Best alternative VPN solutions to replace StrongVPN?

WireGuard is a VPN protocol, like OpenVPN or IPsec. To use it you need a server on the other end of the tunnel. Your preferred VPN service provides those servers – if that service is “off line” then what VPN server are you using instead?

I have all of the parameters needed to set up a WG tunnel to a server in Georgia. If if my local IP host is actively blocking one of VPN providers, I can still set up the WG tunnel. And I recently had to do that on a trip to a place where………

I’ve been using Firefox browser’s bulltin VPN to watch Canadian TV shows without the fuss of setting up a full VPN. I’d trust Mozilla more than many other providers. 50GB free/month.

1 Like

I saw that in the latest version of FireFox and have been meaning to try it. For my rather limited use of VPN that might actually be all I need.

One caveat to using browser-based VPNs, like Firefox’s built-in VPN: they only work in their particular browser.

For example, if you use the Firefox VPN and start a Safari session, Safari traffic will not be protected by the Firefox VPN.

That’s not a criticism of such VPNs at all; it’s just a reminder of how they work.

2 Likes

Worth looking at the recommendations here too:

2 Likes

I just read on itsfoss about another approach to vpn service, called Obscura, which may or may not help the OP’s issues (Mac/Win/Lin/iOS/Android apps are there).

A good half of the article is technically over my head, so would appreciate evaluation by those smart in the subject. LMK if I should split this into a new Topic, this one being the most recent I recalled on VPNs so it made sense at the mo to add this here.

It’s a reasonable idea. It’s sort of halfway between a traditional VPN (where all your traffic passes through a VPN provider whom you must trust, as they know who you are and every site you access) and Tor (which passes your browsing through three anonymized volunteer-run servers, no one of which knows who you are and where you’re going). Obscura uses their own entry point (“guard relay” in Tor parlance) and a third-party (Mullvad) exit point. The guard knows who you are (at least your IP address, and whatever information they get from your payment method), but the data is encrypted on your device and passed through the guard to the exit, so the guard knows very little about your data. They don’t know what sites you visit and exactly what data you exchange with them, but they can get a broad picture of your usage (when you’re online, and probably when you’re streaming video or audio vs. reading email or surfing web pages).

The exit doesn’t know who you are, just that you’re an Obscura user. Your device IP address is (mostly) hidden from the sites you visit. There are a panoply of de-anonymization attacks that work against most browsers, though, which is a big reason that Tor uses its own browser (a hardened fork of Firefox). Of course, if Mullvad and Obscura have a special relationship (which they do, obviously) they can easily exchange user information and you’re back to what you’d have with a crooked or sloppy VPN operator, but the fact that you’d probably need two bad players (or rogue employees, or incompetent programmers) does make it safer.

Tomes have been written about the privacy and security (or lack thereof) of cryptocurrency payment systems, but they’re certainly likely to be safer than whipping out your American Express card. I assume other VPN providers offer cryptocurrency payments also, though.

Of course, you have to trust that the VPN client apps themselves aren’t faulty or otherwise corrupt, but Obscura offer you a way to configure your own WireGuard instance to work with their systems. WireGuard is FOSS and well scrutinized. That doesn’t make it perfect, but with proprietary products it’s a lot harder to do more than “just trust us.” They say that their source code is available, but that reproducible builds are planned for the future. They don’t say whether or not you can build your own client now, so I’m guessing from their wording that isn’t supported. Unless/until it is, you’re back to the same “just trust us” model that you have with proprietary products. Were I using Obscura, I’d opt for the WireGuard client configuration even though you lose some of Obscura’s privacy features (QUIC protocol).

“We…never log your IP address” is, of course, just a pinky-swear.

As always with security products, if you are just asking “Is this secure?” then the answer must be “Against what?” If you’re planning an adversarial action against a nation-state, sticking with Tor is probably your best bet (and far from bulletproof). If you really cannot articulate a threat model, then perhaps you don’t really need a VPN at all.

I’m not qualified to weigh in on the legal implications. I suppose the fact that a government agent would have to subpoena both Obscura and Mullvad to find out who you are and where you’re surfing would be something of a barrier, but if your adversary is a state actor, you’d best consult a lawyer.

1 Like