HN user

coderrr

292 karma
Posts16
Comments97
View on HN
On Encryption 13 years ago

We'll use standard DHE if the user selects an RSA cert (2048, 3072, or 4096). And we'll use ECDHE if the user selects an Elliptic Curve cert. We'll also be displaying a disclaimer about the potential issues with ECC (certain experts believe TLS curves may be compromised/weakened) if the user selects that.

On Encryption 13 years ago

You're probably right. We've already changed to 2048 DH everywhere. Do you have any opinion on if that is a strong enough default?

On Encryption 13 years ago

For OpenVPN - which is the only protocol we advise for real security (PPTP and IPSec/L2TP are fine for just hiding your IP) - we don't use pre-shared keys. OpenVPN uses TLS for exchanging strong symmetric keys. Your password is only used for authentication and its entropy isn't related to your session's security.

Uh, no. We aren't subsidized by the NSA or any part of any government or any organization or person for that matter. We bootstrapped Private Internet Access with 500$ and a lot of caffeine and have been profitable since our second month in operation.

We believe what the NSA is referring to when talking about "VPN startups" is the initial stages of PPTP sessions. PPTP has been crackable for a while, check out moxie's cloudcracker.com. We believe it highly unlikely that they have broken OpenVPN (which is what our application uses) or SSL.

Please see our stance on PRISM: https://www.privateinternetaccess.com/blog/2013/06/prism/

Stripe Checkout 14 years ago

Has anyone else not been receiving 'charge.succeeded' events on their Stripe webhooks? We have been receiving all events except that one, even when all charges are succeeding as verified through the management panel. This is a big problem as that is the event that's used to actually process a payment and create a new account.

The problem seems to have been going over for around 8 hours now.

We've received no reply from their support in 4 hours.

Anyone have any ideas how to get in contact with them at this time?

You're correct HTTP connections over flash will use HTTP proxy settings. The problem is many sites don't stream over HTTP, they use some custom streaming protocol using raw flash sockets. And these do not respect SOCKS proxy settings.

This is being reposted. The last post got killed from the front page due to a paragraph which was giving prizes through coinbase.com to first 5 insightful comments. That's now been removed as it was seen as scammy/cheating and of course that was not the purpose of it.

Cheating on getting comments? I really didn't care if we had comments or not, I thought it was a good enough post on its own. I thought giving the first 5 people a prize through a YC company wouldn't be seen as scamming.

I could see the argument that if everyone did that HN would be shit. But I don't really see HN having many opportunities for people to do that.

We removed the end of our post about paying the first 5 people 0.5 BTC through coinbase since it seems that's probably what got this post killed from the front page. Kinda sad since the intention was clearly to help promote coinbase.com