Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[CONTENT-CHANGE] [ADD] Privacy Respecting Software > Virtual Private Networks > OVPN #12

Closed
atomGit opened this issue Apr 19, 2022 · 2 comments
Assignees
Labels
enhancement New feature or request

Comments

@atomGit
Copy link

atomGit commented Apr 19, 2022

OVPN was just recommended to me by Michael Horowitz who wrote A Defensive Computing Checklist

OVPN (they do WG too) looks like another interesting one (i haven't used it)...

Total infrastructure ownership

All the hardware used to operate OVPN is owned by us. All VPN servers operate without hard drives as the operating system only resides in the RAM memory.

No rented servers, no virtual machines. Just pure baremetal hardware that we've either shipped or installed ourselves.

"Total infrastructure ownership" of course does not refer to the data-centers

also of interest...

OVPN has been in court fighting a two-month long information injunction as user information was requested from us. OVPN emerged victorious due to our no-logging policy.

We have an insurance that covers legal fees. OVPN has never given any information about our customers to a third party.

...

Monthly transparency reports have been published since 2014, detailing server statistics & information requests.

The company running OVPN is incorporated in Sweden and is named "OVPN Integritet AB". Integritet means Privacy in Swedish. That's how engrained our privacy focus is. The physical owners are David Wibergh & Ruben Rehn.

@atomGit atomGit added the enhancement New feature or request label Apr 19, 2022
@Lissy93
Copy link
Owner

Lissy93 commented Apr 20, 2022

Thanks for the request.
Looks really good. I like their security page, clear yet contains everything you'd need to know. Level 7, legal insurance is pretty cool, as they'll be able to fight against a subpoena / data request.

I reached out to them with regards to lack of an audit, no open source apps, warrant canary, and the questions regarding the analytics + data they are collecting on their homepage. And in case anyone is interested, here was their reply:

Our own apps are not open source yet, but that's something on our to-do list. You're free to use the normal WireGuard and OpenVPN Connect apps though if you prefer to use open-source applications, we provide configuration files for that.

No, we don't have a warrant canary. Warrant canary is mostly a sale ploy by some VPN providers; there's nothing that stops the FBI from seeing a warrant canary as a breach.

With that said, there's no equivalence to that in Sweden, we're free to disclose how many times the police have contacted us. We mention in our monthly transparency reports how many times police has contacted us that month.

We haven't had an independent audit, although that is something we hope to have this year. We have had a court case though which we won.

We don't use analytics. The pricing page doe suse PayPal, yes, but that's for PayPal payments. BrainTree is for credit card payments, and Intercom is our support platform. We plan to switch from BrainTree to Stripe, but in that case it'd just switch from BrainTree to Stripe.

As for cryptocurrencies, we're open to suggestions if you have any.

My only concern, and it is a minor one, is that their website is really bad, it's full of analytics, even just visiting the homepage it's sending data to PayPal, Intercom (for chat), Piwik (self-hosted though), Braintree, etc. And for crypto payments they're using coinpayments.net, which has a very questionable privacy policy. And I feel like their answer (above) wasn't very sufficient. My first thought, was if their website is this sloppy, it doesn't instill confidence about how they run the rest of their infrastructure. But that's just my opinion, and it's probably just a side effect of a smaller company.

I do trust Michael Horowitz, and am sure he will have done substantial research before recommending it.
I'm going to try it out properly later today. But 11 quid for a single month with multi-hop, is quite steep!

Unless anyone else has anything to add, or any reservations, I am happy for OVPN to be added to the list.

@Lissy93 Lissy93 transferred this issue from Lissy93/personal-security-checklist Jul 10, 2022
Lissy93 added a commit that referenced this issue Jul 13, 2022
@Lissy93
Copy link
Owner

Lissy93 commented Jul 13, 2022

Added.

@Lissy93 Lissy93 closed this as completed Jul 13, 2022
Lissy93 added a commit that referenced this issue Jan 14, 2023
* Change weather to whether

* Remove track ref

- Links with referential content may violate privacy. so i removed it

* Adds automations to notify if domain expiring

* Updates browser extensions, F-Droid, Thunderbird

Closes #15 Closes #16 Closes #17 Closes #18

* Adds plaintext accounting tools (#14)

* Adds OVPN under VPNs (#12)

* Adds Code Hosting under Development (#6)

* Typo fixes

* Fix my own typo

* Couple more typos

* Typos

* The last typos

* Fixes title in amendment issue template

* Fixes typo, CalmAV →ClamAV (#31)

Fixes #31

* fix very small typo on ScriptSafe extension

yo - > to

* Adds age under File Encryption (#32)

Fixes #32

* Updates contributor SVG

* Updates contributors list

* Renames master branch to main

* feat: add Vikunja

* Fixed spelling of Krita and edited VM description

Fixed the spelling of Krita. I also edited the description for the Virtual Machine section to say "virtual machine (VM)" instead of just "VM".

* Updates contributors list

* Updates contributor SVG

* Creates action for PDF compilation

* Update compile-pdf.yml

* Update compile-pdf.yml

* Adds git push for pdf

* Update compile-pdf.yml

* Generate PDF file

* Add action to check spelling for PRs

* Update spell checker to cover all files

* Adds action for easier rebasing of PRs

* Move Bromite to Browsers table

The table does not include any mobile browsers. Some should probably be included.

* Adds  Logseq under Digital Notes (#40)

Fixes #40

* Move & expand on SearX in Search Engines

Mention SearXNG, split out from main mentions

* Fix typo (FairMail to FairEmail)

Change FairMail to FairEmail

* Adds relevent info link to Extensions

Adds link to page on arkenfox wiki about extensions

* Adds Insular to Mobile Apps

Insular is another sandboxing app

* Tweak Org Mode section

Expands upon and fixes the previous not-too-accurate description

* Fix it's vs its

* Removed uMatrix from Browser Extensions, as unmaintained

uMatrix is [no longer maintained](uBlockOrigin/uMatrix-issues#291 (comment)).

* fix links

* Add utm

* Light works is **not** open source

* Adds action to validate issue title

* Adds missing blank space after VM --> UTM

* Added servers guru

* [FIX] typos

* Update Ricochet messaging app

* Add Prosody, jsxc, xmpp-web to Self-Hosted Svc

- Fix "XMP" -> "XMPP"
- Remove project Candy, seems dead since 2020: candy-chat/candy#519

* Added photoprism entry in two bonus sections

Closes #60

* Changed capitalization

Changed the capitalization of the photoprism Bonus #5 entry for consistency

* Reverting mistake

Deleted a line by mistake, reverted.

* Use only issues for ticket-check trigger

* Update LocalCDN link

- The project has archived their gitlab repository and moved to
codeberg.org

* Fixes the links in the PR template

* Adds action to prevent un-named PRs

* Adds SpotiFlyer under Audio

* Updates order of checks

* Removes title length requirement

* Updates pinned version

* Adds check for checklist

* Automation to label PRs

* Applies brackets

* Updates conditional

* Quoted expression in PR labler

* Updates contributors list

* Updates contributor SVG

* Adds category option to PR template

* Automation for Codeberg mirror

* Changes base action for codeberg mirror

* Inserts link to Codeberg mirror

* Updates issue validator

* Updates ticket validator automation

* Adds check for issue categrory and checklist

* Delete .github/workflows/config directory

* Delete rebase-pr.yml

* Set permissions

* Rewrites the pull request validation

* Fixes default label ignore

* Fixes spelling in comments within PR template

* Updates permissions for PR validator

* Fixes workflow PR permissions

* Adds Betterbird under mail clients (#82)

Fixes #82

* Updates contributors list

* Generate PDF file

* Corrects [Searx URL]

Updates Searx Url throughout readme

* Updates contributor SVG

* Updates contributors list

* Generate PDF file

* Update README.md

Correcting the capitalisation of Bitwarden (as on their website)

* Update README.md

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Various Typo Fixes

 - Quant -> Qwant
 - and -> an
 - Suit -> Suite
 - fre -> free
 - ). -> .

* Updates contributors list

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates contributor SVG

* Updates contributors list

* Generate PDF file

* add Skiff

* correct typos

* remove pages and drive from mail section

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Generate PDF file

* Replace RainLoop with SnappyMail due to vulnerability

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates conflict

* Updates contributors list

* Generate PDF file

* Add Vaultwarden to Bitwarden

* Replace OTR with XMPP clients with OMEMO

* Add Movim for blogging & as XMPP web client

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Improved information about LibreWolf

- Correct spelling
- Correct (new) homepage
- Clear up how it differs from Firefox

* Updates contributors list

* Generate PDF file

* Updates contributor SVG

* Generate PDF file

* Updates formatting on credits page

* Updates contributing info in credits page

* Updates contributors list

* Adds link to credits page

* Updates contributors list

* Generate PDF file

* Remove Vanilla Cookie Manager

See #116

* Removes andOTP from Google Alternatives

* Fixes broken link for NextCloud in Backup & Sync section

Fixes link to sync docs in the backup & sync section for NextCloud.

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Adds Authenticator(BrowserExtension) to Essentials 2-Factor Authentication

* Add monerosms.com to virtual phone numbers

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Update Codeberg entry

* Updates contributor SVG

* Updates contributors list

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Remove Bibliogram as it is discontinued

* Change Libreddit instance to official one

* Resolves conflicts

* Fixing typo

* At Social Networks/Other Notable Mentions added Hubzilla

Hubzilla is kind of the successor of Friendica (the original author auf Friendica went on with Hubzilla). Both systems exists together, both support the widest range of social network protocols.

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Writes an about page

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

Co-authored-by: Kieran <kieranrobson1999@gmail.com>
Co-authored-by: 0x0102121wqs <108590577+0x0102121wqs@users.noreply.github.com>
Co-authored-by: Alicia Sykes <alicia@omg.lol>
Co-authored-by: cole <40342475+colenh@users.noreply.github.com>
Co-authored-by: liss-bot <liss-bot@d0h.co>
Co-authored-by: kolaente <k@knt.li>
Co-authored-by: NylaTheWolf <41797151+NylaTheWolf@users.noreply.github.com>
Co-authored-by: Lilith <78992082+lilithium-hydride@users.noreply.github.com>
Co-authored-by: Maksim Ploski <50287455+plplmax@users.noreply.github.com>
Co-authored-by: A-childs-encyclopedia <abdhllah005@gmail.com>
Co-authored-by: Slade <secher.guillaume@protonmail.com>
Co-authored-by: pnxdxt <paul.nodet@gmail.com>
Co-authored-by: Guillaume <ltGuillaume@users.noreply.github.com>
Co-authored-by: kerbless <kerbless@protonmail.com>
Co-authored-by: Gusted <williamzijl7@hotmail.com>
Co-authored-by: Wesley-Ryan <69822796+Wesley-Ryan@users.noreply.github.com>
Co-authored-by: James Cridland <james@cridland.net>
Co-authored-by: jxhn <1396009+jxhn@users.noreply.github.com>
Co-authored-by: Andrew Milich <milichab@gmail.com>
Co-authored-by: alex <37013819+baddate@users.noreply.github.com>
Co-authored-by: Alex Ogden <1379601+AlexOgden@users.noreply.github.com>
Co-authored-by: Ash Scott <AshboDev@users.noreply.github.com>
Co-authored-by: mrpavan <mr.pavan@gmail.com>
Co-authored-by: Kevin F <beardog@mailbox.org>
Co-authored-by: magical-heyrovsky <101060148+magical-heyrovsky@users.noreply.github.com>
Co-authored-by: Sam Al-Sapti <sam@sapti.me>
Co-authored-by: GhoulBoii <78494833+GhoulBoii@users.noreply.github.com>
Co-authored-by: Tim Schlotfeldt <ts+github@ml.tschlotfeldt.de>
Lissy93 added a commit that referenced this issue Mar 4, 2023
* Change weather to whether

* Remove track ref

- Links with referential content may violate privacy. so i removed it

* Adds automations to notify if domain expiring

* Updates browser extensions, F-Droid, Thunderbird

Closes #15 Closes #16 Closes #17 Closes #18

* Adds plaintext accounting tools (#14)

* Adds OVPN under VPNs (#12)

* Adds Code Hosting under Development (#6)

* Typo fixes

* Fix my own typo

* Couple more typos

* Typos

* The last typos

* Fixes title in amendment issue template

* Fixes typo, CalmAV →ClamAV (#31)

Fixes #31

* fix very small typo on ScriptSafe extension

yo - > to

* Adds age under File Encryption (#32)

Fixes #32

* Updates contributor SVG

* Updates contributors list

* Renames master branch to main

* feat: add Vikunja

* Fixed spelling of Krita and edited VM description

Fixed the spelling of Krita. I also edited the description for the Virtual Machine section to say "virtual machine (VM)" instead of just "VM".

* Updates contributors list

* Updates contributor SVG

* Creates action for PDF compilation

* Update compile-pdf.yml

* Update compile-pdf.yml

* Adds git push for pdf

* Update compile-pdf.yml

* Generate PDF file

* Add action to check spelling for PRs

* Update spell checker to cover all files

* Adds action for easier rebasing of PRs

* Move Bromite to Browsers table

The table does not include any mobile browsers. Some should probably be included.

* Adds  Logseq under Digital Notes (#40)

Fixes #40

* Move & expand on SearX in Search Engines

Mention SearXNG, split out from main mentions

* Fix typo (FairMail to FairEmail)

Change FairMail to FairEmail

* Adds relevent info link to Extensions

Adds link to page on arkenfox wiki about extensions

* Adds Insular to Mobile Apps

Insular is another sandboxing app

* Tweak Org Mode section

Expands upon and fixes the previous not-too-accurate description

* Fix it's vs its

* Removed uMatrix from Browser Extensions, as unmaintained

uMatrix is [no longer maintained](uBlockOrigin/uMatrix-issues#291 (comment)).

* fix links

* Add utm

* Light works is **not** open source

* Adds action to validate issue title

* Adds missing blank space after VM --> UTM

* Added servers guru

* [FIX] typos

* Update Ricochet messaging app

* Add Prosody, jsxc, xmpp-web to Self-Hosted Svc

- Fix "XMP" -> "XMPP"
- Remove project Candy, seems dead since 2020: candy-chat/candy#519

* Added photoprism entry in two bonus sections

Closes #60

* Changed capitalization

Changed the capitalization of the photoprism Bonus #5 entry for consistency

* Reverting mistake

Deleted a line by mistake, reverted.

* Use only issues for ticket-check trigger

* Update LocalCDN link

- The project has archived their gitlab repository and moved to
codeberg.org

* Fixes the links in the PR template

* Adds action to prevent un-named PRs

* Adds SpotiFlyer under Audio

* Updates order of checks

* Removes title length requirement

* Updates pinned version

* Adds check for checklist

* Automation to label PRs

* Applies brackets

* Updates conditional

* Quoted expression in PR labler

* Updates contributors list

* Updates contributor SVG

* Adds category option to PR template

* Automation for Codeberg mirror

* Changes base action for codeberg mirror

* Inserts link to Codeberg mirror

* Updates issue validator

* Updates ticket validator automation

* Adds check for issue categrory and checklist

* Delete .github/workflows/config directory

* Delete rebase-pr.yml

* Set permissions

* Rewrites the pull request validation

* Fixes default label ignore

* Fixes spelling in comments within PR template

* Updates permissions for PR validator

* Fixes workflow PR permissions

* Adds Betterbird under mail clients (#82)

Fixes #82

* Updates contributors list

* Generate PDF file

* Corrects [Searx URL]

Updates Searx Url throughout readme

* Updates contributor SVG

* Updates contributors list

* Generate PDF file

* Update README.md

Correcting the capitalisation of Bitwarden (as on their website)

* Update README.md

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Various Typo Fixes

 - Quant -> Qwant
 - and -> an
 - Suit -> Suite
 - fre -> free
 - ). -> .

* Updates contributors list

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates contributor SVG

* Updates contributors list

* Generate PDF file

* add Skiff

* correct typos

* remove pages and drive from mail section

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Generate PDF file

* Replace RainLoop with SnappyMail due to vulnerability

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates conflict

* Updates contributors list

* Generate PDF file

* Add Vaultwarden to Bitwarden

* Replace OTR with XMPP clients with OMEMO

* Add Movim for blogging & as XMPP web client

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Improved information about LibreWolf

- Correct spelling
- Correct (new) homepage
- Clear up how it differs from Firefox

* Updates contributors list

* Generate PDF file

* Updates contributor SVG

* Generate PDF file

* Updates formatting on credits page

* Updates contributing info in credits page

* Updates contributors list

* Adds link to credits page

* Updates contributors list

* Generate PDF file

* Remove Vanilla Cookie Manager

See #116

* Removes andOTP from Google Alternatives

* Fixes broken link for NextCloud in Backup & Sync section

Fixes link to sync docs in the backup & sync section for NextCloud.

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Adds Authenticator(BrowserExtension) to Essentials 2-Factor Authentication

* Add monerosms.com to virtual phone numbers

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Update Codeberg entry

* Updates contributor SVG

* Updates contributors list

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Remove Bibliogram as it is discontinued

* Change Libreddit instance to official one

* Resolves conflicts

* Fixing typo

* At Social Networks/Other Notable Mentions added Hubzilla

Hubzilla is kind of the successor of Friendica (the original author auf Friendica went on with Hubzilla). Both systems exists together, both support the widest range of social network protocols.

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Writes an about page

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Adds Budzet Zen to Budgeting Tools (#149)

* Add Budget Zen - End-to-End Encrypted Budget/Expense Manager

Full disclosure: I'm the author of [Budget Zen](https://budgetzen.net).

Budget Zen 2.0 is end-to-end encrypted via [userbase](https://userbase.com). You can read more about [that announcement here](https://news.onbrn.com/announcing-budget-zen-2.0-end-to-end-encrypted).

It's also Open Source (AGPL 3.0), and you can [view the source code in GitHub](https://github.com/BrunoBernardino/budgetzen-web).

* Updates BudgetZen

Moves to notable mentions until the project is more mature

Co-authored-by: Alicia Sykes <alicia@omg.lol>

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Updates Enigmail information and Removes TorBirdy (#153)

* Updates Enigmail entry - removes support for Thunderbird and corrects typo.

* Removes TorBirdy - dead project

* fix: remove silence (#154)

* Syncs contributors from upstream

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Updates contributors list

* Generate PDF file

* Put Matrix where it belongs, since it isn't a P2P messenger (#155)

* Generate PDF file

* Delete SecureDNS (#156)

SecureDNS not available after 30 April 2020: https://web.archive.org/web/20200420100210/https://securedns.eu/

* Updates contributors list

* Updates contributor SVG

* Generate PDF file

* Generate PDF file

---------

Co-authored-by: Kieran <kieranrobson1999@gmail.com>
Co-authored-by: 0x0102121wqs <108590577+0x0102121wqs@users.noreply.github.com>
Co-authored-by: Alicia Sykes <alicia@omg.lol>
Co-authored-by: cole <40342475+colenh@users.noreply.github.com>
Co-authored-by: liss-bot <liss-bot@d0h.co>
Co-authored-by: kolaente <k@knt.li>
Co-authored-by: NylaTheWolf <41797151+NylaTheWolf@users.noreply.github.com>
Co-authored-by: Lilith <78992082+lilithium-hydride@users.noreply.github.com>
Co-authored-by: Maksim Ploski <50287455+plplmax@users.noreply.github.com>
Co-authored-by: A-childs-encyclopedia <abdhllah005@gmail.com>
Co-authored-by: Slade <secher.guillaume@protonmail.com>
Co-authored-by: pnxdxt <paul.nodet@gmail.com>
Co-authored-by: Guillaume <ltGuillaume@users.noreply.github.com>
Co-authored-by: kerbless <kerbless@protonmail.com>
Co-authored-by: Gusted <williamzijl7@hotmail.com>
Co-authored-by: Wesley-Ryan <69822796+Wesley-Ryan@users.noreply.github.com>
Co-authored-by: James Cridland <james@cridland.net>
Co-authored-by: jxhn <1396009+jxhn@users.noreply.github.com>
Co-authored-by: Andrew Milich <milichab@gmail.com>
Co-authored-by: alex <37013819+baddate@users.noreply.github.com>
Co-authored-by: Alex Ogden <1379601+AlexOgden@users.noreply.github.com>
Co-authored-by: Ash Scott <AshboDev@users.noreply.github.com>
Co-authored-by: mrpavan <mr.pavan@gmail.com>
Co-authored-by: Kevin F <beardog@mailbox.org>
Co-authored-by: magical-heyrovsky <101060148+magical-heyrovsky@users.noreply.github.com>
Co-authored-by: Sam Al-Sapti <sam@sapti.me>
Co-authored-by: GhoulBoii <78494833+GhoulBoii@users.noreply.github.com>
Co-authored-by: Tim Schlotfeldt <ts+github@ml.tschlotfeldt.de>
Co-authored-by: Bruno Bernardino <hey@bruno.eu>
Co-authored-by: Zhymabek Roman <61125068+ZhymabekRoman@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants