8 ms·
How does this compare to TunnelBear [1]? - TunnelBear is a bit more expensive (4.99$/mo, paid annually vs 4$/mo). - TunnelBear supports up to 5 connections pe
by saintfiends 9y ago
How does this compare to TunnelBear [1]?
- TunnelBear is a bit more expensive (4.99$/mo, paid annually vs 4$/mo).
- TunnelBear supports up to 5 connections per account vs 2.
I use TunnelBear regularly for my browser and phone. Both works great.
My subscription is going to expire soon and I'll be open to try other VPN providers, not that there is anything wrong with TunnelBear. Any recommendations?
This site [2] has feature comparisons but experience using VPN services is another story.
[1] https://www.tunnelbear.com/ https://www.tunnelbear.com/
[2] https://thatoneprivacysite.net/vpn-section/ https://thatoneprivacysite.net/vpn-section/
- fao_ 9y agoprivate internet access appears to be good, but I do not think they are very transparent about their operation.
- daxorid 9y agoI think it's prudent to assume (even if not accurate in every case) that any VPN provider that reaches PIA scale has already been compromised by the relevant State Actor working its jurisdiction. It's the tragedy of success in the privacy industry.
- jorvi 9y agoExcept for the fact that PIA has been subpoenaed by the FBI and state police multiple times and PIA could give them dick all. Yes, their servers could be compromised illicitly, but if the NSA or GCHQ is willing to go to that much trouble just to monitor you, you have bigger problems.
- throwawaymanbot 9y agoThey say theres nothing to give, but how do you really know for sure?
- blacksmith_tb 9y agoIf they have your data but won't give it to the authorities, the result is the same, isn't it? Unless you're suggesting the authorities aren't fooled, and will pry it out of them? That hasn't been the case so far.
- MichaelGG 9y agoThey're asking how do you know they didn't hand the data over but just publicly say they didn't? Or that they agreed to give it to the FBI if the FBI would treat it as a confidential source.
- dahoramanodoceu 9y ago>[...] but if the NSA or GCHQ is willing to go to that much trouble just to monitor you, you have bigger problems. This type of argument contains the assumption that it would be too much trouble for them/not worth it to monitor an affluent anarchist or semi- anti-authortitarian with an above-average IQ. We've seen that A) their resources are as virtually unlimited as their paranoia B) tech developments have driven down the cost of sophisticated surveilance strategies C) xkeyscore and all of the other releases is confirmation. This type of argument does us all a disservice by subtly shaming those who care about state-surveilance of private (and peaceful) citizens who value their privacy and/or who exercise their right to actively participate in progressive movements that challenge the establishment.
- Bartweiss 9y agoIt also embeds an assumption that someone is targeting you instead of people like you. Compromising the servers of a VPN provider makes plenty of sense in the service of full-take or person-of-interest collection. We've already seen that the NSA actively targets people searching for privacy tools (e.g. Tails, Tor). The act of using a VPN is mildly interest-provoking, so it's far from crazy to suspect that someone might try to scrape everything happening there in case some of it is interesting.
- bogomipz 9y ago>"Except for the fact that PIA has been subpoenaed by the FBI and state police multiple times and PIA could give them dick all." How is/was this claim substantiated?
- Loony2 9y agoPIA might actually log everything and send to the FBI as a regular part of their operation, hell, they might even be funded by the FBI and you would never know. You should not trust what people tell you over the internet.
- sr2 9y agoI found malware in the PIA installer. Not sure if it was planted by PIA themselves or I was subjected to a MITM attack, and so I would never use any bespoke VPN software again. Best just downloading the OpenVPN config files and plug them into something like Viscosity[0] (which I trust over the more bespoke VPN clients made by the VPN providers themselves). [0]: https://www.sparklabs.com/viscosity/ https://www.sparklabs.com/viscosity/
- boomboomsubban 9y agoWhat so you mean "found malware?" You checked the installer and found that some aspect was malicious or some software you are running said it found malware? As the installer seems likely to cause false positives. You're still better using independent VPN clients, but I would not trust them at all if the installer actually has malware.
- sr2 9y agoI spotted loads of malicious network traffic, and using the Sysinternals Autoruns[0] utility I was able to spot attempts at persistence. I also checked the outbound connections and they were C&C servers. I can't remember if the installer was digitally signed or not, but there was definitely malware in it. I always make sure to opt-out of any AD ware that might be bundled with an installer, but this seems to have been injected surreptitiously, and installed with very little interaction. Just be careful with the bespoke VPN clients as they are very juicy targets for MITM attacks. I know I would be going after VPN software if I wanted to do ex-filtration for a small subset of users trying to hide their tracks from governments and ISPs. [0] https://technet.microsoft.com/en-us/sysinternals/bb963902.aspx https://technet.microsoft.com/en-us/sysinternals/bb963902.as...
- elmigranto 9y ago> I spotted loads of malicious network traffic Care to provide anything substantial (e.g. net dumps or screenshots at least)? > and they were C&C servers How do you know that, have you MITMD your connection? Do you have anything besides generic spooky words?
- rbritton 9y agoA large portion of PIA's endpoints are blacklisted due to their popularity and related abuse. I found it somewhat annoying to try and use.
- gtf21 9y agoI use VyprVPN [1] which I've found to be good and fast. It's a bit of a tough area to research well. I might give TunnelBear a try. [1]: https://www.goldenfrog.com/vyprvpn https://www.goldenfrog.com/vyprvpn
- yalooze 9y agoVyprVPN do store logs. I used to use them and wasn't aware of it. Just to let you know.
- gtf21 9y agoReally? I know the client stores connection logs (configurable) but I asked them directly and they said they didn't log anything if it's turned off. Their privacy policy says the same [1]. If that's the case then I'm switching immediately. [1]: https://www.goldenfrog.com/privacy https://www.goldenfrog.com/privacy
- yalooze 9y agoThey log when you connect and disconnect, plus what IP you are using when connected. They will pass on DMCA copyright infringement notices (although they say they do not pass on your details to the copyright agent). https://www.reddit.com/r/torrents/comments/17g53i/if_you_thought_you_were_safe_using_golden_frog/ https://www.reddit.com/r/torrents/comments/17g53i/if_you_tho... It doesn't seem like there is a way for them to uphold their copyright policy without storing that information. https://www.goldenfrog.com/copyright https://www.goldenfrog.com/copyright
- gtf21 9y agoThanks for the link. I'll have to look for a new VPN provider then.
- tyoma 9y agoHN gets regular "what VPN should I use?" questions and my answer is always the same: Algo [1]. It is designed to be simple to set up, simple to tear down, and usable with numerous cloud providers or your own Linux server. [1] https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- jug5 9y agoWhy IPSec? Is it even considered secure anymore?
- chc 9y agoIn terms of privacy, doesn't it kind of let the cat out of the bag if you host your own VPN server? It's not your home address, but it's still just as much an address associated with you, isn't it?
- rbritton 9y agoIt's less private for some forms of traffic, but for me, my main goal is to avoid ISP tracking and provide encryption on potentially malicious networks, which it works well enough for.
- DKnoll 9y agoYour ISP in the DC, the DC itself, whoever owns the box your VPS is on or your fellow tenants could be malicious.
- gruturo 9y agoIndeed it doesn't provide anonymity against the sites you visit - quite the opposite, it makes it even easier to correlate your browsing regardless of device/location. But many (the undersigned for example) use VPNs for many other purposes: Unencrypted WiFi (airport, hotel, etc) Secure connectivity but provided by someone you aren't willing to trust (your employer?) Fooling Geo-IP based restrictions (hello Netflix/BBC) Not having your VoIP traffic mangled by a shitty carrier who's trying to extort protection money from you in the form of some "VoIP-optimized" expensive plan Etc etc
- jbeales 9y agoUnless they've changed their policy in the last few months, TunnelBear won't let you use SSH over any port other than 22, so if you need to SSH into a server with a non-standard port you're out of luck.
- drdaeman 9y agoWait. Do you mean they actually inspect traffic and tear down the connection if they see an SSH handshake on any port other than tcp/22?
- elmigranto 9y agoThey whitelist ports, I believe. That's the reason torrents don't work, for example.
- kefka 9y agoSeriously? Wow, well fuck that. If I buy a VPN, I expect data_in = data_out , not sanitized(data_out)
- jbeales 9y agoYeah, my understanding is they whitelist standard ports, and everything else is blocked. They say it's because of BitTorrent, but it prevented me from accessing a server on a non-standard port, so I didn't buy.
- kennethologist 9y agoHere's a good comparison list: https://thatoneprivacysite.net/simple-vpn-comparison-chart/ https://thatoneprivacysite.net/simple-vpn-comparison-chart/
- kakarot 9y agoCheck out Mullvad. I haven't yet found a service that I think is slicker, more convenient, and more serious about privacy. You can generate unlimited free trials until you're confident you want to spend the paltry $5 a month on them. https://mullvad.net https://mullvad.net
- Johnny_Brahms 9y agoI second this. I can't make any claims about the security of the client, but the way they handle things is confidence-inspiring. I have been in touch with them over some issues I have had,and the support is fantastic. I had an issue with mosh over my local network (SSH worked,mosh did not) and got a very detailed reply about why they treated LAN UDP packets that way, and why I was probably not affected since I ran a modern Linux distro and of course the setting that turned that safety feature off. And, if you do t trust them to make such decisions for you (or you run an unsupported OS) they have regular openVPN files
- kakarot 9y agoThey definitely aren't just running a VPN to make a quick buck. The amount of guides and such that they offer for integration, etc. is confidence-inspiring as well. What sold me was their mention of using Qubes OS in-house. They clearly give 100% fucks about keeping their infrastructure safe.
- clairity 9y agothe irony of a site with "privacy" in its name that uses a bunch of google services (that track you out the wazoo). </wry smile> edit: with that said, i really appreciate the compilation of information here, so it's no knock on the site owner.