4 ms·
My biggest concern with any VPN is: do I trust you? I’ve been reluctant to sign up with any of these VPN services that seem to be advertising everywhere nowaday
by kylec 8y ago
My biggest concern with any VPN is: do I trust you? I’ve been reluctant to sign up with any of these VPN services that seem to be advertising everywhere nowadays because I don’t know what they’ll do with my internet traffic.
The CloudFlare VPN is interesting to me because they’re a large, established company with a good reputation, so I trust them more than TunnelBear or ExpressVPN or PIA or whoever’s sponsoring YouTube this week.
If there was a way you could offer a product or service that provided a compelling case for why you won’t (or better yet can’t) snoop on my internet traffic, I’m all ears. Everything else is just gravy on top.
- ignoramous 8y agoWe thought about the trust aspect of it (we have gone through numerous VPN related threads here on news.yc and r/privacy and this has been one of the top concerns). Here's how we plan to convince folks (in our own naive way) we mean business (do serveral or all among): 1. OpenSource vpn server and client, with ability to Cloud-SSH to the server and view what's running. 2. Hands-off, one-click, spin up VPN servers on a VPS of your choice under your control, Streistand/Algo style [0][1], but find a way to provide support (think AWS marketplace). 3. Make privacy-centric commitment legally binding as part of EULA/ToS (is this sufficient?). 4. Run client-side only VPN (like intra, blockada, netguard). The idea is you're still able to analyse traffic and add blacklists client-side, without having to pay for or run a VPN server. Thoughts? [0] https://github.com/StreisandEffect/streisand https://github.com/StreisandEffect/streisand [1] https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- kristofferR 8y agoSounds like something HN readers will like, but which also would be completely commercially unviable.
- ignoramous 8y agoTrue. That's the part where we might need to think hard: A business plan. We haven't thought that far yet, tbh. Our intention is to: Put the control of the mobile device back in the hands of the consumer and empower them with simple but powerful tools. Think keybase, Stripe, or pre-2014 WhatsApp in terms of UX. Mobile VPN is key part of that vision, including building other apps around it. A lot of things triggered this: 1. The prism/carrier-iq snafu from 7yrs back. 2. The uptick in government censorship prevelant in multiple nations (India, Turkey, Pakistan, Russia, etc). 3. Rise of app-economy and the relentless tracking behaviour that entails, esp from Facebook. 4. pi-hole and it's elegant solution to shut out trackers. Though I first saw this solution impl by Sam Hocevar (one of the VLC devs) in 2002 (?): http://sam.zoy.org/writings/internet/doubleclick.html http://sam.zoy.org/writings/internet/doubleclick.html 5. Not very many firms developing products like DuoSecurity did but for the end-consumer. There's a few I could find, like SecureMix (glasswire developer), Objective-See (LuLu Firewall), Jigsaw (primarily for journalists?), Purism, and KeepSafe.
- fonosip 8y agoFiltering, Adblocking, VPNs are commercially viable. More of a B2B play than B2C though
- jakejarvis 8y agoSounds a bit like what Google / Alphabet / Jigsaw are already doing with Outline, but I still think there’s major opportunity there for a transparent and decentralized one-click service. Especially when you add in #4. For some reason, Outline is still mega-targeted at journalists and activists when it could be so much more — it’s been an absolute joy to use so far, and being powered by Shadowsocks certainly doesn’t hurt. https://getoutline.org/en/home https://getoutline.org/en/home
- ignoramous 8y agoThanks. Yes, you're right. Not just Jigsaw (who are excellent, and I've been recommending their DNS app, intra, on news.yc for as long as I can remember), there are multiple other companies in this space (SecureMix, TheGuardianApp, KeepSafe, CopperheadOS, Proton mail/VPN, AdGuard), but not everyone is quite doing what I have in mind related to fighting trackers and censorship with a focus on 'one click and you're done' kind of simplicity (?) I hope to get something ready to show you guys here on news.yc in may be 3 to 6 months from now.
- tigroferoce 8y agoAnother way would be using some trusted computing technology [1] to do that. This would be a good use case for some kind of remote attestation. (Shameless pug: I did my Ph.D. thesis on this, so if you want to discuss this point, cloudflareatvernizzisdotit ;-) ) [1] https://en.wikipedia.org/wiki/Trusted_Computing https://en.wikipedia.org/wiki/Trusted_Computing
- deleted 8y ago[deleted]
- kristofferR 8y agoOne positive for PIA at least is that their "no logs"-policy actually has been proven multiple times by subpoenas. https://torrentfreak.com/vpn-providers-no-logging-claims-tested-in-fbi-case-160312/ https://torrentfreak.com/vpn-providers-no-logging-claims-tes... I'm not aware of any subpoenas directed at Cloudflare that was equally as useless.
- dx034 8y agoSo far that only applied to the DNS, I don't think many would subpoena a DNS provider.
- themusicgod1 8y ago> established company with a good reputation are you insane? CF's reputation is terrible[1]. They are trying to MiTM the entire internet, and frustrate attempts to access some of the most important information online( including but ont limited to evidence of the holocaust, sexual health information and climate change ). They are practically a threat to humanity itself at this point - you shouldn't trust them worth anything. [1] https://notabug.org/themusicgod1/cloudflare-tor/ https://notabug.org/themusicgod1/cloudflare-tor/
- ignoramous 8y agoThe cynicism is fair and I can see where it comes from, but cloudflare CTO, jgrahamc, has replied elsewhere in this thread [0] why tor is a difficult scenario for cloudflare to handle. They did promise to make life easier for tor users but the abuse over tor is apparently relentless, according to them. [0] https://news.ycombinator.com/item?id=19543188 https://news.ycombinator.com/item?id=19543188
- rgoliveira00 8y agoThe IPv6,IPSec and PKI together may be interesting to authenticate and encrypt traffic without any entity managing the traffic. It could eliminate the client/server by activating the authentication and encryption with exchange of certificates by using a PKI. It may provides a full p2p encryption in the network layer without logging your traffic somewhere or third parties. open-sourced would be awesome.