Show HN: Serverless VPN, pay as you go, unlimited devices, no subscriptions
upvpn.app
upvpn.app
Honestly I feel vpns are just kind of like gym memberships, it's not expected for everyone who gets one to use it every day, even though they could.
The only real use case I can foresee this for is for people who might use a VPN for a few hours, a few times a month. With that kind of usage pattern $10 (The min topup value by the look of it) could last you a fair few months so works out cheaper than some of the other mainstream VPN providers who offer a flat fee service.
If I may use analogy to describe UpVPN - its like buying Milk - you pay upfront you bring it home consume it and go to grocery store and buy more.
UpVPN is an option in spectrum of VPN providers. Only you can determine based on your usage if this option makes sense for you.
What UpVPN does provide (unlimited devices without subscription and your never expiring balance stays if you come back months later) other providers do not. And vice-versa UpVPN for its pricing model does not provide unlimited usage.
My home country has TV networks that refuse to work on any of the known VPN providers. They've actually gone to the trouble of IP blocking known exits and the VPNs don't seem to change that often enough.
I know enough to buy a lowendbox and set it up as a VPN and use that and it works (provided the host is oddball enough not to be a known datacenter based IP). But i wonder if the above would work better than the more regular VPN providers.
I would hope that authorities at least would try to build an actual case against you and not just raid your home because of some fraudulent traffic from your IP. I might be too optimistic in that regard.
1: it makes me angry to think about it
2: I have other, positive things I'd rather do
It took them 8 months to return the ~$10k of gear they "stole" from me, and they found nothing.
No apology, no explanation of how I was somehow caught up in their data, just "come collect your stuff".
Ironically, they traumatized my kids (I don't think they even did any background checks on me - I don't believe they even knew there were kids in the house before they barged in).
Luckily my kids are resilient and we can sometimes even joke (bitterly) about it.
I should also make the point that, with one exception, the officers conducting the raid were polite.
Don't feel bad for asking.
I do want to "get it out", and one of the things holding me back is "what's the best way of doing it" (along with "what's not going to invite further negative police attention").
Along with a family member, we've approached our local government representative for advice on how to go about pursuing some kind of action that might help "make the system better" to minimise the incidents of innocent parties being subjected to the violence of the state, but it's mostly been a dead end. But I also don't want it to be what defines the rest of my life either, and pursuing this kind of thing could easily end up eating who I am currently (and I'm quite happy with my current self).
I also don't want media attention, really, in any context.
Now I'm mostly just writing this to understand my own motivations...
Man I really feel this part, though admittedly for a shorter-lived and much simpler reason so I don’t want you to think that I think I fully get it.
My wife and I had two officers walk into our apartment when we were a younger couple. Unannounced, 1 or 2am. Just lights shining around and I jumped up looking for a blunt object. They then announced themselves. Mind you we live in an incredibly gun, friendly state, so if they have done this is somebody else, it is incredibly likely they would’ve had a gun drawn on them, and who knows how it would have gone down. They let themselves in because “the door was unlocked and they were looking for someone.” Mind you to get to our apartment wasn’t a simple thing. You had to walk around a gravel parking lot and up these rear steps. We lived above a restaurant and all that jazz.
I didn’t do anything about it after they left. I just kind of wanted to forget the situation and not think about what could have been. Think god I am white and didn’t have a gun on me, I’ll just leave it at that.
We didn’t even talk about it until probably 5 or 6 years later. What you wrote above made me better realize why.
A lot of people will simply see the headline, assume you're guilty and treat you as such. And a lot of people are willing to treat those they think are pedophiles very very badly (there was a case recently where a murderer serving life in jail killed his pedophile cellmate) Anyone that knows about this incident will probably never allow you to be around kids unattended, regardless of your innocence. You will be a social pariah.
Innocent until proven guilty had to be enshrined in law because most people will treat you guilty until proven innocent, and they don't have much concern about forgetting the 'proven innocent' bit.
But if p2p exit nodes were orders of magnitude more common, then the burden of proof would indisputably be the responsibility of the prosecutors, since anyone could credibly claim "someone else did it."
And that's why this trope of "but what if someone does bad stuff on your network?!" is so frustratingly self-defeating: if everyone just ignored that risk, then everyone could have a p2p exit node, and the risk would be mitigated. It's a sort of prisoner's dilemma where nobody wants to be the early adopter of a system that would, on the whole, benefit all of us.
A society is difficult to surveil when everyone uses Tor as both a client and an exit node, and onion routing is the default method of exchanging packets (some might say it should have been incorporated into the original design of the internet). So it's perhaps worth noting that adversaries of society, such as the NSA or FBI, have a great incentive to perpetuate fearmongering about p2p networks and the threat of "but whatabout muh criminals on muh network!"
If you're reading this, maybe it's time to setup a Tor relay (with config flag `ExitRelay 1`).
I think I'm more cynical about our justice system, but the way I see it, this just gives them ammunition to go after anybody on a whim. Simply getting tangled up in the justice system, even if innocent, is an expensive and stressful thing. Most of us do not have the resources to just have a dedicated team of lawyers taking care of everything. So if everyone was running a Tor exit node, and it was known that there was CSAM accessed through some of them, an overzealous prosecutor could probably push through at least a search warrant of your computers because as a Tor exit node runner, there's a reasonable chance that CSAM was accessed via your node. You're not getting your stuff back for a while if that happens.
As it stands, there's already a certain level of injustice, because corporations like Google and Microsoft facilitate all sorts of illegal communications, and the worst that happens is they get a letter from the feds asking them nicely for their subscriber's information. The investigators don't jump to the conclusion that the CEO of Google is a child predator and seize all the Google servers. But for an independent system admin on a home network, that's exactly what they do, even though there's no fundamental difference other than the size of the operation (and the implicit assumption that exit relays are unusual, which is the unfair assumption I'm trying to draw attention to as an explanation for lack of plausible deniability on the part of the idealistic sysadmin in a world where exit nodes are unusual).
This is impossible in practice though, so while an interesting thought experiment, it has little bearing on reality. Your local court isn't going to be running a Tor exit node on their systems. Your friendly nearby S&P500 corp isn't going to be running Tor exit nodes on their systems. Your local public library probably won't either.
> They can't seize everyone's hardware.
With your thought experiment, yes, but in practice that's not going to be the case. You're more likely to end up with very selective enforcement instead -- if you run a Tor exit node, the justice system can effectively blackmail you because at the very least they can cause you a very expensive headache. "Shame if we had to get a search warrant to make sure it wasn't you downloading some CSAM"
"Arrest first, deal with nerds protesting their innocence later" still involves getting arrested.
Are you asking about the consequences of breaking laws while using someone else's internet access as an exit point, or are you asking about the dynamics of CSAM production?
_that comment is giving off really nasty vibes_
Never ever would you want to pay to do that to yourself lol.
You keep using that word...
Its a computing model people recognize .. https://en.wikipedia.org/wiki/Serverless_computing
Nobody calls Netflix a "serverless VOD platform" either, or Verizon a "serverless wireless carrier".
To me, "serverless" means "you'd normally be setting up a server yourself in some way (whether low-level and manually, or via a standardized VM or container image orchestration solution), but here you don't have to".
As a VPN user (of this type of VPN in any case; corporate VPNs are a different beast), I've never had to set up a server myself – I'm paying to use somebody else's server!
In other words, we also don't call Gmail "serverless".
More seriously, serverless has come to really mean “almost fully outsourced ops”. If all you need to do is check logs and your bill, but you can still run arbitrary code, then it is serverless.
It seems like you can't run any code at all on this service, though.
And if the service provider itself uses a serverless model to run their application which provides a service to me... Why do I care, as a customer?
https://news.ycombinator.com/item?id=36064305
My take is it's either a very quick copy, or the feds. Perhaps both.
The reason most cloud providers have overlapping datacenter locations is generally explainable by the fact that they all rent space in the same physical buildings (e.g. an Equinix datacenter), where they peer with each other and classify the building as an "internet exchange point" (IXP). These buildings tend to congregate near each other for historical or geographical reasons, like proximity to the landing terminal of an undersea cable, or inheriting a building from the old DARPA network.
It's actually quite annoying how clouds will label their region e.g. "gcp-eu-1," but it's actually just a reference to some rack space that Google rents in the same London Equinix datacenter as AWS and Azure.
~ ipinfo upvpn.app
- IP 213.188.207.130- Anycast true
- City Chicago
- Region Illinois
- Country United States (US)
- Currency USD ($)
- Location 41.8500,-87.6500
- Organization AS40509 Fly.io, Inc.
- Postal 60666
- Timezone America/Chicago
15:21:52 $ curl https://upvpn.app/install.sh
#!/bin/sh
# Based on Tailscale: Copyright (c) 2021 Tailscale Inc & AUTHORS All rights reserved.
# Use of this source code is governed by a BSD-style
# license that can be found in the LICENSE file.
#
# This script detects the current operating system, and installs
# upvpn on supported OS.
To be clear, I don't mean to disparage upvpn, in fact I'm impressed they pulled it together so quickly.Just feels crazy to read about it a month ago and see it today, you know?
upvpn is not related to them.
I love Fly.io - they a building a great product.
The website https://upvpn.app is hosted on Fly.io as identified in the comments below. VPN servers are not hosted on Fly.io
So in total: $10 + about $12 + $1.5 (30x connections per day) = $23.5 per month
Mullvad is $5.
Using the big 3 for a VPN is suicide. You do not want to host a business based on bandwidth on those.
A cool tech demo but definitely not viable as a business.
Also, why a California LLC?
ProtonVPN still allows forwarding and is what quite a few fellow pie-rats are now using.
Mullvad is dead.
Other VPN providers claim to not keep logs and you have to take their word for it. But then whoops it turns out they did keep logs after all.
Mullvad is the only VPN provider that puts its money where its mouth is.
Swedish police recently tried to raid Mullvad, but the tech ensured there were no logs for them to take https://www.theverge.com/2023/4/21/23692580/mullvad-vpn-raid...
Meanwhile ProtonMail was legally forced to reveal one of its users IP logs a few months ago. https://www.privacyaffairs.com/protonmail-surrenders-user-lo... What reason is there to believe that Proton will be in a better position to protect their VPN users, than they were at protecting their Mail users?
That being said, Swiss law is very restrictive, and there are a lot of hurdles that one needs to jump through to get a court order. And even with a court order (and has been proved multiple times in court), there is no way to break Proton Mail's encryption. Privacy is not the same as anonymity, and due to the way the internet works, if anonymity is what you are going after, you have to exercise proper infosec and take preventive measures, such as using Tor or VPN.
Under Swiss law, the treatment of VPNs is different. So VPNs can indeed be no-logs. No-logs VPN, is also possible in other countries as well. What makes Switzerland different, and possibly unique, is that within the current Swiss legal framework, Proton VPN also does not have forced logging obligations. So, a no-logs US VPN could for instance, get a NSL (National Security Letter) to start logging particular users, but that's not possible in Switzerland. In addition to that, VPN is mostly impossible for law enforcement to ask for something reasonable, as there's no "identity" for the traffic going out of our server. There's practically no chance of law enforcement to know what account to ask for.
Finally, it's worth noting that in October 2021 (after the case you mentioned), Proton won in court against the Swiss government and as a result, email services cannot be considered telecommunications providers, and consequently are not subject to the data retention requirements imposed on telecommunications providers. You can find more details here: https://proton.me/blog/court-strengthens-email-privacy.
- work on minimizing the cost and carve out a margin
- go to VC and say "hey I have this VPN service, people seem to like it"
I know the pricing page says "Prepaid starting at $10" but isn't that just the minimum top up?
$10 is the minium you can add to your account, and then it deducts from there.
There is no per-month cost, opening account is free.
$10 is your starting prepaid balance - that you consume by using UpVPN.
California LLC because I'm a resident.
For pricing I describe more in detail in these comments: - https://news.ycombinator.com/item?id=36512794 - https://news.ycombinator.com/item?id=36513552 -
I think honestly you should try to phase out the "per hour" pricing, and just somehow make it so that each connection doesn't need a separate server, as it is just routing in the end, I think it would be easier to market just as a "no BS subscription!" VPN service, which I think could have a market.
As for the California LLC, I just asked because the California LLC is kind of known for being a PITA, with the fees, privacy, etc. and from what I know, you don't actually have one unless you have physical presence, but then there's some tax filing implications if you file in e.g. Delaware or Wyoming so I don't know too well.
GL!
If they used some sort of disposable or "trustable" DNS server, it would be awesome!
However, when you use Web Devices, a configuration file or QR code is generated with DNS=1.1.1.1 but you can change it before using.
Do you still share an IP address with the other users? One of the main ways a VPN grants privacy is because everyone shares a handful of IPs. There is still demand for dedicated IPs though, because they trigger blocking less.
I have a need for a good "residential"/"mobile" proxy/VPN service, but I have yet to see a company that I was confident that they were ethically sourcing the servers.
If your willing to manage/self-host it yourself, some ISPs do provide hosting as well, my old ISP provides a VPS at ~$10/mo with a completely clean IP identical to their broadband customers.
Perhaps you could present some common use-cases with example prices?
If you're avoiding doing that because it should show the pricing to be too high, then perhaps that's something that needs to be worked on. In general pay-as-you-go pricing should be lower for the same outcome than the all-you-can-eat version of the same thing, because you should be able to not pay for the downtime.
Could you clarify why this should be true? In the long run, given the costs are the same, then the income of the company also needs to be the same. This means that on average you'd pay the same. Some power-users would pay more with pay-as-you-go, some rarely-users would pay less, since they are cross-subsidizing the power-users in subscription models.
I can imagine some dynamics caused by power-users avoiding pay-as-you-go plans, so subscription plans see different usage patterns. But it's not at all obvious to me why this should be cheaper. On the contrary, all those on-demand resources need to exist and there needs to be infra for spin up/down etc, so I'd actually expect higher pricing.
Contracts/bundles/etc appear to charge less because they bundle together things on the assumption that consumption will follow a predictable distribution, however they are actually a mechanism for raising average selling price by giving people more than they need/want/use and charging them more for it.
They build in a margin on top of the average, or somewhere above it on that curve. This means the average user is likely paying more than for their share of usage. Sure, from the company's perspective they have to keep the resources around, but that's a scaling and cost-base issue for the company, not the concern of the user, and if the company scales well it shouldn't be much of an issue.
Ultimately with this service, the competition is $5/m for effectively unlimited usage. If this service costs the average user $10/m, then only a small fraction at the bottom end of the usage distribution are going to make a saving, and find it a compelling offering, all things being equal in terms of product quality etc.
This doesn't apply to everything of course, different industries, product categories, etc, are priced in different ways and have different customer expectations, but it's common and I think it applies here.
This dynamic is pretty complex and it's not at all clear that your argument holds even with the dynamic considered.
As of now, The pricing section on FAQ page provides examples of pricing https://upvpn.app/faq/#pricing
Moreover, If you like to see it visually the first picture of dashboard on landing page https://upvpn.app showcase real usage and real charges.
I provided addition info on pricing model here: https://news.ycombinator.com/item?id=36512794
Even if someone can spin up VPN server, UpVPN makes it much much quicker and hassle free to do it with one click or one cli command.
1. Someone who uses VPN very infrequently, likely a couple of times per year while using less than 500GB of traffic, and
2. Someone who doesn't use a VPN to bypass georestrictions, excluding most travelers, and
3. Someone who doesn't mind being classified as a bot
That must be an extremely tiny group of people, right?
Pricing is outrageous for daily VPN users, while your use of datacenter IPs means it's going to be almost useless for evading georestrictions.
Besides, I'm struggling to wrap my head around the concept of a "serverless VPNs". If you're actually spinning up a VPS for each customer then that seems like a very wasteful use of resources for no reason.
Taking any feedback and criticism is part of being on Hacker News.
Very slow and actually quite expensive. However, works well with Wireguard app on iOS!
Your comment beautifully describes why upvpn exists: It saves you time and makes it hassle free if you're setting up VPN servers.
I'd rather just use Mullvad for €5/mo.
12 hours of average usage for me would cost $4
Also: you say "when you end your VPN session, we promptly delete the record from our database that links your session to the specific cloud server", does it also get deleted from the database backups? (assuming you do any)
The privacy policy of UpVPN worries me.... Although they assert that protecting user privacy and data is a TOP priority, their logging procedures and data retention guidelines raise some red flags.
By the way, I highly recommend ValeVPN, which you used as an example, to anyone looking for a trusted VPN service to protect their privacy and improve their online experience. I've been a subscriber for over 4 months now, so I checked it out by myself!
In other words, the pitch is suspiciously light on details that actually matter to back their "serverless" claim. The only technical way to parse "serverless" is that their exit nodes are spread over end-user devices. So how did they end up there?
$10 is a prepaid balance you start with (which never expires) and consume by using UpVPN. One you run out of balance say few months down the line - you purchase again.
And maybe a smaller set like me who are geeks but prefer not to manage their own server even from a script. As if using such a script means no problems and you wont be googling for why x y or z isn’t working.
Some of just don't like screwing with servers and are willing to pay a premium for that. I absolutly loathe managing servers.