Show HN: A small bootstrapped independent VPN company in the Netherlands
wifimask.com
wifimask.com
I couldn't see from the website what your VPN is based on in terms of protocol? Or home brewed? OpenVPN?
Have you had 3rd party audits?
Have you considered alternative payment forms? Such as Bitcoin or other?
From your Terms of Service 'What we do not allow on or from our network...' how do you track these? Do you provide a transparency report summarising legal, copyright etc requests made, action taken?
Also from ToS 'What we need our customers to do: - Use responsible disclosure in the event any security vulnerabilities occur in our website, software or infrastructure.' Do you have a public disclosure policy notifying of vulnerabilities?
Choosing a VPN involves placing a lot of trust in a 3rd party. Hence questions.
WifiMask uses OpenVPN for the macOS app and IKEv2/IPSec for iOS. We haven't had 3rd party audits yet, this is definitely on our wish list, because we understand it's all about trust. Alternative payments like bitcoin are on the list as well, we aim for total anonymity for our users, payments are part of that. To be honest we can't track any illegal activity, because we have a strict no log policy, all we can do now is say it is not allowed. We have nothing to hand over to enforcement either, they have to find different ways of getting the information they want. We should investigate and think about transparency reports and a public disclosure policy too, thanks!
1. They're small
2. They're new
3. Their team has more experience developing for Apple devices, thus it was quicker to release for those devices first before tackling Windows, Android, and/or Linux.
What they could do in the meantime is create a web-based tool to generate configurations for OpenVPN and/or Wireguard, like Mullvad does.
While I agree that, as a user, knowing who's behind a service, and in particular a VPN, can help build trust, there are several good reasons why you would want to remain anonymous when running a VPN or any privacy service like secure email and encryption tools. You will be targeted by multiple parties. The technical side of this challenge (both that of operating services like these and that of being a target) is complicated enough. Operator anonymity can mitigate some threats, from social engineering to physical threats, pressure, legal and otherwise, from a range of parties. Anyone with experience in these matters knows what I'm referring to, and don't think for a second operating outside of the US makes that much of a difference. The world is small. Many parties do not play by any rules besides their own.
And yet, Mullvad (Sweden), which seems to be one of the most trusted VPN providers without affiliate marketing, has no issues with publicly listing the names of every single member of the team[1].
Do you know anything about how or if Mullvad cooperates with domestic and foreign entities?
Perhaps threats are unnecessary.
Stating you have a no logging policy does not mean you cannot covertly cooperate.
Fourteen Eyes collaboration is real, and Sweden is not a country where a business not complying with the law stays in business.
I am not aware of this, but unlike the majority of VPN providers, Mullvad at least does not require any personally identifiable information, such as an email address, in order to use it.
And most VPN providers that hide their real locations, such as ExpressVPN (Hong Kong)[1], NordVPN and ProtonVPN (both Lithuania)[2], are just creating an illusion of privacy for their unsuspecting users.
[1] https://vpnscam.com/expressvpn-really-based-in-hong-kong/
[2] http://vpnscam.com/hola-vpn-and-nordvpn-partners-in-data-min...
As I have said in previous comments, I currently use ProtonVPN, but my use case, like many others, is simply avoiding geo-blocks and not leaving my real IP everywhere.
Though, I do think, that if they make money off my data, and they probably do, the service should not charge a subscription (indeed ProtonVPN has a free plan, but it's a bit limited).
EDIT: "We will never share your personal information with any third party, except when we need to respond to a legal request from Dutch authorities" - https://www.wifimask.com/terms
As a VPN service that means it is not thoughtful about privacy.
Our intelligence agency (AIVD) allegedly facilitated the planting of stuxnet (they had a guy in there or something)
So it'd be reasonable to say that "we're not uncooperative"
FWIW I do tech DD for a living and I've seen several places that had 'no log' policies on the outside and yet they would occasionally - or even structurally - log data in order to comply with the law.
The 'WBT' (Retenion duty for Telecommunicationsdata) has been disbanded, which should work to your advantage, but the GDPR makes explicit room for the accomodation of legal and regulatory requirements and this in turn may transcend your 'no log' policy. Please make sure you have appropriate legal advice on the subject, it is complex and getting it wrong can really bite you.
Best of luck with your company!
Thanks!
Even the authorities asking for data have an interest in keeping the VPN's reputation alive in case the VPN does cooperate.
What is under their control (which I have not investigated) is how much logging they do. If they do the absolute minimal logging, then there's very little for the Dutch authorities to review. This of course excludes the very likely possibility that the overly performant Dutch intelligence service is monitoring everything from every angle (they have thus far proven to be very, very capable of doing so).
Big plus one here. I'd trust wifimask if I wasn't capable of hosting my own servers and needed a VPN.
What language(s) do you use?
What libraries do you use?
What static and dynamic security analysis tools do you use?
What style guides and code best practices do you use?
Where do you host your code?
Where are your backups?
Where are your POPs located?
Have you had any pen tests run?
status /dev/null
log /dev/null
verb 0
Part of the IPSec config:
charondebug="asn -1, cfg -1, chd -1, dmn -1, enc -1, esp -1, ike -1, imc -1, imv -1, job -1, knl -1, lib -1, mgr -1, net -1, pts -1, tls -1, tnc -1"
(-1 means absolutely silent)
There are no client connect/disconnect scripts active.
Authorization, Accounting and Authentication log queries in FreeRadius are disabled.
All name server logging is disabled.
iOS subscription receipt validation logging is disabled.
Communication in between servers (for example vpnserver -> dbserver) is encrypted with OpenVPN.
Where do you purchase your servers from?
How trustworthy are the underlying VPS providers across different countries that you've got presence in?
It was recently pointed out that PIA was $30 million in debt... Looks like VPN is a brutal business, but your pricing is (low?) at $4 for unlimited devices and you're bootstrapped. How do you manage to pull it off?
What are the upcoming features that you plan? Consequently, what are the most requested features?
Thanks.
VPN is a brutal business. But because we are bootstrapped and thus no screaming investors/banks behind our backs and we are a small team, costs are low and there's no one who can pull the plug but ourselves. I don't know how many people are working for PIA, but in my opinion you don't need ten's or hundred's of people to build and run a VPN company. I'm not very surprised they are supposedly in that much debt.
The most requested feature is an Android app. ;-) And unblocking Netflix ofcourse, but they seem to get even better at blocking VPN's than the Great Firewall of China. What would your feature request be? :-)
Are there any legal or technical reasons to prefer DigitalOcean over OVH and Hetzner? They seem to be both, much more cost-efficient, and much more privacy-oriented.
> What would your feature request be?
WireGuard.
I'm definitely keeping an eye on WireGuard, it is very promising.
DigitalOcean are capped + 1cent/gb but your offering unlimited.... a few heavy streamers or torrents could ruin your monthly bill?
Edit: a word
I'd expect that they'll have other platforms soon.
- Your last two bullet points for 'what we do not allow' is missing newlines (https://www.wifimask.com/terms)
- You load a number of JS files from third party CDNs including Cloudflare and Google without subresource integrity
- What does this offer me? It seems a lot more restrictive than other companies at lower price points, inability to use it on own libre devices, requiring proprietary software? How is this significantly different than renting a VM or two?
- Based on your cipher list in features, this is an openvpn wrapper?
- "WifiMask will also use your Personal Data to provide you with news, special offers and general information about other goods, services and events which we offer that are similar to those that you have already purchased or enquired about." - This sounds like there is no opt out, no "if you choose to", just that special offers are mandatory to receive
WifiMask uses OpenVPN for the macOS app and IKEv2/IPSec for iOS. Examples of OpenVPN config files can be found at https://www.wifimask.com/contact#androidwindows which allows you to use the WifiMask service on every OpenVPN capable device. Meanwhile an Android and Windows app are in development, so stay tuned. ;-)
Can't find list of hostnames to use with OVPN, seemingly
Good one with the list of hostnames, I will prepare one, for now you can take a look at this JSON file:
The fact that Authy refused to delete user accounts (before they were acquired by Twilio), even when they promised to do so in their terms of service, is also very concerning:
(you say "made in Holland" in your logo)
So, from on high: Den Bosch is now also in Holland, as are Maastricht, Enschede, Middelburg and Groningen, to great chagrin of those living there. It's been a major point of contention between the NBTC and almost all of the rest of the country but 'Made in Holland' has displaced 'Made in The Netherlands' for quite a while now.
That is history :-). https://www.government.nl/latest/news/2019/11/08/new-interna... (3 weeks ago):
"From now on the Netherlands and the Kingdom of the Netherlands can be recognised internationally by a new logo. The logo is characterised by two symbols: NL and a stylised orange tulip. The logo replaces the much used ‘Holland tulip’ of the Netherlands Board of Tourism & Conventions’ (NBTC)”
I think it will be ‘a while’ before ‘Holland’ is gone, if only because ’Nederland’ doesn’t work well in cheering on sports teams.
https://blog.appsecco.com/breaking-full-disk-encryption-from...
What we need our customers to do:
- Use responsible disclosure in the event any security vulnerabilities occur in our website, software or infrastructure.That said, I swapped to Mullvad VPN recently due to the Private Internet Access controversy.
https://news.ycombinator.com/item?id=11366537
So not just launched as I’d expected