HN user

rasengan

4,976 karma

The only VPN that can’t spy on you is VP.NET since you can verify what is running on the servers using Intel SGX attention.

My comments are my own and do not reflect any of the organizations, or nations, I belong to unless I specifically clarify as such in a comment.

Posts323
Comments1,192
View on HN
nsa.2026.action.cr.yp.to 25d ago

NSA's SIGINT Enabling Project includes sabotaging cryptographic standards

rasengan
16pts3
bmail.ag 2mo ago

A Private (PQ Safe) E-Mail Provider You Can Verify End to End

rasengan
2pts0
github.com 3mo ago

Show HN: Clone, a small Rust VMM, forks VMs in under 20ms via CoW

rasengan
11pts3
news.ycombinator.com 3mo ago

I built a free SSH relay for homelab machines behind CGNAT

rasengan
2pts0
news.ycombinator.com 3mo ago

Show HN: Chrome Developer Tools on Android

rasengan
1pts0
github.com 3mo ago

Latch: Terminal multiplexer, like tmux, with SSH, mosh, and web access built in

rasengan
2pts1
github.com 3mo ago

Show HN: Pure Go mosh client, server, and WASM build for the browser

rasengan
1pts1
developer.chrome.com 8mo ago

Google Chrome Developer Tools: AI Powered Suggestions

rasengan
1pts1
ai.vp.net 8mo ago

Verifiably Private AI

rasengan
2pts1
twitter.com 8mo ago

Dr. Daniel J. Bernstein (djb) suspended from IETF

rasengan
6pts2
vp.net 9mo ago

Apple Is Monitoring You

rasengan
2pts1
vp.net 9mo ago

Borders Don't Protect You

rasengan
3pts0
vp.net 9mo ago

Proton's New Governance Links It to State-Supported Foundation?

rasengan
2pts1
vp.net 9mo ago

Fly.io Turned a Security Breach into "BrAnD" Damage Control

rasengan
1pts1
vp.net 9mo ago

These Are the Infrastructure Companies That Know Nearly Every Website You Visit

rasengan
3pts0
vp.net 10mo ago

Verified Privacy vs. "Trust" Marketing: A Case with NordVPN and Obscura

rasengan
2pts0
vp.net 10mo ago

A Zero Trust VPN

rasengan
5pts1
vp.net 10mo ago

Why VPN Audits Don't Protect Your Privacy

rasengan
3pts1
vp.net 11mo ago

The London Bridge Effect

rasengan
1pts2
github.com 11mo ago

Show HN: A Provably Zero Trust VPN

rasengan
10pts2
news.ycombinator.com 11mo ago

Privacy, Code, and the Future

rasengan
10pts4
irc.com 1y ago

Show HN: IRC.com – A Scriptable Web IRC Client

rasengan
5pts6
soj.ooo 1y ago

Show HN: Hello, World – Introducing Soj.ooO

rasengan
2pts3
lowendtalk.com 1y ago

FBI Seizes StarkRDP and Rdp.sh

rasengan
2pts0
github.com 1y ago

Scrcpy: Application mirrors Android devices (A/V) connected via USB or TCP

rasengan
9pts0
www.reuters.com 1y ago

AT&T February wireless outage blocked more than 92M calls, agency says

rasengan
4pts2
twitter.com 2y ago

Jellyfin is suffering from a DDoS attack

rasengan
9pts1
o565.com 2y ago

Drink Me: (Ab)Using a LLM to Compress Text

rasengan
1pts0
ubuntu.com 2y ago

Ubuntu 24.04 LTS

rasengan
5pts2
gofetch.fail 2y ago

GoFetch: Exposing Apple M1 Encryption Keys [pdf]

rasengan
4pts0

I certainly find it fascinating that the majority of those in favor come from signal intelligence agencies, while the majority of those against are PhD cryptographers.

I was happy to see the lead of Europe’s PQC team also voted with the cryptographers.

Ubuntu 26.04 3 months ago

TPM-backed full-disk encryption

This is going to be very useful for servers hosted in third party DCs.

Use latch to ssh, mosh or web into your machine. latch multiplexes terminal windows (like screen or tmux).

We built this for use on UnixShells [1].

All remote connections are verified against the authorized_keys and are, of course, end to end encrypted.

This is MIT licensed. There is also a relay that lets you connect to your latch sessions that are behind NAT - this has a small cost to it for infrastructure. However, you can use tailscale/ngrok or your own external IP for free.

https://github.com/unixshells/latch

[1] https://unixshells.com

I don't know if I agree or not with his views, but the fact that he's moving from complaining about something, to doing something about his beliefs, has convinced me to move from a negative to a significantly positive view of him, as a person; to reiterate, regardless of whether I agree with said views.

The will to fight for what one believes in - I think we can all agree that is an admirable human trait that would result, for those who do follow his views, in him being labeled as a hero and defender of people's rights.

Bravo, Garry.

Memories of .us 8 months ago

Some IRC networks still use naming as such like "server.state.country.dal.net."

[dead] 8 months ago

This is a terrible day for the archival of the internet. Under the guise of copyright, significant information has been de-platformed.

This follows after djb pointed out that the NSA was weakening encryption by recommending and demanding PQ encryption alone instead of the hybrid PQ+ECC pair that is safer, with this being blocked despite considerable opposition by the actual experienced researcher participants in the group.

Bad times for the internet.

Whitehouse.gov 9 months ago

At various times in history, the White House has been known as the “President’s Palace,” the “President’s House,” and the “Executive Mansion.”

I wonder how much longer the structure will be known by its current name, given the growing trend of letting slanderous/fringe uses of words dictate their dominant meanings [1].

[1] For example, the end of the master branch.

The way digital data is decaying [1], books are disappearing and so on, the Internet Archive is critical infrastructure.

Happy Internet Archive Day! :-)

[1] servers gone, hosting sites gone, etc.

[dead] 9 months ago

If a VPN provider can and does log when it receives complaints, it is no longer a “no log” VPN.

[dead] 9 months ago

The archived posts are literally linked in the post.

This is a great list of academic attacks, but it proves less than you think.

Yes, TEEs have been broken in dozens of ways. Side channels, transient execution, voltage manipulation, interrupt timing... etc. To be fair, you could make an equally impressive list for many security primitives.

The question isn't "can TEEs be broken?" since clearly they can, but rather what's your threat model and what are your alternatives?

What TEEs actually defend against is passive compromise. They force an attacker to actively exploit rather than just read memory. That legal and operational distinction matters enormously in practice.

The alternative to TEE is "no hardware isolation at all," and that's strictly worse for every threat model where TEEs provide value.

Additionally, you still get attestation which gives you cryptographic proof of what code is running.

Surveillance is the occupation of the mental space and results in modification of behavior. Default mass surveillance, or in other words suspicionless surveillance, then leads to the end of mental sovereignty and, therefore, freedom.

That is not a state governed by rule of law, but instead, a peoples being ruled by the power of surveillance.

They worked pretty hard as detailed in an archived article changing names and any records they could [1], but you're right - not good enough [2].

As pointed out on this reddit post [3], Proton's appears to contradict itself a number of times.

It's a good thing trust based VPN's are obsolete. After all, trust isn't constant [4] as seen in this article showing how Proton supplied IP addresses to "authorities."

[1] https://archive.ph/wG8t8

[2] https://archive.ph/4bzBm

[3] https://www.reddit.com/r/technology/comments/8x9aik/protonvp...

[4] https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...

My comment still applies regardless of any level of “explaining” [1]:

1. Either Nord/Teso are loose with keys (horrible)

Or

2. Proton isn’t being truthful.

I don’t think it’s a conspiracy or anything that it is Tesonet/Nord. Rather, the problem is you cannot trust someone with your privacy if they can’t even manage their own keys.

[1] The explanation is poor at best and doesn’t explain why they worked so hard to try to delete all of the evidence (all of which was archived already). Additionally, nothing can explain away the lack of security with key management across these two orgs.