• Wobble@lemmy.dbzer0.com
    Aquileo | link
    Aquileo | fedilink
    Aquileo | arrow-up
    92
    Aquileo | arrow-down
    1
    ·
    9 days ago

    In a major win for open-source enthusiasts, Proton VPN has officially launched its proprietary Stealth protocol in beta for Linux.

    Open-source enthusiasts and proprietary software? That does not sound like the happy union.

    • Jo Miran@lemmy.ml
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      51
      ·
      9 days ago

      It’s the author conflating “Linux” and “open source”. In their statement, Proton states “Linux community” snd the author promptly writes “open source community”. Knowing the difference between the two seems like a requirement to write for a tech publication, but maybe that’s just my crazy opinion.

    • shirasho@feddit.online
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      13
      Aquileo | arrow-down
      1
      ·
      9 days ago

      The venn diagram doesn’t need to be perfectly overlapping circles. When open source is not a viable option or you need something beyond the scope of what open source offers, the next best thing is to use a product from a reputable company that has been properly audited and has not completely enshittified.

      Now, whether Proton is truly that company is up for debate. The CEO has made some pretty troubling comments, but the products themselves have not devolved all that much. You can probably find better than Proton, but you can absolutely find a hell of a lot worse.

    • UnfortunateShort@lemmy.world
      Aquileo | link
      Aquileo | fedilink
      English
      Aquileo | arrow-up
      4
      Aquileo | arrow-down
      1
      ·
      9 days ago

      I think the protocol was developed in-house and only the code is open source? I think the protocol itself is not public to make it harder to spot, since its whole purpose is to dodge deep packet inspection

      • aketawi@quokk.au
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        14
        ·
        9 days ago

        Vless/Reality and AWG are both open source and they’re still dodging DPI just fine. Can someone pass the memo to the Security Exprets at Proton that security through obscurity is the worst stake to gamble on when each packet in your transmission is gonna be dissected and studied by a gaggle of state researchers working on DPI anyway

    • staircase@programming.dev
      Aquileo | link
      Aquileo | fedilink
      Aquileo | arrow-up
      18
      Aquileo | arrow-down
      1
      ·
      9 days ago

      I’ve not seen a single article about Proton that’s made me abandon them. Diversified away from, yes, but not abandon.

      The privacy community will be under fire from very powerful interests, so I also take all criticism with a mountain of salt.

      • shirasho@feddit.online
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        19
        Aquileo | arrow-down
        4
        ·
        9 days ago

        Proton is fine.

        The CEO has said some troubling things, but the products themselves are fine for now. It is one thing to be cautious, but it is a problem when you use the ramblings and comments of an executive as an excuse to ignore how the company actually operates.

        If it were like the MyPillow guy I could understand, but we are not there.

      • aketawi@quokk.au
        Aquileo | link
        Aquileo | fedilink
        English
        Aquileo | arrow-up
        4
        Aquileo | arrow-down
        1
        ·
        Aquileo | edit-2
        9 days ago

        not op but you should just self host. VPSs are cheap - entry tariffs are like 3-5$/month for most providers, and thats more than enough to set up a Wireguard or anything else, traffic limits are rarely an issue. if your hosting goes to shit, it’s easy enough to recreate the config elsewhere

        • scoutfdt@lemmy.dbzer0.com
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          2
          ·
          8 days ago

          You are again tied up to the VPS provider in the same way you are tied up to you ISP so there’s not going to be too much privacy there. A VPN like that is useful for using it for other purposes such as playing LAN games, placing your other hosted services behind it as an additional security measure or getting access to multiple servers that don’t have public access (such as your home lab behind a NAT). But it doesn’t annonymize you the way VPN providers “claim” they annonymize you.

        • heppen@fosstodon.org
          Aquileo | link
          Aquileo | fedilink
          Aquileo | arrow-up
          2
          ·
          8 days ago

          @aketawi whats with “selfhost” on vps? Still, you need to trust your vps provider… Also you need to manage it. I though selfhost is a term for selhosting files for example from your home server.

          • aketawi@quokk.au
            Aquileo | link
            Aquileo | fedilink
            English
            Aquileo | arrow-up
            2
            ·
            Aquileo | edit-2
            8 days ago

            not necessarily, you could Host anything by yourSelf on a rented VPS and it will still be “more selfhosted” than buying a commercial VPN. if you’re buying just to use it as a proxy, trust is also a nonissue since your traffic will be encrypted anyhow and you store no sensitive data. just don’t use a plain http proxy lol

      • 6_Electrons@lemmy.world
        Aquileo | link
        Aquileo | fedilink
        Aquileo | arrow-up
        3
        Aquileo | arrow-down
        11
        ·
        9 days ago

        I support mullvad. Please note I don’t think they necessarily provide the best service but I feel like they’re the most ethical. From their pricing model where you pay the same month to month or if you buy 10 years at a time to them not requiring an account.

        That said somehow my speeds on mullvad are double what I could ever get on proton (this confuses me and makes me a bit nervous but if true is cool) and I have yet to have a streaming service block me from being on a VPN (again to clarify I’ve only used mullvad for a couple months)

          • hellmo_luciferrari@lemmy.zip
            Aquileo | link
            Aquileo | fedilink
            Aquileo | arrow-up
            4
            Aquileo | arrow-down
            1
            ·
            9 days ago

            I can understand that. However, ability to pay cash is wonderful. And I may not agree with ehat either people of either company says. But I will say that Mullvad VPN is superior to Proton.

            • teawrecks@sopuli.xyz
              Aquileo | link
              Aquileo | fedilink
              Aquileo | arrow-up
              5
              Aquileo | arrow-down
              1
              ·
              9 days ago

              The nice thing about proton is that they offer a suite of tools comparable to Google, but all privacy respecting (email, docs, drive, etc). So they’re an easy recommendation for people dependent on those services. I almost never use their VPN, but it is neat that I have the option of a paid VPN along with the rest.

              Also I only just noticed the other day that proton offers multi-hop VPNs now, so that your entrance and exit nodes are under different jurisdictions, is that just the standard for VPN services these days? I thought that was a pretty neat feature.

              • hellmo_luciferrari@lemmy.zip
                Aquileo | link
                Aquileo | fedilink
                Aquileo | arrow-up
                3
                ·
                Aquileo | edit-2
                9 days ago

                I am not a lover or hater of proton. I just know that for my needs and desires mullvad checks all boxes. Their VPN infrastructure is diskless (source: https://mullvad.net/en/blog/we-have-successfully-completed-our-migration-to-ram-only-vpn-infrastructure) and the ability to pay with cash. And the fact your account is just a number and no need for entering in other identifiable info. Add in 5he fact I can get OpenVPN config files or Wireguard config files directly exported so I dont have a need for another piece of software I dont need.

                Where as protons VPN client if I am not mistaken is locked behind their proprietary software for connection.

                I absolutely see the value in other things they offer, as I was investigating paying for email through them. But I just haven’t done it.

                Vpns aren’t a silver bullet. They have their use case. I just know i have to have trust in the company in using their service. And with the cooperation with law enforcement proton has stated to do; I am not going to use that offering. And not sure if that is standard for VPNs these days though I like that idea.

                For the other service offerings they have, I self host what I need.

                –Edit: struck through something I believed but could not find the source on it I was sure I had read. By no means do I want to spread misinformation. Apologies.

                • teawrecks@sopuli.xyz
                  Aquileo | link
                  Aquileo | fedilink
                  Aquileo | arrow-up
                  2
                  ·
                  9 days ago

                  Yeah, I do wish proton was more open about their tech. I do know that proton allows you to make free accounts without giving them identifiable info (which makes them a popular choice for scammers, which is annoying when services just block their email domain thinking it’s always nefarious). I don’t recall what the payment options are, but I’d be surprised if they didn’t have any crypto/anonymous ways to pay.

                  I still haven’t made use of the proton VPN, mostly because, yeah, I don’t care for running a proprietary client for something like that, but also the last time I looked into it they did offer wireguard configs that would do the same thing. The client is just intended to be a familiar cross platform interface. No idea about this Stealth mode protocol, though. Seems like that would have to be run locally.

                  If you do pay for their email, I recommend bringing your own domain. 99% of the time the proton.me domain works fine, but for the 1% of the time when a system has a problem, it does make me wonder if there’s somewhere in their system blacklisting their domain.

                  with the cooperation with law enforcement proton has stated to do

                  I’m curious what statements you’re referring to. For a company to continue operating, they have to comply with local law enforcement to the extent the law requires. They don’t have a choice. If you asked mullvad, they would say the same. But the point of all these services is that they (claim to) do their best to not keep any records by design, so that when law enforcement comes with a subpoena, they have as little as possible to hand over in cooperation. But yeah, as you said, at the end of the day we just have to trust that that’s how they operate.

                • Grimdraken@lemmy.world
                  Aquileo | link
                  Aquileo | fedilink
                  English
                  Aquileo | arrow-up
                  1
                  Aquileo | arrow-down
                  1
                  ·
                  8 days ago

                  Not trying to convince you to jump ship, your reasons for using mullvad seem sound, but I wanted to mention you can also export OpenVPN Configs from proton too. You’re not locked to the app.