3 ms·
PIA actually scores as one of the highest on the objective measures. The star count is just a subjective impression and experience with getting it set up. They
by mobitar 9y ago
PIA actually scores as one of the highest on the objective measures. The star count is just a subjective impression and experience with getting it set up. They connect over HTTP on startup instead of HTTPS (which is unacceptable for a privacy company). They then ping almost a hundred servers on startup (no other app does this, at least not to this extent).
- dawnerd 9y agoDon't use their app then. In fact, I can't think of a reason why I'd install any vpns app if they support openvpn.
- wlesieutre 9y agoIt gets you an "automatic" option for which endpoint to use, other than that I can't think of anything.
- rovr138 9y agoSome people like the kill switch. I just think remote port is easier to setup. I sometimes use the app. Mainly use the builtin client of the OS.
- closeparen 9y agoBecause Tunnelblick isn't the greatest UX?
- hendersoon 9y agoTheir app has all of their various points of presence pre-populated. If you use your favorite OpenVPN program to connect you would need to get a couple dozen configs imported. It also tries to find the fastest connection for you, which is useful when traveling.
- jwfxpr 9y agoConsidering your claim to be interested in producing a quality analysis of the various services and clients, and in other reviews you took pains to point out that connections were made to Google analytics servers, I found it pretty disappointing that you didn't explain what the servers that PIA were pinging actually are. Are they, as I suspect (as a PIA user), pinging their own servers worldwide, to find the fastest options available? Are they pinging third parties? Your review basically says "pings are bad m'kay" without demonstrating any understanding of what the client is doing. Furthermore, your questioning of the use of port 80 makes me wonder about your own security knowledge. You really don't understand why a commercial VPN product designed to be used by portable devices in unexpected environments might commence a connection on port 80? These 'objections' you have make me sceptical of your attention to detail in general.
- rasengan 9y agoHi mobitar. Thanks for the highest score in regard to the objective measures. Regarding the subjective impression and experience, I'd like to let you know what's going on. If you feel that this changes your impression, it would be great to update accordingly! The HTTP connection upon startup is for the region data request which is signed and verified upon receipt. It's tamper proof, but you can read it. It's something that anyone with the client can read, and the client is free to download. Arguably, it's more secure to entrust the communication from PIA to the client software itself than to blindly entrust it to HTTPS which has provably been compromised due to bad actors in the past. We're in #privateinternetaccess on irc.freenode.net to discuss anytime as well! Thanks for everything mobitar and for taking the time to produce this report.
- rasengan 9y agoSorry mobitar, I forgot to address the pings. This is to find the best (closest by network latency) path to you. We're really focused on providing the best possible experience, and that experience is simply providing what we do best, in the most unobtrusive way possible. And to that extent, when it comes to your privacy and fighting for your internet civil liberties, we'll be second to none. Cheers, Andrew
- arca_vorago 9y agoI've seen PIA being very active and friendly, along with supporting FOSS which I love, so I say good work. That said, a question: is there a way for a power user to control this startup ping mechanism in favor of using a single server they have selected as the best? The only reason I see to not do this would be if your IP ranges are volatile time-wise for some reason. Or perhaps I'm missing another factor?
- mirimir 9y agoWell, you can use stock OpenVPN, with firewall rules to prevent leaks. Or you can use pfSense as a VPN gateway VM.
- 9y ago
- shmerl 9y agoThey support OpenVPN.
- blacksmith_tb 9y agoI have happily used PIA for years on Ubuntu and macOS and Android, but I never, ever use their clients. Just download the ovpn files[1] and set them up with the native support built into your OS (or use something like Viscosity for more functionality). On an unrelated note, I'm happy to know that my (reasonable) annual subscription allows them to support FOSS projects, they should really publicize that more! 1: https://www.privateinternetaccess.com/openvpn/openvpn.zip https://www.privateinternetaccess.com/openvpn/openvpn.zip 2: https://www.sparklabs.com/viscosity/ https://www.sparklabs.com/viscosity/