If they didn't try so hard to fight it, people might care less.
If they didn't try so hard to fight it, people might care less.
In 2016, Proton created its own subsidiary, and these people are now employed by Proton. But for this historical reason, the ProtonVPN keystore on Android still lists Tesonet as the organization name, even though it is fully controlled by Proton.
None of this is "debunking"; these are just the facts. You can make of them what you will, but you should be honest about what actually happened when you talk about it.
Entirely normal behaviour for a competitor to provide “HR assistance”.
In Proton's case, they already knew each other because Tesonet had previously offered to provide infrastructure during a DDoS attack against Proton.
So maybe it's a conspiracy, or maybe it's just how things go. You can make up your own mind, but you should provide the facts when you make sinister insinuations.
Here's the Handelsregisterauszug for Proton, which shows ownership: https://www.zefix.admin.ch/en/search/entity/list/firm/118926...
Proton's peering relationships: https://bgp.tools/as/62371#asinfo
I'm not sure what exactly you're looking for.
It doesn‘t. It’s a joint-stock corporation and while the shareholders are registered, the register is not public.
But I guess they could be lying.
The point is: we don't know.
So either:
1. Tesonet/Nord are loose with their private keys.
2. Proton isn’t being truthful.
Anyone who understands crypto and key management knows “not your keys, not your _____.”
If those staffers worked for Proton and not Nord, why did they have Nord’s key?
This level of negligence with private key management really can’t be explained away.
https://redlib.catsarch.com/r/ProtonVPN/comments/8ww4h2/prot...
I suppose you're free not to believe them, but I'm unsure what exactly you believe is happening here and what exactly Proton is lying about. Tesonet secretly owns them and has been running a decades-long misinformation campaign to trick you into thinking they don't? To what end? It's not like Tesonet is some nefarious company we should all be afraid of. What would they gain from lying about this if it were true?
And how can they make such an obvious mistake with their certs and then not make another one for the next decade? It's just not plausible.
At some point, you've gotta use some common sense.
1. Either Nord/Teso are loose with keys (horrible)
Or
2. Proton isn’t being truthful.
I don’t think it’s a conspiracy or anything that it is Tesonet/Nord. Rather, the problem is you cannot trust someone with your privacy if they can’t even manage their own keys.
[1] The explanation is poor at best and doesn’t explain why they worked so hard to try to delete all of the evidence (all of which was archived already). Additionally, nothing can explain away the lack of security with key management across these two orgs.
> worked so hard to try to delete all of the evidence
The cert is still there. Apparently, they didn't work nearly hard enough.
As pointed out on this reddit post [3], Proton's appears to contradict itself a number of times.
It's a good thing trust based VPN's are obsolete. After all, trust isn't constant [4] as seen in this article showing how Proton supplied IP addresses to "authorities."
[3] https://www.reddit.com/r/technology/comments/8x9aik/protonvp...
[4] https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
This is a hilarious way to start an ostensibly serious investigation. It's not as if you could easily figure out the answer to that.
At some point, you have to acknowledge that you're a clown.
How? it is obvious.
> During Proton's expansion into Eastern Europe, Tesonet initially assisted Proton with HR, payroll, and local regulation, so for a period of time, people working for Proton were employed by Tesonet, since Proton had no local subsidiary that could hire them. These were not "shared employees", they worked exclusively for Proton.
So basically same people managed teams, same people paid the employes, but my "Links to" is doing heavy lifting and in the previous sentence you say "ProtonVPN is owned by Proton, which has no legal ownership ties with Tesonet."? Who is doing the heavy lifting here?
How much is Tesonet or Proton paying you to post in here?
Sadly, they're not paying me anything, but I would suggest that any belief system in which information contradictory to your belief reinforces your belief is inherently problematic.
So how much is Nord paying you to post here?
Now that I launched a verifiable VPN, they are once again sending legal threats [1].
https://cyberinsider.com/private-internet-access-kape-crossr...
Re verifiability: the point isn’t trust us, it’s that you don’t have to.
We built it so anyone can independently confirm what’s running.
1. All server and client code is published.
2. Builds are reproducible.
3. Each node provides cryptographic attestations of its runtime and routing identity.
4. Enclaves are used for verifiable isolation.
You can peruse the code yourself to see exactly why the transparency we bring makes legacy “trust based” VPNs obsolete: https://github.com/vpdotnet/vpnetd-sgx
Is there some indication the user has that your server isn't simply hard coded to return the right magic number? I don't understand how this provides any assurance of anything.
When the client connects to the server, the server presents a tls certificate that includes an attestation (with OID 1.3.6.1.4.1.311.105.1) which certifies a number of things:
- the TLS certificate's own public key (to make sure the connection is secure) - The enclave hash
It is signed by Intel with a chain of custody going to intel's CA root. It's not "just a magic number" but "a magic number certified by Intel", of course it's up to you to choose to trust Intel or not, but it goes a much longer way than any other VPN.