Live data from Hacker News

Who Owns, Operates, and Develops Your VPN Matters

opentech.fund

91–100 of 203 posts

Re: Who Owns, Operates, and Develops Your VPN Matters

#91
post #7

Commercial VPNs will go down as one of the greatest money-making schemes of the last decade. Outside of a few specific use cases their sales often rely on leveraging non-technical users' fear of what they don't fully understand. I have non-technical friends and relatives that have fully bought into this and when I asked why they use a VPN I got non-specific answers like "you need it for security", "to prevent identit…

Long ago, in the era of Firesheep and exploding prevalence of coffee-shop Wi-Fi, consumer VPN services were definitely valuable. But that was long ago. Now, HTTPS is the norm. The only use cases for consumer VPNs today seem to be (1) "pretend I'm in a different geography so I can stream that show I wanted to see" and (2) "torrent with slightly greater impunity". I live in Seattle and Mullvad VPN seems to have bought…

That assumes that the user isn't connecting to a hotspot he doesn't know is compromised.

Re: Who Owns, Operates, and Develops Your VPN Matters

#92
post #50

Do people here trust their ISPs more than their VPN providers? That’s the question! On the other hand, as far as privacy from the end point is concerned, users can be identified regardless of IP addresses. Visit fingerprint.com, you will get an identifier, then connect to a privacy VPN and change servers once in a while. The website will identify you, tell you are the same user visited last week from such location, a…

Damn, I thought incognito at least did some obfuscation.

https://coveryourtracks.eff.org

I had no idea about "Canvas fingerprinting" or that my browser tells sites how many CPUs I have installed.

Re: Who Owns, Operates, and Develops Your VPN Matters

#93
post #33

MullvadVPN seem to be pretty decent at the moment, but it looks like they're laying down a worldwide VPN infrastructure of sorts that other VPN companies can rent (similar to phone networks) This makes me feel a little uneasy of their unstated longterm goals (corner the entire market), but I do think they are the most trustworthy out there right now

I think Mullvad's market share is still pretty low compared to NordVPN, which actually cornered the market thanks to their suspiciously large advertising budget.

and egregious marketing material. I think they're the ones who pushed the whole "its about security". I remember Tom Scott turning them down a lot because they wanted him to say that for the $$$ and he refused. Eventually I think they backed down and he got paid and did an ad for them without saying how it "improves security".

Re: Who Owns, Operates, and Develops Your VPN Matters

#94
post #83
post #45

Earlier quoted context omitted.

Of the two im more suspicious that NordVPN is a CIA honeypot in the style of Crypto AG.

I also think this is the scandal waiting to emerge in this space; with what we know from Snowden/CryptoAG/Encrypted message app sting operations etc it is borderline impossible for me to believe not one of the major players is owned by a State level intelligence service.

they probably learned from past and this time it will not be publicly known. so that's another option

Re: Who Owns, Operates, and Develops Your VPN Matters

#95
post #46

Earlier quoted context omitted.

This is my feeling too. I also don't think these people realize how none of these groups can refuse a subpoena so the scenario of "the government coming after me," doesn't get addressed either. Worse, some of these are tied to foreign nation state intelligence, who are now analyzing your data when before they couldn't because they didnt have a relationship with your ISP. Domestically, I wouldnt be surprised if all of…

Many major VPN providers claim to keep no logs, and some have had third party audits supporting that claim. Subpeonas don't do anything if the company doesn't keep logs.

[deleted]

Re: Who Owns, Operates, and Develops Your VPN Matters

#96
post #87

How realistic is possibility that some VPN providers use clients (computers of person who installed VPN) to just be able to crawl (or rent crawl infra) sites and make it look like regular residential traffic? (This is speculation i heard somewhere) Like reverse VPN :) on one side makes client look like he's accessing internet from VPN exit location, and on the other end allowing for money someone to pretend that he's…

There are also apps that purport to pay you up to a dollar a gigabyte (no joke) for proxying traffic. And it's not even illegal, not even shady. I see nothing wrong with getting paid to help big companies compete with/destroy each other. As a bonus you help rid the world of Cloudflare. Cloudflare serves more captchas to ISPs with more proxies. When every ISP is captcha'd, every user will hate Cloudflare. It's not a g…

any examples about this? really interesting

Re: Who Owns, Operates, and Develops Your VPN Matters

#98

Earlier quoted context omitted.

Long ago, in the era of Firesheep and exploding prevalence of coffee-shop Wi-Fi, consumer VPN services were definitely valuable. But that was long ago. Now, HTTPS is the norm. The only use cases for consumer VPNs today seem to be (1) "pretend I'm in a different geography so I can stream that show I wanted to see" and (2) "torrent with slightly greater impunity". I live in Seattle and Mullvad VPN seems to have bought…

What about a malicious DNS (on a public spoofed or hacked WiFi) that forwards you to a lookalike domain? Unfortunately many times public WiFi doesn’t work with Google’s or Cloudflare’s DNS servers (I think the Deutsche Bahn’s WiFi was such a case, if I remember correctly, but I know I came across a few on the last few years while traveling). I don’t think there’s anything protecting against that when you’re using a b…

HSTS solves this to some extent. If you've visited the domain in the past (or the site operator submitted to the HSTS preload list), a different certificate presented would be flagged by your browser.

Re: Who Owns, Operates, and Develops Your VPN Matters

#100

Shameless plug: VP.NET [1] runs in a trusted execution environment (enclave) so you can verify it is doing what it is supposed to do and not anything else! [1] https://vp.net/l/en-US/blog/Don%27t-Trust-Verify

Shameless antiplug: It's owned by the guy who destroyed freenode and the other guy who stole $2.4 trillion in bitcoins a decade ago. I'm serious.
Post reply on HN