10 ms·
Private Internet Access Goes Open Source
- Erlangolem 9y agoGreat news! I’ve always liked PIA, but the closed source nature of it did require a certain degree of trust. No offense to anyone, but “trust” and “vpn” should be an uneasy combo. This way I’m not in forced to trust my demonstrably untrustworthy ISP, or a VPN. Thanks PIA.
- iamd3vil 9y agoIf you don't trust PIA's or any VPN's clients, you can always use Openvpn clients directly, provided the vpn supports openvpn.
- Erlangolem 9y agoI do trust them, and I have used them, but I prefer “trust, but verify.” It’s also just the right thing to do, going open source.
- iamd3vil 9y agoYeah true. Also by open sourcing the chrome extension maybe someone can port this to Firefox. I think it should be relatively easy after the recent move by Firefox to webextensions.
- netsharc 9y agoPIA works with OpenVPN, their Windows app was (maybe still is) just a pretty interface on top of OpenVPN, but the trust has nothing to do with the client imo, it lies more in trusting them when they say thry don't do any logging or eagerly cooperate with adversaries. They xlaim they don't log, but how do I prove that?
- craftyguy 9y agoIt still requires a certain degree of trust, this changes very little actually. The server side code is still proprietary, and even when it is not (according to their plans) you still have to trust that what they are actually running is an unmodified version of what they have released. In addition to all of that, you are still funneling traffic through them AND they are still under US jurisdiction, regardless of the license they choose to use for their software.
- Semaphor 9y agoI'm not one of those "VPN services are useless" fanatics, but "“trust” and “vpn” should be an uneasy combo" it's not an uneasy combo, it's pretty much your only option. The amount of trust required for their front-end applications is minimal to the point of non-existence. The real trust you have to afford them lies with the company and what they do or don't do with your data.
- gt_ 9y agoGreat news. PIA is a solid service I can recommend to less tech-friendly family members and the like.
- rckclmbr 9y agoI have been a happy user of PIA for quite a while, and highly recommend their service. I've used their proprietary app for a while, and have just trusted their service based on their public image. I'm glad it's going open source, i'll be contributing.
- ReverseCold 9y ago$35 + some technical/tutorial-following knowledge to setup an IKEv2/OpenVPN server on a Raspberry Pi is better than $100/year for a VPN provider if your threat model is just "Open WiFi is sketchy" or "XYZ network blocks YouTube"
- ikeyany 9y ago1) PIA is less than $35 a year 2) PIA takes less than a minute to setup on every device. Download the app, login, and you pretty much never have to worry about it again. Your alternative is more expensive, more resource-hungry, and more of a pain in the ass.
- kohanz 9y ago... and values your time next to nil.
- bringtheaction 9y agoAlso as someone who has a couple of Raspberry Pis in his house, memory card corruption is real and it’s annoying as hell. If I wanted an OpenVPN gateway I would not want to run it on Raspbian. Maybe on a distro that runs purely in memory after boot. But like the other person said, if you value your time it is almost certainly not worth spending time on setting this up yourself, even if memory card corruption was not an issue.
- walrus01 9y agoI am also super hesitant to rely on a raspberry pi for anything that should really work, networking related, considering that the ethernet interface is actually a USB 2.0 device hung off a very cheap USB bus. It's not like having an Intel or Broadcom PCI-Express interface NIC on the motherboard of an x86-64 platform PC. It also has only one NIC. All of the methods to get >1 NIC on a raspberry pi use additional USB devices and are ugly hacks IMHO.
- celticninja 9y ago>Please note that the extension will protect traffic from the browser only and will offer any protection when using other applications. I'm assuming an error in the sentence above and it should say NOT before offer. Seems like a little proof-reading would have been worthwhile.
- nowsticker 9y agoYep your right - will be fixed when the cache clears!
- nkkollaw 9y agoPIA's server is in the US, though. Isn't that kind of weird for a privacy-focused company?
- AFNobody 9y agoIn what sense? The legal overrides that exist in the US for "national security" also largely exist in the EU.
- nkkollaw 9y agoThe EU has not been caught spying on everyone.
- jkaplowitz 9y agoGCHQ (UK), BND (Germany), France's equivalent (I forget the name), and others I am probably unaware of have been caught doing pretty widespread surveillance. So, technically not the EU, but multiple EU countries.
- nkkollaw 9y agoI doubt you can compare that to the NSA, but sure.
- jkaplowitz 9y agoAt least GCHQ is more comparable than you'd think, and they and NSA often work closely together.
- AFNobody 9y agoGCHQ (UK), BND (Germany), BRGE/Directorate for Internal Security/Directorate for External Security (France) have been spying similarly and engaging in information sharing with the US. The UK, France, and several other EU countries have passed internal surveillance laws that are as bad or worse than the US.
- pasbesoin 9y agoI've been happy with PIA. Except for the increased blocking of commercial VPN's (address spaces, I assume) by services on the Web. Not PIA's fault. Just people looking to solve their problems at the expense of my own security. I waded into PIA's client enough, months back, to observe that it was using OpenVPN. Along with its reputation, I decided I had enough trust for my use -- avoiding connection monitoring/cracking on public WiFi and keeping Comcast and Verizon from data mining me. I do sort of wait, with all these services, with breath half-held for some other shoe to drop. Given the rubber hose and lead pipe legal and extra-legal methods available to various and manifold "three letter agencies". I hope the open-sourcing of the client leads not only to increased trust, but also to some functional improvements. Such as being able to leave PIA switched on on my phone while tethering to it. Without having to root the phone and get into routing scenarios that apparently Android is not designed to support. So, I guess that's an Android problem. But maybe there's some way to address it at the client level. Anyway. PIA keeps taking substantive steps (e.g. prior financial support for open source projects, now open-sourcing the client, etc.) that put it in a good light. P.S. I don't mean blocking by Netflix and the like. I mean, archive.is, Google (prove you're not a bot...), commercial services I use, etc., etc.).
- lima 9y ago> Except for the increased blocking of commercial VPN's (address spaces, I assume) by services on the Web. Tragedy of the commons. At my workplace - an e-commerce platform - we're flagging or blocking customers who use commercial VPNs. The reason for this is simple: almost none of our legitimate customers use VPNs, but the vast majority of fraudsters do. Fraud is a massive issue for any e-commerce business and no other anti-fraud measure is as effective as this one.
- josephholsten 9y agoI've said this elsewhere, but I'm trying to help, not spam! Please make sure to report evidence of blocking to PIA support, they do have some solutions available. Worst case, it gives them evidence that it's time to rotate IPs.
- 9y ago
- kobayashi 9y agoThis is better than nothing, but the fact that it's only _client side applications_ means that this is doesn't add much security for PIA users. The largest threat of PIA has never centred about their client app, but in their server-side business practices. Count me as one of the people concerned about PIA's trustworthiness.
- JumpCrisscross 9y ago> the largest threat of PIA has never centred about their client app, but in their server-side business practices Isn't this inherent to the model of a paid VPN service? (Could one run a VPN through a blockchain?)
- colecut 9y agoNot sure blockchain is what you are looking for, but TOR might be.
- gruez 9y ago>Could one run a VPN through a blockchain? you joke, but if you trust intel/arm, you can conceivably run a provably trusted (via remote attestation) VPN on SGX/TrustZone.
- ohf 9y ago> Could one run a VPN through a blockchain? You can encode any information you want on a blockchain, and it can be anonymous and specific to the user. But it would be ///painfully/// slow.
- josephholsten 9y agoI would be very interested to know what you think a VPN provider could do to assure users that the servers are safe. I've yet to see an example verifiable safe server configuration, but some people have claimed that SGX might do. I'm pretty sure that wouldn't work with stock OpenVPN or StrongSWAN today. Are there any other practices they could adopt that would ease your worries?
- ryanlol 9y agoNothing worthwhile was open sourced, this is just a PIA marketing blog post.
- tnolet 9y agoawesome. Use it every day. I live in Germany, so you kinda have to.
- woolvalley 9y agoWhy do you have to in germany?
- tnolet 9y agoCrazy strict laws with regard to torrenting etc. Heavy fines.
- gregknicholson 9y ago> over the next six months we will be releasing the source code for all our client-side applications They weren't already?! Come back when you've AGPL'd your server-side software. Then I'll believe you're committed to open source; and I'll trust you, because you'll be legally obliged to be honest about what's running on your servers.
- xeeeeeeeeeeenu 9y ago>Come back when you've AGPL'd your server-side software. Then I'll believe you're committed to open source; and I'll trust you, because you'll be legally obliged to be honest about what's running on your servers. It's not how it works. The copyright holder isn't obliged to follow AGPL (or any other FOSS license) terms.
- gregknicholson 9y agoGood point. I was assuming there would be third-party contributions, and the third-parties would retain their copyright.
- freeone3000 9y agoNo, they won't - or at least, no more so than they are now. Licenses grant rights to people who didn't have them previously. They do not restrict rights.
- johnramsden 9y agoI've been using their service with OpenVPN for years and I've always been very impressed. Them going open source, and ultimately being auditable, makes them that much more recommendable.
- df8787s8d778sdf 9y agoThis is great news! PIA is reliable and trustworthy. Also, Rick Falkvinge! (Swedish founder of the original Pirate Party) https://www.privateinternetaccess.com/blog/author/rick/ https://www.privateinternetaccess.com/blog/author/rick/