Show HN: Easily connect to a VPN in a country of your choice
github.com
github.com
Not disputing that it's the worst but it could be even more worse.
It's missing the key component: a curl | bash install and upgrade script running over HTTP (not HTTPS). In this case it'd be extra hilarious as upgrades would presumably go over your existing VPN connection which could then hijack the script and run arbitrary code on your machine.
curl http://pastie.org/pastes/10992864/download | bash
https://news.ycombinator.com/item?id=13454960
This code also writes remote-content to a file, and then passes that to openvpn. Scary stuff.
Seriously people - don't just randomly connect to VPNs: you're essentially bridging your computer / network to a completely untrusted network that's more than likely to have all manor of people doing nefarious / dangerous things on it - do you really want to put yourself at risk as well as be associated with them?
They can grab metadeta but this is already being done with all the traffic we generate anyway, one should assume.
Almost everything I do while on the move falls into this tamper-proof category. It's been a while since I stopped caring which Wi-Fi I connect to. I just borrow anyone's connection and tunnel right through.
Nearly all websites do not using pinning.
Anyway, while these may be valid attack vectors, since I started getting traffic injected by my ISP a few years ago, and DNS hijacked for advertising, my level of trust has dropped to the same as that of some $VPN, wherever, or $WIFI.
But that's just my opinion.
Sorry if I sound like a jerk but, I get tired of this dismissive as if it's excusable. I feel like people think tech savy people should hold everyone's hand and help them figure out how to use technology. No one is forcing them to use technology as far as I can tell.
https://blog.trailofbits.com/2016/12/12/meet-algo-the-vpn-th...
You still trust the cloud providers' upstream. In case of UK providers, the GCHQ sniffs upstream and ingress, so they can correlate traffic. Same for DE (BND, MAD) and basically all countries.
No, but you're making your traffic stick out and yourself a target for dragnet surveillance. The constant flow "packet in, other packet out" is easy to pick up for snoops, compared to "just packets out" from your home ISP.
What would I gain in ease-of-use, performance, or security by switching to Algo?
EDIT: Also, you should assume that any anonymous VPN service has a good chance of being spyware or even malware, so you should sandbox it in a virtual machine or similar.
Hola VPN turns 10M users into exit nodes (2 years ago)
https://news.ycombinator.com/item?id=9614993
Hola VPN Already Exploited by “Bad Guys”, Security Firm Says (2 years ago)
Why would someone do such a thing?
- You can get through the government's firewall to browse restricted web sites (e.g. YouTube).
- You can disguise your IP address to hide your identity while surfing the Internet.
- You can protect yourself by utilizing its strong encryption while using public Wi-Fi.
The list of servers (on the main url) gives throughput and others stats and you can support them by creating a node [1].They use SoftEther for VPN server - does someone have any experience with it?
[0] http://www.vpngate.net/en/about_overview.aspx [1] http://www.vpngate.net/en/join.aspx
It looks like a research project that was then unsuccessfully commercialized, and then released to the public somewhat hastily.
The code quality leaves a lot to be desired (there is nothing offensive, but it still does not inspire confidence for there not being security bugs), and the code style is not great either. The amount of marketing copytext is disproportionately large to the amount of code comments and design documentation.
It generally seems to go for a everything-but-the-kitchen-sink approach in terms of features (which is not a bad thing per se, but an approach that I dislike). The SoftEther repository is 280k lines of C and headers, while OpenVPN is 80k.
currently working providers can be usually found on /r/NetflixByProxy/
Country wouldn't be random in this case
Example: easyvpn -c JP
You can easily build your own IPsec VPN server using a one-liner [1], with support for both IPsec/L2TP and Cisco IPsec.
Disclosure: I am the author of this repo.