10 ms·
Reminder that it looks like NordVPN does shady stuff: https://news.ycombinator.com/item?id=29285988 https://news.ycombinator.com/item?id=29285988 Allegedly, th
by acatton 4y ago
Reminder that it looks like NordVPN does shady stuff: https://news.ycombinator.com/item?id=29285988 https://news.ycombinator.com/item?id=29285988
Allegedly, they are using their customers as botnets to resell traffic from residential IPs, mostly for scraping, through their other business "Oxylabs".
- lr4444lr 4y agoMaybe you're confusing NordVPN with Hola, which was used by Luminati which became or sold to Bright Data. Perhaps Oxylabs is sourcing from somewhere similar, but what evidence do you have that it's NordVPN?
- ehPReth 4y agoI hear there's a dirty secret that more and more companies are doing this to make things like Netflix that block VPNs "just work" though their services. Not sure how true this is or how widespread, though.
- edgyquant 4y agoThis has been brought up before, Netflix does not work with a VPN on. It knows you’re using a VPN and blocks you (asks you to disable it.) Yes this is true even with NordVPN, which I bought specifically to be able to watch Netflix on when expressVPN didn’t work.
- tenacious_tuna 4y agoThat is an exceptionally broad statement. I think it's probable that Netflix doesn't work with large-scale VPN providers because it's broadly easy to identify the traffic source. However, using a wireguard tunnel from my ipad back to my house, netflix works fine.
- causi 4y agoHe obviously didn't mean to include people who are just tunneling back to their residential IP.
- mynameisvlad 4y agoThere’s many ways Netflix could detect VPN use, especially on mobile devices. It’s not obvious at all. Netflix could be doing something as simple as checking the IPs or could be actually checking the use of VPN at a system level. Both are equally valid readings of the GP comment.
- medo-bear 4y agoseems like torrenting is still easier (and safer) than using netflix and co
- LeeroyWasHere 4y agoI was suspended by Disney+ for accidentally turning on my VPN to a location they didn't like...I instantly cancelled my subscription. I couldn't believe the suspension message, banned a paying user... Never again.
- lxgr 4y agoWhat location was that, out of curiosity, and what was the reason given?
- _joel 4y agoespecially if you're on arm linux, it seems
- babypuncher 4y agoI find this "easier" argument amusing. Any solution that requires me to reach behind my TV and plug in my laptop is already not easy. With Netflix you just punch your password into your smart TV and you're watching content.
- wlesieutre 4y agoIf Netflix can see that your traffic is coming out of an AWS datacenter, then yeah they'll block it. If Nord VPN is really bouncing your traffic out of some other residential customer's connection, that would be a lot harder to detect. And a lot more ethically questionable if the other user doesn't realize they're doing it.
- spookthesunset 4y agoBut if the VPN provider really was routing other customers traffic through your internet… you’d know it. You’d see requests and traffic that you didn’t make going across your router. Since you’d be the endpoint for the other dudes VPN you could probably even see what IPs they are connecting to and get an idea about the nature of their requests. I dunno if SSL encrypts the entire HTTP payload or not but could you even figure out the URL’s being requested using a tool like wireshark?
- lxgr 4y agoFull URLs: Definitely not. Path and query parameters are part of the HTTP payload, i.e. encrypted within HTTPS. Host names: Very likely, unless you're using SNI.
- None4U 4y agoYou mean eSNI, SNI is the field containing the hostname and eSNI stands for "encrypted SNI"
- lxgr 4y agoRight, thanks! I keep thinking the "e" is for "enhanced" encryption, i.e. "eSNI 2.0", but what I'm thinking of is actually called ECH (for "encrypted client hello"): https://blog.cloudflare.com/encrypted-client-hello/ https://blog.cloudflare.com/encrypted-client-hello/
- wlesieutre 4y agoIf such a feature exists (and I have no idea if it does) I assume they would only route traffic to known streaming services through it. Otherwise you're making random customers into exit nodes for potentially criminal traffic, which could go very badly.
- 4ggr0 4y agoNo? I've used Netflix with NordVPN like 2 years ago and since then switched to ProtonVPN, which works as well... Using VPNs for Streaming is selling point #1 for tons of people.
- r3trohack3r 4y agoIt fully depends on whether the IP address associated with your VPN tunnel has tripped their automated detection systems or managed to land on a public blacklist like Project Honeypot. But they do actively track and block VPN traffic.
- 4ggr0 4y agoAh, that's probably the case, true. Never had it happen to me but that's very anecdotal.
- r3trohack3r 4y agoWhile working at Netflix this was a real bummer. I had whole home VPN configured and I couldn't access NFLX streaming content from the house. Getting Netflix traffic to bypass the VPN is incredibly difficult without hacking the client side code to have it update the bypass rules on-demand in response to the client side JSON payloads - or hook into DNS resolution and do VPN bypassing there based on a regeular expression of the origin and the returned records. The way NFLX works under the hood, from the client's perspective, is that it makes an initial request to a service hosted in AWS. That service stitches together the list-of-lists on the home page. Then you select a film to watch, it again reaches out to a service hosted in AWS to ask to stream the content. This is really straightforward to get working with whole home VPN, you just bypass the VPN for those origins (using DNS queries to get the IP blocks) and you are golden. A little cron job could keep that IP bypass list fresh and it worked well enough to get through the UI. But then the AWS service responds with a list of streams you are licensed to watch and URLs that point to their location. Those URLs point to Netflix's OpenConnect CDN hosts. Nearly every time I went to stream, I'd pull a different origin for the content and that would route back through the VPN. The list wasn't stable, so I couldn't compile a comprehensive list of origins to route around the VPN with. So NFLX blocks VPNs to protect their licenses, which I understand. But their architecture made it impossible for me to allow their service to bypass my VPN. So any device I wanted/needed to use NFLX on had to have a direct connection to the internet.
- netfortius 4y agoNetflix works just fine through VPN - it just limits the offerings. If I disable VPN I additionally get local-to-the-country offerings, on top of the "through VPN" ones.
- jamiek88 4y agoNetflix does however work with a smart dns spoofer.
- bennysonething 4y agoCan you give an example please? I'd like to do this.
- jamiek88 4y agoI use https://www.smartdnsproxy.com/services/netflix/ https://www.smartdnsproxy.com/services/netflix/ Never had an issue, been signed up for years. It’s possible to set up your own solution I believe but I don’t have the time for that currently. Not affiliated or anything and I’d do your own research on them but I much prefer this as they only see that traffic from me.
- bandrami 4y agoI mean, it works just fine; you can watch all Netflix-owned content on NordVPN. You just can't watch any of the stuff they license for local distribution.
- makingstuffs 4y agoNetflix definitely works with NordVPN. My partner and I regularly use it to enable us to stream content which isn’t available in the UK but is elsewhere in the world. Specifically to watch The Walking Dead if I am honest.
- abofh 4y agoNetflix can be a bit sneaky - there's some content that it won't even show you if you're on VPN, even if the source and destination regions can see it; I use a VPN regularly for other streamers, but netflix I sometimes end up having to turn off my VPN to even find particular shows.
- bleep_bloop 4y agoUsed NordVPN for 3 or so years and I have been sharing my Nord and Netflix account with several different people on and off over the years, none of us have ever had an issue streaming Netflix. Amazon Prime and some other streaming services, yes, but oddly not Netflix. However my current gf often will get interrupted in the middle of streaming while using ExpressVPN so she just switches over to Nord and issue solved.
- duxup 4y agoI ran into a situation where I left a VPN on my phone on and the Target app (US store Target) would pop up an alert "true". I assume someone was detecting if you were using a VPN and testing and it somehow made it into production. I emailed them and never heard back. Granted ... I get why a retailer with financial activity going on might want to know if a VPN was used to possibly apply extra scrutiny to the purchase.
- spookthesunset 4y agoOr used by competitors to see if the prices change depending on network location. I used to work for a company that explicitly changed the prices on the site if the request traffic came from a competitor IP address. Of course this was a hundred years ago in a land far away. I don’t know how much success you’d have even finding your competitors IP’s these days.
- wyldberry 4y agoTarget now also has a world class incident response and forensics team setup after their big breach and being nearly every security vendors topic du jour for years. It's entirely reasonable they do this to add to malicious detection signal, or fraud.
- bennysonething 4y agoThat is terrifying! So someone could access illegal content through my home internet connection (while I have a VPN running)?
- lxgr 4y agoYep! "Exit node" users and VPN customers don't need to be in the same set, though: It's entirely possible that the VPN operator buys residential IP forwarding volume and includes access to it as part of their product offering. That doesn't make things much better for unwitting users sharing their internet connectivity with insufficient or no education, though...
- moremetadata 4y ago[dead]
- DeathArrow 4y agoIs this legal? What is someone else is doing illegal things using your IP?
- acatton 4y agoI used to buy residential IPs from a competitor of Oxylabs in a previous life. Nothing illegal, just scraping data from websites using cloudflare. (Cloudflare has some anti-scraping-scraping protection, even if you do 1 request per 15 second) I asked this question, the answer from this other company was "we would close your account". But they were unable to explain clearly to me how and if they monitored this. In fine, I think this is your responsibility, you basically voluntarily installed some malware.
- dkjaudyeqooe 4y agoIt might be against your provider's terms of service, but it's hardly illegal. If someone else is doing illegal things on your IP address then you could blame the (users of the) service to avoid liability. Still you could find yourself targeted by a lawsuit. I wonder if Oxylabs' terms protect you in this case.
- causi 4y agoMost people wouldn't even know to ask.
- stingraycharles 4y agoAs a previous customer of Oxylabs, I can confirm that this was at least used as the explanation by their sales people. To be honest, apart from botnets, it’s really the only way a company could “legally” get access to millions of residential IPs.
- TecoAndJix 4y agoDigging into this on oxylabs site i found this document: https://oxylabs.io/Oxylabs_Residential_Proxy_Acquisition_Handbook.pdf https://oxylabs.io/Oxylabs_Residential_Proxy_Acquisition_Han... "Consenting and fully aware individuals become a part of a residential proxy network in return for a financial reward or some other benefit. When they choose to participate in our suppliers’ pools, they consent that a part of their internet traffic and a small amount of the device’s hardware resources will be used for a variety of business cases." Does anyone that uses NordVPN know how explicit this is in their client/agreement? If they are even using it...
- spookthesunset 4y agoYou’d almost certainly see that traffic going across your network, right?
- ramesh31 4y ago>You’d almost certainly see that traffic going across your network, right? This is why their marketing campaigns are so aggressive. They completely rely on the unsophisticated masses, to whom a computer is a magical box of fairy dust that plays Netflix shows.
- yunohn 4y ago> completely rely on the unsophisticated masses, to whom a computer is a magical box of fairy dust that plays Netflix shows And that’s perfectly fine - computers are a tool, enabling valuable usecases for everyone.
- ramesh31 4y ago>And that’s perfectly fine - computers are a tool, enabling valuable usecases for everyone. Of course. But the arbitrage of that knowledge leaves open all kinds of profitable businesses, including shady VPNs.
- 4y ago
- that_guy_iain 4y agoI think that's why they're open sourcing their client to show they're not going that?
- dvdbloc 4y agoIs this behavior only enabled by their client? If you use your own OpenVPN client to connect to their OpenVPN server are you avoiding this behavior?
- tjoff 4y agoRegardless, you shouldn't treat trust like that, don't use nordvpn. If I had to trust a mainstream vpn it would be mullvad.
- VonGuard 4y agoThey, and ALL VPN PROVIDERS, sell your DNS data, as well. That's the real business model.
- 3np 4y agoIf this is a concern, one can self-host a fully recursive DNS server and connect over DoT.
- mig39 4y agoDo you know for sure that Mullvad sells DNS data? They claim to not log anything, including DNS.
- _joel 4y agoYea, can even pay with brown envelope of cash. They're the MVP.
- yurishimo 4y agoI don't believe Mullvad sells DNS data, largely in part to their much higher pricing model when compared to Nord/Express/et. al Their FAQ confirms this, assuming you trust them. https://mullvad.net/en/help/no-logging-data-policy/#no-logs https://mullvad.net/en/help/no-logging-data-policy/#no-logs
- lxgr 4y agoA higher price point isn't proof of anything. If a provider can sell a VPN for $1/month as a loss leader and make $5/user after selling all data, what keeps a $10/month VPN from making >$15 doing the exact same thing?
- yurishimo 4y agoMy point was that they charge more for the subscription to avoid putting themselves in a situation where they feel pressure to sell user data to make up for a bad quarter of sales.
- amelius 4y agoThey still offer OpenVPN connections ...
- mynameisvlad 4y agoIs offering a service somehow a problem? Especially the most prominent method of VPN connections for a long time? Most routers and other clients that aren’t updated very frequently still only support OVPN. They also offer WG connections if OVPN bothers you so much.
- amelius 4y agoI'm not bothered by OVPN, on the contrary!
- mynameisvlad 4y agoAh, the problem with reading text on the internet. Totally sounded like a criticism with the ellipses.
- vykintasmak 4y agoHey, Vykintas from NordVPN here. By going open source we are trying to be more open. NordVPN customers aren't used as botnets to resell traffic and you can easily check it using Wireshark as well as look through the code. As you can see majority of it is open source. If you have any questions - shoot them and I can try and answer them. Otherwise - please don't spread information without proper investigation.
- DaiPlusPlus 4y agoWhy should we trust you?
- vykintasmak 4y agoYou shouldn't, but as mentioned - there are numerous ways to verify it
- deleted 4y ago[deleted]
- acatton 4y agoHi Vykintas, thank you for answering. I'm the GP. First of all, I want to reiterate that I purposefully used the word "allegedly" because I have no proof. I only have a smoking gun https://archive.is/bQo0O https://archive.is/bQo0O . Second of all, I want to explain that it is very difficult to verify any of your points. > you can easily [...] look through the code. As you can see majority of it is open source. Yes. This is correct, but at the time of writing this comment, the source has been made available only 9 hour ago. https://github.com/NordSecurity/nordvpn-linux https://github.com/NordSecurity/nordvpn-linux The whole thing is one giant "Initial commit" of what looks like millions of lines of code. Auditing this code will take months for single motivated person. There is little to no comments. "Just read the code" is difficult in this context. Also routing traffic through the client can be done just with 2 lines of code enabling kernel ip forwarding, and another line of code adding a nft/iptable rule to nat traffic from NordVPN to the outside world. This is looking for a needle in a haystack if this is obfuscated. Also your Windows and MacOS clients (which are the most used by non-power-users) are not opensource, at the time of writing. So these ones could still be doing what has been alledged. This would be fine, since it's most likely most of your users. > you can easily check it using Wireshark This is also not that easy. If, as alleged, Oxylabs resells millions of NordVPN IPs to thousands of Oxylabs customers, you only have 1/1000 chance to be the botnet of the day. So you would need to be running Wireshark the one day out of 2½ year to see the traffic going through with Wireshark.
- saurik 4y agoI am the top comment on that post and you got the whole situation backwards and are thereby just spewing FUD with the implication in your comment :/. The idea was never that NordVPN was reselling the network connections of NordVPN customers; it was always that they were, on their backend, originating NordVPN customers traffic from maybe-sketchily-sourced IP addresses. Here is a paragraph I wrote a couple years ago on the topic of how centralized VPN companies manage to bypass blocks by content providers (such as Netflix). > One VPN company that actually seems to do "well" at this is NordVPN: they've even managed to provide access to Disney+! Someone did a deep analysis of how this worked a while back (an article which has since been deleted, weirdly, but a copy can be found on the Internet Archive). They are "linked closely with a Lithuanian data mining company called Tesonet" which also runs Oxynet, which in turn advertises itself to have "32M+ residential proxies…100% anonymous proxies from all over the globe with zero IP blocking", which the author of that analysis believes is how NordVPN is originating their traffic... and how did they get all of those IP addresses? The contention was that they seem to be stealing them, convincing random products to embed malware that attaches them to the Oxynet essentially-a-botnet. https://news.ycombinator.com/item?id=21664692 https://news.ycombinator.com/item?id=21664692 http://web.archive.org/web/20191128170008/https://medium.com/@derek./how-is-nordvpn-unblocking-disney-6c51045dbc30 http://web.archive.org/web/20191128170008/https://medium.com...
- acatton 4y agoSorry, my phrasing was wrong. The second part of my comment had nothing to do with the first link. I am basing the second part on this research: https://www.docdroid.net/kOP3JAh/tesonet-web-of-lies-pdf https://www.docdroid.net/kOP3JAh/tesonet-web-of-lies-pdf I'm not a conspiracy theorist, but the relations of Tesonet, NordVPN and Oxylab is creepy at best. People make the allegation that NordVPN is routing some of Oxylabs' traffic, because that's exactly what HolaVPN and Bright Data (previously known as "Luminati") does. (See https://archive.is/aJY0F https://archive.is/aJY0F ) And Luminati Networks sued Tesonet for patent infringement on this. Just the corporate structure of Tensonet in itself should make people stay away from any of their VPN products.
- throwaway18536 4y ago