6 ms·
I'm really excited about this idea, but I also think it isn't fully baked yet. I'm excited because VPNs are all about shifting trust: I'm no longer trusting Co
by JackC 8y ago
I'm really excited about this idea, but I also think it isn't fully baked yet.
I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If SketchyVPN turns out not to be trustworthy, then I'm paying for something that is worth less than $0 to me, and there's no way to detect that as a user. It's like paying more for organic food in a town where farm stands are paid to lace organic food with arsenic -- why would you?
For VPN service, I trust Mozilla more than to just about anybody: they're nonprofit, have clear and transparent governance, have many mission-driven employees, and would lose more than they could possibly gain by breaking the terms of service on a VPN. They also have a big enough profile that it takes no extra effort to stay up to date on how trustworthy they are -- they do make missteps, but every misstep hits the front page of HN, which is exactly what I want. If they run a VPN, I'm sold that it's worth more than $0.
But the service isn't fully baked yet for me, because they're not explaining how they're enforcing the trustworthiness of ProtonVPN. I have no idea if ProtonVPN is as trustworthy as Mozilla -- maybe it is, but I don't want to learn and stay on top of that. Instead I want premium.firefox.com/vpn/ to convince me that, if I use Mozilla's service, I'm fully benefiting from their trustworthiness.
- Yoric 8y agoSo if I understand correctly, you would want to know the details of how Mozilla audited ProtonVPN, is that it?
- JackC 8y agoRight -- I'm looking for a white-paper level of detail somewhere behind the landing-page level of detail. What threats (internal and external) did you consider, what evidence convinced you they were addressed, and what acceptable risks remain? What would you as an engineer want to be told by another engineer who did the audit, for you to say "great, that's what I would have done, sounds like you did your due diligence, I'll use that"? The white paper won't be read by everybody and shouldn't be targeted at everybody, but it will be read by the most knowledgeable folks and be a source of confidence that filters out to everyone else. This all depends on there actually being an audit -- so far the landing page doesn't even say that! From the text on the page there's no way to tell if Mozilla just read the published policies for a bunch of VPNs and made a recommendation, or has an employee embedded in ProtonVPN's security team and a seat on the board, or somewhere in between. Without knowing the details, it's hard for me to say whether I'm looking for more documentation of the audit that already happened, or a stronger actual relationship behind the endorsement.
- krn 8y agoEveryone in Vilnius, Lithuania knows, that both, NordVPN and ProtonVPN, are being developed here by the people related to Tesonet, which has been recently sued in Texas Eastern District Court for the patent infringement in "Large-scale web data extraction products and services with residential proxy network ( https://oxylabs.io/ https://oxylabs.io/ )"[1] by Luminati Networks, an Israeli data mining company behind HolaVPN[2]. The section from the "About" page of Tesonet (26 Apr 2018)[3], which was suddenly removed in June 2018 after the connection between ProtonVPN and Tesonet was made public by the co-founder of PIA[4]: "For the latest project, Tesonet is working together with an international brand from Switzerland to create a security product that helps users protect their network traffic. As part of this technical partnership, we are collaborating on datacenter and network infrastructure that can easily supply 10 Gbps worth of bandwidth to users around the world. The product is developed using the latest authentication encryption methods and the best practices in the security world." As late as September 2018, NordVPN and ProtonVPN still become affected by the same extremely rare Windows security bugs at the same time[5], even though the CTO of ProtonMail claimed here on Hacker News, that they used Tesonet, a data mining company, for developing ProtonVPN, a free VPN service, only as "an office space provider"[6]. [1] http://litigation.maxval-ip.com/Litigation/DetailView?CaseID=Epee88Womxg%3D&logstat=false&Party=Luminati%20Networks%20Ltd.%20v.%20UAB%20Tesonet http://litigation.maxval-ip.com/Litigation/DetailView?CaseID... [2] http://fortune.com/2015/05/29/hola-luminati-vpn/ http://fortune.com/2015/05/29/hola-luminati-vpn/ [3] https://web.archive.org/web/20180426161609/https://tesonet.com/about/ https://web.archive.org/web/20180426161609/https://tesonet.c... [4] https://news.ycombinator.com/item?id=17258203 https://news.ycombinator.com/item?id=17258203 [5] https://www.pcmag.com/news/363619/protonvpn-and-nordvpn-bugs-left-windows-vulnerable-to-hacker https://www.pcmag.com/news/363619/protonvpn-and-nordvpn-bugs... [6] https://news.ycombinator.com/item?id=17258538 https://news.ycombinator.com/item?id=17258538
- protonmail 7y agoProton team here. Regarding this claim: > Everyone in Vilnius, Lithuania knows, that both, NordVPN and ProtonVPN, are being developed here by the people related to Tesonet This is not true. Proton has staff in Geneva, Zurich, Skopje, Vilnius, and San Francisco. Years ago, we did sublease office space from Tesonet (one of the biggest IT firms in Vilnius) as alleged above, but there is no connection today. ProtonVPN is fully developed (and owned) by Proton Technologies AG, the Swiss company that also operates ProtonMail. This can be verified in the Swiss commercial registry, which also lists all our directors: http://ge.ch/hrcintapp/externalCompanyReport.action?companyOfrcId13=CH-660-1995014-1&ofrcLanguage=4 http://ge.ch/hrcintapp/externalCompanyReport.action?companyO...
- craftyguy 8y ago> But the service isn't fully baked yet for me, because they're not explaining how they're enforcing the trustworthiness of ProtonVPN. I have no idea if ProtonVPN is as trustworthy as Mozilla -- maybe it is, but I don't want to learn and stay on top of that. Instead I want premium.firefox.com/vpn/ to convince me that, if I use Mozilla's service, I'm fully benefiting from their trustworthiness. I'm also interested in this. I cannot help but wonder if the reason is 'because they gave us money to', like Firefox 'partnering' with google to make google search the default provider.
- protonmail 8y agoYou can find details about this on Mozilla's blog post on this topic, which also describes what they did to audit ProtonVPN: https://blog.mozilla.org/futurereleases/2018/10/22/testing-new-ways-to-keep-you-safe-online/ https://blog.mozilla.org/futurereleases/2018/10/22/testing-n...
- Yoric 8y agoTo be fair, that's not very detailed. While I trust Mozilla, I agree that it would be interesting to have more details.
- progval 8y ago> I'm excited because VPNs are all about shifting trust: I'm no longer trusting Comcast not to sell my data, I'm now trusting SketchyVPN. If you use a laptop, it would rather be: "I'm no longer trusting [home ISP] + [workplace's IT staff] + [workplace ISP] + [family I'm visiting's ISP] + [cellular service provider] + [train station hotspot] not to sell my data, I'm now trusting SketchyVPN".
- notamerican 8y agoI fully understand. If you can't trust Proton then you don't _actually_ benefit from anything. If it helps however, ProtonVPN is by the people behind ProtonMail, the security-first email provider. They started in CERN as a mission to provide email to scientists that wouldn't be subject to censorship. Their entire business - email and VPN both - embodies the same philosophy that Mozilla does. It's rare that I trust any company but Mozilla and ProtonMail are two of a _very_ short list.
- krn 8y ago> Their entire business - email and VPN both - embodies the same philosophy that Mozilla does. ProtonMail doesn't report security vulnerabilities to the users, when researchers discover them[1]. It has also publicly boasted about hacking a phishing site, when claimed the journalist's report was based on "unsubstantiated rumors"[2]. I really hope that it has nothing to do with the philosophy Mozilla embodies. [1] https://www.theregister.co.uk/2014/07/07/protonmail_fail_javascript https://www.theregister.co.uk/2014/07/07/protonmail_fail_jav... [2] https://motherboard.vice.com/en_us/article/qvvke7/email-provider-protonmail-says-it-hacked-back-then-walks-claim-back https://motherboard.vice.com/en_us/article/qvvke7/email-prov...
- windexh8er 8y agoI've been toying around with ProtonMail premium service, so this isn't a direct reflection on ProtonVPN the product. However ProtonMail's support is abysmal. For me that hasn't been a direct reflection of the product, however getting anyone from ProtonMail to engage in a cognizant support conversation is next to impossible and takes days to get an answer. They don't seem to treat paying customers any different than those using free service by way of enhanced SLA on support tickets. My interactions have been so bad I've considered getting a refund on all my outstanding credit (hundreds of dollars for multiple users over multiple years). I'm curious how this bleeds over into support of ProtonVPN.
- jedahan 8y agoI switched to ProtonMail about 6 weeks ago and have had nothing but prompt, positive experiences with their support team. Going so far as releasing new import-export tools which specifically address issues I came across when migrating my mail over.
- windexh8er 8y agoBridge has been in development for while. I'm guessing that's the tool you're referring to. I've asked them about a few more complex scenarios with regard to sharing of mailboxes and group send-as features. My questions were well defined and not answered in their existing FAQ. The problem I experienced was that they gave me non-answers to my questions. Sure, I did receive a response (days later) but the response didn't address my questions. Since your issue seems to have been well defined I'm not all that surprised you had a more positive experience.
- jammygit 8y agoPersonally, I never had to use their support. I was lucky enough that everything worked well the whole time. Only reason I switched away was that I wanted a calendar too (using fastmail now)
- windexh8er 8y agoI was/am contemplating ProtonMail from Fastmail. I've been using it for a couple years now and it's been awesome. I was hoping to gain additional security with ProtonMail but maintain the flexibility I need with multiple accounts and shared addresses that Fastmail does very well.
- Digital-Citizen 8y agoHow did you reach the conclusion that you had to trust ProtonVPN? > For VPN service, I trust Mozilla more than to just about anybody: they're nonprofit, have clear and transparent governance, have many mission-driven employees, and would lose more than they could possibly gain by breaking the terms of service on a VPN. It seems to me that none of these are reasons to trust either Mozilla or ProtonVPN. The reason to trust Firefox is that it is free software (free as in freedom to run, inspect, share, and modify). If you don't like what Firefox is doing, you have the permission you need to change your copy, or hire someone to vet and/or change the copy you run, and you can help others by distributing your improved version. The seeds of coming to trust Firefox are in its software freedom, not in any public relations effort or perception about Mozilla's employees. So there's nothing about Firefox that compels you to trust or use ProtonVPN. The limits of how trustworthy you want to make Firefox are up to you individually and other Firefox hackers collectively.
- danShumway 8y ago> I'm excited because VPNs are all about shifting trust I agree overall about the benefits of getting more reliable auditing for VPNs, I think that's important and I'd like to see Mozilla release more details. But I strongly disagree with the "shifting trust" explanation that people use when they talk about VPNs. People bring up this point all the time, that if you can't guarantee trustworthiness, there's no benefit. And it's ridiculous -- even a moderately trustworthy VPN is a benefit over not using a VPN. VPNs consolidate trust. When you don't use a VPN, you aren't just showing your traffic to your ISP. You're also leaking your IP address to any website you visit. You're also trusting any other networks that you connect to when you open up your laptop in a coffee shop or hotel room not to have a sniffer sitting on them. You're trusting tons of faceless organizations across the entire chain of you to the website you visit to be safe with your data. The main benefit of a VPN is not just that it hides your data from your ISP (although that alone is a really good benefit because we already know that most US ISPs are untrustworthy). The main benefit is that you only need to trust one company with your IP address instead of every single individual website that you visit, and that you only need to trust one provider not to sniff your traffic, instead of every single ISP that you connect to. If your VPN is moderately trustworthy, to the same level that you would trust an ISP like Verizon, then it is a strict upgrade in security to use that VPN for all of your traffic, because you're eliminating some of the lowest-hanging network vulnerabilities while you travel and putting a barrier between yourself and the websites you visit so that it's at least slightly harder for them to track you or tie you to a physical location.
- Nullabillity 8y ago> You're also leaking your IP address to any website you visit. As opposed to leaking your VPN's IP address, which is about as meaningful. > You're also trusting any other networks that you connect to when you open up your laptop in a coffee shop or hotel room not to have a sniffer sitting on them. True. Which is why a personal VPN to your home network is useful. > You're trusting tons of faceless organizations across the entire chain of you to the website you visit to be safe with your data. The connection from the VPN provider still goes through a similar chain. It's true that the chain will be substantially different if you, say, connect to a service in the US from the UK via an Australian VPN service. On the other hand, the chain will be way longer if you use that Australian VPN to look up your local pizza place's menu.
- dwild 8y ago> I trust Mozilla more than to just about anybody: they're nonprofit, Mozilla Foundation is non-profit but Mozilla Corporation is for profit. I don't know how that would affect your opinion but it certainly did when I found that that out recently when I wanted to know how much they were paid by search engines.
- pergadad 8y agoBut the for-profit is owned and governed by the non-profit, so overall it's still non-profit. It's probably about the statues of the nonprofit and certainly at least on part about keeping a separation between income (Google) and activities (contrary to Google)