NordVPN library and client code open-sourced
github.com
github.com
NordVPN's official response was to get defensive; they proceeded to actually publicly post a screenshot which included the customer's email address. I couldn't believe it.
That tells you all you need to know about NordVPN's terrible attitude towards privacy.
A VPN is inherently not a privacy tool. It is perceived that way because of the acronym Virtual 'Private' Network but privacy is not in the design specs at all.
It's just for tunneling over untrusted networks like Starbucks Wi-Fi and spoofing your geo-location. That's it. You can't verify the no-logs claims by providers unless you're physically in their building and auditing the setup yourself.
Maybe not, but NordVPN and similar services do heavily market themselves as essential privacy tools.
They could claw some information from certain payment providers (like if you used Stripe to top off your account) if they wanted, but you can pay your bill by putting cash in an envelope and mailing it, if you wanted to.
thats good enough for me. I am sick and tired of websites telling me what I can and cannot do based on my location. Its not the 90s anymore, I refuse to put up with geo blocking.
My DNS queries are sent into a private network. Nobody knows what I'm looking at.
When I torrent movies, my IP cannot be tracked. It is shared with many users.
It is fast.
Those are all grest properties I gladly pay for.
EDIT: At the time you were downvoted, I see it's not longer the case. Further comments about Nord and questionable behavior have also been posted in the thread.
We should judge people and companies (which are ultimately also people) not by whether they make mistakes, but by whether they learn from them.
Allegedly, they are using their customers as botnets to resell traffic from residential IPs, mostly for scraping, through their other business "Oxylabs".
The idea was never that NordVPN was reselling the network connections of NordVPN customers; it was always that they were, on their backend, originating NordVPN customers traffic from maybe-sketchily-sourced IP addresses.
Here is a paragraph I wrote a couple years ago on the topic of how centralized VPN companies manage to bypass blocks by content providers (such as Netflix).
> One VPN company that actually seems to do "well" at this is NordVPN: they've even managed to provide access to Disney+! Someone did a deep analysis of how this worked a while back (an article which has since been deleted, weirdly, but a copy can be found on the Internet Archive). They are "linked closely with a Lithuanian data mining company called Tesonet" which also runs Oxynet, which in turn advertises itself to have "32M+ residential proxies…100% anonymous proxies from all over the globe with zero IP blocking", which the author of that analysis believes is how NordVPN is originating their traffic... and how did they get all of those IP addresses? The contention was that they seem to be stealing them, convincing random products to embed malware that attaches them to the Oxynet essentially-a-botnet.
https://news.ycombinator.com/item?id=21664692
http://web.archive.org/web/20191128170008/https://medium.com...
I am basing the second part on this research: https://www.docdroid.net/kOP3JAh/tesonet-web-of-lies-pdf
I'm not a conspiracy theorist, but the relations of Tesonet, NordVPN and Oxylab is creepy at best.
People make the allegation that NordVPN is routing some of Oxylabs' traffic, because that's exactly what HolaVPN and Bright Data (previously known as "Luminati") does. (See https://archive.is/aJY0F ) And Luminati Networks sued Tesonet for patent infringement on this.
Just the corporate structure of Tensonet in itself should make people stay away from any of their VPN products.
Source: ex-employee.
"Consenting and fully aware individuals become a part of a residential proxy network in return for a financial reward or some other benefit. When they choose to participate in our suppliers’ pools, they consent that a part of their internet traffic and a small amount of the device’s hardware resources will be used for a variety of business cases."
Does anyone that uses NordVPN know how explicit this is in their client/agreement? If they are even using it...
I don't opt in to anything like this (as far as I know). Looking at the preferences, I don't see something that sounds like it maps to the consent above. So ... I'm not really sure.
Nothing in their license agreement and no settings for this at all.
Doesn't appear they are recruiting devices into this residential proxy service.
Since oxylabs allows selecting a proxy at a very granular location, it should be possible for researchers to get a bunch of these dodgy browser extensions and correlate which are forwarding oxylabs traffic.
This is why their marketing campaigns are so aggressive. They completely rely on the unsophisticated masses, to whom a computer is a magical box of fairy dust that plays Netflix shows.
And that’s perfectly fine - computers are a tool, enabling valuable usecases for everyone.
Of course. But the arbitrage of that knowledge leaves open all kinds of profitable businesses, including shady VPNs.
However, I also think this is the only way to bypass streaming sites blocking VPNs - the whole reason for using such a service in the first place.
IMHO the shadiness is only around consent and not the means. Unfortunate, but such is reality.
First of all, I want to reiterate that I purposefully used the word "allegedly" because I have no proof. I only have a smoking gun https://archive.is/bQo0O .
Second of all, I want to explain that it is very difficult to verify any of your points.
> you can easily [...] look through the code. As you can see majority of it is open source.
Yes. This is correct, but at the time of writing this comment, the source has been made available only 9 hour ago. https://github.com/NordSecurity/nordvpn-linux
The whole thing is one giant "Initial commit" of what looks like millions of lines of code. Auditing this code will take months for single motivated person. There is little to no comments. "Just read the code" is difficult in this context. Also routing traffic through the client can be done just with 2 lines of code enabling kernel ip forwarding, and another line of code adding a nft/iptable rule to nat traffic from NordVPN to the outside world. This is looking for a needle in a haystack if this is obfuscated.
Also your Windows and MacOS clients (which are the most used by non-power-users) are not opensource, at the time of writing. So these ones could still be doing what has been alledged. This would be fine, since it's most likely most of your users.
> you can easily check it using Wireshark
This is also not that easy. If, as alleged, Oxylabs resells millions of NordVPN IPs to thousands of Oxylabs customers, you only have 1/1000 chance to be the botnet of the day. So you would need to be running Wireshark the one day out of 2½ year to see the traffic going through with Wireshark.
I assume someone was detecting if you were using a VPN and testing and it somehow made it into production. I emailed them and never heard back.
Granted ... I get why a retailer with financial activity going on might want to know if a VPN was used to possibly apply extra scrutiny to the purchase.
I used to work for a company that explicitly changed the prices on the site if the request traffic came from a competitor IP address.
Of course this was a hundred years ago in a land far away. I don’t know how much success you’d have even finding your competitors IP’s these days.
"Exit node" users and VPN customers don't need to be in the same set, though: It's entirely possible that the VPN operator buys residential IP forwarding volume and includes access to it as part of their product offering.
That doesn't make things much better for unwitting users sharing their internet connectivity with insufficient or no education, though...
Yes this is true even with NordVPN, which I bought specifically to be able to watch Netflix on when expressVPN didn’t work.
It’s not obvious at all. Netflix could be doing something as simple as checking the IPs or could be actually checking the use of VPN at a system level. Both are equally valid readings of the GP comment.
Any solution that requires me to reach behind my TV and plug in my laptop is already not easy.
With Netflix you just punch your password into your smart TV and you're watching content.
It even syncs progress across devices, works on all my devices (doesn't work in the Apple ecosystem).
I had whole home VPN configured and I couldn't access NFLX streaming content from the house. Getting Netflix traffic to bypass the VPN is incredibly difficult without hacking the client side code to have it update the bypass rules on-demand in response to the client side JSON payloads - or hook into DNS resolution and do VPN bypassing there based on a regeular expression of the origin and the returned records.
The way NFLX works under the hood, from the client's perspective, is that it makes an initial request to a service hosted in AWS. That service stitches together the list-of-lists on the home page. Then you select a film to watch, it again reaches out to a service hosted in AWS to ask to stream the content. This is really straightforward to get working with whole home VPN, you just bypass the VPN for those origins (using DNS queries to get the IP blocks) and you are golden. A little cron job could keep that IP bypass list fresh and it worked well enough to get through the UI.
But then the AWS service responds with a list of streams you are licensed to watch and URLs that point to their location. Those URLs point to Netflix's OpenConnect CDN hosts. Nearly every time I went to stream, I'd pull a different origin for the content and that would route back through the VPN. The list wasn't stable, so I couldn't compile a comprehensive list of origins to route around the VPN with.
So NFLX blocks VPNs to protect their licenses, which I understand. But their architecture made it impossible for me to allow their service to bypass my VPN. So any device I wanted/needed to use NFLX on had to have a direct connection to the internet.
If Nord VPN is really bouncing your traffic out of some other residential customer's connection, that would be a lot harder to detect. And a lot more ethically questionable if the other user doesn't realize they're doing it.
I dunno if SSL encrypts the entire HTTP payload or not but could you even figure out the URL’s being requested using a tool like wireshark?
Host names: Very likely, unless you're using SNI.
I keep thinking the "e" is for "enhanced" encryption, i.e. "eSNI 2.0", but what I'm thinking of is actually called ECH (for "encrypted client hello"): https://blog.cloudflare.com/encrypted-client-hello/
Specifically to watch The Walking Dead if I am honest.
Using VPNs for Streaming is selling point #1 for tons of people.
Never had an issue, been signed up for years.
It’s possible to set up your own solution I believe but I don’t have the time for that currently.
Not affiliated or anything and I’d do your own research on them but I much prefer this as they only see that traffic from me.
To be honest, apart from botnets, it’s really the only way a company could “legally” get access to millions of residential IPs.
I asked this question, the answer from this other company was "we would close your account". But they were unable to explain clearly to me how and if they monitored this.
In fine, I think this is your responsibility, you basically voluntarily installed some malware.
If someone else is doing illegal things on your IP address then you could blame the (users of the) service to avoid liability. Still you could find yourself targeted by a lawsuit. I wonder if Oxylabs' terms protect you in this case.
Most routers and other clients that aren’t updated very frequently still only support OVPN.
They also offer WG connections if OVPN bothers you so much.
Not all VPN providers sell data (DNS or otherwise). Some operate for privacy-driven reasons and actively seek to be good stewards for their customers.
Mullvad is the best privacy-focused VPN, hands down.
That might well be true, but anonymous payments are no proof, or even supporting evidence, for your claim.
It could still be very lucrative to resell data in the form of "users who access foo.com often also access bar.com" – and you can probably see why that could easily be deanonymizing.
Their FAQ confirms this, assuming you trust them. https://mullvad.net/en/help/no-logging-data-policy/#no-logs
If a provider can sell a VPN for $1/month as a loss leader and make $5/user after selling all data, what keeps a $10/month VPN from making >$15 doing the exact same thing?
Private Internet Access and ProtonVPN both have tenuous relations to shady stuff. Private Internet Access got purchased by the same company that made Cyberghost (malware), but so far nothing bad has come of it. AFAIK they're also the only VPN that has been truly court-tested.
ProtonVPN has some really weird circumstantial stuff related to TesoNet.
Any other VPN I wouldn't trust by default. Shady business sector.
But I don't buy into the idea that anyone can say "ALL VPN PROVIDERS" do a thing.
I believe NordVPN's open sourcing effort here (whether genuine or not) is motivated by pressure from Proton's open source.
* https://www.youtube.com/watch?v=WVDQEoe6ZWY
And then a few years later with "My robot double sells out (so I don't have to)" he did a follow-up listing useful reasons (geo-based content, better prices on vacation sites, etc) which was sponsored by NordVPN:
There are legitimate uses for VPNs, they're just not the reasons these VPNs advertise (the the parent comment says).
It's not like they can advertise the actual reason people pay for VPNs, which is piracy and other illegal activities.
Besides open sourcing - today we launched Meshnet free so you don't need a subscription to use it to connect your own devices, spin up your own VPN server etc. Hope it will be useful.
If you have doubts about Nord - I will try to answer your questions.
This is EXACTLY the right signal to bring myself (and presumably many other people in the same boat) back as happy customers. Sorry you’re dealing with unhinged conspiracy theories in this thread… but I think in the long run, this open sourcing will go a long way towards shoring up your customer base and keeping power users happy. Great work and TYVM!
There are also random, mostly undocumented, interfaces lying around /everywhere/, in all kinds of places not connected with either the call site or the implementation. My favorite is a custom bools library called "strings".
I haven't found any obvious bugs, but the coding standards are poor. Good on them for open sourcing it, but man, did nobody stop and think "hang on, is this code gonna make us look bad?"
I see NordVPN ads all over youtube, podcasts, and TV. Those overwhelmingly non-technical customers certainly don't care about the code quality, documentation, or constants defined far from where they're used.
It seems to me this is about marketing the product to be perceived as transparent and secure, which is certainly what those customers care about.
I thought people have moved on from using slog for structured logging and instead rely on the same as exposed by the tracing library. In the end, slog was good enough for the task at hand and that's what matters most.
Wouldn't that be the purpose of such a file? One central location to adjust what some magic number is - then reference it (via eg lsp autocompletion) were used?
The OP clearly just skimmed through the code without any interest in understanding how it actually works.
Just a code bashing. Sad
I know that some programmers hate getting their code reviewed. All I can say is that code reviews are, in my experience, strongly correlated with code that's cheaper to maintain and operationally less surprising.
Seeing this code certainly makes me think that the team writing it either doesn't have a culture of taking code reviews seriously, or that they don't have a lot of people who know the best practices in this language (Go). Either way, if they're not catching the easy stuff, I don't trust them to catch the subtle stuff either.
Yeah this review will really give potential Nord users something to really think about before they purchase!
I wonder what their total youtube sponsor spot expenditure has been. It must be a ridiculous amount of money.
It's a bit of a unique market in this way, people are willing to pay $5-$10 per month for something that costs $1.
The fact they're in Panama suggests some kind of money laundering scheme to me at the very least.
EDIT: I've realised my claims about logging were overblown. But I'm not so insecure as to edit it out so here's a disclaimer :)
I'll admit I misread another comment on this post as them definitely being exposed for logging though, my mistake. I've been unable to corroborate it. I did find that the company openly admits it cooperates with law enforcement and does log on behalf of law enforcement.
Additionally there are so many other red flags I'm not inclined to believe anything they say.
Do you think they're buying a bunch of YouTube sponsorships with drug money to then attract customers to an unprofitable business? Or they're buying their product themselves and then advertising to make it seem like they have a legitimate business?
Throw money at Youtubers, they make the ads for you.
Indiscriminately approve the sponsor spots(Check out IncognitoMode's sponsor spots. He practically designs his spots to be unapprovable. NordVPN will always work with him anyway. They don't seem to care).
You get lots of customers, charge them enough that a large profit margin is to be expected. Botnet users to save even more cost on getting hosts. Log user data and sell it on dark markets. That's the money you can then launder with your large clean cashflow.
At least that's the sort of set up I had in mind.
The datamining and botnetting is possibly optional. Dirty money could also be from any other criminal activity, maybe crypto scams or some other e-crime. Or just drugs/sex trafficking. Or here's a wildly speculative one: use your vpn service to aggregate CSAM and sell that on the dark web, then launder the money via your seemingly legit vpn service. Bonus: keep logs for blackmail purposes in case your Dark Web enterprise craters. Blackmail futures!
I feel like I could sit here all day listing viable ways of building a nasty, disturbingly profitable criminal enterprise under the guise of a VPN service.
(I swear I'm not a criminal I just know how to think like one).
I regularly see sponsor spots where they're claimed to protect you from credit card fraud and all sorts of other outlandish stuff.
A VPN provider really needs a lot of trust, easy to lose that.
That's all apart from the fact that most reasons advertised by companies like NordVPN why you need a VPN are bogus or outdated, and that the trustworthiness of a VPN only relies in small parts on the client they use.
(Update: skimming through the code it seems they somehow use openvpn. Not entirely sure if this invalidates my point, but then the question is: Why do they need their own client at all?)
But you don't have to use their client. Most VPN providers (looks like Nord included) allow you to connect with any client that's compatible with one of their protocols. I use a different VPN provider with the official WireGuard client, even though they have their own company-made client.
They've been audited https://mullvad.net/en/blog/2022/6/22/vpn-server-audit-found...
I have no financial incentive to vouch for them. But what do you care, I'm just a random guy on the internet.
For example, this is the writeup of the DeFi Euler hack yesterday by one of the sites listed auditors, who didn't actually audit the code that caused the bug...
https://medium.com/@omniscia.io/euler-finance-incident-post-...
Though I do trust both, as Tesonet is based from here (Lithuania) and from my experiences with people who worked there, they have full trust in them and continue to use their services years after leaving the company.
Do you mean that NordVPN and ProtonVPN are the same 'spiritually' in that they're both companies selling a VPN for profit? Or is there genuinely some business connection between them that I've missed?
From Tesonet[1]:
>We also provided ProtonVPN(opens in new tab) with operational and HR support when they decided to open an office in Vilnius.
>Contrary to all the myths and rumors, operations by different services have never been related to each other. The only common resources are the centralized HR and legal teams. We have strictly relied on this philosophy from the beginning in order to avoid any possible conflict of interest.
[1] - https://www.techradar.com/news/moving-the-vpn-industry-forwa...
Especially not after Kape Technology bought up review sites and VPNs and updated reviews to shill the ones they own.
Kape Technologies was formerly known as Crossrider before it was acquired by Teddy Sagi, an Israeli billionaire that has spent time in jail for insider trading. Crossrider itself never had that great a reputation itself, what with their primary product being a development platform through which they were frequently used by third parties to invade ad platforms to serve up malware. They are now the owners of ExpressVPN, PIA, CyberGhost, and Zenmate.
https://restoreprivacy.com/kape-technologies-owns-expressvpn...
And then j2 global owns a bunch of others.
https://www.techradar.com/news/pc-mag-owner-j2-global-buys-s...
I'm 99% sure every VPN on the market is a honeypot or data broker at this point.
One concerning issue is the Swedish jurisdiction. The nordic countries are better at privacy, but Sweden is a 14-eyes nation. But I can't say it's better or worse than NordVPN's... Panama.
Technical summary of the SPN (Safing Privacy Network):
- A Privacy Network aimed at use cases "between" VPN and Tor.
- Uses onion encryption over multiple hops just like Tor.
- Routes are chosen to cover most distance within the network to increase privacy.
- Exits are chosen near the destination server. This automatically geo-unblocks in many cases.
- Exclude apps and domains/entities from using SPN.
- Change routing algorithm and focus per app.
- Nodes are hosted by Safing (company behind Portmaster) and the community.
- Speeds are pretty decent (>100MBit/s).
- Community nodes are used to diversify server ownership and strengthen the privacy of connections.
- Community nodes may technically act as entry, middle and/or exit nodes.
- Community nodes will never be used for unencrypted connections, only for encrypted connections. We are thinking about a concept of trusted partners, which will also be allowed to handle unencrypted connections - but this is currently not the case.
- We publish advisories [0], which are automatically applied by all clients. This gives us the ability to quickly react to changing situations. Currently, community nodes _are_ being selected as exit nodes, but not as entry nodes.
I hope this cleared things up. I am happy to go into more detail.
[0] https://github.com/safing/intel-data/blob/master/spn/main-in...
Hosted on DigitalOcean and the setup was completely automatic, it deletes its own access after its done.
Note you're still beholden to ToS of your host, but tbh they don't seem to care no matter what I do with it.
I know it from here.
What are you looking for a VPN for. As much as the ads misrepresent the security & privacy aspects of NordVPN, &c., the vast majority of people use VPNs to watch region-restricted media. Mullvad does not support this.
So ... who's the best provider for watching region-restricted media?
NordVPN honestly seems like a very competitive option here
Cons: it can be slow and have issues with disconnects sometimes.
That's a video about NordVPN's dishonest advertising and how deeply it's infected YouTube.
https://www.pcmag.com/news/nordvpn-ad-banned-for-exaggeratin...
> The UK's Advertising Standards Agency(Opens in a new window) has banned a NordVPN commercial for misleading viewers about the privacy risks of using a public Wi-Fi network without also having a VPN.
In essence: HTTPS already does what NordVPN claims you need a VPN to do. More, in fact, because HTTPS validates that the domain you're communicating with is the domain that shows up in your browser's address bar, which a VPN can't do on its own.
This is Tom Scott's 'original' 2019 video called "This Video Is Sponsored By [redacted] VPN" where he explains most of the reasons listed to use VPN by ads is useless.
However a few years later with "My robot double sells out (so I don't have to)" he did a follow-up listing useful reasons (geo-based content, better prices on vacation sites, etc) in which he was sponsored by NordVPN:
[0] https://downloads.nordcdn.com/apps/windows/NordVPN/latest/No...
Really annoying that every service has like a whole essay on what functionality is and then 1 one liner saying they don't support it.
For example, their article on SOCKS vs. HTTP proxies vs. VPNs is factually nonsensical (by e.g. describing HTTP proxies as "always unencrypted", or SOCKS as having higher performance due to "not rewriting packet headers"): https://nordvpn.com/blog/socks5-proxy/
Somewhere there is a FULL article on how to do this on the website or partitionwizard...
WHY?
You see 20 websites with the same info re-hashed. And none of them mention the particular edge case that I'm running into.
I really wish Google goes back to preferring bullet points over prose.
Another example:
Search for 'squirrel bite rabies'. You only get pest control companies telling you how you can get rabies.
Except there have never been any reported cases in the USA.
(I am not a subscriber or an impacted creator, but I did try it out. Honestly you'll have seen all interesting content by the end of the week, but for that price... worth it to buy it every couple years when there is new content.)
Until a VPN service gets that kind of status, you can assume they either follow local laws or haven't gotten a request for data logging for anything bad enough yet (realize that this doesn't have to be even close to murder-for-hire: being complicit in other people sharing movies between them reaches that "bad enough" bar).
It would be great to hear from their CTO on the rationale.
I assume parts of the "full stack" are still closed source then?
Wild to see so many people conjecturing about one of the most scrutinised and researched VPN providers in the world, whose source code is now available for all to see and not a single person, here or on Reddit has been able to flag any code of concern and the result is just pure conspiracy with zero evidence.
I think the only reason now to use a vpn, is to login to a site as if from a different location, if the site blocks your region, or sensor some of its content
Any other good reason to use a vpn
I've recently been describing what a commercial VPN provides to non-technical friends and family as a type of "global virtual Internet cafe" subscription - the pros and cons of using a physical Internet cafe mostly apply. An Internet cafe isn't inherently (i.e. due to technical benefits of underlying technology) any more or less secure than connecting to your home or work wifi/network, and the Internet cafe knows who you are and what websites you're visiting, but your ISP/employer doesn't (since you're "at" the Internet cafe, not on your home/work network).
Of course, your ISP/employer does know that you're visiting the Internet cafe, and in the case of work (and some ISPs) can stop you from doing so.
If you visit a website from an Internet cafe, the website may still be able to figure out who you are, just like they can when you bounce between different networks normally. And of course, if you login to your account on a website or put your shipping address or something in when buying something, you're self identifying (unless you have throwaway accounts or forwarding addresses or whatever).
And finally, if someone really wants to figure out who you are to a high degree of confidence, they will.
I find this lands pretty well and is close enough to being technically correct without getting into the details that non-technical people would start glazing over if I got into.
- untrusted networks (public wifi)
- normalize usage of privacy preserving practices
HTTPS covers the content, but for most people the DNS lookup would still be in plaintext.
Let's say every website is still on HTTP (not S). How does a VPN for daily use help you at all?
Your traffic traverses the Internet unencrypted anyway: either from your ISP to target server, or from the VPN's ISP to target server.
It shifts the responsibility from one party to another, but it doesn't reduce the unencrypted path. Instead of trusting your ISP, you now have to trust a shady operator that often promises not to comply with local laws when the police comes with a warrant. They often also don't have assets to seize, so little reason to be legit. And it's not like you can stop paying the ISP that you are so distrustful of. It only costs you more money.
It's good for hiding metadata like sites you access. In my country there's a recent law demanding ISP to record metadata and allowing many agencies to access it without warrant.
[0]: https://www.cloudflare.com/learning/ssl/what-is-encrypted-sn...
All HTTPS does is make sure they can’t see what you are transferring. There is still meta data to whom.
Why do you think google runs 8.8.8.8? It’s not out of kindness.
Only in some countries ;)
Which is ironic as previously I had trouble separating it from Critical Role thanks to the ad skits Sam Riegel used to do.
Every company who has these spend as much as they can on user acquisition. Why wouldn't they?
Usually the offers in addition have pretty good discounts from original price.