HNHacker News
TopNewBestAskShowJobs

rasengan

4,974 karma · joined December 27, 2010

My comments are my own and do not reflect any of the organizations, or nations, I belong to unless I specifically clarify as such in a comment.
submissionscomments
rasengan··on Trusted Execution Environments? More Like "Trust Us, Bro" Environments
This is a great list of academic attacks, but it proves less than you think.

Yes, TEEs have been broken in dozens of ways. Side channels, transient execution, voltage manipulation, interrupt timing... etc. To be fair, you could make an equally impressive list for many security primitives.

The question isn't "can TEEs be broken?" since clearly they can, but rather what's your threat model and what are your alternatives?

What TEEs actually defend against is passive compromise. They force an attacker to actively exploit rather than just read memory. That legal and operational distinction matters enormously in practice.

The alternative to TEE is "no hardware isolation at all," and that's strictly worse for every threat model where TEEs provide value.

Additionally, you still get attestation which gives you cryptographic proof of what code is running.

rasengan··on Google Safe Browsing incident
Getting on the public suffix list is easier said than done [1]. They can simply say no if they feel like it and are making sure to be able to keep said rights as a "project" vs a "business," [2] which has its pros and cons.

[1] https://github.com/publicsuffix/list/blob/main/public_suffix...

[2] https://groups.google.com/g/publicsuffix-discuss/c/xJZHBlyqq...

rasengan··on Suspicionless ChatControl must be taboo in a state governed by the rule of law
Surveillance is the occupation of the mental space and results in modification of behavior. Default mass surveillance, or in other words suspicionless surveillance, then leads to the end of mental sovereignty and, therefore, freedom.

That is not a state governed by rule of law, but instead, a peoples being ruled by the power of surveillance.

rasengan··on Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
They worked pretty hard as detailed in an archived article changing names and any records they could [1], but you're right - not good enough [2].

As pointed out on this reddit post [3], Proton's appears to contradict itself a number of times.

It's a good thing trust based VPN's are obsolete. After all, trust isn't constant [4] as seen in this article showing how Proton supplied IP addresses to "authorities."

[1] https://archive.ph/wG8t8

[2] https://archive.ph/4bzBm

[3] https://www.reddit.com/r/technology/comments/8x9aik/protonvp...

[4] https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

rasengan··on Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
My comment still applies regardless of any level of “explaining” [1]:

1. Either Nord/Teso are loose with keys (horrible)

Or

2. Proton isn’t being truthful.

I don’t think it’s a conspiracy or anything that it is Tesonet/Nord. Rather, the problem is you cannot trust someone with your privacy if they can’t even manage their own keys.

[1] The explanation is poor at best and doesn’t explain why they worked so hard to try to delete all of the evidence (all of which was archived already). Additionally, nothing can explain away the lack of security with key management across these two orgs.

rasengan··on Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
Yeah, agreed. Most VPNs just move the trust boundary from your ISP to another opaque network and call it privacy. There’s no way to verify what’s running, who controls it, or what happens to your data once it leaves your machine.

We solve this with vp.net, by making the service verifiable. The code can be reviewed, the builds are reproducible, and each node can prove what software it’s running and where your traffic actually goes [1].

It doesn’t turn a VPN into an anonymity tool, but it makes trust measurable instead of blind. That’s the part the industry should have fixed a long time ago.

[1] https://youtu.be/sz7NAe0G1_Y

rasengan··on Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
> so for a period of time, people working for Proton were employed by Tesonet, since Proton had no local subsidiary that could hire them. These were not "shared employees", they worked exclusively for Proton. In 2016, Proton created its own subsidiary, and these people are now employed by Proton. But for this historical reason, the ProtonVPN keystore on Android still lists Tesonet as the organization name, even though it is fully controlled by Proton.

So either:

1. Tesonet/Nord are loose with their private keys.

2. Proton isn’t being truthful.

Anyone who understands crypto and key management knows “not your keys, not your _____.”

If those staffers worked for Proton and not Nord, why did they have Nord’s key?

This level of negligence with private key management really can’t be explained away.

rasengan··on Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
You might find this helpful: https://youtu.be/sz7NAe0G1_Y?si=focPEWli8xv7NCDi

Re verifiability: the point isn’t trust us, it’s that you don’t have to.

We built it so anyone can independently confirm what’s running.

1. All server and client code is published.

2. Builds are reproducible.

3. Each node provides cryptographic attestations of its runtime and routing identity.

4. Enclaves are used for verifiable isolation.

You can peruse the code yourself to see exactly why the transparency we bring makes legacy “trust based” VPNs obsolete: https://github.com/vpdotnet/vpnetd-sgx

rasengan··on Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
I appreciate the engagement, but it’s become clear that this particular user has been repeatedly following my posts to respond negatively - a stalker if you will [1]. I’d prefer to keep the discussion focused on facts, not personalities.

The key point, you don’t have to trust us, and we don’t want you to. Trust code, not people. That’s the foundation of the entire effort.

As for the Freenode situation, the popular narrative has been repeatedly misrepresented. The core claims were debunked and the receipts are here: http://techrights.org/wp-content/uploads/2021/05/lee-side.pd....

To clarify a few historical points:

1. The so-called “takeover” was being organized long before my involvement, as shown by domain registration dates and internal meeting notes. I was a more convenient target than Christel, which might explain why she asked me to buy it from her.

2. False narratives were already being circulated to open source projects before any administrative changes occurred. The subsequent channel topic changes were a reaction to those actions, though I’ve acknowledged those decisions weren’t ideal in hindsight.

On broader context, much of what’s now called “funding FOSS” doesn’t reach active developers. It tends to reward organizers and promoters rather than those writing meaningful code. Supporting individual developers directly remains a better way to sustain real innovation.

Ironically, several of the ex-staff I defended for years against serious allegations (search “OldCoder” if you’re unfamiliar) went on to form Libera, attempted to seize the freenode IRC domain, and created a false narrative about events. It’s disappointing, but not surprising given the leftist politics at play.

If you want to understand the larger trends affecting open source today, I recommend Lunduke’s Journal and similar analyses. Most major FOSS projects are no longer developer run… just look at Mozilla for an example.

[1] https://news.ycombinator.com/item?id=44921771

rasengan··on Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
I did not sell PIA. I entered into a merger agreement to create a publicly owned privacy company. Without getting into detail, I left the company on principle receiving only 1/3rd of the value for the shares.
rasengan··on Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)
Back when I was running PIA, they threatened me a significant amount just for pointing these facts out.

Now that I launched a verifiable VPN, they are once again sending legal threats [1].

[1] https://vp.net/l/en-US/blog/Verified-Privacy-vs-Trust

rasengan··on Show HN: Autism Simulator
Cool game. That said, autism is a spectrum. You can’t just say “this iz wut autism like.”
rasengan··on Trevor Milton's Nikola case dropped by SEC following Trump pardon
Either corruption was always happening maximally, and we've finally begun to notice , or corruption has reached a new maximum.

Either way, it's maximum corruption.

And we, the people, continue to choose "public discourse" as a mechanism to bring awareness and, perhaps, attend to the issue; yet, the discourse available to the people is limited, both economically and even in social media, algorithmically.

I hate to sound like a decentralization fanatic, but decentralizing power away from centralized actors is the only way we will be able to right these wrongs and essentially bring fairness to society.

We, the people, deserve to reap rewards based on skill and the proper application thereof.

rasengan··on PureVPN IPv6 Leak
> If you can't see your VPN's source code, you can almost safely assume that they're broken in some way.

This is definitely true insofar that you better be able to see client code. That said, since you cannot see what the server is running, even if they release their code, you will still end up with a trust actor or two (vpn operator or sometimes multiple vpn operators in double hop cases).

That’s exactly the reason we introduced deterministic and verifiable VPN technology on https://VP.NET which allows you to actually see the code the VPN servers are running. Instead of trust in a non deterministic human actor you can now trust deterministic and verifiable code.

It is the end of privacy theater!

[1] I am a co-founder of VP.NET

rasengan··on PureVPN IPv6 Leak
You do need to trust Intel as it relates to deterministic and verifiable SGX hardware. SGX has had issues, but these are fixed pretty quickly [1]. Creating the isolated layer like SGX gives you verification of what is running on VP.NET's servers though, and the code is available to review and compile yourself so you can verify it is the same [2].

From a defense in depth standpoint, the more layered and isolated securities, the better.

[1] https://sgx.fail

[2] https://github.com/vpdotnet/vpnetd-sgx

rasengan··on PureVPN IPv6 Leak
VP.NET doesn't require any trust at all [1][2].

[1] https://vp.net/l/en-US/blog/Don%27t-Trust-Verify

[2] I work for VP.NET and can answer any questions regarding the technology as well!

rasengan··on PureVPN IPv6 Leak
Separately, PureVPN is one of the providers you can’t trust [1].

[1] https://www.makeuseof.com/worst-vpns-you-shouldnt-trust/

rasengan··on Pass: Unix Password Manager
Another great software contribution to the world by Jason Donenfeld, creator of WireGuard!
rasengan··on The Murder of Charlie Kirk Didn't Help Anyone
> But I recognize that violence can sometimes become a necessity—which is why I say that people should forgo the use of violence unless all non-violent paths to resolve a conflict have either been exhausted or taken off the table.

> Lethal violence is the line that should only be crossed when it, too, is the last available option.

No, violence is never necessary. Once you use violence, you start the downward spiral of perpetual hatred; after all, if someone harms one that you love, forgiveness becomes difficult.

The only solution to perpetual hatred is peace, understanding and love.

As long as you think violence is a solution, you'll gravitate toward the short term gratification that may or may not come therewith.

Get that out of your head.

Violence is never the answer.

rasengan··on Who Owns, Operates, and Develops Your VPN Matters
You can since the enclave attests to what is running!

This is also coupled with the crypto and NAT occuring in-enclave with various timing/obfuscations. It's verifiably private.

rasengan··on The London Bridge Effect
Oops!
rasengan··on A Zero Trust VPN
VP.NET is the first VPN provider that you don't have to trust, but instead, can verify directly.

See the source, which is verifiable: https://github.com/vpdotnet/vpnetd-sgx

You can learn more here: https://vp.net/l/en-US/blog/Don%27t-Trust-Verify

rasengan··on Who Owns, Operates, and Develops Your VPN Matters
Shameless plug: VP.NET [1] runs in a trusted execution environment (enclave) so you can verify it is doing what it is supposed to do and not anything else!

[1] https://vp.net/l/en-US/blog/Don%27t-Trust-Verify

rasengan··on A privacy VPN you can verify
Thanks for this as it was a bit more thoughtful and an almost accurate depiction.

However, there are some discrepancies:

1. The ex staffers were already preparing their takeover event long before my name came in the picture. Domain registration dates and meeting minutes notes proves this. I was likely an easier target than Christel - or maybe that’s why she asked me to buy it from her.

2. The ex staffers had already begun emailing false narratives to open source projects before any of these actions began.

The channel topic changes did occur as a result of #2, but timing and reasoning is important. I do, however, think that these actions were a mistake.

Today, it’s pointless to fund FOSS projects since many of these funds end up going to non developers who are good at socializing but not meaningful development. Instead it’s better to support individual developers.

rasengan··on A privacy VPN you can verify
If you’re still debating trust in a VPN you’re doing it wrong, but that’s your prerogative. For the rest, code is more important than words from non-deterministic people.

As for the freenode issue, look at the facts before parroting false narratives. I posted receipts - they are clear.

rasengan··on A privacy VPN you can verify
I think you should look into the narrative before parroting falsehoods. Further, I’m not sure what came off as a “revenge” in my response unless facts are being interpreted as such.
rasengan··on A privacy VPN you can verify
It would probably make sense to look into details before parroting false narratives.

Additionally, if you’re still talking about trust it means you don’t understand the technical implications of this.

rasengan··on A privacy VPN you can verify
Defense in depth dictates that this is more secure than standard VPNs out there (Mullvad, Proton, Nord, Express, etc.).

Any real security researcher recognizes this.

If you think 'trusting random strangers' is a better security architecture, then you should not work in security.

rasengan··on A privacy VPN you can verify
> guy who destroyed Mt Gox

Let me correct that for you - the guy who brought you the first Bitcoin exchange and arguably helped pave the way for cryptocurrencies today.

> guy who destroyed Freenode

This was already debunked [1]. I tried to save freenode - I was the only one funding it up until the point where freenode's ownership "gave" it to me essentially which resulted in the non-developer staff to attempt to hostile takeover the network [2].

The end result was that they gave control of the domain back to me (and as a result, freenode).

> Personally, I'd rather trust in Mullvad.

Trusting random teams of people on the internet isn't exactly a form of security or privacy.

Developers and cypherpunks trust code, not words.

If you're a developer, I'd highly suggest you read the code.

> This VPN requires you to trust in Intel

You really can't use the internet or any internet-distributed software without trusting Intel. Maybe you're better off logging out if that is your policy. ¯\_(ツ)_/¯

[1] http://techrights.org/wp-content/uploads/2021/05/lee-side.pd...

[2] Funny how non-developers keep ruining Open Source (Mozilla, and many others - see Lunduke Journal for more).

rasengan··on A privacy VPN you can verify
The whole point here is you don’t have to trust us - we don’t want you to. We want you to trust code, period.

That said, the freenode issue was debunked and you can see receipts here: http://techrights.org/wp-content/uploads/2021/05/lee-side.pd...

I funded freenode since 2011 so any narrative that makes it seem I just appeared out of nowhere is factually untrue. Also, I was handed it because Christel felt I was a good custodian thereof. Instead, former staff who I protected from allegations made by OldCoder for years, went on to form Libera, tried to steal the domain for a developers irc network when they themselves shockingly couldn’t even code a simple irc client, and then made up a false narrative.

The state of open source generally isn’t what you think and you would do well for yourself to read Lunduke’s Journal among other things. The developers don’t actually run most of the projects these days. Look at Mozilla.

← PreviousPage 2 of 34Next →