The trouble with VPN and privacy review sites
blog.privacytools.io
blog.privacytools.io
https://thewirecutter.com/reviews/best-vpn-service/#how-we-p...
Full disclosure, I'm the author of AlgoVPN, a set of scripts for hosting your own VPN rather than using a 3rd party service, and was interviewed by Wirecutter for their article. You should use Algo if you're at all capable of doing so: https://github.com/trailofbits/algo
Do you think the internal auditing and security controls at an independent data center would be more effective than those at AWS or Google?
You can get good security arrangements if you colocate in sufficient volume (locked rooms etc). That's where reading security reviews is useful.
Also, you can't trust what a VPN service says about where their servers are, how they're manages, and so on.
So you need to distribute trust. [Please see my other recent comment about how to do that.]
Probably a really bad idea, but the principle is clear. If you want to minimize legislative reach, take a service from the other side of the planet. Maybe not Australia.
And using nested VPN chains, you can pick appropriately.
For the first (entry) VPN, I use one that's innocuous and popular for streaming etc. For the middle ones, I pick ones that are either apparently honest or do business from jurisdictions that won't likely cooperate with my country's. And for the last (exit) VPN, I pick another that's innocuous, with IPs that don't often get blacklisted.
Access the internet via an anonymous SIM card (tethering), then use TOR to access your VPN (paid in Bitcoins, money order or whatever). This gives you a decent level of anonymity, if need be.
I am going to try to figure out how to deploy a home VPN solution using it this weekend.
If you want to point Android/iOS to a custom DoH/DoT resolver, https://getintra.org (Android) does DoH whilst Nebulo (iOS and Android) [2] does DoT. Setting up DoH/DoT resolvers (say, using NLNet's Unbound) might be cheaper than a full fledged VPN?
[0] https://apps.apple.com/us/app/dnscloak-secure-dns-client/id1...
Why do you consider OpenVPN risky?
Writeup with links available in our FAQ: https://github.com/trailofbits/algo/blob/master/docs/faq.md#...
I mean, it is basically just changing your IP and putting an additional hop in. You aren't mixing with other's traffic, making it very easy to fingerprint you.
I guess this is all dependent on someone's threat model, but I am not really sure if there is any benefit of running your own VPN besides being slightly more sure your VPN provider or someone who hacked your VPN provider isn't watching you.
Or an American ISP.
Besides that, as others pointed out, it's a safe way to get out of a compromised network.
And with a DNS blocker on the VPN endpoint, you are also able to block ads/tracking scripts (think of PiHole).
If that IP is in Russia, on a cheap supplier that has hundreds of similar VPS sitting behind a NAT, I wish em luck in fingerprinting you. Or extracting logs for that matter.
It seems like the thing that someone could roll into an iOS or android app for even easier deployment.
Not that it’s relevant to trust in algo, but I also recall some very acrimonious exchanges on hn previously when discussing algo, based on trailofbits’s support of USA govt spying. I cannot what the accusations are though, so if anyone who knows more could help me out that’d be great.
It's a well-documented fact that we work with DARPA on a number of research programs, which lets us release things like this to the public:
https://blog.trailofbits.com/2019/11/01/two-new-tools-that-t...
Well, a VPN provides privacy, not anonymity. But setting up a VPN is trivial. In fact, I could do it with a one liner on the Shell.
"censorship avoidance"
This is the tricky part. You may want to look into Softether.
A pox on the entire commercial VPN "industry". They all deserve each other.
While I don't think you should use any of these commercial VPN servers, I'll give props to WireCutter for at least attempting to do a serious job of impartial reviews.
[1] https://www.privacytools.io/sponsors/
[2] https://opencollective.com/privacytoolsio
[3] https://www.privacytools.io/providers/vpn/
[4] https://github.com/privacytoolsIO/privacytools.io/issues/113...
[5] https://github.com/privacytoolsIO/privacytools.io/pull/1174
1. We currently get _no_ money from _any_ VPN provider (our site makes other recommendations too that are not related to VPN services), our finances are very transparent:
• https://blog.privacytools.io/privacytools-io-joins-the-open-...
• https://opencollective.com/privacytoolsio#section-goals
2. Being a part of the sponsorship program does not get you on the website, you must still meet the criteria which a VPN provider could do for free (so there's no incentive for them to pay us anything).
3. We don't use referral links
4. No single member of the team can add/remove things (everything is also logged in git commit logs). Pull requests also require more than 2 members to sign off. Technically jonaharagon as owner could add things, but it would be pretty suspicious if new VPN providers started appearing without any discussion.... lol. I know I'd be asking questions.
What I really need is Cloudflare's WARP via wireguard config. I love the idea that they'll shield me from my ISP but still provide my real IP to service providers.
I can do this right now with a hack someone wrote https://github.com/maple3142/cf-warp but I don't want to anger Cloudflare.
Cloudflare, if you're listening, is it ok to extract wireguard credentials from your app and use them on my whole network? I'll gladly pay the $5/mo, but I don't want to be banned from Cloudflare or do something you may construe is illegal by extracting keys from your Android app.
There are a lot of equilibria where most free review sites are mostly, but not completely, trustworthy. With enough review sites in that model, an end-user can effectively triangulate the objective truth with arbitrarily high certainty.
They're also already committed to censorship, so I don't fathom how they'd run a VPN service.
The benefits to privacy would be:
- It may still make it harder for your ISP to track you, which can be worthwhile.
- It can still be useful to help hide your physical location, since your IP won't be in the same county as you. That's also not nothing.
For 3rd-party sites, you'll be making your traffic easier to correlate across domains, locations, etc... Up to you whether or not that's part of your threat model.
Sure, but they retain records.
- Rolling your own VPN (control your own infrastructure)
- Using an existing VPN service (crowd-based anonymity)
- Doing nothing (privacy nihilism)
Each decision has their own benefits and tradeoffs. If you're someone who torrents, you should probably be using crowd-based anonymity. If you really dislike the trust relationship you have with your VPN and you're technically inclined, you can roll your own VPN. If you don't want to spend the time worrying about this stuff, setting up a VPN on its own and doing nothing else won't make you private anyway.
I (very cautiously) lean towards advising people to use an existing VPN service, but that's not a strong opinion. I do think people who argue that rolling your own VPN is the only sensible choice are either full of crap, or haven't thought through the actual threat models real people face.
There's a big movement in some portions of the security industry to say that moving trust around isn't valuable, and that doing nothing is better than centralizing your trust. I'm not going to mince words, I think that's a really dumb perspective.
Google, Amazon, etc. are huge businesses which get a ton of scrutiny by large business and government customers: if they get caught cheating, especially in a way which jeopardize customer data, they’ll lose orders of magnitude more money than any VPN user is worth and as a publicly traded company in the United States they’re going to have a much harder time avoiding legal consequences.
> and the people behind it can just setup another shell company
I think this may be true for the smaller ones, but not for the larger companies, like for example ProtonVpn. They would loose their entire business if they get caught "cheating".
> Google, Amazon... if they get caught cheating... For example Google is getting caught with privacy violations constantly/on a regular basis. For example lately they were caught following Android devices even with Location Services turned off!
I don't trust my VPN provider. But I do trust Swiss privacy laws. At least more than I trust my American cable provider.
Also, using your own VPN, you're likely the only one using it. There's zero anonymity. And so an adversary would figure that out, and then focus on the VPS provider.
The sad truth is that you can't trust anyone. So your best option is distributing trust. That way, compromise depends on collusion among providers. Or on their joint compromise by your adversaries.
That's how Tor is designed. User traffic gets routed through three relays. User clients pick the relays in advance, for each circuit. The first (guard) relay only knows the IPs of the user and the second (middle) relay. The middle relay only knows the IPs of the guard and the third (exit) relay. And the exit relay only knows the IPs of the middle relay and the internet resource.
And you can do the same thing with VPN services. That is, nested VPN chains. You can do it either using multiple pfSense VMs as VPN gateways.[0] Or less securely, just with routing and iptables.[1,2]
0) https://www.ivpn.net/privacy-guides/advanced-privacy-and-ano...
A list, what features each provider has, and leave it to yourself to make the judgement. If you're being told why it's good there is bias involved somewhere along the line.
Of course, you need to understand whether the site has updated their information and presenting it truthfully, which should be easily verifiable.
My personal recommendation is AirVPN, but I wish they supported wireguard.
I think alot of this vpn hand-wringing is really just meant to discourage vpn usage in general. There have only been afew cases of paid vpn services giving up user information and they are well publicized.
Actually, they have "shielded" customers facing criminal charges.
https://www.techradar.com/news/cyberghost-owner-buys-pia-for...
check out 2. WireGuard privacy concerns and logs
They do have both wireguard and openvpn options, as well as an app with a GUI (with support for both).
My favourite part is the support though. I got help with weird openvpn configs that didn't get answered in the openVPN forums for ages, within an hour.
I am a very very happy customer.
Connection dropping is one of the major issues with any commercial VPN provider. I recommend to create a script which runs openvpn and immediately after that "ip link eth0 down" to prevent leaks.
They mention ThatOnePrivacySite.net but criticize him:
"Here's the difference. They include virtually every provider — the good and the bad — and present them at equal value to sort through. Instead of providing their readers with answers, they provide them with information that can be used to deduce their own recommendations, based on their values as an individual. "
1st: providing them all guarantees that there is no conflict of interest
2nd: "Instead of providing their readers with answers" You can not provide this answer since there a tons of reasons to use a VPN
"Your VPN provider should not be hiding away in Panama controlled by anonymous leadership."
This is also bullshit. In fact, some of the most resilient VPN provides provide no legislation at all. They only exists in Cyberspace. "Sue us!"
I actually have written the ThatOnePrivacySite.net guy and asked him to put this VPN on the list: https://www.rapidvpn.com/setup-vpn-softether-ubuntu
It is the only VPN that I am aware of that works out of the box with softether. I have not tried it yet. I currently use Astrill. Astrill is not cheap but works pretty well to circumvent censorship. A disadvantage of Astrill is that it often leaks DNS like a motherf....
This should prevent DNS leaks on Linux if UFW is installed.
ufw default deny outgoing
ufw allow out on tun0
ufw allow out on tun0 to 84.200.69.80 port 53
Should also keep in mind a few years ago Astril was using weak keys like ExpressVPN. That really makes me wonder what they know about running VPN servers. I think you only get one chance with your reputation on things like this.
http://blog.zorinaq.com/my-experience-with-the-great-firewal...
0: https://www.howtogeek.com/275474/how-to-use-androids-wi-fi-a...
1: https://techcrunch.com/2018/11/13/googles-project-fi-gets-an...
Looking at their own list[1], "Mullvad" is the only VPN provider listed at the top of the list under "Recommended VPN Services".
Just something that caught my eye and which I considered an interesting coincidence.
specifically the item that got it there was that they had external auditing.
> Mullvad's VPN clients have been audited by Cure53 and Assured AB in a pentest report published at cure53.de. The security researchers concluded: https://cure53.de/pentest-report_mullvad_v2.pdf
We would like to see more VPN providers do this. Then we could have more good choices to choose from. A lot of the larger ones could certainly afford it.
Privacy from your ISP? Okay, but I've replaced that problem with privacy from my VPN provider. Is that a better problem? Is my VPN provider going to exploit me less than my ISP would have?
Geographic restrictions? That's a genuine benefit. Alas, it would end up as a bit of an arms race as websites that really don't want me to visit would start blocking VPN providers.
Well, probably the answer is yes, since we have many years of experience with the terrible behavior of ISPs. VPNs have a much smaller userbase, so I suppose they have less of an opportunity to screw you over, but come on, even the worst of them has to be better than something like Comcast.
I think Sven does a decent job of analyzing each service/offering and presenting the information in an approachable way.
That being said, it is wise to take his rankings/thoughts on each service with a grain of salt.
I just wanted others interested in this topic to be aware of another resource that I have found useful.
https://restoreprivacy.com/nordvpn
https://www.cnet.com/news/after-the-breach-nord-is-asking-us...
Their "Best VPN List" doesn't mention it, either. That's extremely damning to Restore Privacy's credibility as a review site, and highlights how financial conflicts of interest can degrade the quality of a site's content.
But it’s mentioned, right at the start, on the page you link:
> In October 2019, news broke about a NordVPN security incident.
Which links to a full article on it[0].
He sort of downplays the hack, which then led me to read the article you posted. And the TechCrunch article it mentions.
They take a more “trust is compromised” stance. So to reiterate:
> it is wise to take his rankings/thoughts on each service with a grain of salt.
https://web.archive.org/web/20191118050427/https://restorepr...
https://restoreprivacy.com/nordvpn/
The most recent Wayback Machine archive (November 18) shows that the "Trust issues?" paragraph wasn't in the NordVPN review until very recently. Thanks for getting the paragraph added in, because transparency is important.
However, you might want to consider using the pronoun "I" or "we" instead of "he", because astroturfing is not a transparent thing to do. It doesn't take a genius to see that you're affiliated with Restore Privacy just as Restore Privacy is affiliated with NordVPN.
Interestingly, it looks like he doesn't censor/hadn't censored the couple of comments mentioning the breach on that page.
His article on the breach/hack was published in Oct. But his Nord VPN review was published/updated the month prior (from your waybackmachine link). So a month later.
It's plausible to me that he just never got around to updating the original post/review. But apparently your comment prompted him to do so.
However, he hasn't bothered to jump in this thread and comment that was the case. So although I think RestorePrivacy is still a useful site, perhaps a larger grain of salt is needed.
> However, you might want to consider using the pronoun "I" or "we" instead of "he", because astroturfing is not a transparent thing to do
Not Sven and not astroturfing. Merely suggesting what I thought was a decent privacy resource - in a related topic's thread.
(I accurately guessed the above before even going to the article...)
On its face, affiliate reviews are ok if the company has integrity, like Wirecutter attempts. If they pick a profitless product as first over one that makes them money.
Credit card reviews are another one that have gone off the chain. There are thousands of identical sites ranking the same cards.
"Whether or not you choose to get free credit monitoring from Equifax, the company will continue to collect information about you."
In other words:
"Even though we got hacked, we're still going to collect your information so it can get leaked again, lolz".
Awesome FTC right there.
[1]: https://www.ftc.gov/enforcement/cases-proceedings/refunds/eq...
I have a lot more respect for the sites that prominently disclose their relationships, like Wirecutter. Most of these sites are a business, they've gotta make money somehow. But IMO most readers aren't seeking out such disclosures automatically when they see a "review", so the hidden-in-the-footer nonsense is entirely useless.
People are always quick to throw Amazon under the buss for reviews but it's not just Amazon/Newegg etc but I don't trust reviews anymore, at all, the only time I trust a 'review' is when a friend is like "yeah man I've been using this thing for such and such and it's great".
Even when friends recommend something I've been burnt simply by listening to just 1 or 2. Altman mentions a specific mattress cooler in one of his blog posts, I bought it without even checking other online reviews because I respect Sam and value his opinions (he also has no reason to plug a specific product, especially when he is in no way involved with the company). Man it was great, oh man was it great, until I'd been using it a couple of months and was changing my sheets and saw mildew all over my mattress protector from the condensation forming on the tubes at night while I slept. San Francisco doesn't have the summer humidity that Indiana does and in the 2 weeks between sheet changing...