@HNmods, any reason this was removed from the first page?
HN user
coderrr
Here is a way some of our customers are using OpenVPN on iOS:
https://www.privateinternetaccess.com/forum/index.php?p=/dis...
FYI, this is the info page for our new (beta) OpenVPN based client which supports multiple encryption options:
https://www.privateinternetaccess.com/forum/index.php?p=/dis...
We'll use standard DHE if the user selects an RSA cert (2048, 3072, or 4096). And we'll use ECDHE if the user selects an Elliptic Curve cert. We'll also be displaying a disclaimer about the potential issues with ECC (certain experts believe TLS curves may be compromised/weakened) if the user selects that.
You're probably right. We've already changed to 2048 DH everywhere. Do you have any opinion on if that is a strong enough default?
For OpenVPN - which is the only protocol we advise for real security (PPTP and IPSec/L2TP are fine for just hiding your IP) - we don't use pre-shared keys. OpenVPN uses TLS for exchanging strong symmetric keys. Your password is only used for authentication and its entropy isn't related to your session's security.
If you use PIA our Windows (and OSX) app has a feature (on by default) which blocks IPv6 while you're on the VPN.
https://www.privateinternetaccess.com/pages/client-support/#...
Uh, no. We aren't subsidized by the NSA or any part of any government or any organization or person for that matter. We bootstrapped Private Internet Access with 500$ and a lot of caffeine and have been profitable since our second month in operation.
We believe what the NSA is referring to when talking about "VPN startups" is the initial stages of PPTP sessions. PPTP has been crackable for a while, check out moxie's cloudcracker.com. We believe it highly unlikely that they have broken OpenVPN (which is what our application uses) or SSL.
Please see our stance on PRISM: https://www.privateinternetaccess.com/blog/2013/06/prism/
Looks like app.net isn't perfect either. Their HSTS isn't implemented correctly. Only 'alpha.app.net' and 'join.app.net' are protected while 'app.net' is not. They fell into one of the common pitfalls with their http->https redirects: http://coderrr.wordpress.com/2010/12/27/canonical-redirect-p... You can verify this at: chrome://net-internals/#hsts
http://bitcoin.stackexchange.com/users/85/david-schwartz?tab... ... ctrl-f, ripple
Has anyone else not been receiving 'charge.succeeded' events on their Stripe webhooks? We have been receiving all events except that one, even when all charges are succeeding as verified through the management panel. This is a big problem as that is the event that's used to actually process a payment and create a new account.
The problem seems to have been going over for around 8 hours now.
We've received no reply from their support in 4 hours.
Anyone have any ideas how to get in contact with them at this time?
I just remembered it's not actually custom protocols with raw sockets that are common and don't respect SOCKS settings but rather Flash's RTMP protocol.
Yea I should have. I guess I forgot to because I had already done so in these other comments [1] and wrongly assumed everyone had read them as well. Anyway, I'm the cofounder of said service.
[1] http://news.ycombinator.com/item?id=4307364 and http://news.ycombinator.com/item?id=4307380
If you email me at coderrr.contact@gmail.com I can try to help figure out why you get slow speeds on some of our US servers. None of our servers are even running near capacity.
You're correct HTTP connections over flash will use HTTP proxy settings. The problem is many sites don't stream over HTTP, they use some custom streaming protocol using raw flash sockets. And these do not respect SOCKS proxy settings.
You actually can, but it's quite complicated. I wrote a post on how to do it using linux a long time ago: http://coderrr.wordpress.com/2009/07/29/how-to-force-flash-o...
I had a similar setup working with OSX using ipfw and natd. Really complex and disgusting setup though IMO. Using a VPN is so much cleaner.
As I've said in other comments. This is fun and hackerish but it's cheaper and simpler to just sign up for a VPN for a month that has UK gateways. Like https://www.privateinternetaccess.com/ for $6.95
Or you could sign up at https://www.privateinternetaccess.com for our VPN with two UK gateways for 6.95 for one month. Cheaper and much easier to setup.
And from what I remember flash does not follow the system SOCKS proxy settings: http://coderrr.wordpress.com/2009/07/29/how-to-force-flash-o...
Our VPN at https://www.privateinternetaccess.com also has multiple gigabits of bandwidth available through our two UK gateways. We have an app that provides one click setup on both windows and osx.
I'm the original creator of this site. The initial version had no market rate chart (the one in the middle). It was purely a live version of the bids/asks (see bottom graph http://bitcoincharts.com/markets/mtgoxUSD.html). After making that it didn't take much creativity to realize a price chart would fit nicely in the middle.
added indirectly in the title
that said:
endorse 1) to approve, support, or sustain
it might not be exact, but I don't think it's that far off
This is being reposted. The last post got killed from the front page due to a paragraph which was giving prizes through coinbase.com to first 5 insightful comments. That's now been removed as it was seen as scammy/cheating and of course that was not the purpose of it.
I see 'believing that there is money to be made in Bitcoin services' as 'indirectly endorsing Bitcoin'
Cheating on getting comments? I really didn't care if we had comments or not, I thought it was a good enough post on its own. I thought giving the first 5 people a prize through a YC company wouldn't be seen as scamming.
I could see the argument that if everyone did that HN would be shit. But I don't really see HN having many opportunities for people to do that.
We removed the end of our post about paying the first 5 people 0.5 BTC through coinbase since it seems that's probably what got this post killed from the front page. Kinda sad since the intention was clearly to help promote coinbase.com
How about his indirect endorsement?
The goal is to help spread usage of the YC startup and indirectly bitcoin.
if you want 0.5 BTC you gotta put an email because I'm going to send it through coinbase.com not the BTC network itself
Hey Matt, thanks a lot for investigating, I've updated the post.
please read this book:
http://www.amazon.com/Facts-Fallacies-Software-Engineering-R...