Live data from Hacker News

Mozilla VPN

blog.mozilla.org

91–100 of 531 posts

Re: Mozilla VPN

#91
post #37

Earlier quoted context omitted.

I use ProtonVPN. Same company as ProtonMail. Highly reputable with a business model around doing privacy and encryption well.

IMHO ProtonVPN (and Mail) are the perfect honeypots

ProtonVPN provides the source code for their desktop and mobile clients in their GitHub organization [1]. Yes open source != safe; however this level of transparency is at least a step in the right direction.

They also have regularly been audited by independent organizations that are openly available for the public to see their compliance [2][3][4][5][6].

Do you have any evidence to suggest that they are honeypots?

[1] https://github.com/ProtonVPN

[2] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...

[3] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...

[4] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...

[5] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...

[6] https://protonvpn.com/blog/open-source/

Re: Mozilla VPN

#92
post #81
post #22

Earlier quoted context omitted.

Ask yourself why you want a VPN. Is it to avoid your ISP collecting browsing data off you and selling it? Perhaps using 8.8.8.8 or 1.1.1.1 as your DNS might be good enough. Is it to watch geo region blocked videos? Then pretty much any service will work for you. Except that video streaming sites have caught on and blocked hosting provider IP blocks. So that might require you to shop around. Do you want the most priva…

Just FYI just setting your DNS to 8.8.8.8 or 1.1.1.1 may not do that much. Not only is DNS in plaintext, but some ISPs simply redirect all port 53 DNS requests to their own DNS. If you want privacy with your DNS, you should setup DoH using dnscrypt-proxy or perhaps DNS over TLS. Personally, I think a better strategy with this whole vpn aspect is to just setup a vpn with pis in various countries + pihole. At least tha…

T-Mobile US was definitely doing this at one point: silently rerouting popular third-party DNS services back to their servers

Re: Mozilla VPN

#93

What good is a VPN if you have to reveal all of your personally identifiable information to the vendor? You're better off using Mullvad directly--it looks like they don't require you to fork over personal information to use their service. Shameless plug: SatoshiVPN ( https://satoshivpn.com ) gives you access to your own private and anonymous VPN server with Outline pre-installed, no questions asked. Payments in Bitco…

Assuming Mozilla isn't compelled by law to share it's entire database of user information on a rolling basis without a warrant, I suspect (in the U.S.) it would be somewhat effective at shielding yourself from bulk metadata collection (government mass surveillance) of your online communications by obfuscating that metadata.

Compare this to your ISP and telecom providers. A subset of the larger providers willingly handed over the communication metadata of their users without warrant.

Re: Mozilla VPN

#94
post #22

Earlier quoted context omitted.

Ask yourself why you want a VPN. Is it to avoid your ISP collecting browsing data off you and selling it? Perhaps using 8.8.8.8 or 1.1.1.1 as your DNS might be good enough. Is it to watch geo region blocked videos? Then pretty much any service will work for you. Except that video streaming sites have caught on and blocked hosting provider IP blocks. So that might require you to shop around. Do you want the most priva…

> Is it to avoid your ISP collecting browsing data off you and selling it? Perhaps using 8.8.8.8 or 1.1.1.1 as your DNS might be good enough. Wouldn't your ISP still see what IP's you are visiting? Then, your ISP could just reverse DNS that IP to get the domain name, right?

Not necessarily, many sites are hosted on the same VPS, or the IP could just be one of 5000 CloudFlare servers serving up the page you requested.

Re: Mozilla VPN

#95
post #22

Earlier quoted context omitted.

Ask yourself why you want a VPN. Is it to avoid your ISP collecting browsing data off you and selling it? Perhaps using 8.8.8.8 or 1.1.1.1 as your DNS might be good enough. Is it to watch geo region blocked videos? Then pretty much any service will work for you. Except that video streaming sites have caught on and blocked hosting provider IP blocks. So that might require you to shop around. Do you want the most priva…

> Is it to avoid your ISP collecting browsing data off you and selling it? Perhaps using 8.8.8.8 or 1.1.1.1 as your DNS might be good enough. Wouldn't your ISP still see what IP's you are visiting? Then, your ISP could just reverse DNS that IP to get the domain name, right?

Maybe, but most ISPs are lazy/cheap and can't do a full-take packet capture of all customers data at the same time. The ones that I have seen usually have a custom or logging DNS server that associates each domain request with a customer account. So yes, in many cases, changing your DNS server is enough to avoid the larger DNS sniffing operations. You should also use an IP check query to make sure that you are really using the DNS server you think, and that you're not being DNATed back to your ISP's DNS server.

Re: Mozilla VPN

#96

> At Mozilla, we are working hard to build products to help you control of your privacy and stay safe online. > We know that we are on the right path to building a VPN that makes your online experience safer Commercial VPNs are good for censorship circumvention or location spoofing. It is irresponsible to market VPNs as something which “protects” you online. In reality, they do nothing to improve security, and very l…

I see this take a lot. Serious question: doesn't the U.S. government surveillance program focus on collecting communication metadata for U.S. citizens? While it isn't clear what that metadata includes, we do have examples of past programs that have leaked (and the legal theory used to justify them) to guide us. Given what we publicly know about these surveillance programs I could see FISC approving bulk metadata coll…

This is a good question and I would like to discuss it.

If the government is able to passively collect metadata from your ISP, couldn’t they do the same thing with a VPN company?

Re: Mozilla VPN

#97
When you connect to a VPN you advertise the fact that you are connected to a VPN to your local network, and hide your tunneled traffic. The tunneled traffic emerges elsewhere, with the extra encryption removed and proceeds as normal. Basically all a VPN provides is a mechanism to pretend that your butt is in a different seat. You hide your traffic from one network and expose it on another.

If you are on public wifi somewhere and are concerned about traffic that isn't otherwise encrypted (DNS comes to mind), or if your connection is in some way restricted (govt, shitty isp, etc), then a VPN can address these issues. But you have to keep in mind that your new network is similarly untrustworthy.

You might argue that by hiding behind your VPN provider, you are gaining anonymity. This might be true under the best circumstances, but this can _very_ easily break down. For example, the moment you load tracking_pixel.png then you are de-anonymized. That is saying nothing about the shady practices of the VPN providers themselves, or the governments that regulate them.

When people connect to a VPN, especially lay-people, there is this feeling that the VPN is providing security, and privacy. This is largely marketing BS designed to sell more subscriptions. When I connect to a VPN I might be able to obscure my activity from state actors, or avoid some coffee shops bogus DNS server. What I can't do with a VPN is avoid literally every other form of tracking. And of course if I connect to a VPN, then I should be ok with those same bad-actors knowing I am connecting to a VPN. And I should be OK with the VPN provider being able to monitor my unencrypted traffic. And I should be ok aggregating all of my encrypted traffic into one easy to watch place.

So what is a VPN providing the average consumer? If you want privacy install ad block software, https everywhere, enable DoH, don't log into social media sites, and clear your browser's cache frequently. If you want to avoid a state actor, then your best hope is probably something like Tor Browser.

Re: Mozilla VPN

#99
post #36
post #29

Earlier quoted context omitted.

>Want to do something illegal? Don't expect a VPN to save you. I'm not condoning piracy, but VPNs are generally a foolproof way to avoid DMCA letters from your ISP. Privacy means something different to every individual, everyone's threat model is different. And many models can benefit from a VPN; journalists, activists, and many others might find benefit from using a VPN.

Are DMCA letters still a thing? It seems like Torrenting died out significantly over the last 5 years.

I got one about a month ago (United States, the smallest of the three ISPs available in my area). My ISP had a screwy way of injecting the complaint, which I almost missed. I had to call them and actually request the complaint be sent by mail so I could see the details, which I don't understand why they didn't do in the first place... They actually served it to a guest in my house, who thankfully told me about it, so I could investigate.

Re: Mozilla VPN

#100
post #22

Earlier quoted context omitted.

Ask yourself why you want a VPN. Is it to avoid your ISP collecting browsing data off you and selling it? Perhaps using 8.8.8.8 or 1.1.1.1 as your DNS might be good enough. Is it to watch geo region blocked videos? Then pretty much any service will work for you. Except that video streaming sites have caught on and blocked hosting provider IP blocks. So that might require you to shop around. Do you want the most priva…

> Is it to avoid your ISP collecting browsing data off you and selling it? Perhaps using 8.8.8.8 or 1.1.1.1 as your DNS might be good enough. Wouldn't your ISP still see what IP's you are visiting? Then, your ISP could just reverse DNS that IP to get the domain name, right?

Most ISP's wouldn't care... and they shouldn't
Post reply on HN