Pornhub launches VPNhub, its own virtual private network app
venturebeat.com
venturebeat.com
So wait, as a UK citizen I can use Pornhub's VPN to circumvent the UK Government's "Porn Filter", a system that's run by..... Pornhub.
I believe there was some bureaucracy involved and maybe a "porn tax" you had to pay to disable the filter, but maybe this VPN service effectively solves both of those problems.
Sure, for the low, low price of $12/month.
Though I didn't actually RTFM, was posted elsewhere here.
So unlimited free use, but restricted speed and injected ads. Not horrible, but I'd definitely read the T&C very carefully, I didn't see any mention of what logs they keep.
This is separate from ISP supplied filters in that it applies to the porn companies themselves, not the end consumers. Obviously a company like Mind Geek having your ID and all your porn browsing history is not worrisome at all.
1: https://www.ispreview.co.uk/index.php/2018/03/age-verificati...
I had no idea that PornHub is in charge of filtering adult content for the UK government. Got any more info about this relationship?
> AgeID, has been developed by MindGeek, a company that also owns several pornographic websites including Pornhub, RedTube and YouPorn.
> AgeID currently uses official documents such as driver's licences and passports to verify a person's age - but submitting a mobile number tied to a contract phone could be another option.
> The tool is due to be implemented from April 2018 across all adult sites within the UK in accordance with The Digital Economy Act 2017 that was laid out by the government.
It will be regulated by the British Board of Film Classification (BBFC).
It looks like this:
rating RTA-5042-1996-1400-1577-RTA
and it can be sent via http headers, or embeded in web pages.Requiring people to register with PII is just asking for trouble.
It's such a weird area.
Edit, so after reading - the filter is less a filter, and more mandated age-check verification? Isn't that like claiming a guy checking ID's at the door to a pub is an alcohol filter?
It's a gigantic conflict of interest that plays out exactly how you'd expect. I've never been carded going to a bar near my former university.
Breweries and bars might be different too
It's not in the bars' financial interest to create a minimum drinking age via regulatory capture just so they can hire bouncers, or accept bribes or sell fake IDs or whatever. That's analogous to the insinuation I picked up upthread (if I read that comment correctly). Expecting industries to self-regulate until they show themselves incapable of doing so is pretty standard.
The law is a filter because of the obvious chilling effect: do you really want to risk an inevitable leak where your co-workers will potentially look up info about your porn habits tied to your real name?
Why would it have your 'habits' tied to it? It's meant to ensure you're over 18 or whatever age - what possible reason would it have to identify individual URLs a particular identity visited?
Money. Marketing. Targeted advertising. Etc, etc, etc. Pornhub (and others) are completely free and use more bandwidth than I can wrap my head around. How do you think they pay for that stuff?
Pornhub sells a subscription service with additional features / content.
Renting a porn vhs and having the guy photocopy and file your ID is a much bigger deterrant than just having to show your ID to the clerk.
The system was mandated by UK law. Mindgeek isn't the only provider that makes an age verification service, though they are the largest (since they own most of the largest pornographic brands on the web).
David Cameron was the one who pushed for the law that put all of this into effect; Pornhub isn't remotely responsible. They're just creating a verification service that they're now legally required to run to comply with the law.
/s
But if you hired someone you've given them a tremendous amount of responsibility and power, if you can't trust them to do their job without monitoring everything they do then you should just fire them and hire someone more trustworthy.
Trust but verify, as Reagan used to say. We give even more power to the presidents and senators, but imagine what would happen in there was not plenty of people around to monitor what they did with that power.
A year ago we've been bought by a big company to help them do what we did untill then but on a much bigger scale. The first thing we did was to get rid of the restricted internet. And now we again help our customers (big car manufacturers) to make their processes better. And even for here every developer has free access to the Internet to be able to work efficiently.
But as I said in the beginning, I'm really interested in the reasons for this behaviour of those large companies. My suspission is that it's just easier for the IT department to work against the developers instead of helping them to do their job.
The reason is that large firms are legally obligated to make sure that insiders aren't exfiltrating protected or confidential information.
If it makes people feel better about this, the same countermeasures also help with the case "Adversary pops any laptop in the company via e.g. phishing or malware and then pivots to All The Things." i.e. you don't need to posit non-trust of employees to want to implement continuous monitoring of work equipment.
Even assuming we don't care about worker privacy and all the stuff, I think we can still do better.
I have no insider information about this (not a Google employee and definitely not associated with the project) but I read some good things about BeyondCorp
https://news.ycombinator.com/item?id=14596613
Regardless of the threat model, "security" has be practical. The main thing business should care about is productivity. I've done subversion checkouts that slow down to a crawl because the malware detection hogs down the disk IO. I've seen "anti-theft" agent go haywire sending a heartbeat too often and making network access unusable.
I haven't had to deal with being denied access to stack overflow and frankly I would take the first offer and quit if I ever had to.
That being said, I think I am OK with random crap running on company owned machines as long as it is reasonable and does not hurt performance. Oh and there should be no expectation that I will take them home with me.
This reminds me of another funny story. One place I worked at, we were not allowed to leave our computers at our desk at the end of the day. We either had to put it in a locked cabinet or take it home with us. Nobody believes me when I tell this story but it is true.
And then there's the problem with allowing unrestricted, unmonitored Internet access with regards to auditing and establishing a timeline of events if you ever need to do so.
You can visit sites that aren't blacklisted on the company's network which makes it easier to social engineer you. You have less control over what stupid things your employees can do.
You're right, this wouldn't be any more dangerous than being on a coffee shop's wifi but you already don't care about network security if that's how you're working.
For PH it makes sense due to them already have infra to support it especially video streaming.
The challenge with privacy VPNs is a matter of trust.
I could imagine cryptocurrency potentially offering a solution to this which solves both issues of trust and economics, but it would be a challenge to guarantee its security.
It is not their infrastructure.
They appear to be using this white-label service according to code in the app (verified by looking at network traffic): https://wlvpn.com/
I'm also confused by why the gentleman in the ad was going to browse PornHub in a crowded coffee shop while waiting on his coffee.
For example, I use tor to access torrent sites that have been blocked by ISPs after high court orders in the UK. I have no interests in the privacy aspects of tor for that use. I just want to get around the filter.
And I care less about a Pornhub knowing what I watch - if anything ;) - than the Government, ISP, or anyone in a position of power. With browser/cookie fingerprinting PH probably already can id people reasonably accurately, VPN or not, if they wanted to.
It's not about anonymizing to PornHub, but about anonymizing to your ISP or AP.
Regarding the coffee shop thing: I was walking past a place some time back and I saw a woman staring thoughtfully at her laptop. She was sitting with her back to the wall. Behind her was a glass-covered painting, allowing me to see a reflection of her laptop screen. She was browsing porn. I guess it's not that uncommon.
It doesn't make you anonymous at all. It announces: "I'm using Pornhub".
> ge untapped market in eg Islamic countries
Do you have any evidence of that? What's an 'Islamic country'? Is every country that you've lumped together in this category the same in regard to this issue? Is Islam even one uniform religion?
> I guess it's not that uncommon.
That is not evidence of frequency except in that coffee shop at that moment. I have far more evidence: In all the time I've been in coffee shops, I've never observed it.
It is unclear why you are asking these questions in the first place. What is a "Christian country"? It's a country founded on predominately christian ideals. If you thought about it, I think you can come up with some countries that definitely fall under that category. Do something similar to come to a list of countries that are predominately Muslim. While they obviously will not have identical standpoints, there is at least one that springs to mind instantly when you think "banned pornography". No, it is not one uniform religion, but thankfully that also wasn't the point.
That is false, and it's important that VPN users are not mislead about it: Anyone with visibility into your network traffic, including your employer, your ISP, and government, knows exactly the address of the VPN you are using; they will know the address belongs to Pornhub's VPN. If you want to mitigate that risk (imperfectly), use Tor. And if you try to use both Tor and a VPN, make sure you know what you are doing or you could get it very wrong.
> What is a "Christian country"? It's a country founded on predominately christian ideals.
Most advanced countries actively eschew support of any specific religion, are overwhelmingly secular, and are founded on Enlightenment ideals such as individual liberty (including freedom of religion), limited government, and on reason and science as opposed to religion. This isn't the Middle Ages.
And certainly Christianity doesn't embrace pornography! I don't see religious leaders of any stripe advocating for it. Let's drop the absurd, hateful Christian nationalism - nationalism has a really bad track record, and is a convenient excuse to abuse and exclude others, including Muslims. For a religion founded on the compassion and love of the Gospels, it's ironic that the nationalists are the most judgmental, prejudiced, and abusive toward others - but the reality is that it's true of all nationalists.
> there is at least one that springs to mind instantly when you think "banned pornography".
I think of the UK, and almost every business' HR policy.
Unfortunately the vpnhub site appears to have been hammered into the ground as of time of posting.
However, I'm just as happy paying someone a nominal amount for convenience. It's the same reason I don't tend to spin up my own servers for basic web hosting - there are people who do that and who keep track of security updates affecting their specific systems, and for a small amount of money per month I don't have to worry about it.
Or did Algo use StrongSwan and now uses Wireguard?!
OpenVPN is its own protocol, using TLS as a control channel.
WireGuard is also its own protocol, based on Noise.
strongSwan has cryptography designed in the 1990s. OpenVPN relies on TLS, which for all intents and purposes is also 15-20 years old. WireGuard is modern, with a design that comes from Signal Protocol's cryptographer.
strongSwan and OpenVPN have gigantic C codebases. WireGuard's kernel implementation is just 4500 lines of carefully designed code.
You should use WireGuard if you can.
Thanks for the clarifications, by the way.
Either just blocking the IP or using DPI.
yes, at both the network level (by blocking IP ranges belonging to VPN services) and protocol level (ie. known handshake sequences for VPN software). but both can be easily bypassed with a few google searches.
>“It’s also developed by us, the leading adult entertainment platform in the world".