• 1 Post
  • 93 Comments
Joined 1 month ago
cake
Cake day: July 18th, 2026

help-circle







  • Could you have a residential static VPN as one of the wireguard profiles and have it be somewhat local to you so you could use banking apps etc on specific devices? Trying to get this to pass the wife test but if streaming or banking is affected I will have to roll back to no vpn.

    Absolutely, my setup I have a catchall rule that captures the entire 10.6.0.0/24 range however I can specify the IP’s individually so if I want to put a remote device behind my WAN and not through another WireGuard tunnel I can do that.

    You can kind of see that in my second screenshot in my previous comment, I have a couple devices individually behind WGC4 and my catchall rule sitting on WCG5, the router will prioritize WCG4 over WGC5.


    Edit: the Asus router also comes with a built in DDNS feature, you can either use Asus’s free domains and associate your dynamic IP with them or setup your own domain, it’ll keep your A records up to date whenever your IP changes.

    For example I use this script to update my Cloudflare record for my domain - https://github.com/clayauld/asus-merlin-cloudflare-ddns




  • Picked myself up an Asus WRT router (AX86U) flashed it with Merlin firmware - the custom firmware includes a feature called “VPN Director” which lets me connect up to 5 different WireGuard clients and route my devices through whichever one I choose, given that the Asus WRT router is also capable of hosting its own WireGuard server I created a VPN director rule that routes that server through one of these clients.

    The VPN director has a priority ruleset, so if for example WireGuard client 5 dies it will either kill all outbound connections and wait until it’s back online or fallback to WireGuard client 4, WireGuard client 1 being the highest priority right before WAN.

    I like this setup because it’s my router doing the routing, not a secondary server hosting WireGuard like Tailscale.

    Edit; It also works with oVPN if you prefer that protocol over WireGuard.




  • CyberGhost currently has alway an excellent review in IT publications and independent benchmarks

    In that very same article…

    It’s Not Just Mid VPNs

    Kape doesn’t just own multiple VPN companies, they also own several media outlets and other ‘cybersecurity’ software. Let’s start by looking at one of their most egregiously misleading ‘cybersecurity’ software offerings: ReImage.

    ReImage is/(was?) marketed as a PC scan and repair tool. It’s actually something called scareware and it’s specifically designed to ping you with alarming messages about your computer containing multiple vulnerabilities, and prompting you to purchase a license to have their software perform the critical fixes necessary. I say ‘was’ marketed because when you go to their website, it doesn’t work. I was only able to look at their website through the web archive tool. Their crunchbase page gives the appearance that they’re still in operation, and you can still download their software off third-party websites. I wouldn’t though.

    Kape Owns VPN Review Sites Too

    You know what’s better than gobbling up market share of the VPN space? Gobbling up the websites that review them too, and creating your own vertical integration.

    So not only does Kape own some of the biggest VPNs in terms of market share, but they also have complete control over the affiliate ecosystem that shills their subpar products onto unwitting consumers. Oh and that’s not all, they also own a middle-man company that specializes “in monetizing high-quality traffic by connecting them with the brands they need.” In other words, they own the VPNs, the VPN affiliate marketing platforms, and the VPN review websites. They’ve created an entire ecosystem that they control, all explicitly designed to go after your data and your wallet.

    Here are some of the Kape Controlled entities that you may or may not have heard of before:

    • Webselence
      • Affiliate monetization platform.
    • VPN Mentor
      • VPN “review” site peppered with affiliate links from Kape VPNs and other owned software like Intego antivirus.
    • Safety Detectives
      • Another VPN “review” website, loaded up with affiliate links from Kape-owned businesses.

    Whether or not you trust a company with the initial intention of distributing malware is on you, and by using their Proxy you’re still pushing your traffic to their servers albeit in a less-secure manner, and to believe they don’t retain your data is merely laughable as they’re obliged by the Five Eyes Alliance due to their headquarters being in London and are required to retain personal information you provide them.

    I don’t use Windscribe myself because they’re a Canadian company and obliged by FVEY, but at least they’re independent from Kape Technologies.


  • CyberGhost extension

    Suggest digging into CyberGhost and their history and association with Kape Technologies.

    https://windscribe.com/blog/what-is-kape-technologies/

    Kape’s Sketchy Beginnings

    Let’s just take a brief moment to look at the origins of Kape. It wasn’t always known by this name, the original company was called Crossrider.

    Crossrider dealt in Malware (they called it “ad injection”), and their specialty was building a platform that allowed mobile app developers to easily inject ads into their software or web application. They were so good at it, they caught the attention of Google’s security research team who were incredibly alarmed by what they had found: an entire ecosystem of thousands of companies, broken down into various segments (Software, Distribution, Injection, and Ads).

    Crossrider’s main purpose was to function as a distributor, and they were incredibly effective at this. They used their network to drive as many installs as possible, all while collecting a commission for each install of the ad injection software. For those curious about this ecosystem, an archived version of Google’s Security Blog can be found here.

    Rebranding as Kape Technologies

    Due to the increasing negative attention their antics were causing, the company underwent a massive rebranding and emerged as Kape Technologies.

    Nowadays, Kape Technologies is a conglomerate of multiple “privacy-first” software companies, including Express VPN. Express is not their only play in the VPN space though: they’ve also acquired a few larger-scale VPN operations over the past few years. Their first VPN acquisition was Cyberghost for €9.1M back in 2017, followed by Private Internet Access for $127M and Zenmate for €4.8M in 2018. Then came the Express VPN whale in 2021 for $936M, giving Kape a massive foothold in the VPN marketplace.

    If Kape VPNs are known for anything, it’s being kinda sketchy. Since we’ve already covered Express in a previous article, the focus will be on the other three lesser-known VPNs that are part of the Kape Corporate Umbrella

    Kape Acquires Cyberghost

    Cyberghost was the first VPN that Kape acquired, back when they were still called Crossrider. Cyberghost was founded in 2011 by German entrepreneur Robert Knapp, who moved to Bucharest with $100,000 in seed capital ready to exploit the cheaper labor market in Romania. Robert’s own bio on the Cyberghost website claims that he’s passionate about building a privacy-preserving product, yet he had no problem cashing out for almost $10 Million to a company run by ex-Israeli spies and insider-trading billionaires. The irony is apparently lost in translation I suppose.

    There’s also an issue with vulnerabilities. In 2023, professional pen testers exposed a vulnerability in the Cyberghost VPN client that could lead to system compromise, yet they had an incredibly difficult time getting any sort of response from the Kape security team (who quickly and quietly patched the issue).



  • I have been laughed out every time I’ve mentioned it for years.

    I got approval from my managers and IT to install a Linux based OS on my work desktop, then a half-wit Windows-fanboy dev chimed in claiming our insurance would not cover the operating system if there were ever a security breach, data loss, etc. to say I was infuriated was an understatement.

    All we use is a Web-App to accomplish our tasks, no in-house proprietary executables or anything along those lines, hell they claimed their Web-App wouldn’t work on Firefox browsers, which of course was a lie.