19 ms·
Proton announces release of a new VPN protocol, "Stealth"
- xeromal 2y agoI'm interested to try this out for a game I'm banned from. My little brother did a thing little brothers tend to do (lol) and I got caught in the crossfire. This is my baseline test for all VPN services.
- Macha 2y agoSeems to be more focused on preventing VPN detection by middleboxes than by endpoints.
- xeromal 2y agoI'm a big dummy but do you care to elaborate on that?
- Macha 2y agoThere are two types of VPN detection people are worried about: - Endpoints (e.g. Netflix or video game) detecting VPNs and blocking users of VPNs from their server because they don't trust the user to not be bypassing their rules - Middleboxes (e.g. airport wifi or the great firewall) detecting VPNs and blocking the user from the internet because they don't want the user to have unfiltered internet access. The latter group have a lot more tools to see if something is VPN traffic since they have access to the entire (encrypted) traffic, so can do stuff like checking are you constantly exchanging the vast majority of your requests through a few hosts. The former don't have as much information, but they have one really easy, really effective option, which is to contract with one of the IP classification databases that lets them see if the client is on a home internet connection. If it's not, they can just block you. Watching Netflix from your EC2 instance isn't going to be that reliable. And it's hard for the VPN providers to reliably get IPs that look residential, residential service usually prohibits such uses, companies that run both residential and business services still usually run them separately from an infra perspective as it makes their life easier, and even if you found an ISP to co-operate and let you use their residential addresses to run your VPN, the databases can just mark the entire ISP as having this kind of use, which would hurt the ISP's users, which counts as a strong disincentive for an ISP to become known for this kind of business. So for VPNs to bypass blocks by remote services, it means they're going from (most legitimate) shopping around ISPs willing to host them on residential IPs on the down low to the more sketchy end buying residential IP traffic from places that sell residential IP space from e.g. malware or software that buries this detail in its T&Cs. There's also the Tor exit node route of using your users as a sort of mesh network to get residential IPs, but legitimate VPN providers are not going to do that because of the risk it exposes their users to legal liability. This is not really something that can be fixed with protocol updates like Proton is doing here - the protocol updates are more about evading the middleware style traffic analysis mentioned here
- KolmogorovComp 2y ago> There's also the Tor exit node route of using your users as a sort of mesh network to get residential IPs, but legitimate VPN providers are not going to do that because of the risk it exposes their users to legal liability. Could there be a middle ground? Unless using encrypted DNS, the VPN has access to the website name, and could use a list of legitimate services that ban VPNs (like Netflix) and only then use their users as a mesh.
- devilbunny 2y agoThe endpoint blocking is pretty easy to bypass if you run your own VPN (e.g., Tailscale with an exit node in your home network, or an OpenVPN server). My workplace recently blocked all VPN exiting traffic, even on the guest network. I found this quite bothersome, as I do prefer to tunnel everything through my house. I never use public WiFi without VPN; not because I'm doing illegal things, nor because I think it keeps the NSA from spying if they want to (after all, they can just monitor my house). It keeps the coffeeshop and airport and hotel networks from watching my moves, though. It also doesn't trigger multi-location detection on Netflix, etc.
- KomoD 2y agoA VPN protocol won't really make a difference for that, usually online services detect VPNs based on IP addresses.
- sparkling 2y agoWhen they talk about detection, they are most likely referring to protocol level detection by ISPs forced to block VPN traffic, hostile local networks, corporate firewalls and such. The actual service you are connecting to (example: website, game server etc.) most likely uses a IP-based detection service such as https://focsec.com/ https://focsec.com/ or similar. In such cases, the protocol will not make a difference.
- xeromal 2y agoThanks for the info. That's a bummer!
- phone8675309 2y agoThis you? https://steamcommunity.com/discussions/forum/9/364040166685962694 https://steamcommunity.com/discussions/forum/9/3640401666859...
- xeromal 2y agohaha. I wish. I play 4s with my little bro and a couple of my friends and my little bro thought it would be funny to hot mic a hitler speech. We all got banned. lol
- scblock 2y agoFAFO. Sounds justified.
- xeromal 2y agoMy absolute favorite reddit expression. I actually donate to an animal shelter every time I read it.
- phone8675309 2y agoLooking forward to seeing the pictures of the animals you sponsored
- lopatamd 2y ago[dead]
- nasaeclipse 2y agoDoes it work in China? I would think it would've been best to keep this update "silent", so to speak, to avoid letting said parties know of this new protocol.
- tuetuopay 2y agoIt will be interesting how robust this new protocol is against traffic pattern analysis. A regular HTTPS connection has different patterns over time than a VPN, mainly because it carries only HTTPS and not all of the machine’s traffic; and only for a specific "website" (simplification here) instead of bundling the whole web to a "single server". The latter may be easier to evade, but the former will be hard. Anyways kudos to them, and I can’t wait to see how it fares against China’s GFW.
- elisbce 2y agoUnfortunately it's not gonna work. The GFW periodically disturbs/resets any persistent or large-enough traffic to IPs outside of China and bans them. That's why even if you have the best obfuscation protocol (like setting up your own server outside with truly indistinguishable traffic like a normal HTTPS), you still cannot have stable connections with large traffic. The current reliable ways of evading GFW are using IPs inside China via non-GFW controlled IEPL connections. These are loopholes deliberately left by GFW in order for certain legit use cases to bypass them (like research / big international corps etc.)
- codedokode 2y agoCan VPN providers rotate used IPs faster than they are blocked or it is too expensive?
- elisbce 2y agoI'm sure they have monitoring services to detect banned IPs and rotate on new IPs. However, in my experience, the most popular VPN providers are actually not specialized in evading GFW despite what they claim. During sensitive periods of time, most of the them couldn't be connected reliably. Those providers specializing in providing GFW evasion are called 'airports' or 'ladders' in the Chinese community and they use custom non-VPN protocols and tools for their services.
- iforgotpassword 2y agoMight depend on provider? I have a single endpoint and no such issues. Transferring multiple GBs on some days. I'm using a custom protocol though that's basically udp but with the tcp protocol number in the ip next protocol field. I'm simply ignoring any injected rst packets etc.
- _rs 2y agoIs there documentation for the protocol anywhere, or is this going to be a proprietary protocol to Proton that doesn’t gain much adoption outside of their users? If their claims are true this could be a great alternative for certain use cases
- hypeatei 2y ago> in the constantly evolving battle for online freedom, our work is not finished. I'm assuming this boils down to a cat and mouse game, then? E.g. popular firewalls patch this and Proton releases an update to bypass filters? Also, couldn't access this site directly because of corporate firewall, how ironic.
- okneil 2y agoI wonder what differentiates this from something like Stunnel?
- dtx1 2y agoIt's Proton branded.
- dtx1 2y agoProviders like petfect privacy have offered stuff like this for over a decade and they, like others, don't advertise their blatant misunderstandings[0] of the threat models people in censored countries face. I don't see why this is being shilled here so much, it's as close to an obvious honeypot as you'll ever see. https://news.ycombinator.com/item?id=41079157 https://news.ycombinator.com/item?id=41079157
- causal 2y agoAwesome. Question though: don't most VPN filters simply block a list of all known VPN endpoints? Maybe I missed something but I don't see how Proton's Stealth evades this simple filter?
- codedokode 2y agoBy not telling what their endpoints are?
- jiveturkey 2y agoI would assume https (websocket) with domain fronting
- pzmarzly 2y agoIs there a good comparison of "undetectable" VPN protocols? Wireguard[0], Shadowsocks[1], VLess[2], VMess[3], Trojan[4], etc. All of them seemed to work for me during my recent trip to China. [0] The article says Wireguard is easy to block, but in my experience GFW lets it through. [1] https://shadowsocks.org https://shadowsocks.org [2] https://xtls.github.io/en/development/protocols/vless.html https://xtls.github.io/en/development/protocols/vless.html [3] https://xtls.github.io/en/development/protocols/vmess.html https://xtls.github.io/en/development/protocols/vmess.html [4] https://trojan-gfw.github.io/trojan/protocol https://trojan-gfw.github.io/trojan/protocol
- olalonde 2y ago> [0] The article says Wireguard is easy to block, but in my experience GFW lets it through. For some time. After a while, the connection eventually gets blocked or throttled. The annoying thing about understanding the GFW is that it's not quite deterministic.
- kelnos 2y ago> All of them seemed to work for me during my recent trip to China. Depending on how you were connecting, your traffic may have been explicitly allowed. If you were connecting via your cell phone, using roaming with your home SIM card, you're not subject to the Great Firewall (all your data was essentially VPNed through your wireless carrier's PoP already). And IIRC many larger hotel chains that cater to foreigners (and would likely refuse to allow a citizen to stay there) also aren't GFW'd
- roughly 2y agoYeah, AIUI the Chinese government cares that Chinese citizens can't bypass the GFW, but either explicitly or implicitly does not care if foreigners do.
- warkdarrior 2y agoAs it should be -- a government's duty is to serve its citizens, not any foreigners who happen to be visiting.
- WhatsName 2y ago> Without going into too much detail, Stealth also establishes VPN connections in a specific and unique way that avoids alerting internet filters. I began mistrusting Proton some time ago with their hit piece on RAM-only VPN server confirming my bias. Let's assume any adversary interested in reversing that new protocol, what's the point of not being transparent on how this new and fancy obfuscation works. The TOR project has a lot of innovation in censorship circumvention[1] while still being transparent to their userbase. [1] https://snowflake.torproject.org/ https://snowflake.torproject.org/
- rasengan 2y ago> With Stealth enabled, your Proton VPN connection will be almost completely undetectable. In their defense, they're basically saying this doesn't do anything since it's still detectable.
- SahAssar 2y agoIs this just a brand name for tunneling traffic over TLS on port 443 (which has been a thing for decades) or am I missing something here?
- codedokode 2y agoMasquerading as legitimate traffic is important for many VPN users, I guess. Many don't want ISP to know they are using a VPN, and others don't want to get their VPN blocked.
- SahAssar 2y agoAbsolutely, but this is announcing this as a "new" protocol. I'd like to know what is new or if I'm missing something.
- kelsey98765431 2y agoDon't trust companies that save and hand over data. Don't trust proprietary security solutions. If this is literally just TLS based vpn wrapping, it's no different from using an onion bridge to get to your VPN endpoint. Proton gives data to federal agencies. Proton keeps user data. Proton removed their warrant canary. Use something better. EDIT: If you want a truly safe VPN, you will need to do some work on both adversary modeling and technical implementation. If you are just worried about your ISP (filesharing of legally protected digital backups), use whatever. If you are worried that your data may be collected by your VPN provider, use a series of tor/vpn multihop. If you are a paranoid mf, use a privacy coin to purchase a VPS and then connect to it via tor on a public wifi network, set up a .onion hidden service for your ssh/chisel/etc port, connect over tor to forward your tunnel port to localhost, use that tunnel to connect to a multihop VPN system. Suggestions include mullvad, PIA, cryptostorm, whatever you want really. Throw a VPS with generic openvpn in the middle of your multi-provider hops, again paid in a privacy coin. Pay a homeless man to colocate a physical server that has DRAC and luks along with something like AMD TSME, then run containerized multihop there aswell. Basically if you want something done right, at least do some of it yourself.
- coldblues 2y agoProton does not care anymore. Maybe they never did? Their new wallet wholeheartedly cements any skepticism I've had previously about them.
- realfeel78 2y agoElaborate on this?
- OutOfHere 2y agoProton has multiple services, and the data retention of one service may have little to do with another. In particular, any data retention for their VPN service is going to be very different from say email for obvious reasons. Even for email, afaik, it was the recovery email address that gave access to the data in the account. What's a better VPN service anyway? Mullvad? I see Proton's stealth feature as being valuable. Disclaimer: I have no conflict of interest whatsoever with Proton other than being a free user.
- olalonde 2y agoIt seems their Android app is open source... Maybe the protocol could be reverse engineered? https://github.com/ProtonVPN/android-app https://github.com/ProtonVPN/android-app PS: Tried their free plan in China and it won't connect ("Connection Timeout"). In fact, I had to use another VPN to get past their app's loading screen (guessing it got stuck while doing a request to their server)...
- EMIRELADERO 2y agoFrom a cursory glance, it seems to be Wireguard + TLS https://github.com/ProtonVPN/android-app/blob/fc9e7f500fe56bacfb2bf5247611fc6f5c082f69/app/src/main/res/values/strings.xml#L214 https://github.com/ProtonVPN/android-app/blob/fc9e7f500fe56b...
- tptacek 2y ago"Stealth" isn't a property of core VPN tunneling protocols --- establishing a secure channel is. Stealth is something you'd build on a transport underneath a VPN protocol. Completely replacing WireGuard or IPSEC just to beat DPI seems pretty silly.
- saurik 2y agoFWIW, when this same URL was being discussed two years ago, someone looked into it and decided that it was, in fact, "Wireguard over TLS". https://news.ycombinator.com/item?id=33171089 https://news.ycombinator.com/item?id=33171089
- tptacek 2y agoYeah, I see someone else on the thread has evidence of the same. If they're just tunneling WireGuard over something, I don't care, knock yourself out, it's fine.
- KomoD 2y agoDo we really need yet another VPN protocol?
- jiveturkey 2y agowe do, actually. you're missing the point. this is to evade VPN blocking.
- KomoD 2y agoI'm not, protocols like these already exist and since this is ProtonVPN's own protocol all you need to do is block the IP addresses and it would be useless anyway. It doesn't work against GFW nor in Russia. I've seen some people saying they're having issues in Iran as well. If you had a protocol like this combined with something like MysteriumVPN (which has "decentralized" VPN nodes) then yeah, it'd probably help.
- daft_pink 2y agoWill it work in China? You guys go back and forth about whether you trust VPN companies, but for me I’m just looking for something that works with 100% reliability in China.
- apitman 2y agoThis is too light on details to determine if there's anything interesting here. Similar to others, these are my main concerns: * Is this an open protocol? * I would like to see a detailed comparison to similar solutions * Looks like it's TCP so head-of-line blocking may cause performance issues. * What prevents entities from detecting that all your traffic is going to a single endpoint, or just blocking known VPN servers directly?
- gr4vityWall 2y agoThis sounds more like a press release for a company than a technical overview of the protocol. Is there a reference implementation available?
- brewdad 2y agoI mainly use Proton to get around geo-blocks. FWIW, I tried this new protocol out on BBC iPlayer and it failed horribly. I tried the Wireguard UDP I normally use and streamed without any problem. It's a single data point but if the goal is to avoid sites knowing you are on a VPN, it isn't fit for purpose.
- majorchord 2y agoI don't think this is enough information to quantifiably say that your issue was caused specifically by the Stealth protocol itself and nothing else.
- thayne 2y ago> Stealth does this by using obfuscated TLS tunneling over TCP. This is different from most popular VPN protocols that typically use UDP The reason most VPN protocols use UDP is for performance. With TCP, a single blocked packet can delay multiple streams. And fwiw, openvpn supports using TLS over TCP, but it is less performant than udp. I would be more interested in a protocol that uses quic and looks like http/3
- tptacek 2y agoUDP is a complete red herring and you should carefully reread any analysis that says a VPN protocol is superior to WireGuard because it uses TCP and not UDP. It's trivial to run WireGuard over TCP (it's our default for all our users, because something like 1 in 20 users has problems getting UDP out to the public Internet).
- xezzed 2y agoFriend of mine just tried this in Russia. DOESN'T WORK
- kgeist 2y agoProtonVPN's IP ranges blocked?
- xezzed 2y agoI dunno. But they advertise their "Stealth" protocol as a solution for everything. And there are still problems.
- throwaway74354 2y agoDo they happen to use the Russian App Store? If so, the app hadn't been updated to utilize the new protocol because Apple had delisted[1] ProtonVPN in mid July. [1] https://apps.apple.com/ru/app/proton-vpn-fast-secure/id1437005085 https://apps.apple.com/ru/app/proton-vpn-fast-secure/id14370...
- xezzed 2y agoHe is permanent resident of Spain but he is in Russia currently. So he has Spanish AppStore
- majorchord 2y agoThe issue reported here (unanswered since March) says they are using Stealth in Russia and it is still not working: https://github.com/ProtonVPN/android-app/issues/130 https://github.com/ProtonVPN/android-app/issues/130
- ranger_danger 2y agoThis your friend? https://github.com/ProtonVPN/android-app/issues/130 https://github.com/ProtonVPN/android-app/issues/130
- saurik 2y agoThis was "published" now, but this same URL was discussed two years ago here about the same thing? https://news.ycombinator.com/item?id=33170028 https://news.ycombinator.com/item?id=33170028
- ark4579 2y agocoincidentally, while searching for "proton vpn stealth" i came across this exact article 2 days ago and was surprised seeing it here with latest publish date. But, in previous article "windows" was not included in the list of platforms stealth was available on. I guess with today's proton VPN update, it became available on windows too and so they updated the article.
- deleted 2y ago[deleted]
- sinkasapa 2y agoI use protonvpn because I pay for protonmail. It is frustrating because I feel like I need to pay another VPN provider to get decent service. The client is ridiculously unstable and doesn't have the features found on other platforms. If you're not already using their mail services, use linux, and don't like being snubbed despite being a paying customer, look for another provider. Note that the stealth mode is not available for linux, just another way to tell their linux customers that they don't matter.
- commandersaki 2y agoHow does it address TCP over TCP reliability layer collision? Reference: https://web.archive.org/web/20230310043036/http:/sites.inka.de/bigred/devel/tcp-tcp.html https://web.archive.org/web/20230310043036/http:/sites.inka....