<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Hacker News: yegor</title><link>https://news.ycombinator.com/user?id=yegor</link><description>Hacker News RSS</description><docs>https://hnrss.org/</docs><generator>hnrss v2.1.1</generator><lastBuildDate>Sat, 18 Apr 2026 07:28:16 +0000</lastBuildDate><atom:link href="https://hnrss.org/user?id=yegor" rel="self" type="application/rss+xml"></atom:link><item><title><![CDATA[New comment by yegor in "Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)"]]></title><description><![CDATA[
<p>Proton used to have mail, they they launched a VPN. Then cloud storage, then password manager, then docs + calendar, then wallet, now also AI and MFA app. They're following literally in Nord's footsteps, all Nord needs to do is launch a mail service and the circle is complete.<p>Proton is doing influencer marketing now too btw. Parallels are uncanny. All this while claiming to fight Google/big tech, but essentially offering the same products that store the same personal data.</p>
]]></description><pubDate>Tue, 07 Oct 2025 02:04:56 +0000</pubDate><link>https://news.ycombinator.com/item?id=45498660</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=45498660</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45498660</guid></item><item><title><![CDATA[New comment by yegor in "Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)"]]></title><description><![CDATA[
<p>Company who's blog post this is ain't bad either if you're looking for a non-ecosystem VPN. Proton is trying to be Nord and create an ecosystem of products that store all your most private data, all under the umbrella of 1 company which defeats the whole point of a VPN who should have no data on you (not even an email).<p>PS. I'm from the company who's blog post this is.</p>
]]></description><pubDate>Tue, 07 Oct 2025 01:42:13 +0000</pubDate><link>https://news.ycombinator.com/item?id=45498525</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=45498525</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45498525</guid></item><item><title><![CDATA[New comment by yegor in "Who owns Express VPN, Nord, Surfshark? VPN relationships explained (2024)"]]></title><description><![CDATA[
<p>Ohh cool, we made that map (I'm from Windscribe). If you spot any errors, let me know.</p>
]]></description><pubDate>Tue, 07 Oct 2025 00:50:54 +0000</pubDate><link>https://news.ycombinator.com/item?id=45498136</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=45498136</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45498136</guid></item><item><title><![CDATA[New comment by yegor in "Ask HN: The government of my country blocked VPN access. What should I use?"]]></title><description><![CDATA[
<p>Full disclosure, I run a commercial VPN service (Windscribe).<p>There are 2 paths you can take here:<p>1. Roll your own VPN server on a VPS at a less common cloud provider and use it. If you're tech savvy and know what you're doing, you can get this going in <1hr. Be mindful of the downsides of being the sole user of your custom VPN server you pay for: cloud providers log all TCP flows and traffic correlation is trivial. You do something "bad", your gov subpoenas the provider who hands over your personal info. If you used fake info, your TCP flows are still there, which means your ISP's IP is logged, and deanonymizing you after that is a piece of cake (no court order needed in many countries).<p>2. Get a paid commercial VPN service that values your privacy, has a diverse network of endpoints and protocols. Do not use any random free VPN apps from the Play/App stores, as they're either Chinese honeypots (<a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/china-linked-vpns-still-offered-in-apple-and-google-stores-report-warns" rel="nofollow">https://www.bitdefender.com/en-us/blog/hotforsecurity/china-...</a>) or total scams (<a href="https://www.tomsguide.com/computing/vpns/this-shady-vpn-has-seemingly-been-caught-stealing-from-windscribe" rel="nofollow">https://www.tomsguide.com/computing/vpns/this-shady-vpn-has-...</a>).<p>Do not go with a VPN service that is "mainstream" (advertised by a Youtuber) or one that has an affiliate program. Doing/having both of these things essentially requires a provider to resort so dishonest billing practices where your subscription renews at 2-5x of the original price. This is because VPNs that advertise or run affiliate programs don't make a profit on the initial purchase for that amazing deal thats 27 months with 4 months free or whatever the random numbers are, they pay all of this to an affiliate, sometimes more. Since commercial VPNs are not charities, they need ROI and that comes only when someone rebills. Since many people cancel their subscriptions immediately after purchase (to avoid the thing that follows) the rebill price is usually significantly more than the initial "amazing deal". This is why both Nord and Express have multiple class action lawsuits for dishonest billing practices - they have to do it, to get their bag (back). It's a race to the bottom of who can offer the most $ to affiliates, and shaft their customers as the inevitable result.<p>Billing quirks aside, a VPN you choose should offer multiple VPN protocols, and obfuscation techniques. There is no 1 magic protocol that just works everywhere, as every country does censorship differently, using different tools.<p>- Some do basic DNS filtering, in which case you don't need a VPN at all, just use an encrypted DNS protocol like DOH, from any provider (Cloudflare, Google, Control D[I also run this company], NextDNS, Adguard DNS)<p>- Then there is SNI filtering, where changing your DNS provider won't have any effect and you will have to use a VPN or a secure proxy (HTTPS forward proxy, or something fancier like shadowsocks or v2ray).<p>- Finally there is full protocol aware DPI that can be implemented with various degrees of aggressiveness that will perform all kinds of unholy traffic inspection on all TCP and UDP flows, for some or all IP subnets.<p>For this last type, having a variety of protocols and endpoints you can connect to is what's gonna define your chance of success to bypass restrictions. Beyond variety of protocols, some VPN providers (like Windscribe, and Mullvad) will mess with packets in order to bypass DPI engines, which works with variable degree of success and is very region/ISP specific. You can learn about some of these concepts in this very handy project: <a href="https://github.com/ValdikSS/GoodbyeDPI" rel="nofollow">https://github.com/ValdikSS/GoodbyeDPI</a> (we borrow some concepts from here, and have a few of our own).<p>Soooo... what are good VPNs that don't do shady stuff, keeps your privacy in mind, have a reasonably sized server footprint and have features that go beyond basic traffic proxying? There is IVPN, Mullvad, and maybe even Windscribe. All are audited, have open source clients and in case of Windscribe, also court proven to keep no logs (ask me about that 1 time I got criminally charged in Greece for actions of a Windscribe user).<p>If you have any questions, I'd be happy to answer them.</p>
]]></description><pubDate>Thu, 28 Aug 2025 21:36:01 +0000</pubDate><link>https://news.ycombinator.com/item?id=45057318</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=45057318</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=45057318</guid></item><item><title><![CDATA[New comment by yegor in "The European public DNS that makes your Internet safer"]]></title><description><![CDATA[
<p>Sure, I'll go to court on your behalf, instead of selling you out: <a href="https://windscribe.com/blog/windscribe-greek-court-case/" rel="nofollow">https://windscribe.com/blog/windscribe-greek-court-case/</a><p>"a non-profit with a member-elected board" will 100% not do that.</p>
]]></description><pubDate>Sat, 21 Jun 2025 00:05:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=44333294</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=44333294</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44333294</guid></item><item><title><![CDATA[New comment by yegor in "The European public DNS that makes your Internet safer"]]></title><description><![CDATA[
<p>Try this instead, also based in Canada: <a href="https://controld.com/free-dns" rel="nofollow">https://controld.com/free-dns</a> (self-promotion)</p>
]]></description><pubDate>Fri, 13 Jun 2025 22:52:11 +0000</pubDate><link>https://news.ycombinator.com/item?id=44272992</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=44272992</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=44272992</guid></item><item><title><![CDATA[New comment by yegor in "Personal VPN services are snake oil"]]></title><description><![CDATA[
<p>I run a commercial VPN service (Windscribe). Here are my thoughts on this.<p>At its core, a basic VPN is a trust shift service, nothing more. Do you trust your ISP less than an some anonymous shell company owned by Siberian forest dwellers? In many cases, the answer is no.<p>That being said, depending on where you are and if you choose the "right" VPN, the answer could be yes. Here are some reasons why you may want to use a good commercial VPN, which goes beyond just the ability to tunnel your traffic through a remote endpoint:<p>- You are in Russia, China, Iran or other countries with heavily censored Internet. Over 3 billion people live in such places, or nearly 50% of the world's population.<p>- If you don't live in such places, laws in certain US states criminalize certain behaviors. This will only get worse, even in "western democracies". Using a quality VPN service is much better than barebacking the Internet.<p>- You want your traffic to be "lost in the crowd", something you cannot achieve with your Digital Ocean droplet, no matter how well you configure it. Changing your IP does absolutely nothing, safe a few exceptions (piracy, or keeping an alter ego if your opsec is good)<p>- Additional features: server side DNS filtering / blocking. Yes you can use uBlock origin, but not on mobile, and not outside the browser. Yes you can run Pi-Hole, and setup WG tunnels to your homelab. 99% of people won't.<p>- Advanced features: Companion browser extensions that block ads, trackers, malicious domains, mess with your browser settings to reduce chances of fingerprinting. Yes you can install 5+ different extensions to do that. Most people won't.<p>TLDR; If you're an elite haxor, you can do everything yourself. You will spend time, and money doing so. Most people will not bother or not be able to do these things, and a quality commercial VPN service can check a lot of the boxes I mentioned above. Just avoid the ones that advertise heavily, those are marketing / snakeoil sales companies, as the author suggested.</p>
]]></description><pubDate>Sun, 14 Apr 2024 22:26:40 +0000</pubDate><link>https://news.ycombinator.com/item?id=40035038</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=40035038</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=40035038</guid></item><item><title><![CDATA[New comment by yegor in "Connecting HoneyGain to NordVPN and Parent Company OxyLabs"]]></title><description><![CDATA[
<p>Interesting/juicy details here.</p>
]]></description><pubDate>Wed, 18 Oct 2023 16:29:57 +0000</pubDate><link>https://news.ycombinator.com/item?id=37931051</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=37931051</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37931051</guid></item><item><title><![CDATA[New comment by yegor in "2023 Paid VPN Relationship and Corporate VPN Ownership Map"]]></title><description><![CDATA[
<p>Hide your DNS queries and SNI from your network admin mom, as you browse pornhub.com<p>Also, Azerbaijanian Netflix is real hot these days.</p>
]]></description><pubDate>Wed, 30 Aug 2023 17:23:23 +0000</pubDate><link>https://news.ycombinator.com/item?id=37325573</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=37325573</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37325573</guid></item><item><title><![CDATA[New comment by yegor in "2023 Paid VPN Relationship and Corporate VPN Ownership Map"]]></title><description><![CDATA[
<p>This list isn't about "dirt" but rather connections between companies and organizations. Windscribe is independent, and 100% privately owned.<p>Source: Me, as a co-founder.<p>If you want dirt on us, you can find it on our blog, written by me. 
<a href="https://blog.windscribe.com/ukrainian-server-seizure-a-commentary-and-state-of-the-industry-e71e8d205b26/" rel="nofollow noreferrer">https://blog.windscribe.com/ukrainian-server-seizure-a-comme...</a></p>
]]></description><pubDate>Wed, 30 Aug 2023 17:20:47 +0000</pubDate><link>https://news.ycombinator.com/item?id=37325531</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=37325531</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37325531</guid></item><item><title><![CDATA[New comment by yegor in "2023 Paid VPN Relationship and Corporate VPN Ownership Map"]]></title><description><![CDATA[
<p>Contrary to popular belief, IP blocking isn't the most common way VPNs are blocked these days. Additionally, GFW isn't the same in all of China. Different networks, different cities, have different filtering policies and rule sets. Same as in Russia now.</p>
]]></description><pubDate>Wed, 30 Aug 2023 17:17:32 +0000</pubDate><link>https://news.ycombinator.com/item?id=37325463</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=37325463</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37325463</guid></item><item><title><![CDATA[New comment by yegor in "2023 Paid VPN Relationship and Corporate VPN Ownership Map"]]></title><description><![CDATA[
<p>VPNmentor, a VPN review site, was acquired by Kape "Technologies" for 150M.<p>PrivateInternetAccess, a major VPN service was acquired by the same company for 95M.<p>A VPN review site is worth more than most VPN services it promotes due to insane $CPA they pay to these types of sites, that masquerade  as "security exports" while in reality ran by marketing people.<p>Look at their staff: <a href="https://www.vpnmentor.com/about-us/" rel="nofollow noreferrer">https://www.vpnmentor.com/about-us/</a><p>Every "favorite" VPN is a property they own, except for the sole NordVPN guy.</p>
]]></description><pubDate>Wed, 30 Aug 2023 17:10:38 +0000</pubDate><link>https://news.ycombinator.com/item?id=37325356</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=37325356</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37325356</guid></item><item><title><![CDATA[New comment by yegor in "2023 Paid VPN Relationship and Corporate VPN Ownership Map"]]></title><description><![CDATA[
<p>A VPN is not an ISP, at least as Canadian law (currently) is concerned. ISPs are required to store IP assignment logs, VPNs are not. Additionally, VPNs (in Canada) cannot be compelled to log users.<p>Source: Our law firm (I'm from Windscribe), and first hand experience with RCMP.</p>
]]></description><pubDate>Wed, 30 Aug 2023 17:02:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=37325217</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=37325217</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37325217</guid></item><item><title><![CDATA[New comment by yegor in "2023 Paid VPN Relationship and Corporate VPN Ownership Map"]]></title><description><![CDATA[
<p>Your network probably intercepts TLS, are you on a work/school network?</p>
]]></description><pubDate>Wed, 30 Aug 2023 16:58:28 +0000</pubDate><link>https://news.ycombinator.com/item?id=37325131</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=37325131</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=37325131</guid></item><item><title><![CDATA[New comment by yegor in "Make your own VPN with Fly.io, tailscale and GitHub"]]></title><description><![CDATA[
<p>You're not wrong. All of those are possible. However some countries are better than others for some points you raised. For example, Canada has no NSL (National security letter) equivalents. We cannot be compelled to covertly log some/all of our users with the current laws on the books. Of course this can change in the future.<p>Shady businesses are out of scope when it comes to laws, but that's true for any industry. There are ways to protect yourself, if your opsec warrants it, by "double wrapping" and using 2 separate VPN providers simultaneously.<p>Greed is also a huge factor. Dishonest providers can implement all kinds of SDKs into their software and 2-3x their revenues. This is why its important to use VPNs that offer open source apps you can audit and compile yourself which would protect against some obvious violations, but one can do all kinds of evil shit server side without the end user ever knowing.</p>
]]></description><pubDate>Thu, 25 May 2023 18:49:43 +0000</pubDate><link>https://news.ycombinator.com/item?id=36074514</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=36074514</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36074514</guid></item><item><title><![CDATA[New comment by yegor in "Make your own VPN with Fly.io, tailscale and GitHub"]]></title><description><![CDATA[
<p>Indeed. DNS-only is 1/2 the price.<p>Just be mindful that despite it being able to spoof your location, SNI is still in the clear. <a href="https://en.wikipedia.org/wiki/Server_Name_Indication" rel="nofollow">https://en.wikipedia.org/wiki/Server_Name_Indication</a></p>
]]></description><pubDate>Thu, 25 May 2023 02:58:59 +0000</pubDate><link>https://news.ycombinator.com/item?id=36066619</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=36066619</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36066619</guid></item><item><title><![CDATA[New comment by yegor in "Make your own VPN with Fly.io, tailscale and GitHub"]]></title><description><![CDATA[
<p>If your use case is to access home content/services while abroad, spinning up a WG server at home, or even using Tailscale "exit node feature" (<a href="https://tailscale.com/kb/1103/exit-nodes/" rel="nofollow">https://tailscale.com/kb/1103/exit-nodes/</a>) would accomplish what you need.<p>On a commercial side, we take reports from users. If someone tells us bank X doesn't work from VPN country location Y, we can fix that in minutes.</p>
]]></description><pubDate>Thu, 25 May 2023 02:25:55 +0000</pubDate><link>https://news.ycombinator.com/item?id=36066428</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=36066428</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36066428</guid></item><item><title><![CDATA[New comment by yegor in "Make your own VPN with Fly.io, tailscale and GitHub"]]></title><description><![CDATA[
<p>Literally any social network, ad network or any of these <a href="https://whotracks.me/companies/reach-chart.html" rel="nofollow">https://whotracks.me/companies/reach-chart.html</a></p>
]]></description><pubDate>Thu, 25 May 2023 02:22:31 +0000</pubDate><link>https://news.ycombinator.com/item?id=36066409</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=36066409</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36066409</guid></item><item><title><![CDATA[New comment by yegor in "Make your own VPN with Fly.io, tailscale and GitHub"]]></title><description><![CDATA[
<p>It would be suicidal for a commercial "non logging" VPN to keep track of IPs + timestamps. It also costs money to store this (best DB is no DB), and does not guarantee 1:1 mapping even if it was in place as exit IPs are shared by multiple users at any given moment.</p>
]]></description><pubDate>Thu, 25 May 2023 02:21:03 +0000</pubDate><link>https://news.ycombinator.com/item?id=36066402</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=36066402</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36066402</guid></item><item><title><![CDATA[New comment by yegor in "Make your own VPN with Fly.io, tailscale and GitHub"]]></title><description><![CDATA[
<p>Probably, in theory, yes.</p>
]]></description><pubDate>Thu, 25 May 2023 02:19:09 +0000</pubDate><link>https://news.ycombinator.com/item?id=36066394</link><dc:creator>yegor</dc:creator><comments>https://news.ycombinator.com/item?id=36066394</comments><guid isPermaLink="false">https://news.ycombinator.com/item?id=36066394</guid></item></channel></rss>