8 ms·
Detailed VPN Comparison Chart
- ryanlol 10y agoThis is terrible. Whoever "That One Privacy Guy" is, should really consider not being a dick and stop pushing VPNs as a privacy tool. And yes, you're a dick if you even kind-of imply that VPNs might be good for privacy without immediately providing a strong disclaimer: if it matters, they aren't. Edit: Oh wow, it's worse than I expected. Check out https://thatoneprivacysite.net/choosing-the-best-vpn-for-you/ https://thatoneprivacysite.net/choosing-the-best-vpn-for-you... The vast majority of the recommendations here have absolutely no connection with reality. This entire website is bullshit, here's a few quick quotes. >a. More on Trust >As a lawyer represents your legal interests, a VPN service (among others) represents your privacy interests. >c. Jurisdiction >In the last few years, certain revelations have been made manifest regarding the mass surveillance programs of various countries around the globe. These countries are known as the five, nine, and fourteen eyes. These countries not only spy on their own citizens where they can get away with it, but they spy on each others, and swap notes to bypass governmental restrictions on power. If a service, or the people who run a service is based in one of these countries, it’s not unreasonable to expect that they may be susceptible to unlawful searches and compromises made in the name of national security Suggesting that NSA & Co. don't spy outside of FVEY (or fourteen eyes if that's what you prefer) countries is utterly ridiculous at it's face and just makes it look like the author hasn't studied this stuff at all. Instead of blogging about mass surveillance and unlawful searches, maybe focus on the more realistic issues like search and wiretap warrants which are ridiculously easy to get in some countries?
- photoGrant 10y agoWhat's your advice?
- ryanlol 10y agoIf privacy is the concern? Tor.
- antihero 10y agoSure, but for day to day browsing, Tor is shit. This is more to prevent dragnet bullshit like the UK RIPA which requires ISPs to keep a list of sites visited.
- ryanlol 10y ago>Sure, but for day to day browsing, Tor is shit. Sure, but for privacy, VPNs are shit. You can't recommend VPNs for privacy. If this was branded differently, I'm sure it could be a great resource. >This is more to prevent dragnet bullshit like the UK RIPA which requires ISPs to keep a list of sites visited. The site doesn't really read like that, it has several suggestions that don't seem to apply to those seeking only for minimal levels of privacy to maybe hide from the local government. As a quick example: >Avoid VPNs that use CloudFlare, Incapsula, and other such services. Doesn't seem like a major concern for someone only worried about UK RIPA.
- Freak_NL 10y ago> Sure, but for privacy, VPNs are shit. You can't recommend VPNs for privacy. Why not? Doesn't it depend on your purpose and threat level? If you have state level actors chasing you than VPNs will only be part of your opsec toolchest — preferring TOR where possible and being very strict about where you access the internet (certainly not at home). But if you are just downloading the latest episode of Sherlock from your local hive of wretched scum and villainy, a VPN will surely help. VPNs are only part of the solution of course (not using any social media, not connecting to any of your normal accounts, limiting VPN use to whatever it is you want to keep private), but you seem adamant that even this is not a valid use of VPNs, or am I misreading your posts?
- ryanlol 10y ago>But if you are just downloading the latest episode of Sherlock from your local hive of wretched scum and villainy, a VPN will surely help. Then you should recommend VPNs for that specific purpose, never for generic "privacy". >VPNs are only part of the solution of course (not using any social media, not connecting to any of your normal accounts, limiting VPN use to whatever it is you want to keep private), but you seem adamant that even this is not a valid use of VPNs, or am I misreading your posts? This is reasonable, I use VPNs for similar purposes too. But recommending VPNs for "privacy" needs to come with a big disclaimer. "If it's something that actually matters, they won't help you." If you do something illegal using a VPN in very many cases your local police department will be able to use mutual legal assistance treaties to search and/or wiretap your VPN providers.
- noja 10y agoI can see you complaining, very strongly, but wouldn't it be better provide some kind of constructive feedback.
- ryanlol 10y agoI guess you replied to the wrong post, I made a rather explicit recommendation. >you're a dick if you even kind-of imply that VPNs might be good for privacy without immediately providing a strong disclaimer: if it matters, they aren't. This website reads like it's written by an amateur from some torrenting subreddit, there's not much constructive feedback to be given here besides "do some actual research and do it all again"
- noja 10y agoHave you done some research? Can you tell us what you recommend?
- ryanlol 10y ago>Have you done some research? Yes. >Can you tell us what you recommend? For privacy? Tor.
- throwaway-hn123 10y agoHahahahahahahaha - brilliant trolling!
- deleted 10y ago[deleted]
- pc86 10y agoIf the feedback "this is utter garbage" I'm not sure there is any constructive feedback. Sometimes you just need to say something is garbage and move on.
- vpnspeedtest 10y agohttp://vpnspeedtest.org/ http://vpnspeedtest.org/ tests over 20 VPN services to find the maximum speed of each VPN from 8 locations around the world. ThatOnePrivacyGuy should use their open source speed test tool instead as the tests are verifiable (unlike his tests from a single location which nobody can reproduce).
- jlgaddis 10y agoI don't see a "disclaimer/disclosure" (kinda standard practice around here) so I assume your username is entirely coincidental?
- gduplessy 10y agoHis post history points to the contrary eh
- jessaustin 10y agoThe 'name and the link are less than a centimeter apart on one's screen. That seems enough to clue in most readers?
- jlgaddis 10y agoIt was mere chance that I noticed it at all. I normally don't (consciously) pay much attention to usernames. "GOOGLE CEO" could reply to me and I probably wouldn't notice it so the disclaimers are a nice addition, IMO.
- jagermo 10y agoplus, the OP talks in the third person "should use their serivce", so it is a little misleading.
- okbake 10y agoYeah, it's not so subtle. But then again: > ThatOnePrivacyGuy should use their open source speed test tool instead Using their instead of our makes it sound like there is no affiliation.
- mulrian 10y agoThink its suffering from the HN effect - out of resources for me.
- Codywastaken 10y agoInternet hug of death
- adontz 10y agoError 508. Resource Limit Is Reached
- pedro2 10y agoThat site should have a top 3 pick, tailored for paranoia, torrenting and normal unsecured wifi hotspot hardening. Personally: I use AirVPN because to me it matters the client is open source. For all others, I guess PIA (Private Internet Access) is fine.
- Freak_NL 10y ago> I use AirVPN because to me it matters the client is open source. Don't most VPN providers offer OpenVPN as an option? Private Internet Access does. I always assumed that the client offered is to have an easy setup method for users who don't know how to configure a normal VPN client safely.
- subliminalpanda 10y agoIt's been a while but the last time I used PIA I noticed that their configurations were woefully insecure (BF-CBC Ciphers, no tls-auth, pre-shared keys instead of certificates). This was maybe a couple of years ago. Has that changed recently?
- PTRFRLL 10y agoYes, they recently updated their OpenVPN configuration and now have a 'strong' OpenVPN config option. >All our servers are now running OpenVPN on UDP port 1197 with our 4096bit RSA server certificate, 4096bit Diffie-Helman key exchange, AES-256-CBC, SHA256 and TLS v1.0-1.2 support. https://www.privateinternetaccess.com/forum/discussion/20093/using-stock-openvpn-with-strong-encryption-settings https://www.privateinternetaccess.com/forum/discussion/20093...
- ggregoire 10y agoI use ExpressVPN mainly for Netflix, but most of their servers are banned and it's quite expensive. What VPN do you use for this purpose?
- Freak_NL 10y agoThat's pointless. Netflix bans each and every VPN IP address they can get their hands on — they are quite thorough. You might as well get a cheaper VPN subscription with a VPN provider who condones torrenting and access the shows you are missing that way.
- spookyuser 10y agoWell then they haven't got every vpn ip because expressvpn has been working with netflix for almost 6 months straight in my experience.
- DylanFuery 10y agoNordVPN allows access to Netflix (American) if you want, even connecting to say a Canadian server gives you access automatically. Hasn't been blocked In the year I've used it, works great, fast and always get 1080P streams. Torrents on the other hand, I've been having connection issues to other peers. Not sure what's up there.
- Tinyyy 10y agoHow much profit does a VPN operator make? Since running my own box on DigitalOcean costs as much as a VPN ($5), at <10% traffic utilisation.
- AlexCoventry 10y agoWouldn't a VPN run off DO hosts quickly trigger their network abuse filters?
- nine_k 10y agoWhy would it? As long as you're in within your traffic limits, I suppose DO is happy to sell you the service you paid for. You're also likely not adding much SSD IOPS by running a VPN, but you have paid for a bit of storage, so you're a lucrative customer :) Anecdotally, people routinely run small-scale VPN off DO or even AWS free tier hosts.
- AlexCoventry 10y agoI was mostly thinking about the DMCA notices, the spam and the CP traffic you would end up being associated with.
- JosephRedfern 10y agoI know that NordVPN use DO for some of their VPN servers. I don't know how (or if) they handle abuse reports from DO.
- JorgeGT 10y agoI also run my VPN on a cheap VPS. Dedicated VPN companies can easily come under attack/scrutiny, or could have temptations of selling user data if subscribers fall, but I doubt anyone is monitoring individual, ephemeral DO droplets/AWS instances.
- sarsaparilla 10y agoIf you're the only user of your VPN, doesn't that make it pretty easy to trace your usage back to you? I would have thought that using a VPN Provider would assist privacy by making it hard to figure out which client initiated the any request coming out of the VPN node...
- michaelt 10y agoIf I was the NSA, I'd certainly be looking to launch a VPN company or two - maybe even subsidising their offerings, to get them to the top of the performance and value for money charts. After all, getting users to voluntarily direct their traffic through your network would be much easier than installing snooping hardware at every ISP, backdooring hardware in transit or snooping on undersea cables.
- pilif 10y ago> If I was the NSA, I'd certainly be looking to launch a VPN company or two not worth the trouble when you can just compel existing VPN companies to send all traffic to you.
- deleted 10y ago[deleted]
- ionised 10y agoIn foreign jurisdictions?
- sixothree 10y agoThe obvious answer to this is - if you're paying for a VPN in hopes of avoiding the NSA then you're using the wrong technology. But since the NSA apparently shares its findings with other agencies, then the same applies if you're using a VPN in hopes of avoiding any sort of government monitoring. So a VPN is only useful to (possibly) help protect yourself from corporate spying.
- patcheudor 10y agoMeh, just get vendors to mess up the implementation of their VPN protocol stack. This one was likely far from intentional but demonstrates quite clearly what can happen when implementations go south: https://www.kb.cert.org/vuls/id/905344 https://www.kb.cert.org/vuls/id/905344
- ryanlol 10y agoIf you were the NSA you could hack any VPN company on demand. Hell, most of them host in super cheap DCs too so guess how good the physical security is?
- gambiting 10y agoI just get an AJAX error when trying to filter the list.
- Johnny555 10y agoI've seen lots of VPN comparisons that rate VPN providers on what they do and do not log. But who really verifies this? What's to stop VPN provider X from claiming "We don't log anything", while simultaneously streaming a real-time log to any government agency that asks for it?
- PTRFRLL 10y agoDefinitely a valid point. A recent court case involving VPN provider Private Internet Access seemed to back up their 'no logs' policy. >“A subpoena was sent to London Trust Media and the only information they could provide is that the cluster of IP addresses being used was from the east coast of the United States,” the FBI’s complaint reads.[1] Unfortunately, waiting for a court case involving your VPN provider isn't a great way to determine what they log. [1] https://torrentfreak.com/vpn-providers-no-logging-claims-tested-in-fbi-case-160312/ https://torrentfreak.com/vpn-providers-no-logging-claims-tes...
- inertial 10y agoAnd a few DIY VPN options (open source ansible etc. scripts) that have been features on HN recently (in order of popularity) https://github.com/jlund/streisand https://github.com/jlund/streisand (6000+ stars) https://github.com/sovereign/sovereign https://github.com/sovereign/sovereign (6000+ stars) https://github.com/Nyr/openvpn-install https://github.com/Nyr/openvpn-install (3000+ stars) https://github.com/ttlequals0/autovpn https://github.com/ttlequals0/autovpn (1400+ stars) https://github.com/trailofbits/algo https://github.com/trailofbits/algo (1100+ stars) https://github.com/robbintt/popup-openvpn https://github.com/robbintt/popup-openvpn (700+ stars)
- brotherjerky 10y agoHas anyone setup OpenVPN via Docker? I've seen some of the images, just wondering if anyone has actually got it working.
- nmjohn 10y agoYes, it works quite well - For an example setup, this is my setup script [0] to bootstrap a digital ocean droplet + launch an openvpn container using this image [1] [0]: https://github.com/n-johnson/setup-openvpn-server https://github.com/n-johnson/setup-openvpn-server [1]: https://github.com/n-johnson/dockvpn https://github.com/n-johnson/dockvpn
- Smushman 10y agoUsing openvpn with deluge in UnRaid as a container - runs flawlessly, and not leaking (re: data out of the VPN) as verified by firewall logs for 3 months now.
- brotherjerky 10y agoNice, which docker image?
- Smushman 10y agoI believe this is what you were looking for: binhex/arch-delugevpn If you have trouble reach out again.
- jeppesen-io 10y agoSurprised not see Pritunl on the list, or here. Its such a nice product. https://pritunl.com/ https://pritunl.com/
- RJIb8RBYxzAMX9u 10y agoGenuine question: why's OpenVPN so popular over L2TP/IPsec? Configuration on the server side is maybe a little more complicated, but configuration on the client side is super simple, as all major OS, mobile or otherwise, have support built-in. I've read arguments that firewalls tend to block IPsec packets, but there's also UDP encapsulation. And IME, I've never had connectivity issues, from multiple random coffee shop / airport WiFi, in multiple countries. I suspect it's because Cisco's VPN product used to (still?) uses IPsec, just with proprietary authentication schemes, and a lot of businesses use it, so most firewalls are configured to let it through.
- walrus01 10y agoat the expense of latency and performance, openvpn can run in purely TCP mode which is more likely to survive shitty wifi connections and aggressive/stupid captive portal wifi and firewalls/NATs like you might find in an airport. I have an openvpn server running its public interface on port 443 in tcp mode which is frequently accessible when ipsec stuff is blocked. openvpn can also be used with obfsproxy
- RJIb8RBYxzAMX9u 10y ago> [...] openvpn can run in purely TCP mode which is more likely to survive shitty wifi connections and aggressive/stupid captive portal wifi and firewalls/NATs like you might find in an airport [...] That's contrary to my own experience, hence my original post. Obviously I've not been to every airport, but I've been to a handful of different ones over the last decade, and I've never had problems with IPsec. And IME airport / coffee shop / hotel WiFi are usually not the ones most locked down, but corporate guest WiFi. The last one I used blocked everything except TCP port 80, 443...and UDP port 500, 1723, and 4500. I used to run OpenVPN to my home network, since that's the general recommendation, and Cisco VPN to the school, and later work, networks, and I've had more connectivity issues with OpenVPN. Switching to one of ports 53, 80, or 443 generally works, but Cisco VPN always "just works"...connectivity wise anyway. The client software broke like every other minor OS update. I even switched to PPTP for a while, because it'd also always worked, plus support was built into the OS. And that's what drew my attention to L2TP/IPsec. Finally, when Tunnelblick stopped working after one of the OS X major upgrade, I looked into setting up L2TP/IPsec, and have been using it since. Maybe IPsec is more often blocked in Europe / Asia / Africa?