Skip to content

Comment on Show HN: A small bootstrapped independent VPN company in the Netherlands

Comments

First, it looks good like you declare who you are. Many VPN providers seem to want to hide their real identities which is a big red flag.

I couldn't see from the website what your VPN is based on in terms of protocol? Or home brewed? OpenVPN?

Have you had 3rd party audits?

Have you considered alternative payment forms? Such as Bitcoin or other?

From your Terms of Service 'What we do not allow on or from our network...' how do you track these? Do you provide a transparency report summarising legal, copyright etc requests made, action taken?

Also from ToS 'What we need our customers to do: - Use responsible disclosure in the event any security vulnerabilities occur in our website, software or infrastructure.' Do you have a public disclosure policy notifying of vulnerabilities?

Choosing a VPN involves placing a lot of trust in a 3rd party. Hence questions.

First, it looks good like you declare who you are. Many VPN providers seem to want to hide their real identities which is a big red flag.

While I agree that, as a user, knowing who's behind a service, and in particular a VPN, can help build trust, there are several good reasons why you would want to remain anonymous when running a VPN or any privacy service like secure email and encryption tools. You will be targeted by multiple parties. The technical side of this challenge (both that of operating services like these and that of being a target) is complicated enough. Operator anonymity can mitigate some threats, from social engineering to physical threats, pressure, legal and otherwise, from a range of parties. Anyone with experience in these matters knows what I'm referring to, and don't think for a second operating outside of the US makes that much of a difference. The world is small. Many parties do not play by any rules besides their own.

Operator anonymity can mitigate some threats, from social engineering to physical threats, pressure, legal and otherwise, from a range of parties.

And yet, Mullvad (Sweden), which seems to be one of the most trusted VPN providers without affiliate marketing, has no issues with publicly listing the names of every single member of the team[1].

[1] https://mullvad.net/en/what-is-privacy/

Sweden is known to buckle under foreign pressure.

Do you know anything about how or if Mullvad cooperates with domestic and foreign entities?

Perhaps threats are unnecessary.

Stating you have a no logging policy does not mean you cannot covertly cooperate.

Fourteen Eyes collaboration is real, and Sweden is not a country where a business not complying with the law stays in business.

Do you know anything about how or if Mullvad cooperates with domestic and foreign entities?

I am not aware of this, but unlike the majority of VPN providers, Mullvad at least does not require any personally identifiable information, such as an email address, in order to use it.

And most VPN providers that hide their real locations, such as ExpressVPN (Hong Kong)[1], NordVPN and ProtonVPN (both Lithuania)[2], are just creating an illusion of privacy for their unsuspecting users.

[1] https://vpnscam.com/expressvpn-really-based-in-hong-kong/

[2] http://vpnscam.com/hola-vpn-and-nordvpn-partners-in-data-min...

Yes... at this point, IMO, there are no VPN providers that can be trusted to not sell you out (or your data). It's all very shady.

As I have said in previous comments, I currently use ProtonVPN, but my use case, like many others, is simply avoiding geo-blocks and not leaving my real IP everywhere.

Though, I do think, that if they make money off my data, and they probably do, the service should not charge a subscription (indeed ProtonVPN has a free plan, but it's a bit limited).

Thank you for your questions and feedback!

WifiMask uses OpenVPN for the macOS app and IKEv2/IPSec for iOS. We haven't had 3rd party audits yet, this is definitely on our wish list, because we understand it's all about trust. Alternative payments like bitcoin are on the list as well, we aim for total anonymity for our users, payments are part of that. To be honest we can't track any illegal activity, because we have a strict no log policy, all we can do now is say it is not allowed. We have nothing to hand over to enforcement either, they have to find different ways of getting the information they want. We should investigate and think about transparency reports and a public disclosure policy too, thanks!

Then... May I ask why only Apple devices are officially supported right now?

I have no affiliation with the service, but I assume that:

1. They're small

2. They're new

3. Their team has more experience developing for Apple devices, thus it was quicker to release for those devices first before tackling Windows, Android, and/or Linux.

What they could do in the meantime is create a web-based tool to generate configurations for OpenVPN and/or Wireguard, like Mullvad does.

Appreciate the replies, thanks.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.