VPNs

  • Want to keep track of this thread?
    Accounts can bookmark posts, watch threads for updates, and jump back to where you stopped reading.
    Create account
Maybe, maybe not. I use pretty much all of these but some of these are outdated. Some notes:

1) Hysteria 2 and all UDP/QUIC (TUIC) based protocols are now blockable because SNI is not encrypted in the original iteration. Downgrade attack exists unless you force the new version (purposely blocked in China). Read this paper for details. UDP is blocked in the classic port range, use port range higher than the regular boundaries.
Linux hosts typically use an ephemeral port range of 32768 to 60999, while macOS and Windows Vista or later use the range 49152 to 65535.

2) Trojan hasn't been updated in a while. Rumor was dev got vanned by the MSS.

3) Mirror a site on Naiveproxy server to look more legit. Set TLS to 1.3 and prevent 1.2 downgrade attack to decrypt SNI

4) Encrypt DNS with DNSCRYPT and DOH (DNS over HTTPS) or DOT (DNS over TLS). If using DOH on firefox change server from cloudcuck. DOT can be blocked by ISPs.

5) Split-DNS (not available on windows I think) and Split-tunnel your apps so your traffic looks normal

6) Change from default ports if possible.

7) Spoof useragent and timezone. Some isps block UA by forcing javascript. Run something in a VM instead.
 
(L | A)
In 2023, Israeli and Unit 8200 Affiliated Teddy Sagi purchased Kape Technologies for $1.58 billion in cash.

"Being from Israel, Teddy Sagi had connections with the Israeli military intelligence sphere and was able to procure himself a real-life cyber spy [his co-founder] from the famed Unit 8200 (kinda like Israel’s version of the NSA)" https://windscribe.com/blog/what-is-kape-technologies/

Kape directly or indirectly owns: Kape VPNs, Express VPN, Cyberghost, Private Internet Access, Zenmate, Private VPN, and GooseVPN
who-owns-kape.png
(full map, direct link)

Kape VPN companies also have paid relationships or paid affiliates with may other VPN and content companies. Kape also owns the VPN recommendation site vpnMentor.
 
Has anyone tried MEGA's VPN? What do you think about it?

I use MEGA frequently, mainly to share files between my devices and to host a huge catalog of mods from an old, now-defunct forum, so the idea of getting both services with a single subscription seems tempting.
 
Is there a way to turn off auto renewal billing in ProtonVPN? I literally can't find the setting anywhere.
 
Is there any functional difference between a VPN that runs as a browser extension vs a desktop app? Assuming the only traffic I care about hiding is in the browser.
 
Is there any functional difference between a VPN that runs as a browser extension vs a desktop app? Assuming the only traffic I care about hiding is in the browser.
If you only care about hiding what's in your browser, then a browser extension is fine. Though, I'd use the desktop app if you're using Windows.
 
We've been PIA customers for years, but the experience is abysmal when trying to use streaming/banking sites. Are there any VPNs that play nicely with those, particularly with YouTube? I've looked at Mullvad but the need to register/unregister devices seems like it would be a pain.
 
We've been PIA customers for years, but the experience is abysmal when trying to use streaming/banking sites. Are there any VPNs that play nicely with those, particularly with YouTube? I've looked at Mullvad but the need to register/unregister devices seems like it would be a pain.
Maybe banks know what Israeli-owned companies are capable of and prefer to downgrade service from such sites to discourage their use for critically confidential information. I would avoid them (and CyberGhost and ExpressVPN).
 
Maybe banks know what Israeli-owned companies are capable of and prefer to downgrade service from such sites to discourage their use for critically confidential information. I would avoid them (and CyberGhost and ExpressVPN).
What provider(s) would you suggest instead? We do not plan to renew our PIA subscription if we find something better.
 
We've been PIA customers for years, but the experience is abysmal when trying to use streaming/banking sites. Are there any VPNs that play nicely with those, particularly with YouTube? I've looked at Mullvad but the need to register/unregister devices seems like it would be a pain.
Proton or Windscribe.

Both are streaming friendly. I haven't had issues with banking on either but I think that is more dependent on your bank. I would reach out to support for both and research online regarding your bank.
 
I've looked at Mullvad but the need to register/unregister devices seems like it would be a pain.
Its not really a pain, all you have to do is copy/paste a code they give you - it basically acts as your account credentials. Not sure what this 'registering' is about?

Been using Mullvad for a few years now and have no complaints except P2P kinda sucks. But I don't use it that often and can't be fucked finding an alternative. I love that I don't have to use my credit card to buy time, and I'm not a crypto fag either, so I buy those little gift cards which makes me nostalgic for when you'd have to buy software licenses that way.
 
Tom's Hardware: Dutch authorities allegedly seize VPN server without a warrant — company claims that law enforcement will return it after analyzing the device fully (archive)
Canada-based Windscribe, a VPN provider, just said that one of its European servers has been allegedly seized by Dutch authorities without a warrant. According to the company’s post on X, law enforcement said that they will return it to the service provider after they “fully analyze it.” It’s unclear why law enforcement impounded just a single rack from Windscribe’s cabinet, but the VPN provider said that it only uses RAM disk servers, meaning anyone who would look through the installed SSDs would only find a stock Ubuntu install on it, so the servers shouldn't hold any trackable data.
RAM cannot retain data after it loses power, which is why security-conscious companies use it over traditional SSDs and hard drives. But other X users were quick to point out that “it is standard practice to keep a seized server powered on or otherwise technically accessible until investigators can perform a live memory (RAM) capture in a forensic lab.”
https://x.com/windscribecom/status/2019529769008685438 (archive) (nitter)
https://x.com/windscribecom/status/2019538939728515381 (archive) (nitter)
 
Last edited:
Ten bucks says they did nothing to keep the server powered when they seized it.
The smartasses snarking about that on twitter are fucking idiots. Do they have any idea how much of a fucking pain in the ass it would be to keep a racked server powered on to preserve its state while getting it otherwise disconnected and removed from a rack and then physically transported somewhere for cryogenic RAM forensics?

I mean, they're fucking kidding, right?
 
The smartasses snarking about that on twitter are fucking idiots. Do they have any idea how much of a fucking pain in the ass it would be to keep a racked server powered on to preserve its state while getting it otherwise disconnected and removed from a rack and then physically transported somewhere for cryogenic RAM forensics?

I mean, they're fucking kidding, right?
Nowadays there are a lot more off the shelf options for that kind of thing because of solar power's advancements. There are power banks that support main's power output for quite a decent capacity. It's still not trivial and I guess dependent on it having dual power supplies configured in the first place (I'm not sure how you would do a switcheroo mid boot if it only had one PSU)
 
Is anyone surprised?

Last year they outright seized and looted a Chinese chipmaker (Nexperia). The politically brainrotten niggercattle were all cheering this classic Dutch move on. Now that they've gotten away with it, they'll be going further. First it's gonna be national interests, now it's to protect kids or something. The drones are gonna eat all of this up and then wonder why nobody's there when their government seizes and loots their house for naughty posts on social media.
 
Back
Top Bottom