9 ms·
Well said. This is a nothing-burger for all VPNs except the ones that are likely heavily leaking already due to the absence of basic firewall rules. Their "sid
by banister 2y ago
Well said. This is a nothing-burger for all VPNs except the ones that are likely heavily leaking already due to the absence of basic firewall rules.
Their "side channel attack" also made me spit out my drink.
EDIT: looks like NordVPN (at least on mac) doesn't have those basic firewall rules and so IS vulnerable to this exploit.
- foobiekr 2y agoA general rule for life is that companies making a big deal about military grade encryption or about how they are affiliated with Nordic countries are scams.
- codetrotter 2y agoYeah. But Mullvad VPN, based in Sweden, is an actual good one.
- pests 2y agoMigadu for email hosting is amazing as well, also Sweden I beleive.
- ChymeraXYZ 2y agoMigadu is Swiss
- prmoustache 2y agoWhy do people keep mistaking Sweden and Switzerland?
- short_sells_poo 2y agoPeople confuse Switzerland and Swaziland and those two aren't even on the same continent :)
- thenthenthen 2y agoSomething something Austria
- pests 2y agoMy mistake, I did know they were one of the two. I should have double checked. In general I know the difference between the two just forgot which Migadu was based on.
- froddd 2y agoCan you expand on that? Specifically the affiliation with Nordic countries? I’m a Nord VPN customer, I’d quite like to know more — may help inform any future decision on renewing or even staying with them.
- sigmoid10 2y agoIn general, Nordic countries are known for their extensive privacy laws, which in theory would make it harder for law enforcement to gain access to your traffic (and with a court order it is very easy to decloak your VPN traffic). However, as all Nordic countries are part of the Schengen Area, they are bound by European laws - and their enforcement. When Europol started cracking down on VPN providers that didn't comply, NordVPN (and all others who wanted to remain in the European market) were forced to admit [1] that they do comply with law enforcement orders. Today, all VPNs that you can legally buy are worthless in the aspects they advertise to you. You neither get extra security through encryption when browsing the web (https is already good enough for public wifi) nor actual privacy from your own government. There is exactly one use case for public commercial VPNs these days: If you want to easily access the internet from a different location to bypass geoblocking. But many big services like Netflix have started to simply block or otherwise limit access from traffic that comes from big VPN provider IP ranges, so even that use-case is becoming more worthless every year. [1] https://www.pcmag.com/news/nordvpn-actually-we-do-comply-with-law-enforcement-data-requests https://www.pcmag.com/news/nordvpn-actually-we-do-comply-wit...
- stavros 2y agoEven Mullvad?
- actionfromafar 2y agoMullvad complies, but they go out of their way to keep very little information. If you don't have the information in the first place, you can't surrender it.
- 2y ago
- berniedurfee 2y agoOr more generally, marketing budget and trustworthiness tend to be inversely proportional.
- ikiris 2y agoWhat was the side channel attack? There’s no way I’m reading 20 pages of networking for absolute toddlers to try to find it.
- josephcsible 2y agoThe side channel attack lets the attacker determine whether or not you're trying to connect to certain IP addresses over your VPN. If you properly fix this, then even when the DHCP server is performing the attack, the traffic in question still goes through your VPN. If you just mitigate it, then when the DHCP server is performing the attack, the traffic will be dropped. The side channel is that if you just mitigate it, then the attacker can repeatedly start and stop the attack for specific IP addresses, while monitoring how much VPN traffic you're sending and receiving.
- ikiris 2y agoThat’s certainly a take.