Hacker News new | ask | show | jobs
by kevinr 3230 days ago
lololol. Half of these VPN vendors show up on Kenn White's VPN Hall of Shame for offering unsafe configurations:

https://gist.github.com/kennwhite/1f3bc4d889b02b35d8aa

For anything actually sensitive, you're better off not using a VPN than using a VPN which provides an unsafe configuration.

If you'd rather not do your own pager duty for something like Algo, here's a recommendation I put together a while ago:

https://free-dissociation.com/blog/posts/2017/03/quick-and-d...

3 comments

Regarding the blog post you shared [0]

> In general, US persons today on residential broadband are safest not using a VPN.

> Only connect to US-based VPN servers while in the US. Even if your VPN provider offers servers outside the US.

What? No reasons given. Smells like FUD.

[0] https://free-dissociation.com/blog/posts/2017/03/quick-and-d...

In the two comments at the bottom, someone asked about both those points, and got detailed answers.
>lololol. Half of these VPN vendors show up on Kenn White's VPN Hall of Shame for offering unsafe configurations:

having a per-user PSK isn't going to protect you if the protocol is fundamentally broken, which is the case for PPTP/l2tp

That's why Kenn only recommends using services with per-user PSK for geo-shifting video streams.

For all other uses, Kenn recommends Algo, and I recommend Cloak, neither of which uses PPTP/l2tp.

I wish that people would stop citing White's page without explanation. His stuff about using known secret keys is all about IPsec. People using VPN services mostly use OpenVPN.
When I'm providing security advice to a general audience, I can't expect people to reliably follow detailed instructions. "Oh, use VyperVPN, except you have to use OpenVPN, except on iOS where you're forced to use IPsec, and <detailed description of crypto settings follows>."

I can tell them one thing: use Cloak. And I know that, no matter how they do so, they won't be less safe than they would have been without it.

For more on this, see my followup to the VPN post: https://free-dissociation.com/blog/posts/2017/04/public-heal...

Well, there's your problem, starting with "Oh, use VyperVPN". IVPN, for example, has leak-free apps for Windows, OS X and iOS. And are working on Android.