u/EducatorHonest1161

Microsoft is bringing Chrome’s uBlock Origin problem to Edge.

In the recent announcement, Microsoft described the end of the technology known as Manifest V2 from the previous versions of Edge browsers. Starting from August 2023, the old extensions built using Manifest V2 will be disabled by default. The technology will end completely by the end of 2026.

This situation with Manifest V2 can lead to the disappearance of the traditional version of uBlock Origin which is not affected by Manifest V3. Manifest V3 limits the number of filtering rules to 30000 items and removes the network access that ad blockers require to track and deny advertisements before they are loaded. The author of the original uBlock Origin called the implementation of Manifest V3 a crime against the ad blocking industry.

Microsoft attempts to present it as an improvement from the viewpoint of security. However, EFF claims MV3 to be a backdoor in favor of advertisement companies. Chrome had a similar experience in 2025 and Microsoft is simply following the path of Chromium technologies.

As a result of this, two of the largest web browsers in the world are now discontinuing the feature that uses technology to prevent tracking from occurring, rather than merely blocking ads. Firefox and Brave, however, are not embracing this trend. It's good to be aware of it before your own add-ons are discarded without warning.

reddit.com
u/EducatorHonest1161 — 2 days ago

The EU just published its first official rulebook for determining whether a VPN is actually secure with NordVPN and Surfshark helping write it.

This week, ETSI published EN 304 620, the first recognized cybersecurity standard for VPNs under the EU's Cyber Resilience Act. Previously, any provider could assert that its encryption was "military-level" without any evidence to validate it.

The most interesting part is that NordVPN (representing Nord Security) and Surfshark played a part in creating it together with Palo Alto Networks, Cisco, Google, and Airbus, with Miguel Fornés from Surfshark being directly involved in parts of its drafting.

The standard will be available in the public domain this month while the enforcement date is scheduled on December 11, 2027 and violations will incur fines of up to €15 million or 2.5% of the annual turnover.

It looks like there’s a real progress when it comes to having VPNs validate their security claims rather than just market them, however, we should also take into consideration the fact that VPN companies participated in drafting their test as well.

What do you think? Would anything actually change by 2027?

reddit.com
u/EducatorHonest1161 — 4 days ago

Russia’s VPN crackdown escalates as more than 20 services are blocked in its largest sweep yet.

On August 4, users in Russia started to complain about an unusual failure of many popular VPN services. Some security experts wrote that this is one of the largest attacks against VPNs ever seen, because the hacker activity was aimed at blocking IP subnets owned by VPN providers, not a single server.

This was not just an instance of a few servers going offline. The hackers worked on the entire hosting subnet, meaning that they made it impossible for any entities relying on this hosting site to use their servers. Although VPN services have made changes in their server placement, this is just the beginning of a long-lasting confrontation.

What does it mean: users in any country, especially those living in a heavily censored area, are now advised to have alternative means of communication.

Has anyone here noticed connectivity issues in Russia or nearby regions since Aug 4th?

reddit.com
u/EducatorHonest1161 — 6 days ago

ExpressVPN quietly stopped honoring its money-back guarantee for two months.

ExpressVPN had a zero-refund policy during the event for the full 60 days, beginning from July 11 to August 9. Those who signed up received entries to a raffle for the iPhone 17 Pro, however, "all sales are final" in this duration.

From the company's own reasoning, the situation is quite clear; the guarantee seems not to exist in order for users not to join the raffle, then cancel their subscriptions, and claim refunds in case they don’t win.

People talking about the matter on ExpressVPN weren’t happy, with one person calling the company’s practices "predatory" and another one questioning "who came up with that idea?" The company claims that the promotional terms were displayed in the checkout process and that they treat refund requests on a case-by-case basis.

In other words, the 30-day money-back guarantee, which has been used by ExpressVPN as a trust-building tactic, failed to operate for two months and was substituted with a phone raffle.

reddit.com
u/EducatorHonest1161 — 7 days ago

A “free VPN manager” on github was secretly turning servers into a botnet.

Flare analyst Assaf Morag discovered the vulnerability when the honeypot server was infiltrated by FirewallFalcon Manager – an open-source tool promoted on Telegram for the management of VPN and SSH tunnel servers.

In simpler words, it is a bogus certificate that redirects traffic through the developer's own servers invisibly while appearing to be secure. Previous versions were more daring as they included a hardcoded SSH account that allowed the developer to gain access to any computer that installed it.

There are already more than 650 servers under attack, and many Telegram accounts are affected. Users assumed that they had established their own VPN.

Being "open-source" does not mean being safe. If you're employing a tunneling software that was offered to you on Telegram instead of the one that underwent the proper auditing, be sure to check it out now.

Has anyone here ever provided VPN services to others?

reddit.com
u/EducatorHonest1161 — 8 days ago

Could your most trusted VPN be linked to a former adware company?

When using VPN services like ExpressVPN, CyberGhost, Private Internet Access, or ZenMate, you're actually paying for one company and its services through their core company called Kape Technologies. Each of these four providers provides services independently but has the same owner company.

But being owned and operated by one company is not shocking—it's shocking that Kape used to be called Crossrider and it used to be an ad injector software provider that was notorious for adware-like behavior and raising alarm of security researchers. And this same company is in the business of acquiring privacy services.

The reviews issue also lies here. We all know that Kape is the owner of vpnMentor, which is one of the most quoted “independent” reviewing sites about VPNs. They take VPNs and express their opinion on them as independent journalists.

Teddy Sagi, an Israeli billionaire, is the principal owner of Kape. He was found guilty of insider trading back in the 1990s, long before Kape became a business. However, the important thing is that there are four VPNs owned by Sagi who has a say in a big part of the VPN reviews.

The last statement about checking the ownership of your mobile apps is also relevant. Does everyone here already know this?

reddit.com
u/EducatorHonest1161 — 9 days ago

Check point VPN flaw went undetected for over a month, allowing passwordless access.

Check Point announced the vulnerability, CVE-2026-50751 on June 8th, which describes a significant bypass (with a CVSS score of 9.3) within its Remote Access VPN and Mobile Access devices. The fault in question lies in the fact that an attacker can utilize a VPN with broken certificate checks and without having to authenticate. IN terms of the timeline for exploitation, it started on May 7th, but Check Point only became aware of the problem on June 4th, leading to a potential window of exploitation extending for 33 days.

It is believed that at least one intrusion connected to Qilin Ransomware has already taken place. Only those systems which utilized the outdated IKEv1 protocol are affected by this problem, and CISA allowed 3 full days for federal agencies to resolve the problem once it became public knowledge.

reddit.com
u/EducatorHonest1161 — 11 days ago

Illinois wants Apple, Google, and Microsoft to ID-check your kid before they open an app. What could go wrong?

Illinois has enacted a law that requires all devices connected to the Internet to ask the age of the user before they can be activated. This law applies to the device itself, not to the operating system or any applications.

Let's think about this for a moment. The phone, laptop, and TV you use will report your age to every platform no sooner than you turn on the device.

In essence, this means that you will be required to show your ID before entering your house every time you want to use your gadgets.

The statement that this initiative is aimed at protecting children is awful. It just becomes obvious, the collection of information about people's age provides no effect.

Children are also unable to lose any physical possessions in this place, as anonymous access to support forums has been cut out, making any device identifiable to the government. However, teens will work around this restriction long before their parents find out that the government passed this law.

Designed to protect children, but instead has made all electronic devices tracking devices.

reddit.com
u/EducatorHonest1161 — 13 days ago

Proton dropped OpenVPN on Android, and the app got 36% smaller.

Proton VPN decided to remove OpenVPN from its Android application completely. The remaining protocols in the application include WireGuard and Stable Core, which is Proton's protocol that adds another layer of security to the WireGuard.

The advantage of this approach is simple. OpenVPN is a much older technology, and being slower and heavier than the new protocols, keeping it in operation would only slow down and increase the weight of the application for the minority of its users. With OpenVPN support being eliminated, the application got smaller by 36%, and its speed improved as well.

What does it mean for the current users? Those who are using OpenVPN will no longer have access to this option. Corporate users and some older routers greatly rely on OpenVPN protocol. Nevertheless, most users will not even notice this removal, except for the reduced application size and increased speed.

It is the same situation that we can observe recently with NordVPN. OpenVPN protocol gets eliminated completely in favor of newer technologies that were created with the purpose of speeding up the operation of VPNs.

reddit.com
u/EducatorHonest1161 — 15 days ago

India tightens VPN rules, requiring providers to establish local offices.

A leaked framework from July 3 indicates that offshore VPN operators must have a physical presence in India, a compliance officer acting as the government point of contact, as well as retain subscribers’ information (including records, personal information, and IP addresses) for 5 years. If they do not obey the government, their local staff will be liable to criminal prosecution.

The official explanation is that the CERT-In directive passed in 2022 already included similar data retention obligations, which were neglected before by the providers. In 2025, India has already blocked almost 24,000 sites, almost double compared to the previous year.

What is important to understand here is that most VPNs that prioritized privacy moved their servers offshore from India in order to avoid the impact of this jurisdiction. This requirement is aimed specifically at re-establishing the jurisdictional authority of law over these VPNs and obliging them to re-enter the Indian market if they want to continue their work.

India is already known for the largest number of internet shutdowns in the world, and that is not something completely new, it is just closing a loophole from three years ago policy.

Will there be a mass breakout of VPN services not having a presence in India if this policy is passed?

reddit.com
u/EducatorHonest1161 — 17 days ago

With VPNs Failing, Russians Are Turning to Self-Built Proxy Networks.

The censorship of Russia has progressed from merely blocking apps to utilizing deep packet inspection to intercept the protocols used by VPNs, including the most common ones out there. Companies that create VPN software are frequently blocked quickly, while common tunneling protocols can be detected and throttled.

So now people are creating their own. These DIY proxies disguise traffic from being monitored by appearing as normal HTTPS that is indistinguishable from someone browsing a website. There is no user-friendly app that conveniently disguises the identity of the user. It’s just clunky configurations that are created and recreated by people by hand.

However, the problem is this is an arms race. A method may work for a few weeks, only to break and require minor changes. There is no permanent solution, just a continuous patching against a state that is trying to detect the technicalities of the system used to bypass their controls.

This is exactly why the advice to use VPN is no longer valid. Once a country learns to identify the pattern of the protocols, all the commercially available means are rendered helpless.

Has anyone here helped anyone in Russia to set up a VPN connection lately?

reddit.com
u/EducatorHonest1161 — 21 days ago
▲ 19 r/RecommandedVPN+1 crossposts

Use a VPN, they said. Now you're treated like a foreign target for using one .

According to sources, several Democratic legislators including Wyden, Padilla, Markey, Warren, Jacobs, and Jayapal have sent a letter to DNI Tulsi Gabbard seeking answers on a highly uncomfortable question for every American who uses a commercial VPN: does the use of a commercial VPN mean that someone loses Fourth Amendment rights protecting them against warrantless surveillance?

As per the mechanism laid down in FISA Section 702 and Executive Order 12333, if an intelligence agency is unable to determine the location of a user, it is presumed to be foreign. Foreigners from other countries aren’t entitled to Fourth Amendment protection. VPNs are designed in a way to cover actual location. Thus, if someone routes VPN connection through servers located in another country, they are being classified without authorization as a non-person because according to the privacy rules no warrant is needed for breaching their privacy.

The ironic part is that legalization has pointed out itself that in fact FBI, NSA, and FTC are advising the public to use VPNs in order to prevent losing their information. This serves as another proof that the same government institution which advised people to use the VPN may be using this tool to breach the privacy.

The letter does not serve as a proof of anything but rather a request for explanation from Gabbard.

The instrument advocated by everyone as the basic privacy hygiene is the very means that is slowly affecting your legal protection. Was there ever any case when the agency answered your question regarding privacy issues?

reddit.com
u/EducatorHonest1161 — 23 days ago

Proton just published its transparency report, and the numbers are almost boring, in the best way.

There have been 47 requests for legal data regarding Proton VPN users made by courts located in Switzerland in the first half of 2026. All claims were rejected by Proton VPN on account of their no-logs system, which means that there is nothing for authorities to disclose, in case the court orders it.

Since 2017, Proton has received 458 requests in total, 458 denials. And every time, they could not comply with an official order not because they did not want to. They do not keep any connection logs either, which is essential in this matter. Thus, we see what the no-logs policy is practically in the real world, not a marketing strategy.

It is also important to note that everything is different for ProtonMail; this is another issue. The FBI investigation this year provided an example of Proton being asked to provide an identifier linked to an email account because an email contains more information than other means of communications.

Has anyone here actually had to test a no-logs claim like this the hard way, through a legal request on your own account?

reddit.com
u/EducatorHonest1161 — 24 days ago

Australia's "child safety" regulator just admitted the real target is VPNs.

Australia's agency for online safety, eSafety, has announced that 90 percent of the websites for adults use the new age verification system. Were the established goals achieved? Absolutely not. eSafety immediately started looking into how people could have managed to get around the new system with the use of VPNs. The same things can be said of the social media ban for people younger than 16 in terms of evading the regulations.

This is interesting because the measures were beaten by the simplest privacy tool available on the market, and instead of admitting that this method does not work, the agency's focus has changed to trying to eliminate VPNs. The very agency that tries to provide safety on the internet claims that the technology, which has made people safer online, is the issue.

Mullvad predicted this. The measure concerning age verification is going to broaden beyond the lines of intended use. The same thing is happening in the UK and the EU.

Is there a democracy left where regulating VPNs doesn't eventually protect the children, or is that not really a question anymore?

reddit.com
u/EducatorHonest1161 — 27 days ago

Microsoft just patched a vulnerability that let attackers crash your work VPN with one packet.

This month's Windows security updates, which were issued on July 14, included four different CVEs affecting Always On VPN services, with one of the vulnerabilities warranting more attention than simply appearing in the changelog. CVE-2026-50721 and CVE-2026-50722 are both denial-of-service vulnerabilities related to IKEv2, but the other vulnerability present is a remote code execution vulnerability in SSTP, the protocol that is being used by the majority of the Always On VPN connections to access the Internet.

The reason that the SSTP vulnerability is more dangerous than the other vulnerability is that SSTP is intentionally designed to work over the Internet, which enables a company computer to connect from anywhere. This also enables the RCE vulnerability to be exploited from anywhere once the VPN is connected. Although Microsoft rated the IKE vulnerabilities as "important" instead of "critical," the fact that it is rated as "important" leads to many possibilities.

It's important to make the distinction between what is truly newsworthy and what is the usual occurrence all the Patch Tuesdays give us many CVEs that usually get filed and are soon forgotten. But any significance of this release should be pointed out since Always On VPN is part of much remote work infrastructure that works behind the scenes. And the fact that the protocol carrying this traffic has a critical vulnerability makes it something that cannot and should not be left unpatched.

If you are using a VPN for personal reasons, this flaw won’t affect you. However, if your company uses Always On VPN and hasn’t updated it yet, you might remind IT about the necessity to do so.

Is there anybody managing the VPN infrastructure in your company, and did you hear about this vulnerability?

reddit.com
u/EducatorHonest1161 — 1 month ago

VPN recommendations and comparisons: the official megathread.

So many of you keep dropping "what VPN should I get" as standalone posts that we're just consolidating it into one spot. This runs every two months and stays pinned, so it's always the place to go instead of starting a new thread every time.

A good recommendation actually explains something. Before you drop a name:

• What problem were you solving, price, streaming, torrenting, just wanting peace of mind on public wifi?

• What's your actual day-to-day experience been, not the marketing page?

• Would you tell a friend to switch to it, and why specifically?

• Single-word "just use X" comments get removed, they don't help anyone deciding.

Keeping it clean:

》Zero affiliate or referral links, no exceptions.

》Don't link out to a provider's site or a third-party review page.

》If it reads like it was written by their marketing team, it's coming down.

Want a shortcut before typing anything out? We put together a running VPN comparison sheet with pricing, jurisdiction, logging policy, and protocol support laid out side by side. worth a scan before you ask, might already answer your question.

Mods are watching this one closely, so keep it on-topic and keep it decent. That's what keeps this whole thread useful instead of turning into another ad wall.

reddit.com
u/EducatorHonest1161 — 1 month ago

Russia just launched a state-approved "white VPN," and the irony is thick.

From June 9, Beeline, which is one of the leading mobile operators in Russia, has started utilizing a unique approach to assist its customers, allowing them to reach Netflix, Spotify, Ticketmaster, and Brawl Stars regardless of the fact that these services withdrew from Russia back in 2022. Consumers of the company have not to download any applications and configure their devices because the services are available just by default on Beeline’s “Bee” plan.

According to Beeline CEO Sergey Anokhin, this interesting initiative was born because these services are not officially banned in Russia but left the market, therefore requiring people to use VPNs to reach them are “inconvenient and unfair”. He explained that the company was able to gain government approval for their newly-introduced service.

There are two separate ideas being mentioned in here, and once again, we should realize that this is not a state-wide VPN for the free internet. It is, in fact, just a narrow whitelist that gives back the services that the Kremlin does not mind you using, while retaining the censorship machine just like before. Just like those authorities have been exerting pressure on independent VPNs for years and years, they finally came up with a legitimate version of the workaround for those parts they feel as if they are going to be acceptable.

What strikes me most of all is that they managed to frame it. They called it a "whitelist," therefore making Beeline look like a company that cares about consumers. But if we were to call it by its real name, "a government-approved way of accessing blocked sites," we would get a much clearer picture of how the Kremlin realized the benefits of VPN names over blocking. Other operators, such as T2, are reportedly planning to offer a similar service.

reddit.com
u/EducatorHonest1161 — 1 month ago

University of Michigan just tested 281 Android VPN apps, and the results aren't great.

Researchers from the University of Michigan have developed a new testing tool called MVPNalyzer and tested it on 281 of the most popular Android VPNs. The results presented at NDSS 2026 should definitely make anyone considering free VPNs pause for thought. 29 of the tested VPNs leaked DNS and traffic which contradicts the very purpose of having a VPN. And more than 20% of apps sent data without encryption. Over 60% of applications performed poorly in terms of security levels. Of all the 108 VPN apps studied by the researchers, 107 ignored or misapplied best practices when it comes to encryption.

What particularly concerns me is the fact that 76 VPNs transmitted ID numbers of the devices to some third-party users. Hence, the application that is supposed to help you “hide your identity” does the opposite and practically allows to spy on you. The lead researcher Ms. Roya Ensafi points out that the idea behind MVPNalyzer was to show users, regulators, and application developers the truth about what goes on behind the app creators’ promises.

It's important to note that this is only for Android and mobile VPNs have been completely overlooked for the most part and audits tend to focus on desktop applications. Therefore, the real figure could be different depending on iOS and other less popular applications.

This makes one question the old advice of "any VPN is better than no VPN." Has anyone checked whether their VPN belongs to any of the categories mentioned?

reddit.com
u/EducatorHonest1161 — 1 month ago

NordVPN quietly swapped its obfuscation protocol.

According to the recent iOS software update note by NordVPN, the company has improved its obfuscated servers technology. For a long time, the company was able to deliver obfuscation only thanks to OpenVPN, but it appears that now its obfuscation solution is based on NordWhisper protocol, developed by Nord.

This improvement is significant considering that OpenVPN mechanism has always been quite slow due to the extra load added to the system. In fact, NordWhisper is developed from scratch to act like regular HTTPS traffic, which assures the customers of the faster speeds and wider range of locations. There is no quality compromise because NordWhisper uses the same security technology as all the other NordVPN protocols.

This improvement is a big signal of what the company is going to do in the future. It has been stated that NordWhisper will get to becoming an absolutely TLS-based solution and will be developed along the QUIC technology. QUIC is said to be not only the solution for obfuscation but also a highly progressive technology in the realm of VPNs, whereas the development within the protocols can easily be seen with the example of such companies as Surfshark and NymVPN.

If you have been employing obfuscated OpenVPN as your way of circumventing limitations imposed on networks, it is advisable to verify your application as the method in question could already have been replaced. Is there anyone who has been trying NordWhisper on truly restricted networks?

reddit.com
u/EducatorHonest1161 — 1 month ago

WhatsApp just officially recommended Mullvad and Amnezia VPN in its own Help Center.

WhatsApp has revised its FAQ section under "connecting when your network doesn't work" by mentioning Mullvad and Amnezia VPN services as "high-profile services" along with the links to both of them and the EFF guide on best VPNs.

According to the statistics, WhatsApp has suffered global downtimes affecting 46% of users, while 52 countries have imposed a ban on the app either temporarily or permanently. WhatsApp was blocked in Russia in February because authorities wanted people to start using their own application MAX.

It's interesting to note that both Mullvad and Amnezia, which are listed among the recommended providers on WhatsApp's website, are not known names in the VPN industry. Mullvad is an anonymous VPN that does not require creating an account and accepts cash payments. Amnezia, on the other hand, is an open source self-hosted privacy solution designed specifically for users living in countries with strict censorship laws.

But the most interesting thing in this story is that Meta was once the owner of Onavo, the VPN service that was actually a spyware harvesting the user data.

In summary, the company that has previously been found to be running a VPN for the sole purpose of spying on its users is the same one that now promotes one of the best VPNs in the market. EFF's endorsement of Mullvad shows that the irony and contradiction in this scenario is remarkable. Meta's motivation in this scenario is clear.

reddit.com
u/EducatorHonest1161 — 1 month ago