Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

So how can we be sure now that todays VPNs are not tomorrows Onavos. :(


First, all VPNs spy on you, just don't believe these claims because they are forced by law to do it. Second, don't use a VPN that clearly states that they're analyzing your traffic data.


> forced by law

Which law?


National Security Letters.


Not a law.


and your ISP will not spy on you?


Don’t install additional root certificates.

That’s what Facebook enticed users to do here. Without that root cert they wouldn’t have been able to see as much as they did.


Certificate pinning and validation in apps for one. Onavo's VPN was really clear it collected market research data. It was as informed consent as a click-through could be.


Interception of encrypted communications is beyond the expectation of what most people would consider "collecting market research data"


I would expect the exact nature of the collection to be spelled out in some TOS that users probably clicked through.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: