3 ms·
I'll be sticking with iPredator, and here's why: I don't care what my VPN client looks like -- I care about how secure it is. I have immense trust for Peter Sun
by thejerz 13y ago
I'll be sticking with iPredator, and here's why: I don't care what my VPN client looks like -- I care about how secure it is. I have immense trust for Peter Sunde & Friends. They are not in this business to Get Rich Quick™. They are in it for deeply held moral, social reasons; reasons, so deeply held, they have put their own personal safety and freedom at risk. I feel very safe knowing they will NEVER comply with NSA, Interpol, etc., and that they are always one step ahead of BigBrother. I'm sure the Tunnel Bear people are cool and all, but no one can touch the Pirate Bay team. End of conversation.
- intslack 13y agoDespite their best intentions, cooperation on part of the service provider might not be needed: https://www.schneier.com/blog/archives/2014/03/how_the_nsa_exp.html https://www.schneier.com/blog/archives/2014/03/how_the_nsa_e... http://www.theguardian.com/world/interactive/2013/jul/31/nsa-xkeyscore-program-full-presentation http://www.theguardian.com/world/interactive/2013/jul/31/nsa... (page 17)
- svintus 13y agoHi, I'm Ivan Sergeyenko, also known as iBear. I am one of the engineers on the TunnelBear team. We all hold deep respect for Peter Sunde and his team. iPredator is definitely one of the most trustworthy VPN services out there. Our goal, however, is different. We aim to bring VPN/privacy protection to people who have never heard of VPN (notice that we don't have "VPN" anywhere on our site, except for in a quote from TNW and in the help section). Despite there being 100's (if not 1000's) of VPN services out there, very few of them, sadly, care about the non-tech-savvy audience.
- deleted 13y ago[deleted]
- ris 13y ago"We aim to bring VPN/privacy protection to people who have never heard of VPN" Will such people understand the subtle ways in which using a VPN will make your communications less secure, though?
- DonGateley 13y agoHow about giving us a clue rather than just being cryptic.
- patcon 13y agoHey svintus, I think your friend Gita was just telling me about you a few weeks ago :) Do you quit your job to work on tunnelbear, huh? People like you belong on my hero-bookcase I'm trying to avoid proprietary OS's now -- I don't suppose I could get into the linux beta you mention here: http://help.tunnelbear.com/customer/portal/articles/824779-is-there-a-tunnelbear-application-for-linux- http://help.tunnelbear.com/customer/portal/articles/824779-i...
- DonGateley 13y agoHey, Ivan, have you folks fixed the security hole yet where your tunnel can potentially drop and the connection simply reverts to clear without the user knowing it? Have you yet included a function similar to VPNCheck which blocks traffic in that event? Unfortunately, because TunnleBear uses it's own client rather than the standard Windows VPN mechanism VPNCheck can't be used with it. While I love your company and the generous touch of humor and whimsy you bring to a normally somber market, I can't live with a product with that gaping a security hole. If and when that's fixed and if the performance is about an order of magnitude better than it was when I tested it a year or so ago I'll be on board in a heartbeat.
- fiatmoney 13y agoiPredator is indeed awesome, and surprisingly cheap for the value it provides as well.
- grugq 13y agoUnfortunately, it doesn't matter what beliefs the owners of a Swedish VPN have. The FRA law [0] means that any data which goes over Swedish links will be logged. One can only assume that the iPredator service is heavily monitored by the IC, just on principle. If you are concerned about your privacy and want to use a VPN, then I would recommend using cryptostorm [1]. Firstly because it is run by people passionate about privacy, who have devoted considerable time and effort into creating a service that is both "safe" and fast. Secondly because those efforts have been directed at solving the right problems: unlinking, best practices crypto, and fast links. The primary strength of cryptostorm is their decoupling of the VPN service provider and account management. You don't buy VPN service, you buy a token that is redeemable for VPN service. Their banking is handled by a First Nation's bank (so effectively a country), and the financial transaction is between you and a 3rd party (not cryptostorm the VPN service provider). So while some companies claim "we don't log account access", cryptostorm literally has nothing that they can log. They do not have access to any personal information at all. It is all handled by other people. Even if cryptostorm was compromised, or they lie about not logging, or they are forced to log due to court order - they are unable to provide any personal information. So they solved the important problem: you are anonymous to your VPN service provider. Their openvpn config is heavily tweaked to ensure that it uses only the most robust crypto (no RC4, thank you very much). Of course, a VPN isn't really much use against a nation state level actor, but at least it can provide protection against local miscreants on an open wifi. (Full disclosure: I've spoken with the cryptostorm guys about privacy and security, I respect their skills and knowledge. I might be biased for that reason [I also know anakata, teimo and peter sunde, and no disrespect to them but the cryptostorm guys did it correctly]) [0]: http://en.wikipedia.org/wiki/FRA_law http://en.wikipedia.org/wiki/FRA_law [1]: http://cryptostorm.is http://cryptostorm.is
- schabernakk 13y ago2 questions: 1) cryptostorm would still have the ip the isp assigned a user. mapping this ip to a real name is trivial. right? 2) The cryptostorm team decided to remain 'pseudoanonymous' at this point. The points they outline (privacy activists get constantly hassled and threatened) make sense but don't help me verify the integrity of the service. You saying that you spoke to them and that they are trustful doesn't do much either. Why should i trust them? I know in the end i should trust no one, but your argument boils down to cryptostorm being outside of FRA jurisdiction? You could argue that iPredator is not a real crypto/security vpn service in the first place. I think they are using 128bit encryption which can be cracked if enough effort is put into it. They are just making it more difficult, eliminating 'drive by snooping'. Lastly: no offense, but that website is not very trust-inducing. i know it shouldnt matter but still....