Mozilla VPN
blog.mozilla.org
blog.mozilla.org
I cannot find anything reliable that suggests this! Thanks.
In particular, the claim that tesonet controls protonvpn's release signing key.
https://news.ycombinator.com/item?id=18611863
It seems very likely now, that ProtonMail just decided to use NordVPN's white-label solution to bootstrap its ProtonVPN business:
What really? Some proof for that? ProtonVPN and ProtonMail is located in Switzerland Genève, i dont see any open positions for estonia
They also have regularly been audited by independent organizations that are openly available for the public to see their compliance [2][3][4][5][6].
Do you have any evidence to suggest that they are honeypots?
[1] https://github.com/ProtonVPN
[2] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...
[3] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...
[4] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...
[5] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...
You can download the entire repository, and self compile yourself after you inspect the code.
Everything is opensource, the data s are located in Switzerland on there own hardware. They have open communication and a yearly transparency report:
Is it to avoid your ISP collecting browsing data off you and selling it?
Perhaps using 8.8.8.8 or 1.1.1.1 as your DNS might be good enough.
Is it to watch geo region blocked videos?
Then pretty much any service will work for you. Except that video streaming sites have caught on and blocked hosting provider IP blocks. So that might require you to shop around.
Do you want the most privacy or want to get around blocking?
Then get a VM from a provider and configure a VPN to it. Wireguard works fine.
Want to do something illegal?
Don't expect a VPN to save you.
I'm not condoning piracy, but VPNs are generally a foolproof way to avoid DMCA letters from your ISP. Privacy means something different to every individual, everyone's threat model is different. And many models can benefit from a VPN; journalists, activists, and many others might find benefit from using a VPN.
It seems like Torrenting died out significantly over the last 5 years.
Obviously, I have no interest in testing this out myself, so I take their word for it.
Except for those Linux ISOs, of course.
Just don't bother with Big Media content and they won't need a VPN...
There's plenty to do in life other than torrenting the latest HBO series.
And, "Plenty to do in life" is a value judgment, and isn't relevant to this discussion.
i just never wanted my job to hire some dumb IT consulting firm to do some cross between IPs on a swam and IPs VPNing in as a "threat analysis" and my dumb name getting dragged into an office. I know it's far fetched, but $40 a year of PIA keeps my mind at ease.
Defiantly don't spin up these VPN/VPSs on an account you don't mind losing.
They got a $1bi shakedown in a local court because they successfully fought the RIA in 2015 and won (it was $25mi then).
This time, Cox legal team tried to simply stand behind the DMCA safe-harbor (just like google does) and somehow lost.
it will appeal and win (or likely settle out of court as RIAA already got what it wanted, a hole in safe-harbor)
Which is sad because their pricing model is less stupid than most of the competition.
Wouldn't your ISP still see what IP's you are visiting? Then, your ISP could just reverse DNS that IP to get the domain name, right?
8.8.8.8 is Google’s DNS so you’re really just trading being tracked by an ISP to a giant advertising company...
(Disclosure: I work for Google)
A lot of google engineers read hacker news comments, reddit threads, etc. all the time, and generally try and route good feedback where it belongs.
People arguing against DNS over HTTPS claim stuff the doesn't happen so it'd be good to have definite examples.
If you want privacy with your DNS, you should setup DoH using dnscrypt-proxy or perhaps DNS over TLS.
Personally, I think a better strategy with this whole vpn aspect is to just setup a vpn with pis in various countries + pihole. At least that way I know what the setup is happening in each locations and what expectations of privacy I can expect.
At a conference I was talking to one of the OpenDNS engineers on the DoH project and when I asked "so how does DoH help snooping if people can just look at IP headers?" they conceded that it really doesn't help if someone is determined to snoop.
Edit: it _is_ easy to read the destination address from TCP packets though.
Also, unless it’s behind Cloudflare. Most nontrivial sites today have a unique IP so even with DoH there’s a good probability any specific site will be identified.
If you want your ISP to stay ignorant of where you surf, you MUsT have a VPN.
I'm immediately reminded of some shady search engine CEO going on OAN and other fringe shows posing as a security researcher to spread FUD about DDG to drive traffic to his site (can't find the link for it now.) That OAN video even went around the security industry (among compliance and less technical folk) who were persuaded DDG was now worse than Google for consumer privacy.
For this reason I am highly suspicious of any VPN service that markets itself as some “magical privacy wormhole”, which is 99% of VPN providers.
Honest ones I know of are Encrypt.me and Mullvad, who both tell you they should be mainly used to secure yourself on open WiFi and to circumvent geo blocks.
If you want a private internet connection, use TOR.
* Some consumer VPN services have been found to be doing sketchy things. And you can imagine the business is attractive to people intending to do sketchy things, since it's a powerful/lucrative position to be in right now. (In addition to the business possibly being attractive to people just wanting to provide a useful and honest service for a fair price.)
* There seem to have long been referral kickbacks by some consumer VPN services, which I assume is the cause of some of the huge amounts of noise on the Web and such about them (e.g., search hits on some non-VPN topics, such as some home theatre search terms, overwhelmed by SEO articles, the purpose of which is to then herd the reader towards particular VPN services with a kickback). Even some endorsements by organizations might essentially be more about revenue than about merits.
* I speculate that it doesn't help if one of the main historical uses of consumer VPNs has been for activity that would be considered copyright-violating in the US (e.g., unauthorized trading of video files, or circumventing region restrictions). Without making any moral judgments, I think it's fair to say that constitutes "conscious rule-breaking" for some, so I wouldn't be surprised if there's an disproportionate culture of rule-breaking around the whole space.
Please tell me - What makes a VPN provider trustworthy, and how do you _know_?
Personally I believe a trustworthy provider is _characterized_ by consistent actions that show transparency, honesty, and conscientiousness. Nevertheless, such consistent action doesn’t actually prove trustworthiness.
A good VPN honeypot, or reseller of your network traffic, is publicly indistinguishable from a trustworthy one. So what can the users do? What tools, technology, process, or ecosystem do they need to tell honest and dishonest apart? What do we need to build?
We all recognize that VPN providers are in a great position of power over their users. How do we tilt the scales in the users’ favor? What are _strong_ signals of trustworthiness?
Disclosure: I co-founded Mullvad.
What is the deal with Mullvad and Firefox? Are they completely using your services but with their name on it? Would you rather a client directly or through Firefox (bit cheaper now in $ )?
To quote https://fpn.firefox.com/vpn - “The VPN is built by Firefox and runs on a global network of servers powered by our partner Mullvad using the WireGuard® protocol.“
Regarding using us directly or through Mozilla, I think both are good options. If you pay directly to us we will put your money to good use. Same goes for Mozilla. And they are not mutually exclusive. You could also sign up directly with us AND set up a monthly donation to Mozilla for Firefox development :)
Perhaps the users should pay for an audit as in "Check this one for us!"
Question is, how that could be organized. I guess the user community would have to unite for it andthe VPN provider would need to declare ahead of time, that they are fine with being audited by an independent party, paid by the customers.
Reason for TunnelBear: independent audit. They had had an audit that went through their system and, at least how I understood it, confirmed what they had said they were doing.
Reason for PIA: they had a history of being questioned by authorities and providing nothing - because they had nothing.
The latter is why I continue to trust Apple more than Google, too.
I've joined several popular VPN services this year in my work on VPN Wire, and Mullvad's signup flow was by far the most enjoyable. Not only because there's no email required (a little disorienting, but very refreshing), but also because, unlike the experience on many of your competitors' sites, I didn't feel pressured to buy/commit every step of the way. User-friendly site design, in other words, is a positive signal.
I personally regard audits and pentests as strong positive signals. For example, PwC's audit of NordVPN's no logs policy was a positive for me. As someone in the industry, I'm curious if you feel the same.
Open source software and public APIs are very nice to see.
> What tools, technology, process, or ecosystem do they need to tell honest and dishonest apart?
Other than audits, I don't have a good answer to this one. I would love to hear some technical solutions, and hope other people reply!
And as an aside, kudos on running a very speedy network :) https://vpnwire.co
Audits are good and definitely have a place. There’s much more that can be done. I agree open source is also an important one.
We’ve tried to identify strong signals of trustworthiness together with a few other services here: https://mullvad.net/blog/2018/10/17/signals-trustworthy-vpns...
A technical solution Mullvad is working on is something we call System Transparency. You can read more about that here: https://mullvad.net/blog/2019/6/3/system-transparency-future...
Give me that real internet stuff - email, calendar, file sync, chat(?) - give me Firefox Premium. Bundle in the Lockwise password manager. I'd pay good money to see a company fill the void of paid, privacy first essential internet services and I think Mozilla is one of the foremost existing players to pull it off. They've started talking about Firefox Premium a while ago now [2] and it's obviously not easy to build all of this in a lean way, but I'll happily pitch in. If only to help make Firefox development less dependant on Google or Yahoo.
[1]: https://donate.mozilla.org/
[2]: https://www.theverge.com/2019/6/10/18660344/firefox-subscrip...
- Frontier
- Green Man Gaming
- Paperspace
- Rainway
- SquareTrade
See https://www.fastmail.com/help/account/migratetofastmail.html
No connection to them, just a happy customer!
Eventually, when I jumped to FastMail, I repointed my domain name to it, and most of my new emails started coming over automatically, since the email address is now something I control. I monitored Gmail for a while regularly to catch straggler services. (I chose not to forward to avoid complacency with stuff going to Gmail before reaching my FastMail account.)
1) Sign up for Fastmail.
2) Sync all mail from GMail account to Fastmail (via the Fastmail web UI; you grant FM access to your GMail data through OAuth - once sync is complete you can revoke this access).
3) Set up an auto-forward rule in GMail for all incoming mail to go to your Fastmail address.
4) Set up a rule in Fastmail to put all incoming mail sent to your GMail address into a separate folder (or labeled with a special label if you're signed up for Fastmail's label beta). Any time you get email in that folder, that's a task for you to either unsubscribe or update the corresponding account to your new email address.
I'm currently in month #10 of migration. Most commonly used accounts were updated during the first couple of weeks. But be careful that the tail of services that are still configured to use your old email address tends to be long, and in my experience those are some of the more important emails that you don't want to miss. The ones that are only sent once every couple years.
Also, it really helps if you've been using GMail with a personal domain name (e.g. through Google Apps). In this case migrating is a matter of pointing the MX DNS records to Fastmail's servers. Bonus points: Fastmail allows wildcard recipients, so if you prefer to have unique addresses for each service you sign up for, you don't even need to set up a separate xyz@example.com alias. Just register with <whatever>@example.com and you'll get all email delivered to that address in your inbox, and you'll be able to specify it as the sender's address if you decide to reply to some of those mails. Having a separate email address for each web service also makes looking up who leaked what on haveibeenpwned.com more fun.
0) Get your own domain and set up MX record to fastmail servers
This way if you ever migrate again, you will not need to do it all over again. One word of advice - keep your registrar login and emails associated with the domains _not_ on your domain, otherwise it is going to present a problem should you ever need to fix anything related to domains.
I have to manage a domain and have a basic understanding of how DNS works, that is unavoidable.
DNS is a bit complicated to describe in short reply but on a very high level: say I register a domain example.com. Registrars usually give you an interface to manage DNS where you can set A records (association with IP), you basically put there 2-5 IP addresses of the DNS servers serving your domain. You can also setup MX records that are used to resolve mail servers for your domain. Setting up fastmail is simple: you tell them that you want them to serve mail for example.com and setup couple of MX records pointing to the Fastmail servers (they give you the full host names).
Basically, if you register your domain through namecheap, then after setting up email at *@ximeng.net, don't update your email address to be namecheap@ximeng.net when changing the rest of your accounts. Reason being, if for some reason there is a problem with the domain, you don't want your only means of fixing that problem to potentially be invalid.
Therefore it wouldn't be a bad idea to keep the account associated with your registrar still on the original Gmail address (or if you are really paranoid, create a new email address through someone like protonmail just for your registrar account).
Recently my provider decided to randomly cancel my domain, getting it back from transfer with everything out of date was painful.
First, do a one-time import from Gmail. Fastmail has an import tool that does this over OAuth. Took me ~45 minutes to import ~50,000 emails.
Next, setup IMAP and SMTP on Fastmail for your Gmail account. This way, you can continue to receive and reply to emails sent to Gmail, using Fastmail as the client. When replying to an email, Fastmail defaults to the right sender (identity) based on whom the email is sent to (abc@fastmail.com or abc@gmail.com).
An alternative is to setup email forwarding in Gmail, so you get a copy of emails sent to your old address.
If you don't have a custom domain, I highly recommend getting one and use that going forward. There might come a day when you want to migrate off Fastmail. With a custom domain, you just need to update the MX records.
On top, I had some burts of motivation to step through my password manager vault occasionally and update accounts I don't log in to too much.
Seems like it is Apple, Google, Outlook or nothing.
Isn't it down to the app to support those standards?
That’s entirely calendly’s fault.
An open spec is great, but it has to be adopted to be used.
First, no phone support. Hardly acceptable when even Google has this.
Second, no collaboration suite like Drive/Docs.
Third, no addons I’m accustomed to having in my daily driver email suite. Things I miss include schedule to send later, default reply all, and no priority inbox.
Im stuck using Google for email and maps. I hate google and want to get off them entirely but Gsuite with 1Tb of disk space for my single user personal domain is so powerful and so cheap it’s impossible for me to switch without giving up too much.
Google maps I think has some real competition at least. I’m hopeful Apple Maps gets continued improvements so it can get the job done well enough I can drop Google maps this year.
When you use gmail you conflate the standard with the app.
Priority inbox is also something that can be done client-side. FWIW FastMail does actually have internal flags for "$ismailinglist" and "$isnotification" that you can access via advanced search, but they don't have any intelligent customization of these flags, no way to tell FastMail "hey this email was categorized wrong". You can write a Sieve script that adds/removes the flags yourself but that only works for stuff you can detect in a sieve script, i.e. no ML. Still, it's better than nothing when using the web app.
IMAP actually has client-defined flags, but support on the clients is sketchy and not uniform
If you want reliable email service without the nice app, there are much cheaper alternatives.
One good thing that Fastmail is doing is promoting a REST-like IMAP alternative ( https://jmap.io/ ) that makes it easier[1] to go back to the distinction application/protocol.
[1] by this I mean that implementing an app like gmail over IMAP would be a terrible idea, while JMAP would be at least a bit better (it also adds browser support as it allows HTTP as transport layer)
I will argue that if you use the right data structures--not that anyone does--it really isn't that hard to make that work on the server, and the benefits to the client are actually enormous... particularly on mobile!
The way IMAP handles message identifiers allows for the client to pretend to manage a ridiculously large list of messages without storing any state locally that isn't visible on the screen (like it is _so good at this_ as Mark Crispin seriously intended the original IMAP protocol to be used by thin clients for mail: synchronizing mail over IMAP was never the intended usage model), as the entire problem of managing that consistent view has been pushed to the server (where it is solvable, just no one cares enough to even do a basic implementation correct much less a good one as everyone misunderstands and detests IMAP).
FWIW, the argument for how JMAP supports update batching over push notification channels is in fact interesting for mobile clients :(. That is so totally the fault of the mobile networks and OS people, though :(. The correct solution for that is to provide a flow control layer for wireless IP, at which point every app could be doing its own end-to-end encrypted push notification stuff without having to go through Apple/Google, but the incentive structure to centralize notifications through a middleman was just too great :/.
The issue for mobile is that unrestricted push notifications are a serious battery drain. I think that JMAP makes the correct choice here, a push notification is just an external action/url, how the notification is delivered to the human is left out of the protocol. I would say that it allows for both openness and centralization without a bias for one or the other.
My understanding is that a important property is that the device does not receive network packets that are not "replies". So that it has control on when it is fine to power down the network (in a very gross simplification)
So maybe something like what you are describing would be a protocol where the client can say "pin me back with this for this category of events but no sooner than X minutes", but at a network level, like a tagged TCP sleep function.
I never thought of this possibility. In the form I have imagined it it is technically inferior, but it would be an interesting approach to decentralization and surely could be improved.
As far as I know a couple things that are pain points for me when using thunderbird/other IMAP clients (weird search limitations, strict folder hierarchy organization) are due to how IMAP was designed, but these are mostly minor issues that I imagine would not require a new protocol.
What I hope the advantage of JMAP will be is that it will provide a more flexible foundation for gmail-like interfaces on an open protocol.
At least all IMAP clients I have used have always felt... clunky and counter intuitive (I started using email with gmail, so maybe I just never learned the skills) even if IMAP already had all the good things JMAP claim, I think that the different focus on message and less historical baggage have a good change of producing designs that will feel more natural to me.
IMAP has one (two actually, IDLE and NOTIFY) but they are not really adapted to the way we use email today (mobile and browser-based apps).
Did I not understand you statement correctly? Like did you mean that you cannot set it up with other mail apps on the phone?
It just works.
(I'd actually be more worried about the AU legislation about permissible snooping, but... and I can't believe I'm saying this... It works well enough that I don't care. Most providers have learned to not send actual sensitive info by email.)
...you can reach Google over the phone?
I’ve called them for help with a Office 365 issue and they were very helpful.
I’ve called them once for an Xbox issue (I wanted to buy an Xbox 360 game and it wasn’t letting me) and the rep didn’t really have a clue. I ended up finding the answer after searching a few Xbox forums.
When it comes to big-brand software and services, it can really pay off to buy via a good reseller or consultancy, who often offer much better support than the company that actually makes the product. Of course, that's not actionable advice when we're discussing which mail provider is best for personal use. (Although I suggest the answer is still "not O365".)
The single case where I used it was a good experience (though obviously you'll find a lot of people who had issues the support couldn't resolve).
You cannot if you just have your personal @gmail.com email.
- It is more expensive than my current plan with Fastmail. Hey mail is 99$/year.
- As all of my current emails and contacts are in fastmail, I am not likely to switch to another providers. Also, because I am happy user, I don't see the need to switch.
Let's be realistic: it's an email service. Complaining it doesn't do everything Google does seems a little unfair.
I hate myself a little for tying my kids into Google with their own Gmail addresses but the process is too easy to ignore, I don't have time to cobble together a mishmash of services. One part of me thinks Google needs to be broken up, the other thinks it will be a pain in the ass.
If you want secure, you wouldn’t be using email in the first place.
I wouldn't consider them equivalent. Australian laws are some of the most intrusive on the planet and are shared amongst the 5/14 eyes without a warrant.
i'm happily paying for e-mail and tend to think putting money down ensures I keep myself honest and maintain a workflow. Now I only save e-mails that are important to me, instead of archiving everything.
Spammers are going to find your domain name and spam it at obvious usernames anyway (eg contact@).
Besides what use-case do people have for throwaway addresses? In my experience in most cases the addresses you use aren't throwaway at all.
Fastmail does subdomain aliasing and I've been using that for years with my own domain without issues. Every subscription I have has its own email address. I don't need someone else's domains for that.
I don't think it's a given that spammers will find your domain, if you only provide your email to real people, and give generated emails to online services.
Email addresses that I use now look like this: reddit@subdomain.domain.com
If this leaks, I can track the source and I can bounce messages for this address.
While what you're saying is possible, a spammer needs to target you personally and that's not cost effective. It's not easy for them to try every possible English name at that address, because then they quickly get blacklisted.
Spammers collect addresses via scripts that crawl the web or via data leaks. It's more cost effective for them to get addresses that have been validated. All the spam I get are on these aliased addresses, biggest problem being the one I publish on my website, which I change periodically.
---
I like using my own domain even for aliased addresses because I can change service providers on a whim. I love Fastmail, but if they ever piss me off, I can change to Google Suite or whatever over night, the only thing required is some flexibility in setting up aliases.
This contrasts with Hey which will forward your old hey.com address to another address after you stop paying, and not make it available to future customers.
I also use a lot of the other fastmail features, like mail aliases, DNS, and file storage and web site serving. I'm very happy to pay the money.
While I would like to be able to, I suspect this is a typo...? :-)
The better option is to register your own domain for $10 a year, something hey doesn't seem to support?
I use net guard to stop basically everything in my phone from contacting the Internet.
Also, consider if possible affordability for students and senior, who might not be able to afford a subscription. Maybe limited bandwidth for free w/o subscription? Something like ProtonVPN provided.
Otherwise it's fine. The multiple Vaults is great to share passwords among family or maybe your co-workers. It has features like TOTP and supports many types of other fields.
4/10 on usability 10/10 on its core feature set. Probably a 9/10 on osx.
There's a slightly easier way - escape out of the basic auth dialog box, open the 1password menu which will be showing you the website you're on and select 'Autofill', and then reload the page (ie Ctrl-R) and the basic auth is supplied from 1password.
Not great, but easier and faster than copying in username and password fields manually (and with keyboard shortcuts available to do each step it can be quite fast).
From 1password comments I believe the limitation is because Firefox does not allow 1password to interact with the auth dialog box (which isn't strictly a bad policy from a general security point of view).
The major pro for me is that I know exactly how it is encrypted end to end, and have control over how and where it is stored, and can move the storage as I please, all entirely for free.
Having said that, Bitwarden is a big pain in the ass. I still can't open the main window when I'm in private browsing window.
Unlike the other options, it's a deterministic password manager. This means that you don't need to sync anything, and there's no risk of losing your password database. As long as you know what website you're signing in to, and remember your one master password, you can regenerate all other passwords.
Once Keychain got good enough, I transitioned to Safari 98% and dropped 1Password. iCloud syncing is nice too.
--
Anecdotally, it just seems like a lot of web sites are poorly tested against Safari, so I run into weird stuff. Also, Safari now inevitably abends, seemingly after binging YouTube.
I favor Safari, mostly because of lower power consumption. I have only positive things to say about Firefox. I've always liked it and I've read they keep improving the power stuff. If I ever do front end work again, I'll definitely go back to 50/50.
--
Leaving gmail is on my to do list. I've just been too lazy to follow thru. I dunno why, but if Mozilla partnered with FastMail, I'd be more motivated. Probably for bragging rights, virtue signaling.
Omg, my thoughts exactly! I dont want services... I dont want anything except that with the donations they will break away from google. That is it. And I bet a lot of us here would gladly donate, I donate to EFF while mozilla could in theory have more impact.
Yeah, no. The least they should do is enhace the size for syncing extension-data. It's today limited to 100kb per extension, which destroys syncing for most useful extensions like ublock, greasemonkey or some mature manager for bookmarks and notes. Giving any paying user some GB as global storeage and remove the per-extenions-limitation would push productivity immense.
This already exists: https://chat.mozilla.org/
You can use it with your Firefox account.
Time for them to reclaim the throne.
Taken a little deeper, your statement would imply that people should build and maintain their own data centers and host all services by themselves (this argument could be stretched even further).
One doesn't need a data center to host these kinds of services. Nextcloud on a Raspberry Pi works just fine.
Yes, yes they should; it's called a personal computer; IBM used to sell pre-built ones.
I did not imply anything of the sort, and I am astonished and confused as to why you would think that. How in the world does mentioning that it's not a good idea to give a company a monopoly over your personal usage lead to people should build their own personal data services? Obviously the real implication is that it's better to use multiple different providers of software services instead of one, or use as many different open source software as possible. The benefits being if or when a company decides to use your data for nefarious purposes they can only use a portion instead of all of your data. Likewise a security breach to one of those companies would only expose a portion as well.
Sorry, Google pays more. :)
As much as you would like to be, you are not Mozilla's customer. You are, as they say, a "product". The subject of an ongoing marketing study. There are people willing to pay for the results of that study, and they are willing and able to pay much more than you will ever pay for Mozilla's open source software or use of its servers to store your personal data (email, calendar, files, etc.).
We are told that Mozilla has to keep pace with Chrome (because ..., and that's because ....), and the only way they believe they can do that is to take money from Google. Mozilla's CEO and employees are far too expensive for their salaries to ever be paid by end users.
Especially when a small unknown company can take the same abandoned platform to become a viable player in the smartphone ecosystem[1] just by targeting the right device for the OS & right strategic partnerships.
At least Mozilla seems to have signed a deal with KaiOS to develop the Gecko engine further[2].
[1]https://en.wikipedia.org/wiki/KaiOS
[2]https://www.kaiostech.com/press/kaios-technologies-and-mozil...
I agree with your second paragraph, which is more in line with directly supporting Firefox and other products with money.
[1] https://nordvpn.com/white-label/
[2] https://vpnscam.com/tesonet-data-mining-company-owns-nordvpn...
https://mullvad.net/en/blog/2019/12/3/mullvad-partnerships-p...
From the privacy point of view, Mullvad doesn't ask for an email address, accepts payments in cash, publicly states the full names of all the people behind the company, and doesn't pay any affiliate commissions.
It was fairly popular in some corporates for a while, until Lotus/IBM and MS stepped up their collaboration game.
---
Although a great 'client' experience is absolutely crucial for Firefox Premium's success and would be a modern resurrection of Netscape Communicator in that sense, what I mostly need is convenient 'servers' from a company that I can trust and a business model I can support. In a sense that would be a modern way of meeting the needs of Netscape Communicator, sure :)
Would you then use a Mozilla run mail service similar to gmail complete with calendaring and document storage, all built into a suite of client apps ?
I think for a certain demographic this could turn into a good Google competitor if done right.
Or they push thunderbird, the mail-client they brought into the world to just ignore it for such a long time. A trustable privacy-first mail-client with brainless configuration and maybe some useful modern PIM-features would sell well enough to satisfy a price. I mean there are already services doing that, mozilla couild cooperate with them or just push their own weight in the ring.
Or just putting their support behind one?
Too much power corrupts.
So why people are buying this service confuses me.
I am also confused at why people can run these services so cheaply. I looked into doing it myself (I had some ideas for actual value add), and the economics didn't seem that good. There is a lot of software between "ifup wg0" and "collect money from people that want a VPN". It seems expensive to write all that, unless a "yolo" strategy of starting up openvpn and setting up a couple NAT rules actually scales. (At the very least, you need to be able to distribute keys to pre-built clients, and if you want to make it smooth, you are looking at writing your own Windows/Mac/Android/iOS clients. Then you need all the business management software on top of that -- didn't get the Bitcoins so delete their private key, etc.) It seems like quite a bit of work that is quite expensive.
But these things exist left and right and have huge advertising budgets. So obviously I am misunderstanding something.
The fact that all these people are paying for a service plus VPN means the services are leaving money on the table. If they would simply offer what we want, when we want, where we want it, on the device we want, on a single service without a hassle, many consumer would be lined up for that.
If I am not mistaken, that's 10 hours of video streaming in excellent quality per day.
that Facebook cookie works regardless of what your IP address is
Firefox has been blocking third-party cookies by known trackers, including Facebook, since last year [1]. Safari started blocking all third-party cookies (not just known trackers) in March [2], and Chrome committed in January to work towards removing third-party cookies [3].
And of course, all major browsers have provided the option to block third-party cookies since before IE6. I use this option, it rarely breaks things, and it's only getting rarer—and I don't use a VPN, so this would make me measurably harder to track across sites.
[1]: https://blog.mozilla.org/blog/2019/09/03/todays-firefox-bloc... [2]: https://webkit.org/blog/10218/full-third-party-cookie-blocki... [3]: https://blog.chromium.org/2020/01/building-more-private-web-...
I don't understand this argument, but would like to.
I run https://everytwoyears.org, a political non-profit focused on ending the warrantless metadata collection of U.S. citizens' communications. From everything I know about these programs, they are _explicitly_ not collecting content of communications. These programs only collect the metadata about a communication. As citizens, we don't get to have a clear definition of "metadata" (that is classified!) but we can assume anything that isn't the message itself is at risk of being considered metadata, especially if it was shared with a service provider in the normal course of conducting business (i.e. routing a request).
For HTTP requests, I assume the body of the request would require a warrant before it can be persisted on a government server. The HTTP headers, if unencrypted, _might_ be considered metadata but I would be surprised. The IPV4 headers are more than likely metadata. DNS queries are more than likely metadata.
If you are trying to avoid _active_ surveillance, where your government has a warrant, a VPN isn't going to help you. If you are trying to avoid _active_ surveillance where your adversary doesn't need/want a warrant to search you, a VPN isn't going to help you. But if you are trying to avoid having your internet activity ending up, de-anonymized, in a metadata database that your government does bulk analysis on, a VPN does seem like it would help. It seems like it would help a lot.
There are a lot of people that think anything less than 100% isn't worth your time, so they suggest TOR - but TOR has all sorts of annoying limitations that preclude daily usage. Absolute solutions are seldom worth the 10x extra effort they frequently require.
Another set of half-solutions can be seen here which will make you more secure...
https://www.cloudflare.com/ssl/encrypted-sni/
ESNI, DoH, DNSSEC, and TLS1.3 are fairly easy to setup - and worth your time .
Using Firefox with uBlock Origin & PrivacyBadger plus the above gets me to a good enough place.
Illegal stuff on the other hand -> TOR.
The problem with doing illegal stuff with only half-protections is that the authorities don't need to use the metadata to prove your guilt. After they raid your house they'll have all the parallel construction they need to make it stick. ...then again if you're just buying personal use amounts of drugs - no one at the FBI cares.
Tunneling (even through TOR) isn't sufficient if you have someone well funded, highly skilled, and very motivated to watch you. I would posit that purely technical solutions will never solve human problems. Perfect, unbreakable, encryption can be trivially passed with a set of cleverly placed jumper cables.
The key, in my opinion, is trying to align technology with the laws that (mostly) already successfully protect us from jumper cable wielding adversaries.
From my understanding, The U.S. government interprets "metadata" as having no societal expectation of privacy and therefor they don't need a warrant to collect it. These questionable metadata collection programs seem like they can be effectively thwarted through half measures, like E2E encryption of the metadata (use HTTPS and DNS over HTTPS), obfuscation of the metadata through tunneling (use VPNs), etc.
Some metadata I don't have a good answer for, like location data when my cellphone pings the local towers. I can chose to share my location data w/ the tower so it can route calls to me, and submit to that possibly ending up in a government database, or I can keep my phone from talking to the cell tower being unable to send/receive calls. I don't see a half measure...
I was using Brave until this story came out and switched over to Vivaldi for the stuff that absolutely demands the Blink engine.
Point one, if they _repeatedly_ continue to do this kind of thing, what kind of stuff are they also getting away with? Or what's the next big surprise around the corner?
The second point is I really no prefer Vivaldi as things like sync work (it's been broken for a long time in Brave) and there's more exposed in the prefs for techie types who like to tinker with that kind of thing.
Firefox continues to be the every day browser and it keeps getting better as time goes on (another +1 for take my money for email, calendar, file storage, etc.).
This has the added benefit of being good for the whole network (your whole house) including gaming systems and smart TVs.
Unencryptable metadata (destination IP) makes it pretty worthless. Even on shared services like Cloudflare, things that are of interest for collection are probably paying enough that they get stuck on dedicated IPs. The 4chans of the world that might not be paying still make sense from a provider perspective to move to isolated IPs for DDoS mitigation.
Censoring proxies actually look at SNI to deconflict shared IPs where pornsite.com and travelblog.com are on the same Cloudflare IP, and will just revert to blocking the destination by default.
(I'm picking on Cloudflare here specifically because they are pushing it - but this applies to MaxCDN, Akamai, etc just as much)
Good. That's way better than being able to tell which site you were trying to go to. It's more expensive for the misbehaving network operators as well; block some popular sites just because they share an IP address with something you want to censor and people are bound to complain, even if they couldn't care less about the censored sites.
A public VPN service is good for localized privacy. Even a cheap Ubiquity setup will be able to tell about your habits. It's probably good enough to avoid the attention of a civil or informal inquiry (DMCA, employer, etc).
It's not clear to me whether the methods trackers use to de-anonymize you are considered "content" or "metadata", and whether the U.S. government would need a warrant to access tracker information.
Do you have thoughts?
VPNs seems like a really obvious bypass of controls and surveillance capability. I’m sure the folks at NSA, et al thought of it too.
Just because they know its a way to thwart their system doesn't mean they have another "legal" way to collect the same data.
I use Mullvad, paid using BTC that came straight from a tumbler. I don't use it for any nefarious reasons, just wanted to see how such a setup would work. It was surprisingly painless. I think it took 15 minutes in total from moving my btc to the tumbler and having the tumbler move the btc to my Mullvad account.
Am I 100% secure? No, they know what IP I'm connecting from. Is my name attached to the VPN? No, not even close. I suppose if I wanted to further improve my security I wouldn't use my own home network, but public wifi's nearby.
But again, I didn't do it to stay "safe" or anonymous. Just wanted to see how the process would actually be.
> But again, I didn't do it to stay "safe" or anonymous.
I sincerely hope that you're trying to stay safe if you're admitting to money laundering on a public forum.
Tumbling coins is just obscuring their origin.
The two don't inherently have anything to do with each other.
Even if you tumble "dirty" coins, you've got to explain to the IRS the source of income behind the new coins. Tumbling, in and of itself, doesn't achieve that.
It's not right, but that's the way the rules are written.
Someone should let FinCEN know that their definition is incorrect: https://www.fincen.gov/history-anti-money-laundering-laws
Even if you don't have a static IP, I suspect the entropy of your /24 (IPv4) is also a lot smaller when over VPN.
Thus we only have to establish that the VPN provider is at least as trustworthy as my ISP. That's a pretty low bar to clear in many places. I have no doubt some VPNs are operated by nefarious actors (no better way to collect high quality data), but I don't think that's a concern with Mozilla.
Write-ups of the 2013 leaks revealed they did not compel ISPs to correlate traffic to subscriber information. It doesn't seem like they had any subscriber information in their database, only enough metadata about the communications to later compel a ISP to provide the subscriber information _postmortem_ (i.e. who did this cellphone number belong to on this date?).
ISPs weren't even compelled to share that metadata. It was a voluntary program. Some ISPs said no. Others said yes and then later backed out. In the end something like 80% of the traffic the NSA was after was able to be collected through the ISPs that voluntarily shared their data.
But, again, this was 2013. 2013 was forever ago, things may have changed.
Yes, now the NSA have a single point where data can be collected that would be much more interesting than at your ISP.
I think the key for me is that, at least under the original Presidential Surveillance Program, the providers that participated were not compelled to share their user's metadata. They shared it willingly, regularly, and in bulk. There is reference to a service provider backing out of this agreement a few years later, telling the NSA they would feel more comfortable sharing the data if it were compelled.
It's not clear if this has changed since 2013. But assuming Mozilla, or Mullvad, isn't compelled to share _all of their data_ it seems unlikely that they would willingly give that up to a government surveillance program.
I think ISPs have demonstrated they aren't trustworthy. For most people in the U.S., it seems, finding someone more trustworthy than their ISP is literally anyone who isn't admitting that they collect and share their private data. I would be surprised if Mozilla doesn't clear this bar.
This is the explicit danger of VPN providers. Even if the provider is not complicit (which I believe applies to the likes of Mozilla), it still creates a centralized aggregation site for collection.
I'm not even sure a US-based VPN provider is safe. GCHQ just conducts the interception and would share the data with NSA. At that point, you are at the mercy of the NSAs locators being good enough to flag your tunneled traffic as "reasonably a US person" so it gets excluded.
Oh, I am sure that it is not safe, thanks to the PATRIOT Act. Even if they were not storing any metadata, VPN providers can be compelled to 1) share all data about their subscribers, which will include you, then 2) silently wiretap and decrypt everything. US courts will rubber-stamp, as they've consistently done in the past, and "that's all, folks".
Sadly it's not like you'll be much safer elsewhere: as soon as you step outside of the US, one of the strongest cybersec agencies on the planet (NSA) will have free reign on your traffic. But you can resist the legal attack (in some countries) and at least try to make it challenging on a technical level.
I hope Mozilla want to bring some innovation to the table that will make VPNs somehow more resistant to legal attack (not just in the US) but I doubt it.
From write-ups of the 2013 leaks, we saw references to violations of the legal theory used to justify the Presidential Surveillance Program. One of those violations was them unintentionally collecting the wrong data, due to how the ISP was bundling packets or something like that, which constituted a warrantless search, and they supposedly took that very seriously because it jeopardized the whole program.
My take on the surveillance program is that they try very hard to be law abiding, even if they have to stretch what the law means to justify the program. If you are worried they have a warrant for your communication, a VPN isn't going to help you. If they don't have a warrant, they will avoid U.S. citizen's content like the plague for fear of compromising the whole program.
If you do use a VPN to mask your traffic, there are two questions to ask yourself:
1. who are you masking your traffic from?
2. can you trust the VPN network more?
In general, you cannot trust a VPN network more, and HTTPS is the solution as it provides end-to-end encryption with some important caveats (web PKI)
Running your own VPN is not a good solution either, because who owns the servers where your VPN is running?
The bulk metadata programs, as far as we know, only collect metadata. Which two IP addresses communicated, the routes they took, the size of the payloads, etc. are all "metadata".
HTTPS, AFAIK, does not solve this.
Metadata is obviously the least important data to analyze, but for example a VPN does not hide the size of payloads. TLS 1.3 do addresses that and let's you randomly pad messages but I don't think anybody use that.
I also trust many VPN providers more than my ISP, which actively engages in MITM like compressing images to be a lower resolution on HTTP pages on 4G networks.
ISPs can observe your DNS lookups to their servers and assemble a profile on you based on the domain names you look up, and put you into a series of audiences that marketers can then use (for a fee) for ad targeting.
ISPs can also observer your DNS lookups to Google’s or anyone else’s public DNS servers.
ISPs can snoop on your unencrypted traffic, proxy it, and inject headers into HTTP responses to facilitate (you guessed it) the creation and sale of audience data to advertisers.
ISPs can transcode (and downsample) multimedia content to decongest their pipes or airwaves.
If you are a spy or a member of a disfavored political group, you should almost appreciate the scummy practices of ISPs, as it drives a bunch of non-spies and people not associated with disfavored political groups to adopt privacy-enhancing technologies.
If I worked at the NSA or CIA or FSB or Mossad or wherever, I would highly encourage lawmakers to enact laws to protect consumer privacy in order to drastically reduce the perceived need for people not in the above groups (et alia) to adopt VPNs and other technologies; there would be fewer “boring” people using such technologies, giving the needles a lot less haystack to get lost in.
edw, could you elaborate on that, please? I thought changing to public DNS servers like OpenDNS provides some security from ISP tracking.
(I suppose this is one of the problems that DNS-over-HTTPS is designed to fix.)
...
DNS-over-HTTPS can be enabled in Firefox via Network settings, turns out.
Test your own ISP: try something like
nslookup news.ycombinator.com 1.2.3.4
If you get a response, your ISP is gaslighting you.
First, geo blocking often catches it or provider has moved to other means to verify address. I don't use Netflix but for certain streaming sites in Japan that I use and BBC express does nothing.
Second, it doesn't get pass GFW whereas shadowsocks based solution does.
Overall it seems the only benefits are getting better speed sometimes and theoretical privacy benefits.
Protocols are not designed for what we use them for, and buggy legacy applications that won't change their protocols or implement them correctly. The more people use VPNs, the more the problem gets buried behind a wall of abstraction. The proliferation of VPNs is really the burying of a problem, not the solution.
I don't care about being tracked, because I live my life in the open. I'm not a vulnerable minority, so I don't fear for my safety. I don't care what a random corporation (or anyone, really) knows about me. You could log into every digital account I have, and the only thing I'd be worried about you finding is an active session to my bank's website if I was still logged in at the time. I don't care if my ISP "monetizes me".
I also know how to browse the web as securely as possible, and that there are plenty of ways I can be hacked regardless of my network connection. The biggest risk I face is not from a VPN, but from my local network: if my internet modem or router gets compromised (either remotely or through my machine), I'm subject to local attacks a VPN won't protect me from. And if the government wants to hack me, they'll just guess what websites I'm viewing (either by conventional means or statistical traffic analysis), hack the server, and drop a payload through a browser 0-day.
I could see using a VPN if I was an activist, or of a class of citizen that's oppressed by my society or government. But even then, they'd figure out I was using a VPN, and realize I'm hiding something. So you could argue everyone should be on a VPN to make this less noticeable.
But then we go back to the beginning: we're not solving the root problem.
1. Tor is (rightly) used by anyone who has a good reason for remaining anonymous. (See [REALNAMES] for who this can be.) Anyone trying to smear Tor as only used by drug dealers and other unsavory types are themselves suspect of having an agenda of discouraging Tor use for anyone lest they be suspected. This can only lead to an installation of Tor being viewed as a suspicious thing in itself; who would want that?
2. His threat model of Mossad or not-Mossad leaves out one important actor, which we can call the NSA. They, and others like them, unlike Mossad, are not after you personally in that they don't want to do anything to you. Not immediately. Not now. They simply want to get to know you better. They are gathering information. All the information. What you do, what you buy, how you vote, what you think. And they want to do this to everybody, all the time. This might or not bite you in the future. He seems to imply that since nothing immediately bad is happening by using slightly bad security, then it’s OK and we shouldn’t worry about it, since Mossad is not after us. I think that we should have a slightly longer view of what allowing NSA (et al.) to know everything about everybody would mean, and who NSA could some day give this information to, and what those people could do with the information. You have to think a few steps ahead to realize the danger.
[REALNAMES] Who is harmed by a "Real Names" policy? https://geekfeminism.wikia.org/wiki/Who_is_harmed_by_a_%22Re...
Do you have thoughts?
> We know that we are on the right path to building a VPN that makes your online experience safer
Commercial VPNs are good for censorship circumvention or location spoofing. It is irresponsible to market VPNs as something which “protects” you online. In reality, they do nothing to improve security, and very little to improve privacy.
You do not need a VPN.
https://gist.github.com/joepie91/5a9909939e6ce7d09e29
https://schub.io/blog/2019/04/08/very-precarious-narrative.h...
The issue is, VPN companies (Mozilla included) are marketing their service as one that improves your safety when it doesn’t.
Given what we publicly know about these surveillance programs I could see FISC approving bulk metadata collection for the IPv4 header content, insecure HTTP header content, and DNS queries.
Wouldn't using a VPN, DNS over HTTPS, and HTTPS everywhere shield you from these bulk metadata collection programs? I run https://everytwoyears.org, a political non-profit focused on ending these programs, and I view VPNs as a key technical piece of preventing these metadata collection programs from functioning; if the security community doesn't believe they are effective, I would really like to know!
Another way of saying this: collecting _content_ of a communication requires a warrant (and our mass surveillance programs respect that from what we publicly know). Most people that I know aren't trying to avoid active (we have a warrant to search you) monitoring with a VPN, but trying to avoid passive warrantless monitoring. Obscuring communication metadata through encryption and tunneling seems to be an effective way of doing this.
If the government is able to passively collect metadata from your ISP, couldn’t they do the same thing with a VPN company?
This may have changed since 2013.
What percent of the public do you think uses a VPN? And do you think VPN users are a representative sample of the general public?
And for all of those not using a VPN, just ask the ISPs.
This is a bad take. I don't have the energy/time to go too in depth at the moment, but I've commented in more detail in the past. The short version:
- HTTPS isn't perfect, sites sometimes support old encryption protocols that can leak resource information. Most users aren't checking packets from native apps to ensure they're being sent over HTTPS, and browsers don't mark sites that are configured for old SSL/TLS versions as insecure.
- Most people aren't currently using encrypted DNS, and even as browsers like Firefox and Chrome move to turn it on by default, there will still be tons of older devices and native applications that lag behind.
- VPNs only encrypt your connection from you to the provider, but the space between you and the provider is the part that's most likely to be targeted by attackers. You are far more likely to accidentally send a plaintext POST request to an infected router than you are to be targeted by a nation-state actor on the open web.
- VPNs aren't just for hiding what sites you visit from your ISP, they're also for hiding your IP address. The linked claim that IP addresses are irrelevant is just outright wrong, IP addresses are extremely helpful for doxing, and sites like forums don't always secure them[0]. If you know my IP address, you'll be able to get surprisingly close to my real address.
A VPN on its own will not protect you or provide you with a noticeable privacy increase. And a VPN should not be the first thing you reach for if you're trying to improve your privacy. But if you're already using an adblocker, if you're already taking steps to mitigate tracking in Firefox, if you're already disabling Javascript on most sites, if you're already avoiding native apps that break the browser sandbox or engage in hardware tracking, you do eventually reach a point where your IP address is a concern you will want to address.
Ask yourself a few questions:
- If IP addresses don't actually matter for tracking, then why is TOR wasting so much time and energy trying to mask them?
- If masking an IP address doesn't provide any extra privacy, why do some services like Google Captcha penalize shared IP addresses?
- If IP addresses don't matter for tracking, why are so many sites using IP bans at all?
The answer is that IP addresses do matter, they're just not the only thing that matters.
----
> feel empowered, safe, and independent while being online
Huh? This is doing nothing to protect me from any of the common attacks. It's not wiping my cookies. It's not anonymizing my browser fingerprinting. It's not blocking analytics or tracking. It's certainly not protecting my credit card details or password from being hacked from a website's server.
Am I more "empowered"? "Safe"? "Independent"? What is this nonsense marketing fluff?
To market this as being able to control my privacy or stay safe online is just completely disingenuous. Mozilla should be ashamed for trying to imply such strong claims that are just false.
Mullvad additionally supports OpenVPN and other protocols, and is client-agnostic.
That's great - less features and options are a plus for vpn services.
> requires you to use their custom app.
Sounds odd, if it's just using wireguard.
Guard rails can be good depending on your audience.
They support OpenVPN for when that's needed.
Making deeper data exploration possible is a work in progress, but you can see what I have so far here: https://vpnwire.co
Amazing that GSuite's only real competitor in 2020 in Office365.
I'd trust Mozilla.
Purism's Librem One suite [0] comes the closest, but I just don't have the trust in them that I'd want before pulling the trigger. They have a history of making grand claims with sub-par delivery, which just doesn't cut it for a service like a primary email provider. They've claimed plans to add features like file storage for ages now with no updates. Email is just too important a part of daily life to risk it.
I would 100% sign up for hey if I didn't migrate to Fastmail this year.
If you are on public wifi somewhere and are concerned about traffic that isn't otherwise encrypted (DNS comes to mind), or if your connection is in some way restricted (govt, shitty isp, etc), then a VPN can address these issues. But you have to keep in mind that your new network is similarly untrustworthy.
You might argue that by hiding behind your VPN provider, you are gaining anonymity. This might be true under the best circumstances, but this can _very_ easily break down. For example, the moment you load tracking_pixel.png then you are de-anonymized. That is saying nothing about the shady practices of the VPN providers themselves, or the governments that regulate them.
When people connect to a VPN, especially lay-people, there is this feeling that the VPN is providing security, and privacy. This is largely marketing BS designed to sell more subscriptions. When I connect to a VPN I might be able to obscure my activity from state actors, or avoid some coffee shops bogus DNS server. What I can't do with a VPN is avoid literally every other form of tracking. And of course if I connect to a VPN, then I should be ok with those same bad-actors knowing I am connecting to a VPN. And I should be OK with the VPN provider being able to monitor my unencrypted traffic. And I should be ok aggregating all of my encrypted traffic into one easy to watch place.
So what is a VPN providing the average consumer? If you want privacy install ad block software, https everywhere, enable DoH, don't log into social media sites, and clear your browser's cache frequently. If you want to avoid a state actor, then your best hope is probably something like Tor Browser.
Well, does it make people empowered, safe and independent? Never mind what people feel - the users don't know the details of the implementation, so their belief could be mistaken.
Mozilla controls my browser. I have no interest in giving them control over any other part of my online life.
I like how Mozilla is run and hope other organizations emulate them to provide these other essential services.
I guess all these additional services help lure more users to Firefox, so there’s that.
Maybe Mozilla can eventually generate enough revenue to stop nuzzling on Google’s money teat.
I think I just convinced myself that additional services are good overall for Mozilla. But yes, I’m firmly in the spread your online presence wide camp.
Price related I'm paying 5€/month for Mullvad and Mozilla's VPN is at $4.99/month so when it will be available in Europe I expect it to be 4.99€.
If they where offering something more, I'll see the point, but here by them developping their own software to use someone else infrastructure seems to be a huge waste. If they wanted to put their Mozilla logo, they should have gone for a white-label product with Mullvad no ?
Of course there's also the shady side of VPN use. If you're doing that it might be beneficial to use the VPN within a VM with strict firewall rules, i.e. only allow incoming/outgoing to/from the VPN. Doing so allows you to only send the traffic you want to over the VPN, thus reducing your exposure to any nefarious data collection that the provider might be doing.
Please help making Internet decentralized and private again.
* Support for paying content creators without advertising * Decentralized CDN and compute * fast privacy
For example, a while back there were research showing nord was setting up users as proxies, there by making it impossible for Netflix to block these residential ips.
I don’t think Mozilla will do this.
VPN's are the only way of protecting what should be protected speech. You have to not keep logs or anything that allows a court to find the identity of a user.
You don't. You never will. This is the case not just for Mozilla but for all VPN services.
Until there's some kind of hardware-level attestation that verifies a server is running a particular software installation, that's going to remain the case.
> VPN's are the only way of protecting what should be protected speech.
No, if you want safety, a VPN is not the solution. VPN providers have invested a lot of marketing in trying to tell you otherwise but it's simply not true.
All a VPN does is move what little trust you're forced to have in your ISP to a different, often less-regulated ISP.
The solution if you want privacy and/or anonymity is a technology built for that purpose, like Tor or I2P.
"Less-regulated" is usually the entire point of using a VPN. Regulations force your local ISP to keep detailed logs and reveal who was using a certain IP address at a certain time to various entities based on sketchy circumstantial evidence. If you go through a VPN then anyone trying to track back the IP address has to go through the VPN provider first—who probably doesn't keep such detailed access logs, and may well be in a completely different jurisdiction—before they can even begin to approach your local ISP. You certainly shouldn't rely on it exclusively, but it's an important part of defense-in-depth.
I download music, movie, tv, etc files via torrent using my Canadian IP address and I have never seen anything more than an email from my ISP saying essentially "so and so company thinks you downloaded their material, don't do that ok?".
Is the general public so afraid of getting the odd email that paying $5/$10 month to make them disappear is a good deal for them?
Why wouldn't people just use TOR for free? It was extremely fast the last I checked.
i use a VPN (to Montreal since it supports port forwarding) because i work from home and i don't want my IP that VPNs to work for a major company also being part of a torrent swarm.
A cunning way of not starting any rules used for the VPN.
Then they can say "well we were guided by our policy when we secretly kept all your connection details and gave them to a marketing company".
How about being guided by your policies on openness and state precisely and fully how data is used/stored/shared.
Isn't privacy the/a principle feature of a VPN?
The irony of only being able to sign up from outside the USA of you use a VPN is not lost on me.
Naming things: one of the truly hard things in computer science... (But come on, you don't have to fail _that_ hard Mozilla, surely?)
:sigh:
The only people I know that uses VPNs do so to download torrents and evade DMCA notices. And in that case it only really works if the VPN provider is itself located outside of US jurisdiction and collects little to no information about you the user.
What is the reason for developers to pay for this service when they can set one up in less than 5 minutes and automate the whole thing with user-init scripts.
Just to prevent the backend IP address correlation between sites that trackers use.
Technically I know this is probably impossible without tons of virtual NICs
You're better off using Mullvad directly--it looks like they don't require you to fork over personal information to use their service.
Shameless plug: SatoshiVPN (https://satoshivpn.com) gives you access to your own private and anonymous VPN server with Outline pre-installed, no questions asked. Payments in Bitcoin only.
Because most peoples threat model doesn't include actors that can force a VPN provider to give up their data. They just use it because it's making it easier to not get data stolen in a coffee shop and watch US Netflix.
If there's a new provider out with no name, company address, audits or history and tells me they are not sharing personal information I just have to take their word for it. So it's not much better than the alternative if I can't verify it.
Compare this to your ISP and telecom providers. A subset of the larger providers willingly handed over the communication metadata of their users without warrant.
https://www.pta.gov.pk/en/media-center/single-media/public-n...
I wouldn’t expect much different here.
What do you mean? I paid NordVPM for a 2-year contract, which expires in a few weeks. What does "locks locks" refer to?
What have these "feelings" got to do with anything? This is a measure of successful marketing and has nothing to do with the product or its efficacy.
Personally I use Windscribe and I really like it (I've used PIA & Mullvad in the past). I use it for watching US Netflix and to make it slightly less easy to track me on the net (I know there are many other ways). I also like the idea of not having my IP or the gov't spy on me _as easily_.
A product has to get you “Made, Paid or Laid“
Where Made was like a sense of positive promotion like a made-man in the mob I think.
Emotion is everything. If a product doesn’t make you feel good you’ll only buy it because you have to.
I understand you're talking about where those feelings come from -- ie, that the feelings are more useful information when backed by the reason for them. And you do provide some of that in your post (privacy, watching US Netflix). But those are things that any trustworthy VPN with US-based endpoints can provide, so they're not a unique selling point, which means your recommendation basically boils down to unsubstantiated feelings again, to which:
=== Original comment ===
I don't use a VPN and have no horse in this race, but surely you see the irony in:
> What have these "feelings" got to do with anything?
Followed by
> I use Windscribe and I really like it.
So why do I like Windscribe? Good question! I like the ease of use of windscribe clients compared to other VPN clients I've used, the fact that I can add many devices, and the fact that it has endpoints in lots of countries. I had trouble with both the PIA & Mullvad clients & configuration on my desktop and phone eventually. I don't require much, as you say VPN is a commodity product, I just want it to be easy to use & Windscribe is and they seem committed to adding features & fixing bugs. I also have met the team, they're local to me, and they seem trustworthy.
I'm not sure if you read TFA, but here's the context of what I highlighted:
> We started working with a small group of you and learned a lot. With the VPN in your hands, we confirmed some of our initial hypotheses and identified important priorities for the future. For example, over 70% of early Beta-testers say that the VPN helps them feel empowered, safe, and independent while being online.
"we confirmed some of our initial hypotheses and identified important priorities for the future ... Beta-testers say that the VPN helps them feel empowered, safe, and independent"
What type of initial hypotheses might have been confirmed by learning that people "feel empowered" by using a VPN? This is what I don't understand. Of course users motivated enough to try a beta VPN product like using VPNs–I'm not sure what insight that adds. Can you help me connect the dots here?
My feelings about a VPN provider based on personal experience is not beta testing that "proves" a product. Mozilla suggests here that these "feelings" prove "confirm their hypothesis" and put numbers next to the feelings, like 70%. I am questioning the relevancy of these numbers & it strikes me as pseudo-scientific to put these numbers in the intro as some sort of proof that their product has value. Throwing up meaningless numbers like this gives me the impression of smoke and mirrors/bullshit.
Thank you for the feedback. It wasn't meant to be rude, but I see now how it can be interpreted that way (particularly with the unedited original comment below, which was intended to be... not rude, but let's say, harsher than I'm proud of, a few hours later). Text is hard -.-
Asking clarifying questions instead is a good suggestion. Your answers are good, too; if I'm ever in the vpn market, I'll put Windscribe on my shortlist to research more thoroughly.
> I'm not sure if you read TFA
I have not and do not currently intend to. I checked in with the comments because I was curious how it would be received. I replied to your comment because I was frustrated at what seemed to be hypocritical criticism. I still think your original comment is light on detail/justificatipn, so I'm happy my reply, however rude and imperfect, lead to your second comment, which is the type of thing I was hoping to find when I opened the thread :)
Remember Foucault's panopticon: If someone merely thinks they might be surveilled their behavior will change in profound ways. More concretely, if you think the government may be spying on your browsing habits, maybe there are sites you won't visit or comments you won't post or videos you won't watch. It's important not only that the product works, but that people feel it works so that they can behave more freely on the internet.
Any VPN subscribers want to fill me in? The only thing I can think of is hiding the source of pirated media being shared via bittorrent.
I use a VPN daily because without it, there is no Twitter/HackerNews/Reddit/Youtube/... .
As for tracking you and selling your data, I trust my ISP to behave better in that regard than I do some shady VPN provider. And I don’t even trust my IP that much.
And there are people who use it for more legal media consumption, like paying for a subscription-based service and the shows/movies they want to see are region locked.
1) You live in an authoritarian country where mass surveillance is a concern.
2) Evading geo restrictions. Watching US Netlix while in Europe, etc.
3) Evading your work's firewall so they don't know you're on Facebook or whatever.
4) Piracy
I am, in principle against this policy. When it was proposed, I tried activism and letter writing and meeting with Senate staffers to try and fight it. I lost, it became law with bipartisan support from both major parties here. So now I use a VPN.
You find my usecase baffling?
How is this a "launch"? And also, this makes it a bit fishy if you ask me.
Any point's for 'Blokada' being more trustworthy than AT&T ;)
Blokada is pretty popular for Ad blocking on Android. And it's open source too: https://github.com/blokadaorg/blokada
They seem to be relatively safe from forking though, because apparently the code base is too much of a mess. Yay.
Also, your complaint about an ethical business model seems unfounded, especially in this instance.
Which does not pay for the development of Firefox.
If that doesn't satisfy you, note that targetted donations are also a thing.
In other words, targeted donations are not a targeted budget increase.
I have no concern about the VPN service itself since it's Mullvad which I like, but the devaluation of the branding (which I consider a long term problem).
Look at stuff like Firefox Send and Pocket. The latter is proprietary (holy shit, how is that ethical?) and the former bugs you with in-page pop-ups to get an account when you try to change the settings that looks either very stupid or malicious (and they invested a lot of money). I thought it was a bug at first.
They may sound like specific petty issues, but I consider them symptoms of a gigantic systemic problem.
I am aware of Mozilla's financial struggle, but don't think this is a good way to solve it, or much of a viable one at all. I fear it will completely dilute the Firefox brand, lose core user's trust (what they have left, anyway) and result in barely any revenue. It may well result in the permanent ruin of the Firefox (the browser) project, especially since it appears to be 100% dependent on Mozilla because of its high entry barrier.
I do see the idea behind the pivot I think, which is banking on the rising popularity of privacy, but honestly I don't think they even have much of a good reputation on that front. The wide public doesn't know ("Mozilla is like Google, right?") and the techies have been burned too often. Neither do they explain much in their surprisingly widely deployed phsyical ads (how much did that cost?).