12 ms·
NordVPN says its new protocol can circumvent VPN blockers
- netsharc 2y ago> Unfortunately, because VPNs will have many requests being sent from one server, website hosts can recognize when a VPN is being used. A constant stream of requests coming from one computer’s IP address is, of course, unusual behavior. > NordVPN claims to have found a way to make traffic from its service look normal, though admits that it may not always work perfectly. It also says the NordWhisper protocol may introduce more latency. That reads like they're wheel-reinventing Tor, and one fears they'd use other users' computers as exit nodes. But then again this "journalist" might be a too typical one, one who doesn't know what they're talking about. And on the other side of the block, a VPN user in a suppressive regime trying to connect to a regime-known VPN server will just get a spoofed "connection refused" from the regime's firewall. interestingly a P2P-system where they connect to a random home computer somewhere on the planet instead of known commercial VPN servers, plus a hard-to-detect protocol (pretend to be a game? Do games do P2P nowadays or do they always talk to a server?), might be able to get away with it. Anyway, the page doesn't give much detail either: https://nordvpn.com/blog/nordwhisper-protocol/ https://nordvpn.com/blog/nordwhisper-protocol/
- ramesh31 2y ago> and one fears they'd use other users' computers as exit nodes This is already standard practice for commercial VPN providers, and is one of ten thousand reasons you should never use one for any reason ever.
- netsharc 2y agoAah, yet more bullshit on the Internet. Source? I know those freebie VPNs do that, but many commercial providers are still sane.
- WarOnPrivacy 2y ago>>> and one fears they'd use other users' computers as exit nodes >> This is already standard practice for commercial VPN providers > I know those freebie VPNs do that, but many commercial providers are still sane. True. There are free VPN apps that rope their users into a residential proxy net. The combined userbase is sold to bad actors as a residential proxy service. This is not what major VPN providers like Mullvad, OVPN or even Nord do. The first two have a good reputation. Nord, not so much. However, for all it's faults, Nord is no bad actor - they're not in the same category as a ResProxy seller.
- tacomagick 2y agoI'm a user of Mullvad, I can get configurations for Wireguard and OpenVpn through my dashboard. This eliminates the possibility of being used as an exit node as I can read the wg config and see exactly what it does. I think other providers should do the same with their systems. It allows for high flexibility.
- deleted 2y ago[deleted]
- achierius 2y agoHave any others? I haven't seen such pushback on using a VPN before, so I'm curious.
- IncreasePosts 2y agoIs a person running an exit node responsible for the requests coming out of that node? Or will it just make for a very awkward conversations with the authorities if someone requests CP or terrorist paraphernalia via your exit node?
- theoreticalmal 2y agoI’m not aware of specific case law, but there has been an ongoing case regarding a Tor Exit Node and copyright infringement that suggest the exit node hoster is not legally responsible for the data, at least in terms of copyright infringement. Who know about other actions https://torrentfreak.com/tor-exit-node-operator-dodges-bullet-in-piracy-lawsuit/ https://torrentfreak.com/tor-exit-node-operator-dodges-bulle...
- amelius 2y agoWell, if you just run OpenVPN, I suppose that you're using the conventional algorithm.
- ed_mercer 2y agoThis is nonsense. VPNs would be long out of business if this was true.
- thatguy0900 2y agoPlenty of popular games still do p2p
- theoreticalmal 2y agoReally? Can you give some examples? Just for multiplayer or for large asset transfer?
- Numerlor 2y agoOff the top of my mind as a big game GTA V runs P2P, I think most games that aren't competitive do, only using servers for matchmaking
- Arrowmaster 2y agoI was going to respond that most games from the PS3/360 era used p2p but I don't know about recent ones. But GTA5 was a PS3/360 game.
- thatguy0900 2y agoOff the top of my head Warframe is massive and uses p2p while in most missions, Helldivers 2 was a huge launch last year with p2p, dead by daylight, a lot of indie multi-players like risk of rain 2. It's quite popular for coop style games where you need to worry less about cheating. They will use servers to create the matchmaking and then will pick the user with the strongest computer and network typically to actually host the game. I don't know of any games that do p2p asset transfer anymore
- tacomagick 2y agoSteam has a feature for this where for supported games like Counter Strike 2 or Team Fortress 2, your connection will be routed through other players, or just people on your friends list depending on your settings.
- halicarnassus 2y agoI get the occasional request to NordVPN image assets beginning with `/nordvpn/media/` on my server. Apparently this is or was a way to find out if an IP address is acting as an exit node.
- gruuuk 2y ago> That reads like they're wheel-reinventing Tor, and one fears they'd use other users' computers as exit nodes. Why the fear? That would probably improve overall access to privacy/anonymity, and I would assume NordVPN would take any legal heat over this, not their users.
- pseudalopex 2y agoOther services used users' computers as exit nodes without clear disclosure. Users found out when services blocked their IP addresses. And why would you assume NordVPN would take any legal heat?
- gruuuk 2y agoI mean, if this is the case, and their users aren't aware. If the users are aware, and want to run nordvpn equivalents of tor exit nodes, then I don't see a problem.
- deleted 2y ago[deleted]
- bigfatkitten 2y agoNordVPN can't indemnify you against the cops executing a search warrant at your house, and perp walking you out in front of your neighbours because a NordVPN user used your exit node to download child abuse material.
- topranks 2y agoI think it more likely they’re just repackaging XTLS/VMess with domain fronting, or one of those other heavily obfuscated techniques. But yeah who knows, zero detail.
- mountainninja 2y ago[dead]
- Arnt 2y agoSending traffic from many IPv6 addresses perhaps?
- tacomagick 2y agoDo note IPv6 is still not supported everywhere yet.
- portaouflop 2y agoVPNs are snake oil, don’t trust a word they say
- fastily 2y agoSome are, but not all. That’s why you do your research and pick reputable services. I’ve been a happy user of Mullvad & protonvpn for years. They’ve had ample opportunities to mitm me, but I reckon if it hasn’t happened by now it probably won’t
- thousand_nights 2y agotell that to the people who get letters from their isp threatening to cancel service for downloading torrents vpns have their use case, they're definitely not snake oil
- jpc0 2y agoI'm assuming if you are getting let's you are in violation of TOS you agreed to. Advocacy aside, the solution is to not. I know a lot of people can't pick another provider but at the same time they probably didn't need what they were torrenting... Now do I think what I do with my internet is my problem and my ISP can go f themselves. Yes, but I'm also in the privileged position to have many options and quite a few have the "its your internet connection, we will inform you about throttling if we have a technical reason, also if the police asks we are compelled by law to do x" A VPN does not solve your problem and isn't advocacy, it's at best bootlegging.
- clamprecht 2y agoI wonder if it's analagous to spread spectrum[1] with radio comms. [1] https://en.wikipedia.org/wiki/Spread_spectrum https://en.wikipedia.org/wiki/Spread_spectrum
- gamedever 2y agoI really wish Apple and Google would run VPNs. Then, given their markets are so large, they couldn't be blocked by anyone that wanted customers/eyeballs. You'd think "Privacy First" Apple would do this. HN blocks (ghost blocks) VPNs. Make a new account from a VPN. Post. Open a private/incognito window. Load up the thread. Your comment won't appear. Give it few days. It never appears. It only appears for you when you're logged in.
- skibble 2y agoThey do, sort of; iCloud Private Relay. Details: https://support.apple.com/en-gb/102602 https://support.apple.com/en-gb/102602
- puppycodes 2y agoLike a VPN except tied to your location, financials, cloud storage and devices! Great!
- cchance 2y agoYa its less for anonymity and more to prevent unsecure sites and wifi from leaking credentials
- tacomagick 2y agoI don't see how this could prevent unsafe sites leaking credentials (Assuming unsecure == No TLS) as unencrypted data will be sent through the exit node to the web server. It does however help for wifi snooping.
- cchance 2y agoi sort of meant it as a combination, unsecure sites on rogue wifi
- aucisson_masque 2y ago
- puppycodes 2y agoNordVPN continues to give chrome incognito vibes.
- theoreticalmal 2y agoNordVPN probably makes more selling user data than subscriptions for its VPN service. It’s a huge scam
- pseudalopex 2y ago> NordVPN probably makes more selling user data than subscriptions for its VPN service. It’s a huge scam What is the evidence? Is Deloitte part of the scam?[1] [1] https://cybernews.com/news/deloitte-verifies-nordvpn-no-logs-claim/ https://cybernews.com/news/deloitte-verifies-nordvpn-no-logs...
- DannyBee 2y agoNo idea in this case, but often, Deloitte is! See, e.g, https://www.justice.gov/opa/pr/deloitte-touche-agrees-pay-1495-million-settle-claims-arising-its-audits-failed-mortgage https://www.justice.gov/opa/pr/deloitte-touche-agrees-pay-14... https://news.bloomberglaw.com/ip-law/deloitte-sued-over-claims-it-stole-covid-vaccine-rollout-secrets https://news.bloomberglaw.com/ip-law/deloitte-sued-over-clai... https://www.ndtv.com/india-news/deloitte-clears-nigerian-firm-tingo-as-having-470-million-us-probe-finds-only-50-4948217 https://www.ndtv.com/india-news/deloitte-clears-nigerian-fir... https://www.cohenmilstein.com/case-study/ibew-local-98-pension-fund-v-deloitte/ https://www.cohenmilstein.com/case-study/ibew-local-98-pensi... This is a random sampling, there is plenty more.
- techjamie 2y agoWhile not empirical proof I typically distrust anything that has massive marketing budgets. Nord seems to sponsor every Tom, Dick, and Harry on YouTube to push their product and, as we've seen from many other unmasked operations that do that (Honey, Established Titles), that doesn't bode well. I don't use Mullvad, but I've never seen them run ads directly, and they've gotten exposure via word of mouth very effectively.
- _fat_santa 2y agoReading the comments here, it's clear that many have a less than favorable view of NordVPN. With that said, what VPN provider would readers here recommend? I don't know if there is a consensus for a "good VPN provider" that respects privacy, etc or if they are all shitty in one way or another.
- JasonSage 2y agoMullvad
- flarzzarp 2y agomullvad.net usually gets really high praise. I am not a user, but if i was looking for a vpn service, that's what I would personally get.
- puppycodes 2y agoMullvad is the best setup ive seen, with the most accessible interface, and recently audited. The ability to pay with cash in the mail and login with just a generated ID is great. All VPNs require trust however.
- pseudalopex 2y agoAnd in some countries you can buy a scratch card if you don't want to use cryptocurrency or risk sending cash in the mail.
- Arrowmaster 2y agoYou can even buy them from Amazon. The cards don't have any sort of exposed code to scan when it gets sold to activate it like other gift cards. Nothing on them makes one identifiable from another until you scratch it off.
- puppycodes 2y agoAlso many people forget its not just the VPN, its the combination of the VPN and your browser. There are many ways to unmask you even if the provider does everything right. They can't protect against attacks like dom battery monitoring, complex fingerprinting, UDP timing attacks, etc... read the Mullvad audit for more details. They cite the need to enable DAITA by default as a shortcoming. https://www.x41-dsec.de/static/reports/X41-Mullvad-Audit-Public-Report-2024-12-10.pdf https://www.x41-dsec.de/static/reports/X41-Mullvad-Audit-Pub...
- _lvbh 2y agoSuch protocols have been used in China for a long time: v2ray, trojan, xray-core reality, etc My hope is that we never have to use them in the west
- ranger_danger 2y agoI already have to because many places I frequent (hotels, airports/planes, random shops) block not only UDP (so no Wireguard), but also OpenVPN explicitly.
- VTimofeenko 2y agoIs there any technical description of this protocol somewhere? Nord blog[1] (I presume, the original source) is not too heavy on details either. Granted, the company may not want to release _all_ details but quick skim of the TFA reads like it's some form of pixie dust that will bring us to the promised land. [1]: https://nordvpn.com/blog/nordwhisper-protocol/ https://nordvpn.com/blog/nordwhisper-protocol/
- tupolef 2y agoI forgot the name but 10 years ago there was a popular free vpn extension for browsers that let each user exit by the other users ip and you could choose the location with a click. But behind that free service, the model was to provide an expensive service to companies needing high frequency testing or scraping (sometime illegal) with multiple ips and locations. I got a trial for 1 week after a visio with them, it was complicated to setup, but it felt like exploiting unknowing free users.
- edavid3001 2y agoThe vpn NordVPN is backed by USA to return decryption and then decryption for the USA to turn around and send results. All PCs have SSL Decryption available via the US Government... Thus, they have all results which they can decrypt. My PC has Bitdefender that does the same thing. Install their software and view encryption. You will see the encryption is deencryption/middle man/reencryption. Long story short, NordVPC is the USA monitoring individual suspect connections. It doesn't grab your real IP, but it does more times than is doesn't. https://www.dropbox.com/scl/fi/ika4tc7yr0h6kikkdqc5y/Screenshot-2025-01-30-at-9.05.28-AM.png?rlkey=hmy4eda8sbkjn0k765cdptd42&st=fhlhpb3f&dl=0 https://www.dropbox.com/scl/fi/ika4tc7yr0h6kikkdqc5y/Screens... http://acmenews.com/imgtest/scan32.html http://acmenews.com/imgtest/scan32.html