5 ms·
So I just installed ovpn on my phone just now. First place I go to test it is HN. And this story is literally top of the list. Sigh.
by ProxCoques 9y ago
So I just installed ovpn on my phone just now. First place I go to test it is HN. And this story is literally top of the list.
Sigh.
- jagermo 9y agoSomeone else trying out Protonvpn, I see :)
- Kurtz79 9y agoYou don't need necessarily to be using a specific service. You can configure your own OpenVPN server quite easily, and use the available vanilla client applications to connect to it.
- ccrush 9y agoThe fun part is that a somewhat premium (read: more bandwidth) VPN option will cost around the same as a lower tier VPS. So, if you're willing to put up with the 10-15 commands, editing a couple configuration files, and copying config and cert files over, you can get your own VPN and a Linux server to use.
- Spivak 9y agoRight, but for certain classes of users, VPN as a service offers anonymity and endpoints around the world.
- afghanPower 9y agoYup. Most VPNs with decent bandwith cost $4/month. You can get pretty much the same service for $4/year if you buy a cheap NAT VPS server and spend 10 minutes setting up openvpn.
- whoami_nr 9y agoCould you point me towards a $4/Year VPS ? Would gladly buy it.
- afghanPower 9y agoI bought mine from https://i-83.net/ https://i-83.net/ It's £4.50/year, but you can probably find promotion codes that'll make it cheaper. Have also heard good things about http://lowendspirit.com/ http://lowendspirit.com/ (sorry for the late reply)
- throwanem 9y agoI'm not sure these are so dangerous as all that. I see some server and client crashes, but nothing that'd allow transparent MITM, RCE, or the like. Perhaps there's something I have missed, and if so I hope someone more knowledgeable here will point it out - but right now I don't intend to stop using OpenVPN, because even if it's possible that a malicious network might crash the VPN stack on my phone or similar, that's still preferable to sending unprotected traffic over an untrusted network. If my VPN clients die, at least I know something's up!
- mkj 9y agoA double-free can traditionally allow remote code execution. Maybe modern libc mitigations will protect you, maybe not.
- throwanem 9y agoFair point. But it looks like the scope on that one is pretty limited: > There are several issues in the extract_x509_extension() function in ssl_verify_openssl.c. This function is called if the user has used the ‘x509-username-field’ directive in their configuration. That option, per [1], appears to exist in order to support odd TLS certificates that don't use the CN field as an identifier, and is also behind a configure #define that appears not to be enabled by default. So that, if I'm reading this right, is a pretty narrow attack surface in general - not inconsiderable, to be sure, but something of a corner case. [1] https://community.openvpn.net/openvpn/attachment/ticket/124/0001-Documented-x509-username-field-option.patch https://community.openvpn.net/openvpn/attachment/ticket/124/...