Want to read Slashdot from your mobile device? Point it at m.slashdot.org and keep reading!

 



Forgot your password?
typodupeerror
×
The Internet Network Operating Systems Software Windows

Malwarebytes Releases New VPN Service For Windows (bleepingcomputer.com) 24

The popular anti-malware software MalwareBytes is releasing a new Windows VPN service called Malwarebytes Privacy. The company says it plans on offering Mac, iOS, Android, and ChromeOS versions in the future. Bleeping Computer reports: During our tests yesterday, you could select from 10 states in the USA and 30 countries around the world. [...] Malwarebytes told BleepingComputer that this is not a white-label service, but rather one they developed themselves. A trusted-third party built the network infrastructure, and Malwarebytes developers created the app and other components. Malwarebytes Privacy is using the modern WireGuard VPN implementation that was recently integrated into the Linux kernel.

Unfortunately, not much is known about Malwarebytes Privacy's logging and data retention policies. According to Malwarebytes' product page, "Malwarebytes Privacy does not log your online activities, whether it's browsing or accessing any websites." This is what most people want, but it would be good to get more specific language in a dedicated data retention policy or language in their privacy policy.

This discussion has been archived. No new comments can be posted.

Malwarebytes Releases New VPN Service For Windows

Comments Filter:
  • This to me screams there is a lot of lessons to be learnt and pain ahead for users. reinventing security is hard.
    • It's not re-inventing. It's implementing Wireguard, a dramatic simplification of VPNs precisely because doing anything the old way was providing everyone more than enough rope to repeatedly hang themselves.

      Developing themselves is positive too. I'd prefer not all my apps to be a pretty skin on the same base, like browsers on an iOS device.

  • "does not log your online activities, whether it's browsing or accessing any websites"

    So, does it log online activities that aren't "browsing or accessing any websites"?

  • if your web browser and other applications that you use to access the internet has 256 bit strong encryption then why would you need a VPN? wont that be redundant?
    https://i.postimg.cc/2zzqZKg1/... [postimg.cc]
    • They would still know where you went, and a general sense of how much activity.

      Actually I wonder if they could tell that, too, given they may not be able to decode things, but could tell which pages because each encoded to roughly the same unique size.

    • by CastrTroy ( 595695 ) on Friday April 24, 2020 @08:31AM (#59983650)

      The domain name of the website you are visiting is submitted in the clear. It used to not be the case, but quite a while ago they created SNI (Server Name Indication) which would allow for SSL/TLS and certificates to be used for many domains that shared a single IP. Because the domain name is transmitted in the clear, your ISP, or others listening on unencrypted coffee shop/airport style WiFI can see which sites you are visiting. It doesn't transmit the full url, or any other information in the clear, but the domain name can be enough information to track what you are doing.

    • by thegarbz ( 1787294 ) on Friday April 24, 2020 @09:08AM (#59983724)

      You're assuming people use VPNs because they want traffic between domains to be encrypted. The largest use cases are:
      - hiding or faking the origin of the connection (i.e. break Geoblocks)
      - hiding the domains themselves (i.e. it doesn't matter if the video you're watching is called "An educational analysis of internet sensations" if it's being served from www.2girls1cup.com
      - accessing private networks. (i.e. control network access)

  • ...that they say about fools and their money parting. (or... party-ing?,,,)

    "It's only a secret until the cops come to the door."
  • Of course they track you. The human desire to place one's nose deep up the ass hole of another is irresistible.
  • Seems as if a service of this type would be ripe for infiltration by Three Letter Agencies (TLA), or just flat out be a front organization for such.

    • Seems as if a service of this type would be ripe for infiltration by Three Letter Agencies (TLA), or just flat out be a front organization for such.

      I'm sure they are. However, keep in mind that once they go and bust someone using some VPN service that supposedly doesn't keep records for something innocuous like torrenting a movie the cover and potential intelligence use of the service is blown. So unless you're doing Snowden-level stuff or organizing terrorist attacks and are stupid enough to rely on commercial VPN services you're still better off.

  • I'm very excited about this. I've made a lot of VPN systems before, usually using OpenVPN. These systems are often extensive and used for command and control of server and desktop hierarchies involving thousands of nodes. For many use cases though it's been fiddly and overkill. I kid you not, I was recently going to look into implementing a simple VPN over SSH as it's an encrypted tunnel we already have and already does things such as port forwarding.

    My only concern is that I think it can be too simple f

"Just think, with VLSI we can have 100 ENIACS on a chip!" -- Alan Perlis

Working...