24 ms·
NordVPN library and client code open-sourced
- korroziya 4y agoCan't read the words "Nord VPN" without hearing it in my head as Richard Coffin from The Plain Bagel. Which is ironic as previously I had trouble separating it from Critical Role thanks to the ad skits Sam Riegel used to do.
- logichurts 4y ago[dead]
- mistrial9 4y agowhy do they spend so much money on ads? seems like more budget than could be explained via sales to civilians
- bilekas 4y agoThey're certainly not doing it out of the goodness of their heart. Or for the goodness of privacy online.. Doesn't leave many good options but you can be sure, they're not losing money.
- Ekaros 4y agoI have always wondered about these providers. Their margins must be amazing considering they can justify this amount of influencer marketing. Or is there also big amount of VC money they are still burning through? Usually the offers in addition have pretty good discounts from original price.
- yurishimo 4y agoI wish I had a source, but I've heard guesses as high as 90% profit for most VPN subscriptions. Especially overloaded and bloated garbage VPNs. Most people don't know they're being throttled by the VPN if they only use it to watch Netflix.
- risyachka 4y agoBecause they have huge margins and high LTV. Every company who has these spend as much as they can on user acquisition. Why wouldn't they?
- AtNightWeCode 4y agoI am 100% sure that some of these services are state sponsored. NordVPN in particular have been associated with "some" countries. You have to be a complete moron to buy a service like this for privacy. You buy it for getting away with simple crimes like piracy.
- partiallypro 4y agoHopefully this helps the app become more stable, on Windows it has become pretty unstable as of late. I've had background tasks fail, LAN problems, issues with it acting like it's trying to connect still when it's actually successfully connected to the VPN, and sometimes where it won't reconnect to the VPN at all without a reboot. Some of that could be problems from Windows Insider but some of the same happens on a Windows 10 box I have that is on the standard release channel.
- msla 4y agohttps://www.youtube.com/watch?v=WVDQEoe6ZWY https://www.youtube.com/watch?v=WVDQEoe6ZWY That's a video about NordVPN's dishonest advertising and how deeply it's infected YouTube. https://www.pcmag.com/news/nordvpn-ad-banned-for-exaggerating-threat-of-public-wi-fi https://www.pcmag.com/news/nordvpn-ad-banned-for-exaggeratin... > The UK's Advertising Standards Agency(Opens in a new window) has banned a NordVPN commercial for misleading viewers about the privacy risks of using a public Wi-Fi network without also having a VPN. In essence: HTTPS already does what NordVPN claims you need a VPN to do. More, in fact, because HTTPS validates that the domain you're communicating with is the domain that shows up in your browser's address bar, which a VPN can't do on its own.
- PlutoIsAPlanet 4y agoIt's pretty silly when you see it being advertised on various high profile YouTube channels as some kind of magic protection that protects you from ID theft, password leaks, viruses etc.
- phantom784 4y agoSince making that, Tom Scott has done sponsorships for NordVPN (but has always avoided the exaggerated claims from what I've seen).
- throw0101b 4y ago> https://www.youtube.com/watch?v=WVDQEoe6ZWY https://www.youtube.com/watch?v=WVDQEoe6ZWY This is Tom Scott's 'original' 2019 video called "This Video Is Sponsored By [redacted] VPN" where he explains most of the reasons listed to use VPN by ads is useless. However a few years later with "My robot double sells out (so I don't have to)" he did a follow-up listing useful reasons (geo-based content, better prices on vacation sites, etc) in which he was sponsored by NordVPN: * https://www.youtube.com/watch?v=uXlQuTRSmzc&t=6m25s https://www.youtube.com/watch?v=uXlQuTRSmzc&t=6m25s
- DeathArrow 4y agoHTTPS is not going to hide your IP or the IP of the websites you access. Beside HTTPS there are other network protocols people are using.
- appleaday1 4y agoI am taking a look at this. Now do Grammarly next, if we want to go by annoying Youtube ads. Someone should tell Grammarly that they are being excessive and too much advertising actually turns people off your product.
- ankit70 4y agoSame feeling for Wix. Hate those ads.
- hammock 4y agoI wonder if grammarly targets people whose search history has misspellings. I haven’t seen a grammarly ad in years
- Ekaros 4y agoThey still send spam, but it could be they have run out of money on advertising. Or someone run numbers on the returns.
- soiler 4y agoTurns off 1% of potential users, attracts 10%. Net win.
- bleep_bloop 4y agoThats just your opinion. But now when anybody thinks of a website that can help them with writing documents, especially if English isn't their native language, there is exactly one website that comes to everyones minds. In fact, I don't know of a single competitor to mind, that's pretty effective marketing if you ask me.
- acatton 4y agoReminder that it looks like NordVPN does shady stuff: https://news.ycombinator.com/item?id=29285988 https://news.ycombinator.com/item?id=29285988 Allegedly, they are using their customers as botnets to resell traffic from residential IPs, mostly for scraping, through their other business "Oxylabs".
- lr4444lr 4y agoMaybe you're confusing NordVPN with Hola, which was used by Luminati which became or sold to Bright Data. Perhaps Oxylabs is sourcing from somewhere similar, but what evidence do you have that it's NordVPN?
- ehPReth 4y agoI hear there's a dirty secret that more and more companies are doing this to make things like Netflix that block VPNs "just work" though their services. Not sure how true this is or how widespread, though.
- edgyquant 4y agoThis has been brought up before, Netflix does not work with a VPN on. It knows you’re using a VPN and blocks you (asks you to disable it.) Yes this is true even with NordVPN, which I bought specifically to be able to watch Netflix on when expressVPN didn’t work.
- tenacious_tuna 4y agoThat is an exceptionally broad statement. I think it's probable that Netflix doesn't work with large-scale VPN providers because it's broadly easy to identify the traffic source. However, using a wireguard tunnel from my ipad back to my house, netflix works fine.
- causi 4y agoHe obviously didn't mean to include people who are just tunneling back to their residential IP.
- mjdowney 4y agoSince there is so much criticism here of NordVPN (in general, not for open-sourcing), what are the VPNs that people like?
- gjsman-1000 4y agoTake a look at Mullvad for a VPN done right. Completely anonymous usernames, randomly generated, accepts cryptocurrency or cards purchased anonymously at a physical store with cash. One concerning issue is the Swedish jurisdiction. The nordic countries are better at privacy, but Sweden is a 14-eyes nation. But I can't say it's better or worse than NordVPN's... Panama.
- capableweb 4y agoOr if you wanna pay by cash, just send it to them in an envelope. No need to buy a card first then using that, when you can pay by the alternative that gives you the most privacy.
- antihero 4y agoAs long as people still realise that regardless of whether they pay with cash in an envelope or directions to the end of a rainbow, if they connect with their own IP to mullvad’s servers and there’s some compromise of these promises (court order, etc), it’s trivial to be owned.
- switch007 4y agoMullvad
- panick21_ 4y agoMullvad is mostly liked by everybody. Including me.
- bilekas 4y agoMullvad is a great example of how all VPN companies who promote privacy should behave, if only for the signup process itself. Zero personal information required.
- DeathArrow 4y agoI didn't make my mind if I hate NordVPN more or Skillshare. Or maybe Squarespace?
- moffkalast 4y agoIn my mind Raid Shadow Legends definitely pulls ahead quite a bit.
- kachurovskiy 4y agoIs your comment made possible by curiosity stream?
- moffkalast 4y agoIt can be viewed on nebula for sure.
- lucb1e 4y agoI don't mind those two to be honest. They do seem to be by the creators themselves, not some third party that buys advertising time for a shady business. The content is good and the price is right. Perfectly legitimate way of diverting revenue from Google to the creators themselves and making a small step towards a video platform less run by algorithms and advertising. (I am not a subscriber or an impacted creator, but I did try it out. Honestly you'll have seen all interesting content by the end of the week, but for that price... worth it to buy it every couple years when there is new content.)
- recrof 4y agoYou need more "Sponsorblock: skipped Ad" in your life.
- throw0101b 4y agoThis reminds me of the 'original' 2019 video by Tom Scott called "This Video Is Sponsored By [redacted] VPN" where he explains most of the reasons listed to use VPN by ads is useless: * https://www.youtube.com/watch?v=WVDQEoe6ZWY https://www.youtube.com/watch?v=WVDQEoe6ZWY And then a few years later with "My robot double sells out (so I don't have to)" he did a follow-up listing useful reasons (geo-based content, better prices on vacation sites, etc) which was sponsored by NordVPN: * https://www.youtube.com/watch?v=uXlQuTRSmzc&t=6m25s https://www.youtube.com/watch?v=uXlQuTRSmzc&t=6m25s
- moffkalast 4y agoIsn't he now doing a lot of NordVPN ads himself in recent videos too? Turns out everyone has their price.
- neodymiumphish 4y agoThats not selling out. If he keeps the old video up and doesn't make the claim that NordVPN does things it doesn't actually do, then he's just advertising. There are legitimate uses for VPNs, they're just not the reasons these VPNs advertise (the the parent comment says).
- selfmodruntime 4y agoHe‘s still selling his advertisement time to a company that employs shady business tactics?
- deleted 4y ago[deleted]
- moffkalast 4y agoHe doesn't make false claims, but he also doesn't tell people they'll be used as a botnet. Feels like something that would be relevant to know.
- RobotToaster 4y ago>Library and client code I assume parts of the "full stack" are still closed source then?
- politician 4y agoI'd love to learn why they have a mix of Go and Rust. Did they initially use Go and then migrate? Do they use Go for some things and Rust for other things? Have labor market dynamics played a role (lots of Rust devs from crypto startups becoming available)? It would be great to hear from their CTO on the rationale.
- systems 4y agoSo, should we, or should we not use a VPN? If most sites nowadays are on HTTPS, is vpn still needed for daily use I think the only reason now to use a vpn, is to login to a site as if from a different location, if the site blocks your region, or sensor some of its content Any other good reason to use a vpn
- irrational 4y agoI was wondering the same thing. How would my ISP even know that I am using a site like z-library if everything is over HTTPS?
- devmor 4y agoDNS for one, if you're using theirs.
- Laaas 4y agoHost names are commonly unencrypted. See [0]. IP addresses also tell a lot. They can check what domain names map to that IP address. [0]: https://www.cloudflare.com/learning/ssl/what-is-encrypted-sni/ https://www.cloudflare.com/learning/ssl/what-is-encrypted-sn...
- Ekaros 4y agoIP addresses? DNS queries? Later if you either use ISP provided DNS servers or unencrypted DNS. You can identify host from queries and IPs and then match it to TLS connection.
- SV_BubbleTime 4y agoThey still likely get your DNS info, and also they know you are connected to x ip address which is likely y service. All HTTPS does is make sure they can’t see what you are transferring. There is still meta data to whom. Why do you think google runs 8.8.8.8? It’s not out of kindness.
- ed_mercer 4y agoDo I care that can see metadata? If they don’t know what was transferred, how is that useful to them? Data-mining?
- t8sr 4y agoWell, the client code certainly isn't great. Reading through it random, I see a lot of undocumented code, functions with 20 positional arguments (who wants to bet some call sites silently swap two of them?), a file called constants.go where random strings are defined far away from where they're used, etc. There are also random, mostly undocumented, interfaces lying around /everywhere/, in all kinds of places not connected with either the call site or the implementation. My favorite is a custom bools library called "strings". I haven't found any obvious bugs, but the coding standards are poor. Good on them for open sourcing it, but man, did nobody stop and think "hang on, is this code gonna make us look bad?"
- rwc 4y agoThis is not a snarky response, but is it possible the answer is simply "who cares?" I see NordVPN ads all over youtube, podcasts, and TV. Those overwhelmingly non-technical customers certainly don't care about the code quality, documentation, or constants defined far from where they're used. It seems to me this is about marketing the product to be perceived as transparent and secure, which is certainly what those customers care about.
- Kinrany 4y agoIt could work as a forcing function: "people are saying mean things about our code and it harms our sales, let's rewrite"
- ashwagary 4y agoApart from being sloppy, any worrying bits of code throwing up security red flags to you?
- weird-eye-issue 4y agoNo that is why they are nitpicking about recently open sourced code that is "undocumented"
- ashwagary 4y agoI don't see it as a nitpick. The review can be valuable to people working on the code and users wondering how competent the Nord team is.
- deleted 4y ago[deleted]
- user764743 4y agoNordVPN do logs and you will get caught if you do crimes using their services. It happened before during the Dutch KPN blackmail case and it will happen again. Everyone at BalCCon was warned about this a few years ago.
- lucb1e 4y agoEvery service does this. Either that or they're the next Pirate Bay: a service blocked under copyright law without violating copyright, they only linked to places that were happy to infringe copyright (specific torrent peers). Domains were expropriated, IP addresses blocked, ISPs coerced into replacing DNS entries... If I remember correctly, the founders also all have interesting stories about the legacy this carried for them personally when trying to do business later. Until a VPN service gets that kind of status, you can assume they either follow local laws or haven't gotten a request for data logging for anything bad enough yet (realize that this doesn't have to be even close to murder-for-hire: being complicit in other people sharing movies between them reaches that "bad enough" bar).
- bleep_bloop 4y agoTried to find more about this but can't find anything, do you have a link please
- abigail95 4y agoWouldn't that make the product illegal in Europe unless they disclosed it? Or is this some secret SIGINT thing?
- mtlmtlmtlmtl 4y agoNordVPN are far too aggressive about youtube marketing to not be sketchy imo. Open source client doesn't really help because whatever sketchy shit they're up to is probably mostly on the server side anyway. I wonder what their total youtube sponsor spot expenditure has been. It must be a ridiculous amount of money.
- zpeti 4y agoI don't think its sketchy, it's just that the VPN business has extremely large revenues compared to costs of the service, which means A LOT of money remains for marketing. They can spend exorbitant amounts on youtube ads and affiliate review sites. It's a bit of a unique market in this way, people are willing to pay $5-$10 per month for something that costs $1.
- mtlmtlmtlmtl 4y agoNothing shady about fleecing your customers ;) The fact they're in Panama suggests some kind of money laundering scheme to me at the very least.
- ramranch 4y agoEvery VPN worth its salt is located in a similar country, as it's critical for a VPN to operate out of a jurisdiction that does not require log retention for a certain period of time nor cooperates with Five Eyes law enforcement.
- mtlmtlmtlmtl 4y agoThey have a ridiculously high ad spend, ridiculously high prices, located in a tax haven, their advertising routinely makes false, exaggerated claims, they've been exposed as having logs even though they claim otherwise, and may or may not be running a botnet. Everything about this company screams money laundering scheme to me. EDIT: I've realised my claims about logging were overblown. But I'm not so insecure as to edit it out so here's a disclaimer :)
- jedisct1 4y agoThey didn't open source their Windows and macOS clients, which are the most important pieces of the puzzle.
- commoner 4y agoI was misled by the title of this submission. The Linux NordVPN client is now open source (https://github.com/NordSecurity/nordvpn-linux https://github.com/NordSecurity/nordvpn-linux), but the Android, iOS, macOS, and Windows NordVPN clients are still closed source.
- hannob 4y agoThe fact that NordVPN needs its own library should already be seen as a red flag. If you need a VPN at all (which you usually don't) then you should use something that works with widely used and tested protocols. That was historically ipsec or openvpn (both not ideal), these days wireguard is probably a better choice. That's all apart from the fact that most reasons advertised by companies like NordVPN why you need a VPN are bogus or outdated, and that the trustworthiness of a VPN only relies in small parts on the client they use. (Update: skimming through the code it seems they somehow use openvpn. Not entirely sure if this invalidates my point, but then the question is: Why do they need their own client at all?)
- halJordan 4y agoThey need their own client for the litany of value-adds they offer. If you just want an openvpn config from them they'll give you one. Would you give MS this same hassle if i told you they rolled their own vpn libraries?
- SparkyMcUnicorn 4y agoHaving your own client gives the user a good UX. You can't provide a seamless login, server switching experience, and whatever else they offer with a widely used open source client (without forking at least). But you don't have to use their client. Most VPN providers (looks like Nord included) allow you to connect with any client that's compatible with one of their protocols. I use a different VPN provider with the official WireGuard client, even though they have their own company-made client.
- deleted 4y ago[deleted]
- vmoore 4y agoIt's great it's open source and all, but the download[0] is still a binary blob we have to trust. [0] https://downloads.nordcdn.com/apps/windows/NordVPN/latest/NordVPNSetup.exe https://downloads.nordcdn.com/apps/windows/NordVPN/latest/No...
- hnarn 4y agoUnless there’s reproducible builds I guess having the source code gives little comfort. Does the compiled application work with NordVPN services at least?
- logophobia 4y agoI stopped using nordvpn once they started disabling features when I disabled autorenewal: https://old.reddit.com/r/assholedesign/comments/ldf9g9/nordvpn_disables_features_when_you_turn_off/ https://old.reddit.com/r/assholedesign/comments/ldf9g9/nordv... A VPN provider really needs a lot of trust, easy to lose that.
- wackget 4y agoNordVPN, eh? I'll never forget there was a reddit thread on /r/vpn where a NordVPN customer complained about a billing issue or something. NordVPN's official response was to get defensive; they proceeded to actually publicly post a screenshot which included the customer's email address. I couldn't believe it. That tells you all you need to know about NordVPN's terrible attitude towards privacy.
- disadvantage 4y ago> terrible attitude towards privacy A VPN is inherently not a privacy tool. It is perceived that way because of the acronym Virtual 'Private' Network but privacy is not in the design specs at all. It's just for tunneling over untrusted networks like Starbucks Wi-Fi and spoofing your geo-location. That's it. You can't verify the no-logs claims by providers unless you're physically in their building and auditing the setup yourself.
- ganoushoreilly 4y agoI'm curious as to why you're being down voted. Technically VPN is a private network, but what you're getting at isn't wrong either. If you don't own / control the network you have no way to verify. I'm not passing judgement on Nord one way or the other but I get what you're saying. EDIT: At the time you were downvoted, I see it's not longer the case. Further comments about Nord and questionable behavior have also been posted in the thread.
- roelschroeven 4y ago> A VPN is inherently not a privacy tool. Maybe not, but NordVPN and similar services do heavily market themselves as essential privacy tools.
- favorited 4y agoAnd some, like MullvadVPN, don't even ask for common PII. No usernames, no email addresses, no passwords, no persistent billing information. They could claw some information from certain payment providers (like if you used Stripe to top off your account) if they wanted, but you can pay your bill by putting cash in an envelope and mailing it, if you wanted to.
- WirelessGigabit 4y agoIf you Google "NordVPN port mapping" you get an article from them, which explains port mapping, what it is, and then at the end "We don't support it". Really annoying that every service has like a whole essay on what functionality is and then 1 one liner saying they don't support it.
- lxgr 4y agoTheir "articles" largely seem to be SEO/content farm pieces without any meaningful content. For example, their article on SOCKS vs. HTTP proxies vs. VPNs is factually nonsensical (by e.g. describing HTTP proxies as "always unencrypted", or SOCKS as having higher performance due to "not rewriting packet headers"): https://nordvpn.com/blog/socks5-proxy/ https://nordvpn.com/blog/socks5-proxy/
- WirelessGigabit 4y agoYea, same thing happens when you search for 'Console lock timeout' (how long does the login screen show on Windows 11 before it puts the monitor back to sleep, default = 1 minute, not configurable by default). Somewhere there is a FULL article on how to do this on the website or partitionwizard... WHY? You see 20 websites with the same info re-hashed. And none of them mention the particular edge case that I'm running into. I really wish Google goes back to preferring bullet points over prose. Another example: Search for 'squirrel bite rabies'. You only get pest control companies telling you how you can get rabies. Except there have never been any reported cases in the USA.
- bleep_bloop 4y agoI have never seen so much false narrative, misunderstanding, speculation and conspiracy rabbit holes in a HN post. Wild to see so many people conjecturing about one of the most scrutinised and researched VPN providers in the world, whose source code is now available for all to see and not a single person, here or on Reddit has been able to flag any code of concern and the result is just pure conspiracy with zero evidence.
- IYasha 4y agoSo, library aside, Meshnet is becoming free too? I'm hearing about it for the first time and would like to try, but also want to hear pros and cons.
- vykintasmak 4y agoHey, Vykintas from NordVPN here. Hackernews looks to be a tough crowd, so I wanted to add a few things. Today as you correctly spotted we released a Linux app as well as Libtelio and Libdrop open source - a step towards more transparency. Can see quite a few conspiracy theories there, happy to address them. While no service out there is perfect, we are aiming to create the best VPN service. Nord isn't keeping any logs, is continuosly audited and since today looking to build in the open. Nord has never been a part of any kind of botnet. Besides open sourcing - today we launched Meshnet free so you don't need a subscription to use it to connect your own devices, spin up your own VPN server etc. Hope it will be useful. If you have doubts about Nord - I will try to answer your questions.
- deleted 4y ago[deleted]
- deleted 4y ago[deleted]
- wswope 4y agoI canceled my sub months ago after getting completely fed up with the Linux CLI client spamming ad-like output trying to push some new feature after running any sort of command. Definitely coulda come up with a bash alias to scrub it out, but despite really liking Nord’s features otherwise, I didn’t want to play whack-a-mole with a closed source client or suffer the slowness/pain of going the OpenVPN route. This is EXACTLY the right signal to bring myself (and presumably many other people in the same boat) back as happy customers. Sorry you’re dealing with unhinged conspiracy theories in this thread… but I think in the long run, this open sourcing will go a long way towards shoring up your customer base and keeping power users happy. Great work and TYVM!
- cute_boi 4y agoSo, they use a lot of Rust.
- qwertyuiop_ 4y agoBeen happy with both Mullvad and IVPN. Both are privacy first and very affordable.