :) on one side makes client look like he's accessing internet from VPN exit location, and on the other end allowing for money someone to pretend that he's…

There are also apps that purport to pay you up to a dollar a gigabyte (no joke) for proxying traffic.

And it's not even illegal, not even shady. I see nothing wrong with getting paid to help big companies compete with/destroy each other.

As a bonus you help rid the world of Cloudflare. Cloudflare serves more captchas to ISPs with more proxies. When every ISP is captcha'd, every user will hate Cloudflare.

It's not a get rich quick scheme - there's low demand for proxying at that kind of price.

I'm not going to shill specific companies, so just Google 'get paid to share mobile data' or something.

Re: Who Owns, Operates, and Develops Your VPN Matters

#88

I use tailscale with an exit node. I just need location control. Wireguard gives me that.

Wireguard doesn't give you exit nodes, it's just the encrypted L3 stack.

Whomever is responsible for your exit nodes actually gives you this functionality.

If it's tailscale itself then they use mullvad nodes as exit nodes which I welcome very much.

Re: Who Owns, Operates, and Develops Your VPN Matters

#89

Earlier quoted context omitted.

And shitposting here in germany has become slightly more dangerous. If you use a vpn to call your local politician an idiot, you are much less likely to get into legal trouble.

Here in the United States, I don't know that I could trust the vpn to protect me from that. I remember an incident from a few years ago, some idiot at Harvard emailed in a bomb threat to get out of finals. They arrested him only a few hours later. It's possible he misused the vpn, but I suspect that they merely contacted the vpn provider, got a shortlist of people going through that endpoint, and eliminated all of th…

Yeah, it's not gonna help you for that but for low level "crime" (and those "" do some heavy lifting) where the police basically asks providers for logs once and than give up you are fine with any of the more "trustworthy" (and those "" do some heavy lifting) vpn providers.

Correlation attacks are a bitch and i'm sure i'm on a shortlist already but calling a politician an idiot with a burner account made using a vpn should be fine.

Re: Who Owns, Operates, and Develops Your VPN Matters

#90

Earlier quoted context omitted.

I remember that, Schneier talked about it on his blog. It was actually tor (the threat came from tor), and harvard 'found' him by constantly logging what connections were going to known tor entries from on campus. As it turns out he was one or possibly the only one using tor that morning from harvard. Bruce outlines it that he certainly could have stayed tight-lipped (all evidence was circumstantial) but, nevertheles…

Network traffic analysis/DPI strikes again. I wonder how many people think that their VPN usage obscures their identity, when the flow of traffic at certain times gives X% probability that this person visited the site based on the timing/size/speed/length of each TCP stream, increasing in confidence every repeated visit. Hell, how often will someone download a file of exactly 7060378032 bytes? It may not be damning e…

> I'm looking forward to when VPNs always throw up chaff traffic.

Mullvads DAITA (Defense Against AI-guided Traffic Analysis) is going into that direction[0] and Mullvad is one of the better providers. Tor also has some protections against this afaik and the upcoming nym vpn is also doing some traffic obfuscation [1]. But as the saying goes: Correlation Attacks are a bitch.

[0] https://mullvad.net/de/vpn/daita [1] https://nym.com/

Post reply on HN