VPN owners: 97 VPN products run by 23 companies
vpnpro.com
vpnpro.com
Thirdly, the companies who are funding this site through affiliate links, despite not being investigated in this article are arguably more worth of some serious suspicion. For example: NordVPN, one of their "Top VPN providers" is run by the same guy who runs a Lithuanian data harvesting company[2], but don't worry, lots of websites who make money from affiliate links to NordVPN (Sign up Now! 75% off when you use the code "SCAM" at checkout!)
Now, maybe I'm being cynical - but I suspect if NordVPN weren't lining the pockets of all these referral websites their reviews of NordVPN would involve a lot more of the faux concern they show about other VPN companies in this hit piece, rather than the credulous write-ups about how it's totally not a problem that this shifty Panamanian company has suspicious links to data harvesters.
[1]:https://www.fastcompany.com/3065928/sleepopolis-casper-blogg...
[2]:https://www.vpnmentor.com/blog/is-nordvpn-operated-by-tesone...
I just run my own VPN server on my cable internet. It allows all my roaming devices Pi-Hole access, and the same privacy as my cable internet.
The reality is that the customers of those products barely understand them and are buying into the BS of "stay anonymous" and "be private online". It's an easy market, especially considering you don't even need to develop the VPN software, just run instances on some cloud/VPS provider and do a ton of marketing.
The person doing the shilling is marketing himself as a "privacy & crypto expert" and having a masters degree in cybersecurity, reality is dude barely graduated high school. He actually works for a friend of his who runs a whole variety of these sites and is about to clear $10M+ this year alone.
What I've learned from this is that if you Google for some popular product, the first 5 pages are going to be SEO-optimized shilling sites. Just skip to page 10.
Is a less SEO-optimized site less likely to be a scam?
Isn't it? I thought Google was trying to optimize their search engine for finding useful information, so if someone were to make an honest website that just tries to provide useful information (anachronistic as that may seem) wouldn't they hypothetically have the full manpower of Google's search team optimizing for finding it?
Given:
P(shill) = P(!shill) = 0.5
P(optimized|shill) = 0.8
P(optimized|!shill) = 0.6
Then:
P(optimized) = P(shill) * P(optimized|shill) + P(!shill) * P(optimized|!shill) = 0.4 + 0.3 = 0.7
P(shill|optimized) = P(optimized|shill) * P(shill)/P(optimized) = 0.8 * 0.5/0.7 ≈ 0.57
P(shill|!optimized) = P(!optimized|shill) * P(shill)/P(!optimized) = 0.2 * 0.5/0.3 ≈ 0.33
I thought that was the running joke:
Q: Where's the best place to hide a body?
A: Page ten of Google.
But, joking aside, you can install greasemonkey/tampermonkey and get the googlemonkeyr script to manage your search results to be a bit more effective.
https://greasyfork.org/en/scripts/31607-googlemonkeyr-fix-ju...
This is a big problem with Google, today. Say I want to search for something - not to buy it - just some facts. The immediate first pages are all sites on how to buy, costs, online stores. I have to go to 8 or 9 to start seeing what I want.
This is today's Google.
Results not from top 1M (1K, 10K, 100K) sites: https://millionshort.com/
Even worse the VPN provider is usually operating from some country with much less regulation regarding privacy. If it were revealed that some ISP here in Germany is sniffing traffic and selling your data, shit would hit the fan, but if your trusty VPN provider from whoknowswhere does this, good luck going after them.
No, it isn't.
You don't have to use "bank-grade", "military-grade", etc. in your marketing. They don't actually mean anything, and only serve as a red flag for "we don't know what the fuck we're doing".
You can use almost-equally meaningless phrases like "state of the art", "industry standard", etc.
You can sell on a "proven track record" of not selling out to data brokers or yielding to government search warrants (although that mostly hinges on "never been subpoenaed" rather than "resisted a subpoena" in practical terms).
There's lots of other paths to take besides using "${DUMB}-grade" in your marketing copy. Saying "that's just how it goes" is yielding to a lazy cop-out with another lazier cop-out. It absolutely isn't just how it goes.
Nord also says they never hold logs, and locate in Panama to avoid gov't subpoenas. It's not either/or. You can (should) put the technical information on a 'security' page for the people who know enough to find it and read it.
> You live in the US, right? And you pirate stuff, right? Or maybe you Google things that would get you put on the TSA no-fly list? Well, with a VPN, it won’t be your US ISP that has access to your traffic—and then has to give it over to the MPAA and the NSA—but rather a VPN company from some foreign country, who has no such obligations. Sure, they can sell your data to anyone they like... but it’s not like the USGOV or the various media cartels are buying data. If they can’t compel it for free, they don’t bother (and they certainly couldn’t fully trust data sourced from a company headquartered in a non-allied country anyway, so why would they bother?) Someone somewhere might know about your VPN traffic, but it probably won’t be someone out to get you. Just someone out to sell you stuff.
Or, if you prefer:
> You live in Hong Kong, right? And you have some vocal opinions about Chinese sovereignty, right? Well, with a VPN, it’s not the Chinese government that sees your traffic, but rather....
So using a VPN comes down to the fair gamble that someone who promises not to log and use your data is possibly better than the guys who definitely log and use it.
It seems there are a lot of back and forth allegations about this topic on the internet. I don't know the truth. That article doesn't really demonstrate anything, though, and your tone seems unhelpful.
As a general rule of thumb, adjectives are often a crutch for weak arguments.
>"Shifty panamanian company"
But they explicitly chose to locate in Panama because it is exempt from 5 Eyes government data spying. That seems the opposite of shifty.
> "Suspicious links to data harvesters"
Have you ever used Google or Facebook? Run a service on GCP? If you run a service on GCP I could say you have "suspicious links to data harvesters." This seems like a scare tactic, lacking substance.
All I'm saying is that if you're predisposed to buy into the concerns this website is pushing about NordVPN's competitors, then you should absolutely have the exact same worries about NordVPN themselves.
1. Tunnelled & encrypted (and in most cases, easily identifiable as VPN) traffic coming from your VPN client to your server
2. Untunnelled traffic from your server to whatever server endpoint you're visiting.
Correlating the two, even when it's a massive multi-user service, is not difficult for a hosting provider with half a clue to do. Especially when handed a police order (which they usually have an obligation to not tell you about).
> I seriously doubt my hosting provider would jeopardize their business by snooping on ... a vpn given the breach of trust would cause large customers to ditch them.
Any half decent network provider logs sampled flow data by default. This is all that is needed to de-anonymise any vpn session. Even on a host that is shared by hundreds of VPN sessions.
Goals are to hide your traffic from ISP (1) and your real IP from internet (2). Self host VPN achieves (1) but not (2), your VPN's IP is yours truly.
Maybe I just can't always trust my ISP (ex: public wifi).
If I want to also hide my IP I can use Tor with or without a VPN.
Now NordVPN is trying to remove my reviews on my Youtube: https://youtu.be/gZdQx9iv_1U, and they've been caught blackmailing another VPN provider.
The site always rushes to NordVPN's defense when any bad news is going on, and there are several shills on Reddit trying to spread this article around.
Did you even read the article you linked? Nowhere in that article it says that NordVPN is ran by the same guy as data harvesting company. Also the same article you linked says in the end: "However, after thoroughly investigating this recent “scandal”, we still feel confident that NordVPN is still one of the safest VPNs around. It’s quite possible that its rapid growth and increasing popularity are part of the reason it’s being attacked by other VPN providers."
[1] https://i0.wp.com/vpnscam.com/wp-content/uploads/2018/08/201...
If you extrapolate a bit, apply some basic correlation twisting you can infer a lot of wrongful conclusion that is useful to specific agendas. We see this a lot in politics
Is it to imply that the named companies are closely associated with each other? ie/ Tesonet, NordVPN, HolaVPN, ProtonMail/ProtonVPN (and other named company I missed) are proven to have common interest and the common interest involve/include putting customers' privacy in danger?
There are multiple partnerships and ownerships in VPN and data mining industries that are not publicly admitted, unless something goes wrong[1][2].
Although the presence of these relationships alone is not always enough to claim that customers' privacy has been violated, it makes these companies look much less trustworthy in the long run.
[1] https://www.theverge.com/2015/5/29/8685251/hola-vpn-botnet-s...
[2] https://torrentfreak.com/images/Luminati-Networks-LTD-vs-UAB... [pdf]
Just checked out vpnscam.com for the first time, and its content scream in tinfoil hats giving me negative first impression.
It's really a dilemma to me: small providers haven't proven themselves to be trustworthy, while well established ones are connected to another business somewhat. How does one choose a reliable VPN provider?
And same goes with self hosted OpenVPN server, what's to say that the VPS provider will always put customers' interest first?
Learn to do it yourself. If privacy is your top priority, you can't trust any available VPN providers out there.
I think that's because this site is most likely run by some other competing VPN company. They are all trying to win by collecting and publishing everything about each other.
> It's really a dilemma to me: small providers haven't proven themselves to be trustworthy, while well established ones are connected to another business somewhat. How does one choose a reliable VPN provider?
I am personally more inclined to trust VPN providers that don't pay affiliate commissions, don't hide behind offshore companies, don't ask for their costumers' email addresses, state the full names of the people behind the company publicly, and adopt the most advanced open-source solutions early[1].
The other option is self-hosting Algo[2] on OVH or Hetzner.
Although it's not easy to find them on their site, I believe that the https://cure53.de/ vulnerability assessments are more interesting. Google "vpn site:cure53.de".
Glad I chose one of the better ones, their mission list, that they have a status page, that their servers are named after stars and my subjective opinion, that "AirVPN" is actually a bad name (a transparent privacy tunnel?), all pointed me towards believing there are actual nerds behind that one, and in this topic, I consider that very important...
Just a satisfied user. Its 2x what I used to pay, but IMO it's worth it. I don't think it's /always/ true "you get what you pay for", but sometimes it really is.
It is a bit mind boggling that folks are concerned about something and use a VPN...but choose a free one...
Sometimes when people talk about Tor, it reminds me of how people talked about Linux up until a couple years ago - often touting very out-dated impressions as if they were current observations. Tor bandwidth is very different than it was 5-10 years ago.
I just tried again, it took 6 seconds to open Orbot and completely connect to Tor. The rest was business as usual. Maybe a 1, 1.5 second delay getting to YouTube and for the video to start playback. For what Tor offers, that is impressive, and I don't know what could possibly be convincing beyond that point. Not to mention that one can just leave Orbot running as well. And since I'm on Android, I can opt to have specific app traffic sent through Tor, or Orbot can act as a system-wide VPN.
I'd make a video showing how painless it is, but setting it up, recording and uploading would take a hundredfold more time than just trying it out.
edit: I know that it's purely anecdotal, but I just enabled Orbot VPN mode and fired up "Speedtest". It is reporting 7Mbps and 3.65Mbps up. It's not great, but to me that is usable if your privacy needs outweigh need for speed. And a screenshot if it's of interest, you can see that it's in VPN mode and Orbot is running: https://i.imgur.com/UZu4aJs.png
edit2: yikes, I actually just backed up 29 full-resolution screenshots to my Google Photos account without even realizing Orbot was still connected. Convinces me!
(Tor exit nodes have been caught injecting malware into binaries downloaded over HTTP through them, for one possible problem if it isn't)
It's more accurate to say bad actors have been injecting malware into HTTP-downloaded binaries. Some of these bad actors use Tor exit nodes, some use free WiFi hotspots, and some run their own VPN services. Framing this as a Tor problem is like blaming violence on weapons instead of the perpetrators.
At least VPN providers need your money and their reputation and you can chain them for tor like privacy without the poor performance and anonymity.
Tor is obviously another option but I don't strictly speaking categorise that as a VPN.
This is absolutely not an apples to apples comparison, but why is it outrageous to believe there couldn't be a free VPN that focuses on privacy when there are search engines like Duckduckgo and browsers like Firefox that are completely free and are pro-privacy? I haven't done the research, so consider it a rhetorical question.
A VPN on the other hand consists of an application and usually unmetered usage of the company's bandwidth, which costs money.
Precisely. I imagine one of the more popular uses of VPNs is Bittorrent.
If Mozilla did, it probably would get the kind of attention and focus you’re suggesting. I just don’t see a lot of companies with a similar vision as Mozilla that are successful.
[0] https://blog.cloudflare.com/introducing-cloudflare-access/ [1] https://www.cloudflare.com/products/cloudflare-access/
Maybe just a wad of cash?
Considering their costs / questionable ownership / ability to just roll out repeated new "free vpns" that nobody knows who is behind or took the money for the other one?
[1] https://www.ivpn.net/knowledgebase/91/How-can-I-pay-with-cas...
If I mention "The Anarchist Cookbook" then I imagine every username on this page will be added to a GCHQ list, I'll probably have my internet traffic mined to establish if I downloaded it (which they arrest people for in the UK -- https://www.bbc.co.uk/news/uk-england-bristol-41802493). Presumably they have my online purchase history that relates to reagents, etc..
I also expect to be on lists for being critical of the establishment, doing online web security courses, buying remote connectable electronics, etc..
The difficulty I expect is profiling to reduce those lists to meaningful actions that have indicative value.
Brings back memories.
Jolly Rogers cookbook :)
> The Tor Project, a private non-profit that underpins the dark web and enjoys cult status among privacy activists, is almost 100% funded by the US government.
https://surveillancevalley.com/blog/fact-checking-the-tor-pr...
https://www.documentcloud.org/public/search/projectid:37206-...
https://events.linuxfoundation.org/wp-content/uploads/2017/1...
Too many times, the western collective is convinced of its own righteousness in regards to issues which factually were counter to its own survival.
The point is, even if the NSA did have key Linux devs on its roster, we don't have the tools - as the unwashed masses - to counter it. Besides which, the Linux kernel is hardly the right target - compilers, however, are...
For example, Twitter recently fired someone that was leaking information on dissidents to a foreign government.
To contribute to the Windows kernel you'd have to get someone hired by Microsoft, who presumably check their employment history (maybe), they have to actually go and work for Microsoft, etc. Obviously none of that is impossible but it's also obviously much harder than sending a patch to a mailing list.
And when I say generic, I mean ‘I recognise the Semantic UI React default error block’ generic.
I used their live chat support. “Is this normal,” I asked. “No,” I was told.
I tried again a day later. Same.
I tried them on Twitter. Nothing.
So, it seems that ExpressVPN have a good marketing budget and little else. I shan’t be bothering to try again.
you don't happen to work for any one of the competition do you? anyhow I have been very happy with them, their servers tend to be pretty fast. So add that positive anecdote to his negative anecdote, how useless.
(They also have no discretion-- no problems at all shilling Bang energy drinks to an audience of children...)
I wonder how many ran into trouble due to dubious anonymous traffic exiting their IP...
> dubious anonymous traffic
price of freedom from corps and govs.
The volunteer effort is laudable and quite refreshing but can a VPN relying on volunteers be ignorant of the risks those volunteers incur when they open their connection to anonymous traffic?
I understand that this is an issue that every VPN has to face but there should at least be some mention of how that particular VPN service handles law enforcement and abuse requests, or do they expect the volunteers to face the consequences?
Maybe I’m missing that point and it’s clarified somewhere?
I think that must be good then. I've been a happy PIA customer for about 5 years. They probably arn't the fastest (I get aprox 3.5mbit/sec on them) but so far none of the mud slung against them sticks.
There's a lot of shady shit in the VPN industry, so glad they are above it.
Hopefully that's not the case now.
however some sites refuse to do business with you if you are on a vpn (craigslist, BoA, etc) probably due to abuse from the same IP
That's kind of par for the course on a public VPN -- your traffic is being aggregated with a lot of other users, some of whom will be behaving in unusual ways.
Edit: I was being sarcastic. Thought it would be obvious.
1: https://vpnpro.com/blog/hidden-vpn-owners-unveiled-97-vpns-2...
https://thatoneprivacysite.net/vpn-comparison-chart/
I made bad experience with NordVPN based on reliability but they gave my my money back after 3 months with no questions asked.
Astrill is good but pricey. Astill will work in countries that try to block VPNs. CON: Astrill leaks DNS like a mother...er. I can get it under controll with ufw
ufw default deny outgoing && ufw allow out on tun0 && ufw allow out on tun0 to [IP of your DNS] port 53
You may want to use Softether instead of OpenVPN or the provided client of your VPN. I am only awar of two VPNs that provide Softether access:
https://www.rapidvpn.com/setup-vpn-softether-ubuntu
https://proxy.sh/panel/knowledgebase/1893/Securely-connect-t...
This should say 97 VPN services instead. Just nitpicking but it did made me look twice.
This type of development is not unusual. Web hosting companies have been buying each other up since the 90s.
[1]: https://torrentfreak.com/which-vpn-services-keep-you-anonymo...
Projects like mysterium.network, sentinel.co, privatix.io,...
The best I’ve been able to do was use Mozilla as a proxy (because I trust ‘em), and thus bought ProtonVPN (which admittedly has been imperfect).
But its also about hiding your identity from the sites you visit (dependent on how well your browser protects your privacy).
Until TLS 1.4 is deployed, each HTTPS-protected site you visit will still reveal the domain name in its certificate, giving your ISP a pretty good idea of your browsing patterns, which it will in turn sell or turn over to authorities when asked.
- Preventing websites from seeing your true IP? (you'll want to disable webrtc as well[1].) Mostly yes.
- preventing your ISP from spying on your traffic? (allowing Amazon to spy on your traffic in exchange...) Yes.
- Avoiding risk of legal threats if you engage in copyright infringement? Mostly no. They can subpoena Amazon instead of your ISP, and your lightsail/EC2 ip isn't shared.
Routing through a vpn, whether it's a commercial one or through AWS, linode, digitalocean, etc. will get you blocked on far more sites, because it's more difficult to identify individual clients, and there's more fraud and bot activity on any kind of vps or vpn netblock than there is on typical residential netblocks.
[1] https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-l...
btw Turkey is notorious for blocking sites, Youtube got blocked for months, Wikipedia is still blocked today..
What happens if you route it through servers in Qatar, Thailand or Singapore ?
Where are you exiting?
I recommend you read this https://thatoneprivacysite.net/choosing-the-best-vpn-for-you...
those are the only two answers. ProtonVPN is the only VPN company to own any of their own hardware (they own one physical data center in Switzerland). "SecureCore" = route through switzerland data center to destination country, also useful. CEO is a public figure. free service is surprisingly good. company is ideological.
could it all be fake? yes, but it is far less likely than any other company's VPN service to be. if there's one VPN in the world that would go lavabit, it'd be them.
as others have said vpnpro.com and any VPN review websites are all untrustworthy and paid off by VPN companies.