FrootVPN – Surf anonymously on the Internet
frootvpn.com
frootvpn.com
Furthermore, their domain is protected by WhoisGuard (Panama). If they (the people involved, not the servers) were sitting in Sweden this would be unnecessary (compare IPredator). The IP address behind the website points to the same Swedish datacenter(s) that the services surrounding The Pirate Bay use as well (Portlane). IPredator itself seems to have moved to Cyprus though.
Uppercase and underlined "anonymous" next to plain text passwords via email is just unprofessional.
Free is a con.
If you want a cheap VPN that you control (and that's faster than Tor), set up an endpoint on something that takes Bitcoin payment and pay with Bitcoins obtained via an anonymous route. This list might be helpful.
I wrote a script to spin up a new instance when I need it, and to terminate it when I don't. It should cost less than $10/mo, and I only pay for what I use.
https://gist.github.com/anonymous/223853355d67123fdda8
This assumes that you are somewhat familiar with EC2 and have already set up a keypair and a security group that allows incoming port 22. Just read the instructions at the top and change the settings to fit your needs.
Set your browser to use SOCKS host 127.0.0.1, port 5222 (or whatever you change it to). This allows you to have a browser using the tunnel and everything else using your native connection.
Let me know if you have any questions.
Hosting you own VPN server seems overkill for this kind of use case. There are many trustworthy VPN providers that I'd recommend for use cases unrelated tor BitTorrent. A couple of years ago people recommended SwissVPN over and over to me, though I've never used it. I was a happy IPredator customer for quite some time.
If you want to host your own VPN server (let's face it, servers are useful anyway), I'd recommend cloud providers other than Amazon. Iceland, Sweden and Germany are very friendly countries.
There's a fundamental difference here. With EC2, you get a server that knows who you are and what you're saying (at least they know who you're talking with, if you use HTTPS). The TOR entry node only knows who you are, but knows nothing about who you're communicating with or what you're saying.
There is always a server that knows who you are.
Whether it's an OpenVPN server hosted on an EC2
instance or a TOR entry node.
Correction: the TOR entry node only knows the data came from you, but there's no way for it to know whether the data originated from you or not. For all it knows, you could be a relay and the data came from someone else.There's always a server that knows something - but using EC2 means it is extremely easy to tie to your identity through your credit card, shipping and billing addresses, etc.
And Amazon is in bed with everyone VPN users might want to stay anonymous from - so EC2 is an exceptionally poor choice if you care about anonymity.
Okay but please don't mention 'Tor' side by side with VPNs they are essentially different services/solutions, for different needs. Even on HN I see that many people are so confused about Tor that consider the traffic encrypted by default (when it's not not) or they use tor to perform the usual daily web operations (Facebook, twitter, email, etc.) which totally beat the purpose of Tor but would be excellent use case for a (paid or self-hosted) VPN.
Setting up a VPN server takes very little time. From a default Ubuntu installation you only need to install the OpenVPN Access Server package, visit a web page and add a user.
You can do this from a cloud service provider in a location with favorable privacy laws, like Iceland. I do this with GreenQloud, and just spin up my VPN instance when I'm on an untrustworthy wifi network, behind a corporate firewall, traveling to a country that censors, or whatever. Powered on instances cost little, and powered off nearly nothing. The attack surface is low, as it's usually powered off.
People who wish to be nearly untraceable can use a prepaid credit card for anonymity.
Does anyone have experience with this? I tried it once, and found that most places blocked the use of these cards and needed a "real" one.
Can you use it to get money (ATM or cashback)? I assume so, in which case this restriction makes it extra stupid.
At first I figured if it was possible to buy a gift card with a gift card they wouldn't be able to track that very easily / as easily. But then, what about cash. So it does seem like kind of a moot point to me, maybe someone in Finance can explain the reasoning better?
What?
(I am not defending this shady VPN service)
Tor is a service but by reading the source code, you can see (if you understand the code) that nothing monetizable leaves your computer.
I don't have as much confidence in Tox just because it hasn't been around as long (and I haven't read the source).
If the mere possibility than a service you use might in the future have ads is sufficient to justify the phrase "you are the product", then I don't see how anything can be an exception to that. After all, the next release of Tor might have ads! Who knows?
Free software is write once and release; it costs the author nothing to maintain it. Free services require maintenance and incur operating expenses that need to be covered somewhere.
The original quote was always about SaaS anyway.
But yeah, I don't understand how they're paying for it. My best guess would be they found a loophole to exploit peering agreements, similar to how small rural telephone companies will set up free conference bridges because the big telcos have to pay them connection fees.
Or they're just capturing info and selling it (unlikely; personal information just isn't worth that much and it's easy enough to buy already from data brokers).
Or they're MITMing the big ad networks and showing their own ads instead. I consider this the most likely scenario.
On second reading I realize that I basically in no way say that.
Agreed with everything you said though, it's not legit.
They should avoid emailing them however, if they can.
So if you change it immediately to something more secure, and it might not be a security risk after all.
And on top of all that, sending it plaintext via email, itself a largely open format, means they've broadcast it to all kinds of other potentially bad actors.
Plus it indicates (to me) a questionable grasp of security, not a great sign for a VPN provider.
Its just wrong.
It'd be acceptable if it was a random password generated for email-auth reasons. Not acceptable if you're setting the password.
But if every single comment thus far isn't enough of an indication.. as I have never experienced these security issues in the past, I think it's fair to say.. stay away, stay far away...
- free
- no logs
- support
- unlimited bandwidth
Is this some kind of badly executed sting operation?
"We dont keep any logs of any kind. all we ask from you is your email address and username. and thats it. no other information is keept in our system."
One must immediately question a company whose customer facing copy appears in such a way.
Shouldn't that be "back to you"? Not back too you.