Hacker News new | ask | show | jobs
by pipermerriam 2188 days ago
I use ProtonVPN. Same company as ProtonMail. Highly reputable with a business model around doing privacy and encryption well.
2 comments

NordVPN shares offices in Estonia with ProtonVPN. For that reason I find it sketchy.
I would like to read more about this, do you have a source?

I cannot find anything reliable that suggests this! Thanks.

This suggests the opposite of what you say in your original comment.
I was not the original person that replied to you. I was just providing with you with information on the incident they were referring to. Proton denied the claim but it is up to you whether you believe them or not.
You should also link the HN thread where proton categorically denies the claims.

In particular, the claim that tesonet controls protonvpn's release signing key.

https://news.ycombinator.com/item?id=17258203

>NordVPN shares offices in Estonia with ProtonVPN

What really? Some proof for that? ProtonVPN and ProtonMail is located in Switzerland Genève, i dont see any open positions for estonia

https://careers.protonmail.com/

I don't think NordVPN is sketchy, even with their latest hic-ups. They are however located in Panama as far as I know, which probably gives the US access for "drug trafficing".
Link. Please.
IMHO ProtonVPN (and Mail) are the perfect honeypots
ProtonVPN provides the source code for their desktop and mobile clients in their GitHub organization [1]. Yes open source != safe; however this level of transparency is at least a step in the right direction.

They also have regularly been audited by independent organizations that are openly available for the public to see their compliance [2][3][4][5][6].

Do you have any evidence to suggest that they are honeypots?

[1] https://github.com/ProtonVPN

[2] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...

[3] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...

[4] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...

[5] https://protonvpn.com/blog/wp-content/uploads/2020/01/Proton...

[6] https://protonvpn.com/blog/open-source/

And how do you know if what they built is exactly what's in that source?
You seem to not have read my comment. I said open source != safe or trusted.

You can download the entire repository, and self compile yourself after you inspect the code.

Hehe, exactly, oldest trick in the trade
I call that bullshit until you have a single proof for that.

Everything is opensource, the data s are located in Switzerland on there own hardware. They have open communication and a yearly transparency report:

https://protonmail.com/blog/transparency-report/

How/why?