70 ms·
VPN Encryption
- awayand 13y agoor, you could just use https://airvpn.org/ https://airvpn.org/
- xxdesmus 13y agoYeah, that was helpful.
- cowboy_coder 13y agoI hear airvpn is awesome. They have many different options to encrypt your connections.
- beernutz 13y agoThough they do NOT allow multiple simultaneous connections, and are not as inexpensive.
- coderrr 13y agoFYI, this is the info page for our new (beta) OpenVPN based client which supports multiple encryption options: https://www.privateinternetaccess.com/forum/index.php?p=/discussion/1724/encryption-now-it039s-in-your-control-beta https://www.privateinternetaccess.com/forum/index.php?p=/dis...
- jevinskie 13y agoI love PIA but I was too afraid to use it at Black Hat / DEFCON this year. If you use L2TP (required for iOS, handy for OS X because there is a native client) there is no certificate to prevent a MITM. Is there any way to address this? Can you use a certificate instead of a pre-shared key?
- pilif 13y agonitpick: There is a native OpenVPN client for iOS in the AppStore. I don't know how they managed to, but it's plugging into the native iOS VPN functionality and it works perfectly well.
- chriscareycode 13y agoTo my knowledge, there are 7 companies including OpenVPN who have been granted access to private VPN APIs. I personally use the OpenVPN iOS client for "always-on" phone VPN.
- jevinskie 13y agoI see now. I didn't know there was a private API for App Store VPN clients. Cool, I will have to switch to using OpenVPN.
- coderrr 13y agoHere is a way some of our customers are using OpenVPN on iOS: https://www.privateinternetaccess.com/forum/index.php?p=/discussion/951/openvpn-on-ios#Item_17 https://www.privateinternetaccess.com/forum/index.php?p=/dis...
- r0h1n 13y agoInteresting to note that you've hosted your beta clients on Kim Dotcom's Mega service. This is the first time I'm coming across a legit & popular service hosting its public client files on Mega.
- lmm 13y agoI've bought some digital art from a freelancer and received it via there.
- r0h1n 13y agoI've been a happy PIA subscriber since the Snowden controversy. However every time I see them becoming more popular (at least 4 of my friends have signed up with them in the past few weeks) and earnestly trying to make themselves more secure, I also realize that someone, somewhere within the NSA (and yes, other intelligence agencies around the world) is elevating them on a list of VPNs to break.
- sixothree 13y agoDoesn't their business location in the US negate the need to be cracked?
- drdaeman 13y agoBased on their sites, I believe they're UK-based company (and US endpoints are just endpoints, in case someone wants to have US-located exit to access US-only services), so it makes somehow reasonably harder (but not impossible) to correlate between the client and their traffic. Still, I don't see any significant difference between NSA and GHCQ, except that we have (thanks to Snowden) some details of former's operations leaked, but the latter's remain secret (or I didn't pay enough attention to the news, maybe).
- IvyMike 13y agoWe're still talking about PIA? Definitely US-based. From https://www.privateinternetaccess.com/pages/contact-us https://www.privateinternetaccess.com/pages/contact-us "Q: Where are you located? A: We are located in the US. Being in the US is optimal for VPN Privacy services since the US is one of the few countries that does not have a mandatory data retention policy. Countries in the EU are forced to log, even though some claim they do not."
- floatboth 13y agoIPredator: "There are no traffic logs, we do not look into your traffic." http://www.wilderssecurity.com/showthread.php?t=331316 http://www.wilderssecurity.com/showthread.php?t=331316 – "Sweden - Data retention law going into effect in May 2012, but (presumably) not applicable to VPNs"
- canistr 13y agoIt should be noted that while they use curves generated by Certicom, Certicom is now a subsidiary of BlackBerry.
- drdaeman 13y agoI was a bit surprised OpenVPN still doesn't support GCM mode.
- HPLovecraft 13y agoa friend of a friend is a happy customer of PIA for over 9 months now. their customer service is actually really good.
- borski 13y agoWhile I've heard good things about PIA, you're still trusting someone else with your data. Whether you trust them or not is entirely up to you, but it's not that hard to set up your own VPN tunnel. We posted about it a few weeks ago here: https://www.tinfoilsecurity.com/blog/dont-get-pwned-on-public-wifi-use-your-own-vpn-tutorial-guide-how-to https://www.tinfoilsecurity.com/blog/dont-get-pwned-on-publi..., and there was some good HN discussion on it here: https://news.ycombinator.com/item?id=6285458 https://news.ycombinator.com/item?id=6285458
- drdaeman 13y agoYou still have to trust somebody to host your VPN endpoint. (Although, it's probably less risky to use some relatively obscure VPS/dedicated/colocation ISP than major VPN service which certainly attracts some attention of TLAs)
- borski 13y agoFair point, but your personal VPN is also a lot less likely to attract scrutiny and be attractive to snooping than PIA. It's just a much bigger surface area, more popular, and potentially has a lot more useful data than your single box.
- floatboth 13y agoAlso, public VPN services like PIA mix the traffic, i.e. multiple VPN users' traffic is coming from one IP address.
- ineedtosleep 13y ago> Whether you trust them or not is entirely up to you, but it's not that hard to set up your own VPN tunnel. While I agree that trust is a _giant_ issue, speed and price (due bandwidth needed/used) is also a major concern if you're one looking for an always-on VPN solution. I personally used PIA for a few months mostly due to cost and it is at or near my speed cap at all times. I have also rolled my own VPN using a VPS at the same price point, however, considering that bandwidth would be limited and speeds were not as stable, it's hard for me to choose that route for my use cases. Sure, if I need absolute security I wouldn't use PIA and I'd reconsider using a VPN on any VPS on US soil. But then, one would have to consider if it will be worth it.
- gr3yh47 13y agoI use this service, and have been thrilled with it for a long time. They do no logging whatsoever, and their encryption and endpoint options are great. they are also by far the cheapest truly secure option in this space - $40/year
- kzrdude 13y agoPretty bogus preset choices, what is this? If the provider isn't providing the expertise to ensure a safe connection for every customer, what the hell are they doing?
- duaneb 13y agoVPN providers would make great honeypots.
- oleganza 13y agoNote: ECC-521 is not a typo. It is really 521-bit curve. Standard: http://www.secg.org/collateral/sec2_final.pdf http://www.secg.org/collateral/sec2_final.pdf Explanation: http://crypto.stackexchange.com/questions/6219/why-do-the-elliptic-curves-recommended-by-nist-use-521-bits-rather-than-512 http://crypto.stackexchange.com/questions/6219/why-do-the-el...
- coderrr 13y ago@HNmods, any reason this was removed from the first page?
- Fourplealis 13y agoHow is this different from other commercials VPNs? If you really want privacy choose offshore VPN that doesn't keep logs.