• Wobble@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    91
    arrow-down
    1
    ·
    2 days ago

    In a major win for open-source enthusiasts, Proton VPN has officially launched its proprietary Stealth protocol in beta for Linux.

    Open-source enthusiasts and proprietary software? That does not sound like the happy union.

    • Jo Miran@lemmy.ml
      link
      fedilink
      arrow-up
      48
      ·
      2 days ago

      It’s the author conflating “Linux” and “open source”. In their statement, Proton states “Linux community” snd the author promptly writes “open source community”. Knowing the difference between the two seems like a requirement to write for a tech publication, but maybe that’s just my crazy opinion.

    • shirasho@feddit.online
      link
      fedilink
      English
      arrow-up
      13
      arrow-down
      1
      ·
      2 days ago

      The venn diagram doesn’t need to be perfectly overlapping circles. When open source is not a viable option or you need something beyond the scope of what open source offers, the next best thing is to use a product from a reputable company that has been properly audited and has not completely enshittified.

      Now, whether Proton is truly that company is up for debate. The CEO has made some pretty troubling comments, but the products themselves have not devolved all that much. You can probably find better than Proton, but you can absolutely find a hell of a lot worse.

    • MagicShel@lemmy.zip
      link
      fedilink
      English
      arrow-up
      5
      ·
      edit-2
      2 days ago

      What is a proprietary protocol? Is that like mpeg where everyone knows how to implement it but you have to pay them to use it?

    • UnfortunateShort@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      2 days ago

      I think the protocol was developed in-house and only the code is open source? I think the protocol itself is not public to make it harder to spot, since its whole purpose is to dodge deep packet inspection

      • aketawi@quokk.au
        link
        fedilink
        English
        arrow-up
        14
        ·
        edit-2
        2 days ago

        Vless/Reality and AWG are both open source and they’re still dodging DPI just fine. Can someone pass the memo to the Security Exprets at Proton that security through obscurity is the worst stake to gamble on when each packet in your transmission is gonna be dissected and studied by a gaggle of state researchers working on DPI anyway

  • shirasho@feddit.online
    link
    fedilink
    English
    arrow-up
    7
    ·
    2 days ago

    While they have an official app for Arch, this functionality is not yet available on that flavor of distro.

    • staircase@programming.dev
      link
      fedilink
      arrow-up
      17
      arrow-down
      1
      ·
      edit-2
      2 days ago

      I’ve not seen a single article about Proton that’s made me abandon them. Diversified away from, yes, but not abandon.

      The privacy community will be under fire from very powerful interests, so I also take all criticism with a mountain of salt.

      • lIlIlIlIlIlIl@lemmy.world
        link
        fedilink
        arrow-up
        2
        arrow-down
        5
        ·
        2 days ago

        Whatever your comfort level, I hope that turns out OK for you.

        I’m only using providers who have zero “nazi incidents”

          • lIlIlIlIlIlIl@lemmy.world
            link
            fedilink
            arrow-up
            1
            arrow-down
            2
            ·
            edit-2
            1 day ago

            The ones that the Proton CEO knows about - he’s the one whose name keeps miraculously appearing next to “Trump” and “GOP.”

            I use providers who are not “nazi-adjacent”

            • staircase@programming.dev
              link
              fedilink
              arrow-up
              4
              ·
              1 day ago

              Would you mind pointing to a specific example? I know he praised a Trump appointee a while back, regarding approach to big tech. Was there another?

              • lIlIlIlIlIlIl@lemmy.world
                link
                fedilink
                arrow-up
                1
                arrow-down
                3
                ·
                1 day ago

                They’re so easy to find if you don’t mind, since every time I post a link I get pissed off chuds DM’ing me that I hurt their feelings because of email of all things. Email. My god.

    • deadlysodium@lemmus.org
      link
      fedilink
      English
      arrow-up
      5
      arrow-down
      2
      ·
      2 days ago

      Out of curiosity which VPN do you recommend? I have Bazzite and it seemed like Proton was the best choice.

      • shirasho@feddit.online
        link
        fedilink
        English
        arrow-up
        19
        arrow-down
        4
        ·
        2 days ago

        Proton is fine.

        The CEO has said some troubling things, but the products themselves are fine for now. It is one thing to be cautious, but it is a problem when you use the ramblings and comments of an executive as an excuse to ignore how the company actually operates.

        If it were like the MyPillow guy I could understand, but we are not there.

      • aketawi@quokk.au
        link
        fedilink
        English
        arrow-up
        4
        arrow-down
        1
        ·
        edit-2
        2 days ago

        not op but you should just self host. VPSs are cheap - entry tariffs are like 3-5$/month for most providers, and thats more than enough to set up a Wireguard or anything else, traffic limits are rarely an issue. if your hosting goes to shit, it’s easy enough to recreate the config elsewhere

        • scoutfdt@lemmy.dbzer0.com
          link
          fedilink
          arrow-up
          1
          ·
          edit-2
          1 day ago

          You are again tied up to the VPS provider in the same way you are tied up to you ISP so there’s not going to be too much privacy there. A VPN like that is useful for using it for other purposes such as playing LAN games, placing your other hosted services behind it as an additional security measure or getting access to multiple servers that don’t have public access (such as your home lab behind a NAT). But it doesn’t annonymize you the way VPN providers “claim” they annonymize you.

        • heppen@fosstodon.org
          link
          fedilink
          arrow-up
          2
          ·
          2 days ago

          @aketawi whats with “selfhost” on vps? Still, you need to trust your vps provider… Also you need to manage it. I though selfhost is a term for selhosting files for example from your home server.

          • aketawi@quokk.au
            link
            fedilink
            English
            arrow-up
            2
            ·
            edit-2
            2 days ago

            not necessarily, you could Host anything by yourSelf on a rented VPS and it will still be “more selfhosted” than buying a commercial VPN. if you’re buying just to use it as a proxy, trust is also a nonissue since your traffic will be encrypted anyhow and you store no sensitive data. just don’t use a plain http proxy lol

      • 6_Electrons@lemmy.world
        link
        fedilink
        arrow-up
        3
        arrow-down
        11
        ·
        2 days ago

        I support mullvad. Please note I don’t think they necessarily provide the best service but I feel like they’re the most ethical. From their pricing model where you pay the same month to month or if you buy 10 years at a time to them not requiring an account.

        That said somehow my speeds on mullvad are double what I could ever get on proton (this confuses me and makes me a bit nervous but if true is cool) and I have yet to have a streaming service block me from being on a VPN (again to clarify I’ve only used mullvad for a couple months)

          • hellmo_luciferrari@lemmy.zip
            link
            fedilink
            arrow-up
            4
            arrow-down
            1
            ·
            2 days ago

            I can understand that. However, ability to pay cash is wonderful. And I may not agree with ehat either people of either company says. But I will say that Mullvad VPN is superior to Proton.

            • rainwall@piefed.social
              link
              fedilink
              English
              arrow-up
              8
              ·
              edit-2
              2 days ago

              Ivpn is also identity-less, accepts cash, has the same no logging, ram only infrastructure as mullvad, and isn’t run by facists.

            • teawrecks@sopuli.xyz
              link
              fedilink
              arrow-up
              5
              arrow-down
              1
              ·
              2 days ago

              The nice thing about proton is that they offer a suite of tools comparable to Google, but all privacy respecting (email, docs, drive, etc). So they’re an easy recommendation for people dependent on those services. I almost never use their VPN, but it is neat that I have the option of a paid VPN along with the rest.

              Also I only just noticed the other day that proton offers multi-hop VPNs now, so that your entrance and exit nodes are under different jurisdictions, is that just the standard for VPN services these days? I thought that was a pretty neat feature.

              • hellmo_luciferrari@lemmy.zip
                link
                fedilink
                arrow-up
                3
                ·
                edit-2
                2 days ago

                I am not a lover or hater of proton. I just know that for my needs and desires mullvad checks all boxes. Their VPN infrastructure is diskless (source: https://mullvad.net/en/blog/we-have-successfully-completed-our-migration-to-ram-only-vpn-infrastructure) and the ability to pay with cash. And the fact your account is just a number and no need for entering in other identifiable info. Add in 5he fact I can get OpenVPN config files or Wireguard config files directly exported so I dont have a need for another piece of software I dont need.

                Where as protons VPN client if I am not mistaken is locked behind their proprietary software for connection.

                I absolutely see the value in other things they offer, as I was investigating paying for email through them. But I just haven’t done it.

                Vpns aren’t a silver bullet. They have their use case. I just know i have to have trust in the company in using their service. And with the cooperation with law enforcement proton has stated to do; I am not going to use that offering. And not sure if that is standard for VPNs these days though I like that idea.

                For the other service offerings they have, I self host what I need.

                –Edit: struck through something I believed but could not find the source on it I was sure I had read. By no means do I want to spread misinformation. Apologies.

                • teawrecks@sopuli.xyz
                  link
                  fedilink
                  arrow-up
                  2
                  ·
                  2 days ago

                  Yeah, I do wish proton was more open about their tech. I do know that proton allows you to make free accounts without giving them identifiable info (which makes them a popular choice for scammers, which is annoying when services just block their email domain thinking it’s always nefarious). I don’t recall what the payment options are, but I’d be surprised if they didn’t have any crypto/anonymous ways to pay.

                  I still haven’t made use of the proton VPN, mostly because, yeah, I don’t care for running a proprietary client for something like that, but also the last time I looked into it they did offer wireguard configs that would do the same thing. The client is just intended to be a familiar cross platform interface. No idea about this Stealth mode protocol, though. Seems like that would have to be run locally.

                  If you do pay for their email, I recommend bringing your own domain. 99% of the time the proton.me domain works fine, but for the 1% of the time when a system has a problem, it does make me wonder if there’s somewhere in their system blacklisting their domain.

                  with the cooperation with law enforcement proton has stated to do

                  I’m curious what statements you’re referring to. For a company to continue operating, they have to comply with local law enforcement to the extent the law requires. They don’t have a choice. If you asked mullvad, they would say the same. But the point of all these services is that they (claim to) do their best to not keep any records by design, so that when law enforcement comes with a subpoena, they have as little as possible to hand over in cooperation. But yeah, as you said, at the end of the day we just have to trust that that’s how they operate.

                • Grimdraken@lemmy.world
                  link
                  fedilink
                  English
                  arrow-up
                  1
                  arrow-down
                  1
                  ·
                  2 days ago

                  Not trying to convince you to jump ship, your reasons for using mullvad seem sound, but I wanted to mention you can also export OpenVPN Configs from proton too. You’re not locked to the app.

    • village604@adultswim.fan
      link
      fedilink
      English
      arrow-up
      3
      arrow-down
      1
      ·
      edit-2
      2 days ago

      What, the CEO making a comment about a trump appointee or them complying with court orders?