Secure your browsing using a home VPN
sriramk.com
sriramk.com
I'd love feedback from the HN community!
Grab the app, enter your Cloak credentials, and you're done. If Cloak sees you're on on a password-less wireless network, it automatically activates. Cloak's servers are cloud-hosted; the client selects the back-end server that will give the lowest latency. Under the hood, Cloak for OSX is built on industry-standard OpenVPN.
I expect Cloak will exit beta when the iPhone/iPad client is finished, probably in early September. But if you'd like to try it sooner, drop me a line [davepeck at getcloak dot com] and I'll send you a special HN invite code. Cheers!
We support all devices (OpenVPN, PPTP, IPSEC/L2TP) and have servers in US west/midwest/east, UK, and Switzerland.
INFO WE COLLECT
From Clients of our Service
Date and time you connect/disconnect to/from the service. Source IP you use to connect to the service. Bandwidth usage E-mail provided by Paypal. Paypal payment data.
And then this:
DISCLOSURE
If under subpoena, PrivateInternetAccess.com may release data in order to comply with legal obligations or in order to enforce the PrivateInternetAccess.com Terms of Service and/or other agreements.
PrivateInternetAccess.com may release data in order to protect the rights, property and/or safety of PrivateInternetAccess.com, its constituents, and/or other visitors and clients.
http://support.apple.com/kb/dl851 http://support.apple.com/kb/dl926
> Here’s why I picked PPTP and I believe using it with very long passwords/passphrases is acceptable.
Bear in mind that the author is looking to use this in open hotspots such as coffee shops etc. I would not advise that people implement this.
As the author points out, there are a number of vulnerabilities in PPTP, the most serious of which is that the initiation protocol is susceptible to an offline brute force attack using tools like asleap[1].
To be clear, the attacker does not need a rogue access point, nor association with an access point for this to work. They can just passively sniff away, then at some point later go through the pcaps, crack it offline and do what they want. There's an episode of Hak5[2] covering this as well as this useful straight to the point video of asleep and THC pptp-bruter[3]
[1] http://www.willhackforsushi.com/Asleap.html [2] http://revision3.com/hak5/asleap [3] http://blip.tv/g0tmi1k/cracking-vpns-asleap-and-thc-pptp-bru...
The solution is to use L2TP and IPSec if you can and aren't jailbreaking, or to use a TLS VPN if you have jailbroken or don't have iDevices.
It is clear you have put a lot of effort into it though and it's more well written than a lot of guides I've seen, hence my interest in the first place!
If the adversary is reasonably well organised they might use something like AWS to offload the cracking, in which case they may well expend more resources on a bigger and more wordlist. Cloud-based cracking is really interesting, especially when GPU support comes into play as most of the traditional models of attack complexity fall like a house of cards once your average joe can get the kind of supercomputing power only previously available to three letter agencies.
In all honesty I would just avoid PPTP and stick to L2TP or an SSL-based VPN. In TFA the author chose PPTP because he wanted to stick what was available on his router and compatible with his devices. I understand their decision, although personally I don't see this as being any more secure than running a password protected browser-based file manager and port forwarding it to the world. You'd still have to obtain a password, but it's not hard.
So I'm pretty safe from snooping by my employer, home ISP, or whatever 133t hackers are sniffing traffic at McDonald's when I'm browsing and sipping a coffee.
It's not the most elegant solution, but it does the trick. I supposed some day I'll mess around with OpenVPN (which I have deployed before, and do really like), but only when I'm bored or otherwise have nothing else better to do with my time.
it's worth pointing out that you only gain privacy for browsers and apps that _choose_ to use IE's proxy settings. your native IM client, even if it is using HTTP, may or may not use the proxy. Your remote desktop client probably isn't using HTTP so it can't use the proxy.
with VPN you just don't care, all network traffic is routed through the VPN at network-driver level.
The easiest way around this is VPN, but you can also do crazier stuff like use ProxyCap (for windows or OSX) or iptables redirect/transocks setup in Linux: http://coderrr.wordpress.com/2009/07/29/how-to-force-flash-o...
[1] https://github.com/apenwarr/sshuttle [2] For Lion: https://github.com/thatha/sshuttle/blob/macos_10_7_only_hack...
Care to share your squid.conf? I just want a non-caching anonymous forwarding proxy and am finding the huge amount of options a bit of a muddle to work through. Seeing yours would be a help, if you are ok with that.
no_cache deny all
forwarded_for off
via off
The first disables caching, and the last two are for a little extra privacy. You can verify if you're caching by checking your cache spool for files: find /var/spool/squid/ -type fhttp://flatterline.com/index.php/2009/04/23/disposable-proxy...
http://news.ycombinator.com/item?id=2441535
It sucks, but I can see the reason why they just blanket block EC2 rather than trying to find any more nuanced way to identify scrapers.
If I were running scraping bots on EC2, rate-limiting me isn't a real threat since the instant I get throttled for misuse I can just destroy the instance, start up a brand new one on a different IP address, and continue as I was before.
It was a huge pain in the neck to get native support on Mac & various windows flavours. But our normal clients needed a good solution for testing flash & silverlight apps.
Can you comment on how you can offer 100GB\month VPN for $5 but the basic proxy plan is 2GB\month for $20? What use case does the proxy plan meet over the VPN other than more server locations?
DISCLAIMER: AnchorFree's CEO is one of my dearest of friends for nearly 12 years, but that's not why I'm promoting HotSpot Shield here. It just really is that good, and I use it all the time on public hotspots.
I've got a stripped down .config and image that does include OpenVPN, if anyone's interested.
The author of the article on how to implement references the below...
http://www.schneier.com/pptp-faq.html
...I think there's plenty there to disuade you. Would you build your webapp on a framework that stores user credentials in plaintext as a feature? No. Enough said.
Why go through the trouble of implementing something that's known broken? sigh
I had to read it three times, but you are both in agreement.