HN user

Oeck

11 karma
Posts6
Comments10
View on HN

Hi jamesponddotco,

Thanks for taking the time with this.

Unfortunately there is not much we can do about the JS. We can put up static pages for marketing, but ultimately the website is there for the user to control various things to do with their account. It also allows guests to perform various tasks.

As far as your other point about the business itself being open, we are trying to run it in that exact manner. Regarding the audit, I replied to another user ( https://news.ycombinator.com/item?id=23666681 ). However, if you have an idea on how we can run the business more open, I am happy to take it on board. We keep users in the loop, took time with our terms of service and privacy policy, as well as provided a bunch of information in the FAQ.

Regards, Peter @ Oeck.

Hi jamesponddotco,

Thank you very much for taking a look! Although you have found information in your edit, I will reply so that other users viewing the thread have an easier time reading it.

1) The company is incorporated in Hong Kong. Although we are Australian, the privacy laws in Australia suck. We wanted to keep our customers safe, so that is what ultimately lead to the decision. You can find this information at https://www.oeck.com/faq/ and more specifically at https://www.oeck.com/faq/privacy_and_security/

2) The website is built on top of Xenforo ( https://xenforo.com ). Our navigation, .ovpn builder, alerts and other features rely on JS in order to function properly.

3) I answered this in the post above, but here is the copy/paste.

Open Source apps - Due to the way our VPN works, we found the best solution for us was to use the libvpn libraries. They can be found at http://libvpn.com/

These libraries, unfortunately, are not open source. However, they are very powerful and the code is of good quality. Due to this, we are unable to make our apps completely open source.

Again, open sourcing the apps, although it looks good, ultimately doesn't mean anything. Any malicious activity can be done in the back-end. The apps source code may show up fine, but the back-end of the service can do whatever the owners want.

That's not to say open sourcing them isn't a good thing, it is just that aside from the fact that we can't do so, ultimately it means little if the service provider wanted to screw its customers.

Thank you for the Impressum idea. We will add that soon. It is a good idea and easily implemented.

Regards, Peter @ Oeck.

Hi smt88,

Thank you so much for checking it out.

This is a problem. As far as I know there are only two ways to gain trust with an audience when your company is a start up. So I am going to be completely transparent with the answer and hopefully you will see our point of view.

1) Third party security audit - This is one way of a startup gaining trust. Having a third-party audit the VPN and the VPN showing the results. We actually went to see how much something like this would cost and it was in excess of $20,000. We unfortunately do not have this sort of money to put up. In addition to that, most VPN providers who have done so were already established and had a steady stream of income.

The issue I have with this is at the end of the day it is a $20,000+ sticker you can have. Should the VPN provider wish to do so, they can easily change their system after the audit is complete and do what they like anyway. So, I agree it adds to trust, but at the end of the day it can be reversed in the background. Having said that, when we can afford to do so, we will most likely get it done to follow protocol.

2) Open Source apps - Due to the way our VPN works, we found the best solution for us was to use the libvpn libraries. They can be found at http://libvpn.com/

These libraries, unfortunately, are not open source. However, they are very powerful and the code is of good quality. Due to this, we are unable to make our apps completely open source.

Again, open sourcing the apps, although it looks good, ultimately doesn't mean anything. Any malicious activity can be done in the back-end. The apps source code may show up fine, but the back-end of the service can do whatever the owners want.

That's not to say open sourcing them isn't a good thing, it is just that aside from the fact that we can't do so, ultimately it means little if the service provider wanted to screw its customers.

I would love to hear feedback on other ways we could gain trust. In our FAQ we explain about our system and our privacy policy explains what we do not log, what we monitor etc. We also have an EV SSL certificate on the website to help build this trust.

Regards, Peter @ Oeck.

Hi everyone,

We are in need of beta testers for our VPN apps and service. We have a few beta testers, but we are in need of many more.

The VPN provides new features that are unique to Oeck. We also offer high levels of security. Any and all help would be very much appreciated.

The service is completely free for the duration of beta, so please feel free to use the service for as long as you like.

Regards, Peter @ Oeck.

Hi sho,

Yes, this is embarrassing...

We found the issue, it is a setting in Apache. This is due to the torrent of traffic we just received. We were not expecting it, but there it is. We are fixing the cause now and everything should be back up and running very soon.

It is actually good it happened during Beta. That's a "bug" that we can now fix.

EDIT: Fixed. If you get some time, please try the service and let us know what you think so far.

Regards, Peter @ Oeck.

Hi everyone,

We recently launched our VPN into a free, open beta and so far have had good feedback. We wanted to show HN our VPN and see if we could get some feedback from the community.

Our VPN works differently to other VPN services, in that we have implemented automatic region routing for select services. Added to this, we have made our port-forwarding work in a manner that whichever server you connect to, it is always reachable by an automated domain. We have also added the ability for users to create custom DNS block lists as well as use our built-in filtration.

We would love to hear feedback for those who decide to give it a go. Please note, it is still in beta and we are ironing out bugs. So if you do find a bug, please report it to us.

Regards, Peter @ Oeck.

Hi everyone,

My name is Peter and I am from the VPN startup company, Oeck. I am looking to get feedback from advanced computer users regarding our Port-forwarding feature in our VPN primarily. This is a new feature to the industry and we are looking to make it even better.

We are also looking for feedback regarding our Device Profiles feature ( which is again, new to the industry ).

We would really appreciate honest feedback from those of you who try it.

The whole VPN service is completely free during BETA, so please feel free to register an account and test it out :)

Regards, Peter @ Oeck.