At this point one must assume that any "free" vpn software is free because it uses its install base for DDoS / other traffic abuse.
At this point one must assume that any "free" vpn software is free because it uses its install base for DDoS / other traffic abuse.
Hola is ran by luminati/bright data which absolutely are pure scum scam botnet-enabling shitbag company.
Most people exclusively care about scum vs. not scum, and all but vuln-dev level sources shouldn’t distinguish.
Maybe HN fell on the savvy side of this at one point, but it was so long ago…
I will note your posts are reading as activism/consensus building, which gets people removed from hackernews. So you might want to dial it down.
Nuance matters! While the guy who makes sexist jokes and the guy who will rape you if ever alone with you are both scum, that difference really really matters.
I formerly worked in the consumer VPN space (an older, but once quite big player), and use cases go from content access (including everything from getting US Netflix from Germany, to sidestepping national firewalls), to general-purpose paranoia about IP logging by websites. There are also lots of cases that get marketed a bit too liberally by companies like Nord, Express, and the hydra that is Kape, like that VPNs can add meaningful security to submitting payment information online; this is despite the fact that it's harder than ever to MITM payment sites.
It's generally agreed that the state of public Wi-Fi combined with evolving web standards and sky-high HTTPS adoption makes VPNs largely, though definitely not completely obsolete for protecting yourself against someone sniffing traffic at Starbucks.
Having said all that: if you need a VPN and a lack of port-forwarding isn't a dealbreaker, I wholeheartedly recommend Mullvad. My former company never worked with them directly but our team had immense respect for their integrity, ethics, and approach to developing a quality product.
The problem I have with all the "checks" that press foundations do is that none of them seem to know what they're talking about in regards to what tech is trustworthy and audited, and what is not.
I found a nice article about it, skimmed through it and seems to be true and reflect my own research that I did for my cyber defense network [1]
[1] https://vpnpro.com/blog/hidden-vpn-owners-unveiled-97-vpns-2...
They shouldn't keep logs but even if they did there's no personal information metadata.
Just your personal IP, which is via your provider very tied to your person.
(In many places it can trivially linked to your real ID, if there is a court order)
Unless the use case is circumventing region barriers.
If you are just a file sharer or normal low level criminal I doubt the CIA (or whoever may have infiltrated Mullvad) would give anyone your IP.
1. https://www.svt.se/nyheter/lokalt/vast/husrannsakan-mot-vpn-...
Or NSO or some other private actor did so, and now every dictatorship has access to it, and we all know how broad their “terrorist” definition can be…
If you are a dissident in Iran, you really should not trust some random VPN. Tor is probably safe enough, but there is also no guarantee, that the chinese are not sharing with them, because as far as I know (but last time I checked has been some years), many nodes are china based. So they might know.
But if all you do is pirating some videos, then this is not something to worry about.
Just so everyone is clear on a few facts, it is possible for a TLA or agency from another large government to just try to blackbox the VPN nodes and be done with it without needing to infiltrate Mullvad. Just pressure the network provider of the VPN instances to get flow data, and at that point they can match up traffic going in and out and the VPN disappears from the picture.
Mozilla gained good will over the years and I like the browser. The vpn is fairly seamless and permissive for number of devices. I understand it is a wrapper on Mullvad and we are paying a healthy overhead. Still, it is worth it because I’d trust that if the vpn service provider behaves in bad faith that Mozilla will be able to quickly respond and adopt another provider. Whereas if it were up to me I may hear of it years later and not necessarily know what service to adopt instead.
My use is merely hoping to reduce tracking based on ip. I wouldn’t trust it to be subpoena proof. I’m not into pirating music anyway.
Actually, they rather lost a lot over the last years, with various shady things, like tracking for advertisement enabled from the browser by default (called studys).
So sadly, I also would not trust them as a VPN. Way more than some random VPN service, sure, but not completely. But I also do not know of a better alternative.
I've lost track of the times a Mozilla misstep has resulted in people here saying that's the reason they're switching back to chrome, which I find frankly ridiculous. Also, the whole damn thing is open source, so it's not like they're really hiding anything, people just don't care until someone makes a stink and then all of a sudden everyone cares a lot.
No browser is perfect, but Mozilla is definitely one of the better ones for anyone privacy conscious.
We technical folks get it and can deactivate it.
Every non technical person I know, who still uses firefox does not know and has all the defaults activated, until I change it for them.
So sure, they are still better than google and microsoft, where I just assume that they track everything, but that is a really low standard.
Some of the other incidents were overblown but the Cliqz thing shows of a company culture where user data is something which can be sold to make a profit, which is essentially what they did, and not something which is vital to protect.
Yes, it was many years ago now but I have no reason to think that they cleaned up their company culture.
All Mozilla know is the mullvad username. Mullvad don’t know the credit card details of the purchaser. To link a given vpn ip to a specific credit card would require compromising mullvad and Mozilla.
(Or of course the normal way of fingerprinting which doesn’t rely on IPs)
Now sure you can buy mullvad via cash, but that’s far more work. Using Mozilla as a reseller feels like one more step in the chain
This might be useful:
I am also familiar with a recent police investigation where law enforcement subpoenaed NordVPN and the company replied, essentially, that they had no information connecting a particular IP address, at a specific date and time, to any specific user.
https://www.pcmag.com/news/nordvpn-actually-we-do-comply-wit...
They don’t keep traffic logs
Not sure about the links to Proton though.
Where else would they get the 100 million users?
If they're truly hijacking end user clients, why don't you point to the section of their open source client that's responsible for that?
https://github.com/NordSecurity/nordvpn-linux
Easy enough to prove.
Credit or debit card, Klarna, PayPal, Google Pay, Cryptocurrencies
https://news.ycombinator.com/item?id=22532682
NordVPN used residential proxies at one point to enable access to Disney+ and other streaming services; that's a world apart from hijacking end-user connections.
They've got an open source client. Where's the code that's turning end users into endpoints?
I'm sorry but that's incredibly sketchy
But yes, it's also sketchy with the other implications and all, and not the least what kind of traffic that people want to hide that you're unknowingly a proxy to!
The standard linux vpn client clearly has some exitnode capabilities.
"We are a market-leading web intelligence collection platform, driven by the highest business ethics"
I think that's a bit debatable!
Which then makes this viewpoint not that useful at all.
And this issue already been long summed up as “nothing is free in life.”
You might not like something, but does it really make it a dilemma in the sense of 'having to pick which of the 2 bulls horns will impale you?' - i don't think so. (interesting points though, and perhaps i am still missing your point!)
Obviously for consumer it is better to be able to scrape sites. It is only those store owners (greedy capitalists) who do not want consumer to know that their prices are inflated.
Another thing is looking for some information, it is better just to have a language model go around the web and summarize the data for you rather than read someone's site with white letters on black background and weird font.
If a store owner doesn't want the reach, it's their loss. IMHO no need for a DoS attack.
Individuals also, IMO, have a right to sell access to their network for scraping-via-proxy. But they should be prepared to deal with the consequences, like a potential IP ban. Most people using VPNs that resell their residential network for scraping probably don’t know that’s happening, and many scrapers are indeed doing something bad, which is why there is a disdain for the practice.
Yes, I realize that LinkedIn is a self aggrandizing cesspool. I never post anything there.
[0] https://www.techradar.com/news/judge-orders-mediation-after-...
I never looked into that, but always used Nord VPN via the official OpenVPN client.
I wrote an article in 2013 about why free proxies are free [1] and got so much feedback from people who had never thought about that.
This was back in the HTTP only days (very shortly before the Snowden leaks) and it was a good way to make money because your proxy could just replace all ads on all sites with your Google ads and you could see all communication. Insane from today's view
In 2015 I did a followup post where I analyzed the existing proxies for any manipulation of the original site and found that 80% of the free proxies did in fact change something [2]
[1] https://blog.haschek.at/2013/05/why-free-proxies-are-free-js...
[2] https://blog.haschek.at/2015-analyzing-443-free-proxies/