Many thanks for your feedback! Much appreciated. The missing newlines and subresource integrity are now fixed. The Privacy Policy is now updated with information on how to opt-out.
WifiMask uses OpenVPN for the macOS app and IKEv2/IPSec for iOS. Examples of OpenVPN config files can be found at https://www.wifimask.com/contact#androidwindows which allows you to use the WifiMask service on every OpenVPN capable device. Meanwhile an Android and Windows app are in development, so stay tuned. ;-)
The optional 2FA used is Authy, you activate Authy with your phonenumber only once, after that you use Authy to login to your account. So 2FA is not done through SMS text messages for example, where hijacking could be a problem.
Good one with the list of hostnames, I will prepare one, for now you can take a look at this JSON file:
Authy is absolutely not acceptable for privacy applications like VPNs. Authy stores user information on third-party servers, when there are plenty of 2FA apps that work locally on the user's device.
The fact that Authy refused to delete user accounts (before they were acquired by Twilio), even when they promised to do so in their terms of service, is also very concerning:
Comments
Many thanks for your feedback! Much appreciated. The missing newlines and subresource integrity are now fixed. The Privacy Policy is now updated with information on how to opt-out.
WifiMask uses OpenVPN for the macOS app and IKEv2/IPSec for iOS. Examples of OpenVPN config files can be found at https://www.wifimask.com/contact#androidwindows which allows you to use the WifiMask service on every OpenVPN capable device. Meanwhile an Android and Windows app are in development, so stay tuned. ;-)
No 2FA other than mandatory phone number? This is a really, really bad thing. (+ forcing proprietary app?)
Can't find list of hostnames to use with OVPN, seemingly
The optional 2FA used is Authy, you activate Authy with your phonenumber only once, after that you use Authy to login to your account. So 2FA is not done through SMS text messages for example, where hijacking could be a problem.
Good one with the list of hostnames, I will prepare one, for now you can take a look at this JSON file:
https://vpnserver.wifimask.net/vpnservers.json
Authy is absolutely not acceptable for privacy applications like VPNs. Authy stores user information on third-party servers, when there are plenty of 2FA apps that work locally on the user's device.
The fact that Authy refused to delete user accounts (before they were acquired by Twilio), even when they promised to do so in their terms of service, is also very concerning:
https://news.ycombinator.com/item?id=9103606
https://web.archive.org/web/20141011062757/authy.com/terms
Yeah, this is really not a good thing on the Authy part. You should not need to activate it with a phone number.