ProtonVPN has now audited and open source clients. #1658

Merged
dngray merged 18 commits from pr-protonvpn_recommended into master 2020-01-26 02:34:47 +00:00
dngray commented 2020-01-22 13:11:49 +00:00 (Migrated from github.com)
https://deploy-preview-1658--privacytools-io.netlify.com/providers/vpn/
netlify[bot] commented 2020-01-22 13:12:40 +00:00 (Migrated from github.com)

Deploy preview for privacytools-io ready!

Built with commit 344168fad0

https://deploy-preview-1658--privacytools-io.netlify.com

Deploy preview for *privacytools-io* ready! Built with commit 344168fad04b71120f381db5ca5ea182c572a764 https://deploy-preview-1658--privacytools-io.netlify.com
Mikaela (Migrated from github.com) requested changes 2020-01-22 14:03:49 +00:00
Mikaela (Migrated from github.com) left a comment

The upgraded ProtonVPN section becomes inconsistent with the Mullvad section above which has a direct link to the audit rather than a link to an advertisement a blog post.

The upgraded ProtonVPN section becomes inconsistent with the Mullvad section above which has a direct link to the audit rather than a link to ~~an advertisement~~ a blog post.
@ -37,1 +36,4 @@
<p>Mullvad supports the future of networking <a href="https://en.wikipedia.org/wiki/IPv6">IPv6</a>. Their network allows users to <a href="https://mullvad.net/en/blog/2014/9/15/ipv6-support/">access services hosted on IPv6</a> as opposed to other providers who block IPv6 connections.</p>
<h5><span class="badge badge-success">Remote Port Forwarding</span></h5>
<p>Remote <a href="https://en.wikipedia.org/wiki/Port_forwarding">port forwarding</a> is allowed on Mullvad, see <a href="https://mullvad.net/help/port-forwarding-and-mullvad/">Port forwarding with Mullvad VPN</a>.</p>
<h5><span class="badge badge-warning">No Mobile Clients</span></h5>
Mikaela (Migrated from github.com) commented 2020-01-22 14:01:21 +00:00

So where is the audit? Mullvad above has a direct link.

So where is the audit? Mullvad above has a direct link.
Mikaela commented 2020-01-22 14:05:54 +00:00 (Migrated from github.com)

Oh, please also change Recommended VPN Service to plural as this PR results to there being two and the previous section says Other Providers Worth Mentioning which should probably become singular as it's only one at the time of this PR.

Oh, please also change ` Recommended VPN Service` to plural as this PR results to there being two and the previous section says `Other Providers Worth Mentioning` which should probably become singular as it's only one at the time of this PR.
sell commented 2020-01-22 14:21:23 +00:00 (Migrated from github.com)

Quick question, since it is now open-source and on the preview it shows that you will put that it is open source "all ProtonVPN apps are now open source and audited."

Should you also say that mullvadvpn is also opensource?

Quick question, since it is now open-source and on the preview it shows that you will put that it is open source `"all ProtonVPN apps are now open source and audited."` Should you also say that mullvadvpn is also opensource?
ghost commented 2020-01-22 21:17:59 +00:00 (Migrated from github.com)

ProtonVPN does technically accept Bitcoin payments; however, you either need to have an existing account, or contact their support team in advance to register with Bitcoin.

I signed up for there Basic plan yesterday and was offered payment through credit card, PayPal, Bitcoin or cash. Although I did not use it, there acceptance of Bitcoin does not seem to be a technicality, I was offered it without having previously provided any payment details. I think it should be mentioned that the existing account requred is free. Accepting cash is probably also worth a mention?

>ProtonVPN does technically accept Bitcoin payments; however, you either need to have an existing account, or contact their support team in advance to register with Bitcoin. I signed up for there Basic plan yesterday and was offered payment through credit card, PayPal, Bitcoin or cash. Although I did not use it, there acceptance of Bitcoin does not seem to be a technicality, I was offered it without having previously provided any payment details. I think it should be mentioned that the existing account requred is free. Accepting cash is probably also worth a mention?
dngray (Migrated from github.com) reviewed 2020-01-23 02:32:24 +00:00
@ -37,1 +36,4 @@
<p>Mullvad supports the future of networking <a href="https://en.wikipedia.org/wiki/IPv6">IPv6</a>. Their network allows users to <a href="https://mullvad.net/en/blog/2014/9/15/ipv6-support/">access services hosted on IPv6</a> as opposed to other providers who block IPv6 connections.</p>
<h5><span class="badge badge-success">Remote Port Forwarding</span></h5>
<p>Remote <a href="https://en.wikipedia.org/wiki/Port_forwarding">port forwarding</a> is allowed on Mullvad, see <a href="https://mullvad.net/help/port-forwarding-and-mullvad/">Port forwarding with Mullvad VPN</a>.</p>
<h5><span class="badge badge-warning">No Mobile Clients</span></h5>
dngray (Migrated from github.com) commented 2020-01-23 02:32:23 +00:00

We probably should have a link to the Mullvad article.

I don't really see it as an advert because there's no referral link or parameters. We don't get anything from posting the link other than it makes our description slightly smaller.

I guess they could see if users have come from privacytools.io (assuming they're not blocking HTTP referrers though).

I just thought it looked a bit neater.

We probably should have a link to the Mullvad article. I don't really see it as an advert because there's no referral link or parameters. We don't get anything from posting the link other than it makes our description slightly smaller. I guess they could see if users have come from privacytools.io (assuming they're not blocking HTTP referrers though). I just thought it looked a bit neater.
dngray (Migrated from github.com) reviewed 2020-01-23 03:17:41 +00:00
@ -37,1 +36,4 @@
<p>Mullvad supports the future of networking <a href="https://en.wikipedia.org/wiki/IPv6">IPv6</a>. Their network allows users to <a href="https://mullvad.net/en/blog/2014/9/15/ipv6-support/">access services hosted on IPv6</a> as opposed to other providers who block IPv6 connections.</p>
<h5><span class="badge badge-success">Remote Port Forwarding</span></h5>
<p>Remote <a href="https://en.wikipedia.org/wiki/Port_forwarding">port forwarding</a> is allowed on Mullvad, see <a href="https://mullvad.net/help/port-forwarding-and-mullvad/">Port forwarding with Mullvad VPN</a>.</p>
<h5><span class="badge badge-warning">No Mobile Clients</span></h5>
dngray (Migrated from github.com) commented 2020-01-23 03:17:41 +00:00
I was unable to find the Assured AB report for Mullvad in their two blog articles: - https://mullvad.net/blog/2018/9/20/security-audit-mullvad-app-completed-please-upgrade/ - https://mullvad.net/blog/2018/9/24/read-results-security-audit-mullvad-app/
dngray commented 2020-01-23 03:18:27 +00:00 (Migrated from github.com)

Should you also say that mullvadvpn is also opensource?

We should probably have a badge for that.

> Should you also say that mullvadvpn is also opensource? We should probably have a badge for that.
Mikaela (Migrated from github.com) reviewed 2020-01-23 12:08:27 +00:00
Mikaela (Migrated from github.com) left a comment

Thanks, I spotted some other issues now

Thanks, I spotted some other issues now
@ -21,3 +21,3 @@
<p><strong>Mullvad</strong> is a fast and inexpensive VPN with a serious focus on transparency and security. They have been in operation since <strong>2009</strong>. It is the only VPN provider that currently meets our criteria for recommendation. Mullvad is based in <span class="flag-icon flag-icon-se"></span> Sweden and does not have a free trial. Visit <a href="https://mullvad.net/">mullvad.net</a> to create an account.</p>
<p><strong>Mullvad</strong> is a fast and inexpensive VPN with a serious focus on transparency and security. They have been in operation since <strong>2009</strong>. Mullvad is based in <span class="flag-icon flag-icon-se"></span> Sweden and does not have a free trial. Visit <a href="https://mullvad.net/">mullvad.net</a> to create an account.</p>
<h5><span class="badge badge-success">406+ Servers</span></h5>
<p>Mullvad has 409 servers in 39 countries at the time of writing this page. Typically the more servers a provider offers, the better: With hundreds of servers in operation, you are far more likely to find a fast connection and a server geographically closest to you.</p>
Mikaela (Migrated from github.com) commented 2020-01-23 12:01:36 +00:00
    <p>Mullvad's VPN clients have been audited by Cure53 and Assured AB in a pentest report <a href="https://cure53.de/pentest-report_mullvad_v2.pdf">published at cure53.de</a>. The security researchers concluded:</p>

What is this and . ?

```suggestion <p>Mullvad's VPN clients have been audited by Cure53 and Assured AB in a pentest report <a href="https://cure53.de/pentest-report_mullvad_v2.pdf">published at cure53.de</a>. The security researchers concluded:</p> ``` What is this ` and .` ?
Mikaela (Migrated from github.com) commented 2020-01-23 12:03:26 +00:00
    <p>Mullvad provides the source code to their clients <a href="https://github.com/mullvad/mullvadvpn-app">on Github</a>.</p>

I think listing the path is ugly and it's also inconsistent with ProtonVPN below.

```suggestion <p>Mullvad provides the source code to their clients <a href="https://github.com/mullvad/mullvadvpn-app">on Github</a>.</p> ``` I think listing the path is ugly and it's also inconsistent with ProtonVPN below.
@ -71,3 +59,4 @@
<p>ProtonVPN does technically accept Bitcoin payments; however, you either need to have an existing account, or contact their support team in advance to register with Bitcoin.</p>
<h5><span class="badge badge-success">Mobile Clients</span></h5>
<p>In addition to providing standard OpenVPN configuration files, ProtonVPN has mobile clients for iOS or Android allowing for easy connections to their servers.</p>
<h5><span class="badge badge-warning">No Port Forwarding</span></h5>
Mikaela (Migrated from github.com) commented 2020-01-23 12:05:38 +00:00
    <p>The ProtonVPN clients have a built-in killswitch to block internet connections outside of the VPN. They also are able to automatically start on boot. ProtonVPN also offers "Tor" servers allowing you to easily connect to onion sites, but we still strongly recommend using <a href="https://www.torproject.org/">the official Tor Browser</a> for this purpose.</p>

Why to not make this a link?

```suggestion <p>The ProtonVPN clients have a built-in killswitch to block internet connections outside of the VPN. They also are able to automatically start on boot. ProtonVPN also offers "Tor" servers allowing you to easily connect to onion sites, but we still strongly recommend using <a href="https://www.torproject.org/">the official Tor Browser</a> for this purpose.</p> ``` Why to not make this a link?
dngray (Migrated from github.com) reviewed 2020-01-23 13:44:07 +00:00
@ -21,3 +21,3 @@
<p><strong>Mullvad</strong> is a fast and inexpensive VPN with a serious focus on transparency and security. They have been in operation since <strong>2009</strong>. It is the only VPN provider that currently meets our criteria for recommendation. Mullvad is based in <span class="flag-icon flag-icon-se"></span> Sweden and does not have a free trial. Visit <a href="https://mullvad.net/">mullvad.net</a> to create an account.</p>
<p><strong>Mullvad</strong> is a fast and inexpensive VPN with a serious focus on transparency and security. They have been in operation since <strong>2009</strong>. Mullvad is based in <span class="flag-icon flag-icon-se"></span> Sweden and does not have a free trial. Visit <a href="https://mullvad.net/">mullvad.net</a> to create an account.</p>
<h5><span class="badge badge-success">406+ Servers</span></h5>
<p>Mullvad has 409 servers in 39 countries at the time of writing this page. Typically the more servers a provider offers, the better: With hundreds of servers in operation, you are far more likely to find a fast connection and a server geographically closest to you.</p>
dngray (Migrated from github.com) commented 2020-01-23 13:44:06 +00:00

My bad. I was looking for the Assured AB report but it seems the report was a jointly done one which was published by Cure53.

My bad. I was looking for the Assured AB report but it seems the report was a jointly done one which was published by Cure53.
dngray (Migrated from github.com) reviewed 2020-01-23 13:45:23 +00:00
@ -21,3 +21,3 @@
<p><strong>Mullvad</strong> is a fast and inexpensive VPN with a serious focus on transparency and security. They have been in operation since <strong>2009</strong>. It is the only VPN provider that currently meets our criteria for recommendation. Mullvad is based in <span class="flag-icon flag-icon-se"></span> Sweden and does not have a free trial. Visit <a href="https://mullvad.net/">mullvad.net</a> to create an account.</p>
<p><strong>Mullvad</strong> is a fast and inexpensive VPN with a serious focus on transparency and security. They have been in operation since <strong>2009</strong>. Mullvad is based in <span class="flag-icon flag-icon-se"></span> Sweden and does not have a free trial. Visit <a href="https://mullvad.net/">mullvad.net</a> to create an account.</p>
<h5><span class="badge badge-success">406+ Servers</span></h5>
<p>Mullvad has 409 servers in 39 countries at the time of writing this page. Typically the more servers a provider offers, the better: With hundreds of servers in operation, you are far more likely to find a fast connection and a server geographically closest to you.</p>
dngray (Migrated from github.com) commented 2020-01-23 13:45:23 +00:00

Yeah you're probably right. When I wrote the one down below, I realized they keep it all in one repo.

Yeah you're probably right. When I wrote the one down below, I realized they keep it all in one repo.
dngray (Migrated from github.com) reviewed 2020-01-23 13:46:20 +00:00
@ -71,3 +59,4 @@
<p>ProtonVPN does technically accept Bitcoin payments; however, you either need to have an existing account, or contact their support team in advance to register with Bitcoin.</p>
<h5><span class="badge badge-success">Mobile Clients</span></h5>
<p>In addition to providing standard OpenVPN configuration files, ProtonVPN has mobile clients for iOS or Android allowing for easy connections to their servers.</p>
<h5><span class="badge badge-warning">No Port Forwarding</span></h5>
dngray (Migrated from github.com) commented 2020-01-23 13:46:19 +00:00

I see no reason not to.

I see no reason not to.
jonah reviewed 2020-01-24 16:13:19 +00:00
jonah left a comment

Also, reorder the ProtonVPN section so it matches (server count should be first). Otherwise LGTM.

Also, reorder the ProtonVPN section so it matches (server count should be first). Otherwise LGTM.
@ -37,3 +38,4 @@
<p>Remote <a href="https://en.wikipedia.org/wiki/Port_forwarding">port forwarding</a> is allowed on Mullvad, see <a href="https://mullvad.net/help/port-forwarding-and-mullvad/">Port forwarding with Mullvad VPN</a>.</p>
<h5><span class="badge badge-warning">No Mobile Clients</span></h5>
<p>While iOS and Android clients are reportedly in the works, mobile users will need to use a traditional OpenVPN client and configuration files, which are a bit more difficult to configure.</p>
<h5><span class="badge badge-info">Extra Functionality</span></h5>
    <p><strong>ProtonVPN</strong> is a strong contender in the VPN space, and they have been in operation since <strong>2016</strong>. ProtonVPN is based in <span class="flag-icon flag-icon-ch"></span> Switzerland and offers a limited free pricing tier, as well as premium options. Visit <a href="https://protonvpn.com/">protonvpn.com</a> to create an account.</p>
```suggestion <p><strong>ProtonVPN</strong> is a strong contender in the VPN space, and they have been in operation since <strong>2016</strong>. ProtonVPN is based in <span class="flag-icon flag-icon-ch"></span> Switzerland and offers a limited free pricing tier, as well as premium options. Visit <a href="https://protonvpn.com/">protonvpn.com</a> to create an account.</p> ```
dngray (Migrated from github.com) reviewed 2020-01-25 10:20:15 +00:00
@ -37,3 +38,4 @@
<p>Remote <a href="https://en.wikipedia.org/wiki/Port_forwarding">port forwarding</a> is allowed on Mullvad, see <a href="https://mullvad.net/help/port-forwarding-and-mullvad/">Port forwarding with Mullvad VPN</a>.</p>
<h5><span class="badge badge-warning">No Mobile Clients</span></h5>
<p>While iOS and Android clients are reportedly in the works, mobile users will need to use a traditional OpenVPN client and configuration files, which are a bit more difficult to configure.</p>
<h5><span class="badge badge-info">Extra Functionality</span></h5>
dngray (Migrated from github.com) commented 2020-01-25 10:20:15 +00:00

Oh yes, good point.

Oh yes, good point.
Mikaela (Migrated from github.com) reviewed 2020-01-25 11:18:14 +00:00
5a384507-18ce-417c-bb55-d4dfcc8883fe commented 2020-01-25 14:24:59 +00:00 (Migrated from github.com)

Also, in the Mullvad section it states:

No Mobile Clients

While iOS and Android clients are reportedly in the works, mobile users will need to use a traditional OpenVPN client and configuration files, which are a bit more difficult to configure.

And they do have an Android client which is in beta, but still you can use it and it works flawlessly, the only thing is that you can't configure anything besides from which server you want to connect.
I think you could edit that since you are revisiting the whole section.

Also, in the Mullvad section it states: >No Mobile Clients > >While iOS and Android clients are reportedly in the works, mobile users will need to use a traditional OpenVPN client and configuration files, which are a bit more difficult to configure. And they do have an Android client which is in beta, but still you can use it and it works flawlessly, the only thing is that you can't configure anything besides from which server you want to connect. I think you could edit that since you are revisiting the whole section.
nitrohorse (Migrated from github.com) reviewed 2020-01-25 17:04:36 +00:00
nitrohorse (Migrated from github.com) left a comment

Small suggestion but otherwise LGTM

Small suggestion but otherwise LGTM
@ -37,3 +38,4 @@
<p>Remote <a href="https://en.wikipedia.org/wiki/Port_forwarding">port forwarding</a> is allowed on Mullvad, see <a href="https://mullvad.net/help/port-forwarding-and-mullvad/">Port forwarding with Mullvad VPN</a>.</p>
<h5><span class="badge badge-warning">No Mobile Clients</span></h5>
<p>While iOS and Android clients are reportedly in the works, mobile users will need to use a traditional OpenVPN client and configuration files, which are a bit more difficult to configure.</p>
<h5><span class="badge badge-info">Extra Functionality</span></h5>
nitrohorse (Migrated from github.com) commented 2020-01-25 17:04:03 +00:00

I’m wondering if we want to link to the blog post which links to audits for each of their clients? https://protonvpn.com/blog/open-source/

I’m wondering if we want to link to the blog post which links to audits for each of their clients? https://protonvpn.com/blog/open-source/
dngray (Migrated from github.com) reviewed 2020-01-25 18:02:35 +00:00
@ -37,3 +38,4 @@
<p>Remote <a href="https://en.wikipedia.org/wiki/Port_forwarding">port forwarding</a> is allowed on Mullvad, see <a href="https://mullvad.net/help/port-forwarding-and-mullvad/">Port forwarding with Mullvad VPN</a>.</p>
<h5><span class="badge badge-warning">No Mobile Clients</span></h5>
<p>While iOS and Android clients are reportedly in the works, mobile users will need to use a traditional OpenVPN client and configuration files, which are a bit more difficult to configure.</p>
<h5><span class="badge badge-info">Extra Functionality</span></h5>
dngray (Migrated from github.com) commented 2020-01-25 18:02:35 +00:00

Yeah I think you're right. We're going to have to link to the blog article as there are 4 separate reports. This will break with what we did with Mullvad, that was one report in one document.

Yeah I think you're right. We're going to have to link to the blog article as there are 4 separate reports. This will break with what we did with Mullvad, that was one report in one document.
nitrohorse (Migrated from github.com) reviewed 2020-01-25 18:17:18 +00:00
nitrohorse (Migrated from github.com) reviewed 2020-01-26 01:16:47 +00:00
jonah reviewed 2020-01-26 01:31:25 +00:00
jonah approved these changes 2020-01-26 02:03:21 +00:00
nitrohorse (Migrated from github.com) approved these changes 2020-01-26 02:33:44 +00:00
nitrohorse (Migrated from github.com) left a comment

Nice, LGTM 👍

Nice, LGTM :+1:
Mikaela commented 2020-01-26 14:11:36 +00:00 (Migrated from github.com)

I didn't have time to review before merge, but I am going to trust you.

And they do have an Android client which is in beta, but still you can use it and it works flawlessly, the only thing is that you can't configure anything besides from which server you want to connect.

AFAIK, the plan is to wait for them to release the app as per https://github.com/mullvad/mullvadvpn-app/issues/1126#issuecomment-534007313.

I didn't have time to review before merge, but I am going to trust you. > And they do have an Android client which is in beta, but still you can use it and it works flawlessly, the only thing is that you can't configure anything besides from which server you want to connect. AFAIK, the plan is to wait for them to release the app as per https://github.com/mullvad/mullvadvpn-app/issues/1126#issuecomment-534007313.
faern (Migrated from github.com) reviewed 2020-02-07 16:27:21 +00:00
@ -37,1 +36,4 @@
<p>Mullvad supports the future of networking <a href="https://en.wikipedia.org/wiki/IPv6">IPv6</a>. Their network allows users to <a href="https://mullvad.net/en/blog/2014/9/15/ipv6-support/">access services hosted on IPv6</a> as opposed to other providers who block IPv6 connections.</p>
<h5><span class="badge badge-success">Remote Port Forwarding</span></h5>
<p>Remote <a href="https://en.wikipedia.org/wiki/Port_forwarding">port forwarding</a> is allowed on Mullvad, see <a href="https://mullvad.net/help/port-forwarding-and-mullvad/">Port forwarding with Mullvad VPN</a>.</p>
<h5><span class="badge badge-warning">No Mobile Clients</span></h5>
faern (Migrated from github.com) commented 2020-02-07 16:27:21 +00:00

The second link has a section named "Read the report" that links directly to the report in the first paragraph. There is only one report from Cure53+Assured. It was a collaboration between the companies but only a single audit.

The second link has a section named "Read the report" that links directly to the report in the first paragraph. There is only one report from Cure53+Assured. It was a collaboration between the companies but only a single audit.
This repo is archived. You cannot comment on pull requests.
No Milestone
No Assignees
1 Participants
Due Date
The due date is invalid or out of range. Please use the format 'yyyy-mm-dd'.

No due date set.

Dependencies

No dependencies set.

Reference: privacyguides/privacytools.io#1658
No description provided.