Private Internet Access Goes Open Source
privateinternetaccess.com
privateinternetaccess.com
2) PIA takes less than a minute to setup on every device. Download the app, login, and you pretty much never have to worry about it again.
Your alternative is more expensive, more resource-hungry, and more of a pain in the ass.
But like the other person said, if you value your time it is almost certainly not worth spending time on setting this up yourself, even if memory card corruption was not an issue.
The Swiss and Norwegian servers are blocked on almost no sites.
PIA state they don’t keep logs on their servers, they can’t provide those guarantees on the network as they don’t run the networks they operate on.
Plus colo and transit costs more than paying for a slice of resource someone else is already hosting, so there goes that price model.
Hey PIA, mind if I throw my little server in your datacenter? No you can't access it though. I promise it'll be properly secured! Hey! Why are you walking away?
I'm not sure what point you're making about colo and transit costs. Are you saying that operating your own has higher costs? Or that a commercial VPN provider has higher costs? I'd be very interested in a price analysis that beats PIA while offering a remotely similar security profile. Keeping an RPi at your house provides defense against totally different threats.
Do you have a source on this?
If a Raspberry Pi self-hosted VPN gets you what you need, great, but it doesn't do the same things as a large VPN service where your traffic is mixed in with all the other users exiting from the same server.
The Raspberry Pi provides neither of those, and requires occasional maintenance.
He listed the reasons where this is useful. And it definitely is useful for those reasons. Your list is unrelated.
Ideally you want to have both, if you move a lot of vpn traffic (cough cough, 4k HEVC torrented things), you can have your own openvpn setup on a KVM VPS you fully control with root, and also a commercial $3/mo openvpn service where you won't run into a 1 or 2TB/mo limitation.
here's the pricing for a fairly normal commercial openvpn service provider:
> For a Linux user, you can already build such a system yourself quite trivially by getting an FTP account, mounting it locally with curlftpfs, and then using SVN or CVS on the mounted filesystem.
For those saying that anyone setting this up at home doesn't value their time, my router has built-in support for OpenVPN in both server and client mode. The VPN connectivity and tunnel to PIA took me about 15 minutes to configure a couple of years ago and besides having to update the PIA password has required no real maintenance.
This suggestion assumes time has a cost of zero. Not to mention, some solid VPN services (Mullvad) can be had much less than $100/year.
That said, it could be a fun project regardless.
Isn't this inherent to the model of a paid VPN service? (Could one run a VPN through a blockchain?)
you joke, but if you trust intel/arm, you can conceivably run a provably trusted (via remote attestation) VPN on SGX/TrustZone.
You can encode any information you want on a blockchain, and it can be anonymous and specific to the user.
But it would be ///painfully/// slow.
I've yet to see an example verifiable safe server configuration, but some people have claimed that SGX might do. I'm pretty sure that wouldn't work with stock OpenVPN or StrongSWAN today.
Are there any other practices they could adopt that would ease your worries?
Also why do you trust your VPS provider over a VPN provider? They can inspect your VMs memory and do whatever else they want to the machine. Same with whoever owns the real estate that you co-locate your own physical servers.
They simply don't have the resources to log every single memory read/write and every network connection of all their hosts. Thus you would have to already be a known target for them to want to do that. Whereas a VPN provider has a limited scope of what they can log and thus needs a fraction of the resources to log everything.
There are probably logging systems already in place to detect abuse, that would be extended to detect VPN style usage on top of that.
In general, though, if a three letter agency wanted to spy on interesting web traffic, the traffic of people who "have something to hide", then targeting VPN servers would be more fruitful than the general Internet.
Things that have irked me so far about their service:
- That their applications were not open-source so far. Why even sponsor open-source, when clearly you don't care for it too much yourself.
- Google Analytics on their webpage. Literally a service supposed to protect your IP address and the first thing they do when you dare to even look at their service, is tell the biggest data broker on the planet about it. (This is a problem with most VPN providers.)
- The company behind it, London Trust Media Inc., operates from the USA, putting it into one of the least privacy-friendly and least predictable jurisdictions on the planet.
- Their privacy policy isn't bad, aside from the aforementioned Google Analytics and that they use your e-mail address for promotional mails, but it's not good either. If you're so great on privacy anyways, then use your privacy policy to legally bind yourself to your standards and provide your customers with a service that has at least any kind of insurance of what it promises.
As for the US jurisdiction, I couldn't care less, being from Europe.
And well, you should care for the US jurisdiction, whether you're from Europe or anywhere else on the globe. It means that the various three-letter agencies there probably have access to your internet traffic.
Privacy-wise, you are right. I have all my data in Google so the key parts are already there.
PIA is reliable and trustworthy.
Also, Rick Falkvinge! (Swedish founder of the original Pirate Party)
I'm assuming an error in the sentence above and it should say NOT before offer. Seems like a little proof-reading would have been worthwhile.
I waded into PIA's client enough, months back, to observe that it was using OpenVPN. Along with its reputation, I decided I had enough trust for my use -- avoiding connection monitoring/cracking on public WiFi and keeping Comcast and Verizon from data mining me.
I do sort of wait, with all these services, with breath half-held for some other shoe to drop. Given the rubber hose and lead pipe legal and extra-legal methods available to various and manifold "three letter agencies".
I hope the open-sourcing of the client leads not only to increased trust, but also to some functional improvements. Such as being able to leave PIA switched on on my phone while tethering to it. Without having to root the phone and get into routing scenarios that apparently Android is not designed to support. So, I guess that's an Android problem. But maybe there's some way to address it at the client level.
Anyway. PIA keeps taking substantive steps (e.g. prior financial support for open source projects, now open-sourcing the client, etc.) that put it in a good light.
P.S. I don't mean blocking by Netflix and the like. I mean, archive.is, Google (prove you're not a bot...), commercial services I use, etc., etc.).
Tragedy of the commons.
At my workplace - an e-commerce platform - we're flagging or blocking customers who use commercial VPNs.
The reason for this is simple: almost none of our legitimate customers use VPNs, but the vast majority of fraudsters do. Fraud is a massive issue for any e-commerce business and no other anti-fraud measure is as effective as this one.
Please make sure to report evidence of blocking to PIA support, they do have some solutions available. Worst case, it gives them evidence that it's time to rotate IPs.
At home, Comcast is my only option. Verizon is the sole national provider (U.S.) with service in some areas I travel to.
In addition to all of that, you are still funneling traffic through them AND they are still under US jurisdiction, regardless of the license they choose to use for their software.
The amount of trust required for their front-end applications is minimal to the point of non-existence.
The real trust you have to afford them lies with the company and what they do or don't do with your data.
Isn't that kind of weird for a privacy-focused company?
So, technically not the EU, but multiple EU countries.
The UK, France, and several other EU countries have passed internal surveillance laws that are as bad or worse than the US.
None of these countries have strong privacy protections except against corporations.
PIA has lots of gateways [1]. Some of them are outside the United States.
[1] https://www.privateinternetaccess.com/pages/how-it-works/
I'm talking about their website.
They weren't already?!
Come back when you've AGPL'd your server-side software. Then I'll believe you're committed to open source; and I'll trust you, because you'll be legally obliged to be honest about what's running on your servers.
It's not how it works. The copyright holder isn't obliged to follow AGPL (or any other FOSS license) terms.