12 ms·
Who Owns, Operates, and Develops Your VPN Matters
- farceSpherule 1y agoYou get what you pay for...
- leakycap 1y agoI don't think a high price in the VPN market is a reliable indicator of "getting something better" VPN companies often overpackage their offerings and overcharge -- this truism doesn't apply when shopping for VPNs.
- Terr_ 1y agoI'd like to point out that a regime may find it worthwhile to compromise more kinds/sizes of VPNs than we might expect. The evil regime doesn't need to have a popular evil VPN that everybody uses... it may be enough to operate (or hack) a smaller VPN which can unmask enough dissidents that their friend-groups can be found by other means.
- 01HNNWZ0MV43FF 1y agoThat threat model for Signal worries me. If I was the US government, I'd push Google Play to offer compromised updates of Signal silently to a few people I was interested in. Even among the highly-technical, who is going to be inspecting binaries installed on a phone regularly? Does Signal even have reproducible builds? How do I know the code matches the binary? I'd make my own messenger.... but I don't have the money for that at all. I wish these risks could be split up and handled separately - Suppose I run a private dark network for me and my friends, and then the GUI for chatting over it runs in a sandbox where it can only message servers that I control, using public/private keys that I control. Conflating a million lines of Java GUI code with "Noise is a simple and secure protocol" seems like a big attack surface.
- leakycap 1y agoWith online development responsibilities, I don't find VPNs to be compatible with what I do all day. That said, the few implementations I have test before seemed leaky and not as useful as they claim.
- onetokeoverthe 1y ago[dead]
- fujigawa 1y agoCommercial VPNs will go down as one of the greatest money-making schemes of the last decade. Outside of a few specific use cases their sales often rely on leveraging non-technical users' fear of what they don't fully understand. I have non-technical friends and relatives that have fully bought into this and when I asked why they use a VPN I got non-specific answers like "you need it for security", "to prevent identity theft", or my personal favorite: "to protect my bank accounts". Not a single person has said "I pay to route my traffic through an unknown intermediary to obscure its origin" or "I installed new root certificates to increase my security."
- tomrod 1y agoCommercial VPNs do indeed vaguely promise to protect your data, access, etc. For those of us that are technical but unschooled, what resources would you recommend we learn from?
- busterarm 1y agoYou can operate your own VPN (algovpn, openvpn, etc). There's low utility to doing so, but it's fairly straightforward these days. Or run Tailscale (and a self-hosted DERP relay).
- martin_a 1y agoI did this for a while in combination with a PiHole setup on a small vultr.com package. Utility in that was that the traffic of all devices was routed through a "PiHoled VPN", so very little advertisements came through...
- giobox 1y agoA cheap VPS instance + DNS with adblock + self hosted VPN used to be great until around ~5 years ago, when a great many websites (especially streaming sites) just started blocking any IP range associated with a VPS provider. I've given up using VPSes as VPN exit nodes now.
- 1y ago
- CGMthrowaway 1y agoWhat is this list that doesnt include NordVPN and ExpressVPN?
- arewethereyeta 1y agoA list made by NordVPN or ExpressVPN
- akaksbsb 1y ago> ExpressVPN You mean the one owned by an Israeli billionaire? Hopefully they don’t find a way to make your monitor remotely explode.
- NoGravitas 1y agoIt's worse than that. The company bought by said billionaire, and which in turn bought ExpressVPN, was founded by a member of Unit 8200 (Israel's NSA), and started out making browser advertising malware. https://hackread.com/private-internet-access-pia-vpn-sold-israel-privacy-concerns/ https://hackread.com/private-internet-access-pia-vpn-sold-is...
- can16358p 1y agoI'd love to know how many people use VPNs because of "fear of being hacked" (hack covering everything non tech-savvy here). Almost everyone I know use VPNs only to bypass restrictions, not for fear or privacy.
- tetris11 1y agoMullvadVPN seem to be pretty decent at the moment, but it looks like they're laying down a worldwide VPN infrastructure of sorts that other VPN companies can rent (similar to phone networks) This makes me feel a little uneasy of their unstated longterm goals (corner the entire market), but I do think they are the most trustworthy out there right now
- timpera 1y agoI think Mullvad's market share is still pretty low compared to NordVPN, which actually cornered the market thanks to their suspiciously large advertising budget.
- pydry 1y agoOf the two im more suspicious that NordVPN is a CIA honeypot in the style of Crypto AG.
- giobox 1y agoI also think this is the scandal waiting to emerge in this space; with what we know from Snowden/CryptoAG/Encrypted message app sting operations etc it is borderline impossible for me to believe not one of the major players is owned by a State level intelligence service.
- anon191928 1y agothey probably learned from past and this time it will not be publicly known. so that's another option
- qingcharles 1y agoThat and all those Tor nodes too.
- NoGravitas 1y agoKape Technologies, an Israeli firm with ties to Israeli intelligence, owns several well-known VPN companies, including PIA, ExpressVPN, and Cyberghost. https://hackread.com/private-internet-access-pia-vpn-sold-israel-privacy-concerns/ https://hackread.com/private-internet-access-pia-vpn-sold-is...
- John23832 1y agoI use tailscale with an exit node. I just need location control. Wireguard gives me that.
- _zoltan_ 1y agoWireguard doesn't give you exit nodes, it's just the encrypted L3 stack. Whomever is responsible for your exit nodes actually gives you this functionality. If it's tailscale itself then they use mullvad nodes as exit nodes which I welcome very much.
- John23832 1y ago> Wireguard doesn't give you exit nodes, it's just the encrypted L3 stack. That's why I said tailscale lol. But I understand, I guess I said it in a confusing manner. > If it's tailscale itself then they use mullvad nodes as exit nodes which I welcome very much. You can also set on of your devices as an exit node for your Tailscale network. Kind of cool.
- _zoltan_ 1y agoI do this but this means two things: * I am tied to paying the exit node so my identity is known to the provider * I am responsible for the upkeep of said node
- ivape 1y agoVPNs don’t really stop fingerprinting techniques, if anyone is using it for that.
- tashian 1y agoThe notion of "zero trust" shouldn't just mean corporations not having to inherently trust users and networks. It should also mean users not having to inherently trust corporations. VPN providers all run the same two or three VPN protocols, all with similar security guarantees and privacy limitations. I've been playing with MASQUE relays over the last year. Apple's iCloud Private Relay is a MASQUE relay (two, actually). MASQUE can offer genuine privacy improvements via traffic separation, preventing any single party from correlating the traffic source and destination. Some of the privacy concerns of VPN users can be mitigated with better technology. And relays are built into Apple operating systems today. I'm surprised that they aren't very widely deployed yet.
- chneu 1y agoI have no idea why people, especially in the United States, trust companies so much. I bump elbows with a lot of different crowds(rural, urban, conservative, liberal, etc) so I have a pretty decent sample size and without fail most people trust companies waaaay too much. Then they're shocked when a company lets them down because the company could make more money. Stop trusting companies. They only care about 3 month profits.
- rsynnott 1y ago> Yolo Technology Limited I mean, this seems like the company name equivalent of the yellow and black stripes on a wasp. It is a _warning_.
- username135 1y agoIve been a proton supporter since email. I like theor product suite. I use a vpn for all the reasons listed here, but mostly for obfuscating my traffic (and torrenting).
- OutOfHere 1y agoTheir email UI is extremely clunky and unrefined, both on the desktop and on the app. When I delete a message in the app, it just stays there in the folder. When I empty spam in the desktop, its count doesn't update. It's like they don't use their own product. Also, relying on its VPN for illegal activities is incredibly foolish since they log your IP and probably have your payment info.
- mlhpdx 1y agoI’ve been keen to point out there is more utility in the technology underlying VPNs than the VPN functionality itself. The WireGuard handshake and transport encryption are lightweight and secure and I added support for it to my service as an option to secure data in flight. It’s getting used by developers and enterprises, not consumers. IPSec perhaps less so since it is more complicated and open to insecure configurations (transport mode).
- arewethereyeta 1y agoThat's why we sell only the service [1] and point our users to the default app install (Wireguard in our case). Ever since Holla VPN and the entire Brightdata/Luminati clusterf~ VPNs are a risky business for users. Most of them are proxy nodes underneath, they rent you datacenter IPs while they sell your residential internet to third parties. [1] https://www.anonymous-proxies.net/products/ https://www.anonymous-proxies.net/products/
- timpera 1y agoDo you have a source that shows that popular VPN providers such as Mullvad or NordVPN actually sell your residential internet to third parties? That's a bold claim, but pretty scary if true.
- arewethereyeta 1y agoyes, search for NordVPN vs Luminatti (guys behind Holla VPN) scandal: "nordvpn luminati lawsuit patent". Basically Luminatti, now known as bright data, reached out to NordVPN in order to utilise their user's internet as residential proxy nodes. NordVPN thought otherwise and created their own network instead (Oxylabs if I'm not mistaken). They are still in patent wars I believe. I don't know anything bad about Mullvad! That being said I, as a small business owner in this space, will not use any of them, ever. I know it sounds like a "yeah right" because I sell the services but I know better.
- kelnos 1y ago> I don't know anything bad about Mullvad! Is it even possible for them to do something like this for people who just use the OpenVPN/Wireguard configs and don't install an app?
- yjftsjthsd-h 1y ago> That being said I, as a small business owner in this space, will not use any of them, ever. I know it sounds like a "yeah right" because I sell the services but I know better. If you weren't you, would you trust your service?
- try_the_bass 1y agoMy pet theory for a while now has been that all of the biggest VPNs are secretly run by the NSA or other equivalent nation-state organizations.
- arewethereyeta 1y agoOr worse, as the article points out,
- vincnetas 1y agoHow realistic is possibility that some VPN providers use clients (computers of person who installed VPN) to just be able to crawl (or rent crawl infra) sites and make it look like regular residential traffic? (This is speculation i heard somewhere) Like reverse VPN :) on one side makes client look like he's accessing internet from VPN exit location, and on the other end allowing for money someone to pretend that he's a residential client.
- kube-system 1y agoThere are a number of "free" VPN providers that have been documented to do this, if you search you should find some articles about it.
- nostrademons 1y agoThis isn’t VPN providers per se - most want to be able to control their own exit nodes. There are however a fair number of commercial proxies that do exactly that, sometimes via consumer malware. I know several startup founders who have used them as a way to scrape lots of data and not get banned. Usually the interface they provide to the customer is just a normal SaaS “pay us money and give us a list of URLs and we will give you the page content”, and the interface they provide to the end user is a game or marginally useful utility, and nobody but the company realizes they’re doing something dodgy.
- stordoff 1y agoThere are various services that do this, e.g. BrightData: > Bright Data is the World’s Largest Residential Proxy IP Network providing companies the ability to emulate a real user in any country, city or carrier (ASN) in the world. [...] Bright Data has an SDK (software development kit) that is implemented into applications. Bright SDK provides an attractive alternative to advertisements by providing the app user with the choice to opt-in to Bright Data’s network instead. For every user that opts-in to the Bright Data network, Bright Data pays a monthly fee to the application vendor, who passes that value on to the user by not displaying ads. I haven't heard of any of the VPN providers doing this, but it wouldn't really surprise me.
- immibis 1y ago
- toofy 1y agoi’m not sure what this list is, why investigate vpn companies yet dont even look at nordvpn, pia, express, or others that are wildly popular yet still shady af with their real world origins? i mean, those companies are so popular they’re almost normie household names. the couple i looked at from the papers list have a small fraction of downloads compared to the above. i agree that we absolutely need a deeper dive and a lot more transparency on who owns these companies but i’m curious why they chose to avoid the elephants in the room.
- aborsy 1y agoDo people here trust their ISPs more than their VPN providers? That’s the question! On the other hand, as far as privacy from the end point is concerned, users can be identified regardless of IP addresses. Visit fingerprint.com, you will get an identifier, then connect to a privacy VPN and change servers once in a while. The website will identify you, tell you are the same user visited last week from such location, and the number of times you visited. Browsers (except Tor) send so much data that accurate identification is possible without IP address. And services could refuse to work if users don’t provide the required information, although that info could be randomized.
- adiabatichottub 1y agoI'm more worried about all the sites that require my phone number under the auspices of two-factor authentication. It's probably the most trackable bit of personally-identifying information these days.
- thisislife2 1y agoI do trust my ISP more than any foreign VPN service providers because I have the option to take my ISP to court if they violate my rights. I stopped caring about anonymity on political subjects when I realised not being anonymous made me more civil online, and more mindful of what I want to talk about. (Ofcourse, I can think like this because I have the privilege of living a democracy).
- immibis 1y agoIf you lived in a place like Germany or the UK, you could get arrested for posting online that you don't like what Israel is doing in Gaza or that you think Elon Musk is a Nazi (among other things you could get arrested for saying). In this case, routing your traffic through an unknown intermediary makes sense. You said you have to be mindful of what you say and how you say it, in order to comply with the law. In other words, your legitimate speech is being chilled. Why do you think that's okay?
- thisislife2 1y ago
- idiotsecant 1y agoI don't use a VPN for anything that would get me in the cross hairs of a nation-state. I use it to trade crypto outside my jurisdiction, make sure my ISP doesn't get torrenting complaints, obscure my traffic from wifi networks I don't trust, that sort of thing. None of these things have enough money or power behind them that peeling away the VPN is worth it, so it's good enough.
- rasengan 1y agoShameless plug: VP.NET [1] runs in a trusted execution environment (enclave) so you can verify it is doing what it is supposed to do and not anything else! [1] https://vp.net/l/en-US/blog/Don%27t-Trust-Verify https://vp.net/l/en-US/blog/Don%27t-Trust-Verify
- immibis 1y agoShameless antiplug: It's owned by the guy who destroyed freenode and the other guy who stole $2.4 trillion in bitcoins a decade ago. I'm serious.
- ranger_danger 1y agono you can't... you can verify what something is doing, but there's no guarantee it's the same code routing your VPN requests, or that nothing else on the network/server is listening/forwarding your traffic elsewhere.
- rasengan 1y agoYou can since the enclave attests to what is running! This is also coupled with the crypto and NAT occuring in-enclave with various timing/obfuscations. It's verifiably private.
- farceSpherule 1y agoVPN Comparison Table https://docs.google.com/spreadsheets/d/1ijfqfLrJWLUVBfJZ_YalVpstWsjw-JGzkvMd6u2jqEk/edit?gid=231869418#gid=231869418 https://docs.google.com/spreadsheets/d/1ijfqfLrJWLUVBfJZ_Yal...
- preaching5271 1y ago95% of VPN companies are owned by Mossad
- bhouston 1y agoAre you referring to the cluster of VPNs owned by Israeli tech magnate Teddy Sagi? CyberGhost, Private Internet Access (PIA), ZenMate, ExpressVPN, and Intego
- dongcarl 1y agoI'm surprised no one has mentioned iCloud Relay-style Multi-Party Relays yet: https://www.privacyguides.org/articles/2024/11/17/where-are-all-the-mprs/#the-alternative-tor https://www.privacyguides.org/articles/2024/11/17/where-are-... It greatly improves on the existing VPN trust model by separating the "who" (connecting IP, potential payment info, etc.), from the "what" (IP traffic). You no longer have a trust a single entity not being malicious or compromised. Disclaimer: I run obscura.net, which does exactly this with Mullvad (our partner) as the Exit Hop.
- jihadjihad 1y agoI've been happy with AirVPN, curious to hear how others feel about them. Pretty reliable and seems good enough for my purposes, at least.
- nullc 1y agoI don't know why anyone wouldn't assume that any VPN service is run by an intelligence service, potentially one hostile to you, or organized crime. Consider-- people bring their traffic to you to monitor, and particularly people who are trying to conceal their identity or activities. They pay you for this, which means that if you get collateral benefit you can run at a small loss and undercut any legitimate players (if there are any!) or run levels of advertising that a legitimate business couldn't sustain. -- while its simultaneously one of the most cost effective surveillance plays you could imagine, since it's still primarily funded by the victims. VPN services also have good deniability for their surveillance. Although (maybe!) your ISP can't surveil the VPNed traffic the VPN provider's ISP can as well as your counterparties ISP (and any other parties brought into the mix by things like third party content). And like any other electronic surveillance, parallel construction can be highly effective. They can also be stood up by anyone, you can run any number of services. They don't require extremely extensive physical infrastructure, investment, large numbers of employees like running an ISP. You can even target particular actors or populations by using targeted advertising, though it's still most effective as a data hoovering operation. Particularly for the intelligence actors they also have the benefit that issues like getting harassed by the state are among the complications of this business, but that is potentially less of an issue if you are the state. And if there were an actually honest provider, they'd be a prime target for infiltration... all that interesting traffic in one place.
- 1vuio0pswjnm7 1y agoInteresting how the comments heading this thread ignore the effect of VPNs on surveillance and data collection for the benefit of online advertising, i.e., the stuff that so-called "tech" companies rely on as a "business model" Must be that these so-called "tech" companies have no problem figuring out who is the ad target behind each VPN IP address, fingerprinting them and tracking their online behaviour acrosss every computer they use TIL VPNs actually have _no impact_ on the data collection and ad services "business model"
- iszomer 1y agoThis goes back to that old meme from before: "There is no cloud, it's just someone else's computer."
- mikewarot 1y agoI've always assumed that commercial VPN service providers were intelligence agency fronts. One only has to look back on the CIA's Swiss front company[1] selling encryption equipment for decades[2] to our supposed allies to become sufficiently cynical. I assume similar Wikipedia entries will appear in the future about some, if not most of today's VPN providers. [1] https://en.wikipedia.org/wiki/Crypto_AG https://en.wikipedia.org/wiki/Crypto_AG [2] https://en.wikipedia.org/wiki/Operation_Rubicon https://en.wikipedia.org/wiki/Operation_Rubicon
- deleted 1y ago[deleted]
- 1vuio0pswjnm7 1y agohttps://web.archive.org/web/20250904091545if_/https://www.opentech.fund/news/who-owns-operates-and-develops-your-vpn-matters-an-analysis-of-transparency-vs-anonymity-in-the-vpn-ecosystem-and-implications-for-users/ https://web.archive.org/web/20250904091545if_/https://www.op...
- pbronez 1y agoFinal results from the table on page 50: Operates more transparently. No concerning findings identified. • Mullvad (Mullvad) • TunnelBear (TunnelBear) • Lantern (Lantern) • Psiphon (Psiphon) • ProtonVPN (Proton VPN) Operates more anonymously. Potentially concerning, but no definitive findings. • HotVPN (HotVPN) • LetsVPN (LetsVPN) • Astrill VPN (Astrill VPN) • CookieDevs (Cookie, Ciao Proxy Pro) • VPN Super Inc (VPN - Super Unlimited Proxy) • PureVPN (PureVPN) • Potato VPN (Potato VPN) Concerning and suspicious findings (users should avoid). • Innovative Connecting (Turbo VPN - Secure VPN Proxy, Turbo VPN Lite - VPN Proxy, VPN Monster - Secure VPN Proxy) • Autumn Breeze (SnapVPN, Signal Secure VPN - Robot VPN) • Lemon Clove (SuperNet VPN, VPN Proxy Master Pro, VPN Proxy Master Lite) • Matrix Mobile (Global VPN) • ForeRaya Technologies (Melon VPN) • Hong Kong Silence Technology (Super Z VPN) • Yolo Mobile Technology (Touch VPN - Stable & Secure, VPN ProMaster - Secure your net) • Wild Tech (3X VPN - Smooth Browsing, VPN Inf, Melon VPN - Secure Proxy VPN)