> https://en.wikipedia.org/wiki/Crypto_AG
> https://www.washingtonpost.com/graphics/2020/world/national-...
Personally, I just don't see how you can possibly trust any assurance offered in the current world? You are implicitly handing your private traffic to a third party black box and hoping it is as "private" as they claim. For 99 percent of customers I'm sure this is fine, but I would not be surprised in the slightest if we find out in the future one of these was run by an intelligence agency. We've already seen them take advantage of fake/compromised encrypted messaging apps.
In the US, I would suspect all of them. They ply you with multimillion dollar contracts. If you try to resist, they weaponize whatever they can against you. Consider the case of Qwest. After the CEO refused to work with the NSA, he was brought in on unrelated criminal charges: https://www.foxbusiness.com/features/former-qwest-ceo-joe-na...
As with anything relying on trust with a third party, one should definitely actively assess their individual threat models and risk profiles. It might be useful for parts of your traffic, not necessarily all
For outgoing, I also heard that proxychaining is a thing (which might not help you if collaborating actors compromised all obv)
I still haven't gotten any response from SurfShark about why they insist that users install a root SSL certificate and why their service can't be used without it. That alone should be incredibly scary. Installing a cert for negotiation between my computer and my provider's is one thing, but installing a cert that lets my provider spoof any SSL / TLS they want is something else entirely.
Ideally their client would allow for you to accept or even better pre-load a cert they allow.
But some OS's can be finicky about trusting certs that arent loaded into some central trust store that in principle allows you some ability to ensure everything trust IS trustworthy, but also de-facto means a cert trust can be abused.
However thats as true for the google certs, or the Gov certs that are already pre-loaded and updated with OS updates etc as it would be for that service. And rarely are people actually looking at trust chains for the sites/services they use.
That said, i would trust google or even the NSA/gov over some rando vpn provider, if for no other reason than its on literally every install and there are millions of preying eyes watching.
There are many VPN services that begin by reselling white-label VPN solutions, such as provided by NordVPN,[1] because it's cheaper and easier than building your own globally distributed high-capacity, low-latency network. Many suspect Proton VPN did so[2].
[1]https://nordvpn.com/white-label/ (old link, can't find an archived version of the page) [2]https://archive.is/iZ2l2
Even though, to me, it seems like a LOT of trouble since tons of services have managed to roll out a VPN product without resorting to white labelling Nordvpn
I would like to reiterate that this is completely untrue and borders on disinformation.
ProtonVPN maintains its own VPN infrastructure, and we take our commitment to user privacy very seriously.
It shouldn’t be surprising that the VPN space is a very competitive market, and certain people have a vested interest in defaming certain VPN providers, especially among a technical audience.
I don't see why you'd want anything to do with them or their subsidiaries, unless your only research is googling "best VPN" and accepting the resulting misinformation at face value.
I've tried twice, and it just wouldn't work. I tried with their software built from scratch, and I tried their OpenVPN stuff.
Once I can find a way to make it work, I would definitely use it.