Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

ProtonVPN (operated from Switzerland) claims[1]: "Our security team has also identified at least one VPN service which is working on behalf of a state surveillance agency."

If I had to guess, it would be PIA: the most popular, the most accessible, and the most affordable US-based VPN.

When a VPN is run by NSA, of course it will stand up in all courts. How would a state surveillance agency let its tool be so publicly destroyed? And it doesn't have to keep any logs at all. They can just be forwarded in real-time, based on a set of filters and rules ("URLs that are requested by <IP>", "IPs that are requesting <URL>").

[1] https://protonvpn.com/blog/threat-model/



Honest question: Is there any reason to believe that PIA is a US intel operation vs, say a Russian one? I ask because my main privacy concern is state sponsored industrial espionage. I have often thought that if I wanted to gather kompromat on high level professionals, I would probably start an "anonymous" VPN service to further that effort. Say what you will about the NSA, but I am not worried about them in that space.


>Say what you will about the NSA, but I am not worried about them in that space.

We know from leaks that the steal industry secrets.


> Honest question: Is there any reason to believe that PIA is a US intel operation vs, say a Russian one?

I would also like to know the motivation for a US intel agency to want to run a VPN. It seems to me like it wouldn't be worth the bother: VPNs aren't illegal in the US, so it would be too hard to convince everyone to use theirs. Spies, etc. could just use private ones they control. They'd just see a bunch of crap from unsophisticated people.

Seems to me like it would be more likely for US law enforcement to want to do something like that, but I'm skeptical they have the resources.


if you're a spy using it to hide your identity from websites when you visit, it would be good for your VPN to have a mix of normal activity and spy activity. If you run your own, it's going to have a weird pattern of traffic that might stand out to a website with decent analytics.


This is exactly why Tor is publicly available.


> ProtonVPN (operated from Switzerland) claims[1]: "Our security team has also identified at least one VPN service which is working on behalf of a state surveillance agency."

> If I had to guess, it would be PIA: the most popular, the most accessible, and the most affordable US-based VPN.

If I had to guess, the state surveillance agency-run VPN would be one that's still accessible from China. I understand (but I could be wrong) there are still a few that manage to evade the blocks and provide good service despite all the crackdowns. Chinese state security has many more reasons to want to watch domestic VPN traffic than the US does. Their motivation is proven by the fact that they've spent the effort to build and maintain the "Great Firewall," and crack down on VPNs that bypass it.

It would be reasonably clever for the Chinese to crack down on all the VPNs that they don't control, funneling all the "illicit" traffic to the few VPNs they do control. It would make spying, monitoring dissidents, etc. much easier for them.

The NSA and other US intelligence agencies probably don't care very much about anyone that's dumb enough to need to use public VPN. Seems like the only people who would care in the US are domestic law enforcement, like the FBI.


We're not ready to name names at this point, but you're actually correct. If one looks closely at what China lets through the Great Firewall in terms of the major VPN providers, there is something that stands out.


> We're not ready to name names at this point, but you're actually correct.

Where do you plan to announce when you're ready to name names? I may have some need in the future to use a VPN in China and would like to be aware.

Also props on your mail service, it's very impressive. If it had been released a bit earlier, I think I'd have been a customer.


[Comment retracted and removed by author's request.]


In addition to the redacting the above comment, we deleted several comments below by request of their authors. My understanding is that the dispute has been resolved and that the allegations are retracted.


You aren't doing much in terms of brand ambassadorship for PIA by muck raking and bickering with a competitor. It's quite petty. The comment about PIA wasn't put forth by ProtonVPN. They clarified the discrepancy you raised and did so in a civil manner.

I wasn't that familiar with your company before today but I can tell you that I won't be a customer at any time in the future based on your comments.


I feel like the PIA guy is providing a lot of sources for his position. I feel like the counter arguments aren't providing anything, but words.


I checked out the provided links. It is weird. Even if it were a wrong conclusion, it seems fishy.


What PIA co-founder proofed in this thread so far:

- ProtonVPN UAB lists Tesonet's CEO as a director

- ProtonVPN UAB is operated from Tesonet HQ in Vilnius, Lithuania

- ProtonVPN UAB uses previous Tesonet's technical employees

- ProtonVPN uses IP address blocks that belong to Tesonet

- ProtonVPN mobile app is signed by Tesonet

It seems, that ProtonVPN is a free VPN service by a data mining company from Lithuania.


ProtonMail team here. None of the above is correct. ProtonVPN is developed, operated and 100% owned by Proton Technologies AG, the Swiss company that also operates ProtonMail. This can be verified in the Swiss commercial registry, which also lists all our directors: http://ge.ch/hrcintapp/externalCompanyReport.action?companyO...

Proton has also been thoroughly audited/vetted by third parties, including Mozilla: https://blog.mozilla.org/futurereleases/2018/10/22/testing-n... and also the European Commission which partially funds Proton: https://protonmail.com/blog/eu-funding/

Any data mining claims are categorically false, and doing data mining would also subject us to fines of 20 million Euros as discussed here: https://protonvpn.com/blog/is-protonvpn-trustworthy/


That is what I mean. It looks like these things are facts and combined it doesn't look good.


I wasn't aware that ProtonVPN was not run by ProtonMail, even though I happen to be from Vilnius, Lithuania myself and even have a close friend working at Tesonet. If this is true, that makes me question how much anything branded Proton* can be trusted in general.


ProtonMail team here. The above is not correct. ProtonVPN is developed and operated by ProtonMail. However, it exists as a separate legal entity for security reasons. This is to avoid ProtonMail getting banned in jurisdictions where VPNs are illegal. An example is China where ProtonVPN is banned, but ProtonMail is permitted. Had they been the same company, both would have been banned together. So from the legal standpoint, we put as much separation as possible between ProtonMail and ProtonVPN.

Like ProtonMail, the ProtonVPN team is distributed, split between Geneva, Skopje, Vilnius, and San Francisco. Tesonet (one of the biggest IT firms in Vilnius) was previously used as outsourced HR before we incorporated our own entity in Vilnius. We have similar arrangements for our staff in San Francisco, Prague, and Skopje. The above poster's intentions are a bit suspect, given that he's the co-founder of PIA...


> Tesonet was previously used as outsourced HR before we incorporated our own entity in Vilnius

But your entity's business address in Lithuania is still Tesonet's HQ. And Tesonet runs the entire technical infrastructure needed for a VPN service. So, are you partners or competitors?


[deleted]


[deleted]


[deleted]


[deleted]


[deleted]


Yet, the fact is, that the entire ProtonVPN mobile traffic passes through an app signed by a dating mining company from Lithuania.


This is not true, we maintain sole custody and control of our application signing certificates.


How did their security team identify that?


Probably someone venting over beers at a convention?


connect to VPNs, make illegal traffic, see which traffic triggered an investigation ... ?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: