CryptoSeal (YC S11) Offers VPN As A Service
techcrunch.com
techcrunch.com
VPNs aren't anything new, but we're an easy to set up VPN service, and aimed at business/group use, vs. either the "privacy VPN" market or the "national firewall evasion" VPN market.
The idea is that we make it easier to use something like Amazon VPC to put your sensitive internal services behind a firewall, then only allow access to those services (or to admin features of your public-facing service) from a VPN.
We're adding other cool stuff to the VPN -- basically we want to be to your internal users and services what CloudFlare is to your public external users.
We've been running https://www.getcloak.com/ for about a year now. Let's swap "easy-to-set-up, easy-to-use" VPN war stories sometime if you're interested.
We're focused on groups of users and networks.
You may want to make sure that those two types of VPNs use entirely separate infrastructure, to make sure that crazy jurisdictions trying to block the latter don't end up blocking the former as well. You'll probably still have problems with that.
We've been thinking about how to handle the "company has a bunch of users, a few of them go to China sometimes" problem. That we might actually try to solve (by letting you have a private IP and testing against the firewalls out there, which are getting pretty sophisticated). Probably a few months away.
Seriously though, congrats on the launch.
We got started looking at how to make "trusted clouds", using DRM/tamper-resistant tech. The problem is building that in a way that anyone could actually adopt is really hard, so we figured we'd work on some related, easier problems, where we could build some of that tech internally and use it where it makes sense, first (key management, etc.)
Though I wrote the damn thing, so I'm probably biased.
Saved my &*s on several occasions allowing me to connct to a 'non-Internet' facing server.
Does not really have an enterprise feel to it and wonder if it ever will. It also lacks an open protocol description and/or clients on iOS or Android. However, an older build for ARM/Maemo is available. The lack of this limits it currently to a Windows and Linux environment.
I wonder if Salesforce, Oracle, Microsoft Azure, etc. would be likely to do some kind of virtual/software defined network thing in the future. It's an obvious choice for an IaaS provider, but being able to put your SaaS or PaaS on a customer-defined network makes a lot of sense too. Would love to talk to those guys.
It was indeed widely used in gaming circles, but gamers weren't really the target market I designed it for. They just happened to come along in droves, because I added support for network broadcasts and that made LAN games playable over the internet.
Also, I wasn't involved with Hamachi for few years now, but I think they had a plan to switch to TLS altogether, so that must've been done by now.
---
These solutions are amazingly better than trying to host a VPN from DDWRT on a low-powered router -- when the game host isn't on the router's LAN, there's a massive bandwidth penalty. It's worst on RTS and MOBA games, especially Demigod, where clients synchronize gamestate not just with the server, but with all peers. This isn't immediately obvious when hosting games, but every 100ms, each of the 6 clients are sending the checksum of ~1.2gb to 6 other clients, through your router. Twice.
Having a 5.x.x.x address assigned to your machine doesn't make all Internet traffic for that address go to your box. You either don't understand the concept of routing domains or you just feel like trashing Hamachi in general.
Hamachi is effectively null routing legitimate users of the space within their network.
Two - the idea to use 5.x/8 came through me and it dates back to a dot-bubble era managed VPN company I worked for, called eTunnels. These addresses are used for routing inside of virtual networks, which is a separate routing domain, disconnected from the Internet. While this does create a routing ambiguity at the VPN client that wants to talk to the Internet address of 5.x.x.x, it doesn't mean these addresses "leak" to the Internet and somehow disrupt general network flow to/from 5.x.x.x.
You might want to have a look at 100.64.0.0/10, the IANA allocation for carrier NAT implementations. Explicitly allocated to be non-unique and used within networks of private networks.
WRT 100.64.x.x. - back in '07 we pitched IANA an idea to have a dedicated class A network for VPN service providers. This was based on the assumption that while many people might use VPN networking, very few would be on two VPNs at the same time (which is neither too practical nor advisable). So having this space would've meant not needing to compete and resolve conflicts with 1918 addressing and it would also provide single direct-routed space within a VPN that natively supported OS broadcast traffic. Latter is a very big deal in Windows world, because of how a large chunk of Windows Networking works, and it's generally a useful thing to have for proper LAN emulation. IANA just waved us off.
(edit) Followed a link at the post you linked to and there's an official news release that says -
We’ve added IPv6 support to Hamachi a while back, and you can
simply turn off the use of the 5/8 space, but we realize that
IPv4 is still very important to most of you.
It sounds like the IPv6 support is there, but the client defaults to IPv4 addressing. This has probably to do with user-facing issues of using IPv6 (like customizing passthru rules in firewalling software and such) rather than with an inherent inability of Hamachi to run outside of v4 space. It is capable of pure tap tunneling after all.We're currently using the Juniper SSL-VPN hardware/software to support iOS users.
First time, http://cryptoseal.com/beta/ received a 400. Second time, http://connect.cryptoseal.com:8443/beta/thanks/ with a 400: http://cl.ly/image/0s1v1z3X0z3I
Why do you make us sign up for a beta/invite if we can't even use it right away and wait? I don't understand. What's the whole point of a launch if you're going to do that? First, you're having a bad registration flow because I'm already frustrated with your service. Two, I can't even use your product to test it and have to 'wait' for the invitation.
server_tokens off;
to your http section of your nginx.conf
I also don't get the comparison to CloudFlare. CF is a proxy service that optimizes and protects your site from attacks. A VPN provides a secure connection between computers. The only thing that's the same is that they're both security related.
Edit: After re-reading the article, looking at the site, and comments I realized I've misunderstood the service. The TC article made it sound like you were just selling VPN software. Now I understand that you're acting as an intermediary server, allowing clients to connect without setting up their own. It's an interesting idea but my first question still stands. Why not pay someone to setup a server for you?
Within that goal, we're looking at various pricing options, and additional bundled or a la carte services (DLP, logging, backup, etc.). $99/mo is just intended to communicate that if you want a single user VPN to use BitTorrent or IRC, you should look elsewhere. (I'll probably put up some Tor nodes again on separate networks to contribute to the "freedom of information" market)
The CloudFlare analogy is kind of a stretch, but the idea is that they do magic stuff to your front end customer traffic, and we do magic stuff to your back end internal user traffic. They're performance and security (mainly availability, some other security); we're manageability and security.
As for why you'd use a service vs. setting up a server and running it yourself, different users have different internal support costs for different things. I run my own services for some things. I use providers for others. Most businesses are generally happier buying a packaged service vs. paying someone to configure something custom and put it on a server and maintain it. It really depends on the environment.
Curiosity has bit me, so a question:
Have you done any testing regarding the 'cryto/security' space and the dark color theming? I know that dark themes are all the rage but I've always noticed that many people think of 'cryto/security' stuff as a dark, evil topic used by hackers and the like. I'd be curious to know if a more upbeat, lighter theme would have an impact on conversion. "Bringing security into the light" or whatever.
I personally like the style of GitHub more than virtually any other site.
I'm looking at this from the perspective of someone who works at a startup with a fair number of people whom are non-technical (primary developer who gets stuck with IT stuff as a result type situation). I've pushed security best practices on them in various forms to various levels of push back. I'd love a simpler way to get them to use VPNs for various functions, something simpler than sending them single use download links of openVPN installs with their security certificate embedded. This seems like it would help with this, but I can see that would get pushback on the site theme. e.g. "Is this really what I need to sign up for?" e-mails with a screenshot attached.
I'm not trying to be too critical and I hope you don't take it that way. Just trying to provide some feedback based what issue I may have with implementing your service.
You have a desktop VPN client in Java. But, but... why? I'm not trolling. This is such an unconventional choice of language for a VPN software, most of which is written in C or C++. Java is pretty much like going with Perl or Ada.
Linux/FreeBSD/etc. are likely to remain java for a longer period.
I hate Java, myself.
For example if Alice and Bob are both using CryptoSeal Connect then network traffic flows like this?
[Alice] <==> CryptoSeal <==> [Bob]
Also, small typo "We deploy mobile cleint software ..." under "Many Clients Supported". Otherwise nice site (I especially like the "seal" :D).
All of your traffic goes via us to your servers. This isn't ideal from a privacy perspective, but does allow IDS, DLP, etc. filtering. It's a tradeoff.
I wouldn't do it, personally, for individuals. For businesses, however, a contract with a service provider to do this kind of thing is totally reasonable. You still can use ssh/ssl/etc. on all of your traffic to your servers. This protects lower-value stuff and/or is belt-and-suspenders.
Being able to plug into something like this would be useful if it can automate/offload the client side VPN setup and simplify things for a client adding a new connection.
Unsexy and brilliant. I wish I understood your market more, but my only contribution is to say that an old client called me just today asking about VPNs and I bumbled around trying to sound knowledgeable. One swallow does not a summer make, but I have a feeling this is going to do well. Good luck.
What's the protocol here?
This webpage has a redirect loop The webpage at http://www.cryptoseal.com/beta/thanks has resulted in too many redirects. Clearing your cookies for this site or allowing third-party cookies may fix the problem. If not, it is possibly a server configuration issue and not a problem with your computer.
Totally looking to grow the team -- will probably post HN job ads shortly. Essentially we need a good front-end person (not necessarily great at front-end, like would be needed for an end-user consumer product, more generalist preferred), ideally python, who is basically familiar with security and wants to learn more -- and more back end/networking/security developers always.
(We're in the SF Bay Area, but seriously looking at a non-bay-area secondary office -- WA/TX/NV or maybe BC, in a few months.)
We're pretty good for "hiring from our network" on back end people, but not as good for front end/web tech. Even if someone isn't a fit for us, I'd love to talk to people and could maybe think of other places which would be interesting. ryan@cryptoseal.com.
I particularly like the clear straightforward wording on your website, which lets people know exactly what they can expect.