Desktop applications release [v60]

Today we released a new version of the PIA client for Windows, OS X, and Linux. You can download it on the Client Support Page here:

https://www.privateinternetaccess.com/pages/client-support/

This version introduces a new feature called MACE™, an option to block ads, trackers, and malware when connected.  We have also fixed a number of known issues in this release outlined below.

HIGHLIGHTS

  • When you put your laptop to sleep and wake it up after awhile, the app will now auto-reconnect to the VPN on its own.
  • The VPN kill switch will now work with 10.* IP addresses.
  • Fixed issue with the app spawning multiple instances of NW.js in the background; this will no longer happen.
  • If you have spaces or quotes in your OS X or Linux home directory name (e.g. /Users/John's Home), the app will work fine for you now.
  • The installer for OS X is now signed by London Trust Media, so you no longer have to weaken the security of your system to install the app.
  • Implemented auto-disabling of the WPAD feature when the VPN is connected.
  • We have also made some improvements in the area of certificate security.

NOTES:

This version addresses a critical privacy leak issue related to the Web Proxy Auto-Discovery (WPAD) feature in Windows and OS X.  If you have this feature enabled on your system, it is possible for an attacker on your network to man-in-the-middle your connection and route all your web traffic through the attacker's own proxy server.  We have addressed this very serious problem by making the app automatically disable this feature of the OS while it is connected to the VPN.  Now it will no longer be possible for anyone to snoop on your web browsing activity.

«1

Comments

  • Did a clean install and V60 works smoothly without any problems. Please do not forget to introduce another new feature GAME™, an option to allow game clients to connect to internet bypassing PIA while PIA client is still active :)

    And please turn Ukrainian servers on at least instead of Russians. We need some servers from CIS countries. I am using them to purchase some stuff :)
  • edited July 2016
    alex1911 said:
    Did a clean install and V60 works smoothly without any problems. Please do not forget to introduce another new feature GAME™, an option to allow game clients to connect to internet bypassing PIA while PIA client is still active :)
    Game mode would be great. You guys should also put back the Connect Auto option at the top of the server list on the right click menu.
  • So I've been trying out MACE, and it's blocking some of the pages I frequent, most notably phoronix, which is not in any way malware or ad based. Is there any way to whitelist sites, or report incorrectly classified sites?
  • Tritlo said:
    So I've been trying out MACE, and it's blocking some of the pages I frequent, most notably phoronix, which is not in any way malware or ad based. Is there any way to whitelist sites, or report incorrectly classified sites?
    Not blocked here. 
  • edited July 2016
    @admin - More interested in knowing the technical aspects of MACE. How are you doing this without logging anything? 

    The web browsing is a bit faster since the ads are blocked. 
  • Toriko said:
    Tritlo said:
    So I've been trying out MACE, and it's blocking some of the pages I frequent, most notably phoronix, which is not in any way malware or ad based. Is there any way to whitelist sites, or report incorrectly classified sites?
    Not blocked here. 
    Huh. Maybe they just had server problems when I was testing it out? I still think being able to whitelist pages would be nice, since there are some pages I'd like to support by viewing their ads.
  • Toriko said:
    @admin - More interested in knowing the technical aspects of MACE. How are you doing this without logging anything? 

    The web browsing is a bit faster since the ads are blocked. 
    I assume that they just block content from IPs corresponding to a list of DNS addresses, serving empty responses instead. I'd like a technical explanation too though.
  • edited July 2016
    Can any OS X users or PIA staff comment on whether this version is still taking down the OS X firewall when connected? That remains a (poorly understood) dealbreaker for a few of us...  I recall a PIA staffer suggested back in May that this might be something they would give us the option of adjusting in v60.

    Also, it used to be the PIA staff would post the sha256 checksums for new client installers with the change log notes, within the announcement itself. Would like to see you folks resume that practice. :)

    I see for v60, a regular has posted these in another thread: https://www.privateinternetaccess.com/forum/discussion/18694/installer-not-signed
  • ads whitelist will be maybe available when the chrome version will be available. 
  • munr0 said:
    Can any OS X users or PIA staff comment on whether this version is still taking down the OS X firewall when connected? That remains a (poorly understood) dealbreaker for a few of us...  I recall a PIA staffer suggested back in May that this might be something they would give us the option of adjusting in v60.

    Also, it used to be the PIA staff would post the sha256 checksums for new client installers with the change log notes, within the announcement itself. Would like to see you folks resume that practice. :)

    I see for v60, a regular has posted these in another thread: https://www.privateinternetaccess.com/forum/discussion/18694/installer-not-signed
    Hello @munr0,

    I was the person who estimated that the firewall might be available in this release. I'm sorry to have provided potentially misleading information.

    We will be definitely making the changes which are in the best interests of the security and privacy of our users. We know that a lot of our long-term users have expressed concern about this issue.

    In the meantime, as a temporary workaround, I suggest running this command to re-enable the firewall:

    sudo /usr/libexec/ApplicationFirewall/socketfilterfw --setglobalstate on

    after connecting to PIA. Please note that this isn't a supported approach but this does achieve the desired effect of turning the firewall back on, and I've been able to confirm that you can browse and use the lan and internet as required.

    Alternatively you can consider putting this in your crontab, which will run this periodically so it'll re-enable the firewall in a few seconds whenever you connect to PIA.

  • What is up with the horrible pop-up notifications in the new OS X version? PLEASE tell me there is a way to disable them. 
  • I'm still getting weird disconnects using it. If i even open my torrent client, the VPN connection gets killed and i have to disconnect and reconnect. It happens randomly if i am playing a game as well.
  • Could you please name your installer_linux.rar.gz   with the VERSION NUMBER?

    Have to rename it myself in order not to overwrite any earlier version that I have saved.



    Thanks
  • edited July 2016
    What is up with the horrible pop-up notifications in the new OS X version? PLEASE tell me there is a way to disable them. 
    WHOA!!  Those pop-up notifications in the new OSX versions v60/61 are really awful.    Agree - please give an option to disable them as before (or at least polish them a lot).

    Also, please restore the "Connect Auto" option at the top of the server list from the OSX menu bar item.  It's gone in v60/61

    Thanks!
  • edited July 2016

    I'm still getting weird disconnects using it. If i even open my torrent client, the VPN connection gets killed and i have to disconnect and reconnect. It happens randomly if i am playing a game as well.
    @QuestionTime, I thought I was the only one and hopefully some others from PIA Support Staff might be able to comment to help or look into what's causing this.

    @PIA Support, I've always been happy with your service for over 3 years but I'm also noticing a similar occurrence to the quoted message above with the latest v60 PIA Win7 Client (I only ran the updated installer and have not changed any other operating system/router-modem settings). The sheer number of random disconnects (e.g. ~8-9 times within a 6 hour period) is alarming and there is no specific trigger which causes these. The Kill Switch doesn't function as it should during the unknown client disconnect and the non-VPN/True IP ends up revealing once refreshing the browser (e.g. visiting any IP checking website)!

    Prior to v60, I have rarely seen a disconnect of this manner before (maybe a few times in a month!). I haven't changed any settings from the previous default client GUI settings (e.g. tcp/auto/kill switch/dns leak protection all enabled). I haven't enabled the new MACE feature since I still control adblocking/malware protection via FireFox ublock origin + malwarebytes software.

    Anyone else noticing something as described or have some workaround of what we might need to (re)enable or double check again? I don't feel comfortable having to worry about the client disconnecting in such a frequent, unpredictable and erratic way. Thanks for your time and help!
  • re my above comment - refers to link in first post of this thread

    https://www.privateinternetaccess.com/pages/client-support/

    whereas links on

    https://www.privateinternetaccess.com/pages/downloads

    inlude version number in linux install script.
  • I'm also curious about PIA Mace™ and what exactly it does/how it works. Any info on this?

    Cheers!
  • edited July 2016
    repafre said:

    I'm still getting weird disconnects using it. If i even open my torrent client, the VPN connection gets killed and i have to disconnect and reconnect. It happens randomly if i am playing a game as well.
    @QuestionTime, I thought I was the only one and hopefully some others from PIA Support Staff might be able to comment to help or look into what's causing this.

    @PIA Support, I've always been happy with your service for over 3 years but I'm also noticing a similar occurrence to the quoted message above with the latest v60 PIA Win7 Client (I only ran the updated installer and have not changed any other operating system/router-modem settings). The sheer number of random disconnects (e.g. ~8-9 times within a 6 hour period) is alarming and there is no specific trigger which causes these. The Kill Switch doesn't function as it should during the unknown client disconnect and the non-VPN/True IP ends up revealing once refreshing the browser (e.g. visiting any IP checking website)!

    Prior to v60, I have rarely seen a disconnect of this manner before (maybe a few times in a month!). I haven't changed any settings from the previous default client GUI settings (e.g. tcp/auto/kill switch/dns leak protection all enabled). I haven't enabled the new MACE feature since I still control adblocking/malware protection via FireFox ublock origin + malwarebytes software.

    Anyone else noticing something as described or have some workaround of what we might need to (re)enable or double check again? I don't feel comfortable having to worry about the client disconnecting in such a frequent, unpredictable and erratic way. Thanks for your time and help!
    alex1911 said:
    @alex1911, thanks for the heads-up! :)

    The upgrade from v60 (July 07, 2016) to v61 (July 08, 2016) also showed up within the client GUI to upgrade when checking your link... I'll have to see whether this connectivity issue has been resolved today... crossing my fingers but thankful to the PIA Staff on coming up with a quick 1-day revision release to address a known issue!

    From the changelog to Windows v61 (July 08, 2016 update) :

    • Fixed connectivity issues related to WPAD on Windows and OS X.
    • Minor interface improvements.

    menopia said:


    This version introduces a new feature called MACE™, an option to block ads, trackers, and malware when connected.  We have also fixed a number of known issues in this release outlined below.

    HIGHLIGHTS

    • When you put your laptop to sleep and wake it up after awhile, the app will now auto-reconnect to the VPN on its own.
    • The VPN kill switch will now work with 10.* IP addresses.
    • Fixed issue with the app spawning multiple instances of NW.js in the background; this will no longer happen.
    • If you have spaces or quotes in your OS X or Linux home directory name (e.g. /Users/John's Home), the app will work fine for you now.
    • The installer for OS X is now signed by London Trust Media, so you no longer have to weaken the security of your system to install the app.
    • Implemented auto-disabling of the WPAD feature when the VPN is connected.
    • We have also made some improvements in the area of certificate security.

    NOTES:

    This version addresses a critical privacy leak issue related to the Web Proxy Auto-Discovery (WPAD) feature in Windows and OS X.  If you have this feature enabled on your system, it is possible for an attacker on your network to man-in-the-middle your connection and route all your web traffic through the attacker's own proxy server.  We have addressed this very serious problem by making the app automatically disable this feature of the OS while it is connected to the VPN.  Now it will no longer be possible for anyone to snoop on your web browsing activity.

    @PIA Staff
    @menopia

    How do we know whether WPAD is actually disabled (e.g. in Windows)? I have Windows 7 and went to the services menu :

    WinHTTP Web Proxy Auto-Discovery Service (WinHttpAutoProxySvc) is currently listed as "Started" in status, startup type "Manual" while connected to PIA VPN v61 (and in v60).


    paddy said:
    I'm also curious about PIA Mace™ and what exactly it does/how it works. Any info on this?

    Cheers!

    @paddy + @PIA, would like to still hear on this as well and how much of a difference this is from browser-based adblock plugins like Ublock Origins for Chrome/Firefox and other antimalware software that runs live (e.g. Microsoft Security Essentials + Malwarebytes).
  • I just updated my Win desktop client, and noticed Russian proxy is missing. Also I connected through Romania and upon checking with SPeedtest, its showing London. Also, I dont see the new feature available?
  • It's absolutely fine when you are connected using one country but speedtest shows another. IP addresses are not propagated yet (It happens sometimes, like for example there may be hard rain but after 1 minute sun will shine again).

    As for the Russian IPs. PIA dropped support of Russian servers because:

    Russia just enacted a new "anti-terror"  law that requires company's to hand over there encryption keys

    "The bill also requires communications companies to hand over encryption keys to state security agencies on demand, allowing them to read encrypted data. Non-compliance could cost companies between 800,000 and 1 million rubles ($12,300 – $15,400) in fines."

    It forces company"s to keep call logs and meta data. So let's say "Thanks" to Putin and his homeless gang.
    mactrlz10 said:
    I just updated my Win desktop client, and noticed Russian proxy is missing. Also I connected through Romania and upon checking with SPeedtest, its showing London. Also, I dont see the new feature available?

  • edited July 2016
    I wholly agree with this user! Especially the "Auto" connection is very handy, please give it back to us!
    bbbdog said:
    WHOA!!  Those pop-up notifications in the new OSX versions v60/61 are really awful.    Agree - please give an option to disable them as before (or at least polish them a lot).
    Also, please restore the "Connect Auto" option at the top of the server list from the OSX menu bar item.  It's gone in v60/61

    Thanks!

  • repafre said:
    Happens to me just like you describe it! Win 10 and latest version. Nothing helps. Support gives the usual vague responses (Avast, Comodo f/w etc., TCP/UDP ports). I really ask myself how more crappy this app can get. As if it wasnt enough that it always creates new executable through this rubyw so I can´t set it once and for all through my firewall!
  • alex1911 said:
    It's absolutely fine when you are connected using one country but speedtest shows another. IP addresses are not propagated yet (It happens sometimes, like for example there may be hard rain but after 1 minute sun will shine again).

    As for the Russian IPs. PIA dropped support of Russian servers because:

    Russia just enacted a new "anti-terror"  law that requires company's to hand over there encryption keys

    "The bill also requires communications companies to hand over encryption keys to state security agencies on demand, allowing them to read encrypted data. Non-compliance could cost companies between 800,000 and 1 million rubles ($12,300 – $15,400) in fines."

    It forces company"s to keep call logs and meta data. So let's say "Thanks" to Putin and his homeless gang.
    mactrlz10 said:
    I just updated my Win desktop client, and noticed Russian proxy is missing. Also I connected through Romania and upon checking with SPeedtest, its showing London. Also, I dont see the new feature available?

    Wow! great, thanks for the explanation.
  • after much bellyaching about v59 connection and disconnect issues, I can honestly say v61 is running smooth as silk for me...givin' you your props this time guys..nice job fixing the previous issues!
  • So upgrading to v61 for me has resulted in PIA causing problems connecting to my internet and also not running on Startup.  I'm wondering if this is a bug other people are experiencing.  I've reverted back to v60 because these problems do not occur there.
  • Since the upgrade to v60 and v61 I have had multiple disconnects to the extent that I have had to stop using PIA. I am using Windows 7.It also would load at startup but would not autoconnect.
    Prior to these upgrades I have never had a single issue.
  • Hi there , few issues with the new upgrade , speed seems to be slower , and the option of sending a "low speed" notice is gone, when I try there is a msg , " it can not be sent while connected to the service " real pain , it means one has to cancel dld , send request, reconnect/restart download.. the old way worked real well ,, why change it ? Looking @ the task manager now I have 3x nwjs processes blacked out and 1x nwjs red or green when connected. I have been using PIA for years , this is the 1st time I see this process ! What is it and why I have so many running? Then there's 2x PIA manager plus Open VPV and 2x Ruby Interpreter running as well . Also , I can not access settings to check on stuff while connected.. why? This is a Windows 8.1 64 bit laptop... would be grateful if someone offered a solution and/or explanation ! TIA
  • pcblues said:
    Hi there , few issues with the new upgrade , speed seems to be slower , and the option of sending a "low speed" notice is gone, when I try there is a msg , " it can not be sent while connected to the service " real pain , it means one has to cancel dld , send request, reconnect/restart download.. the old way worked real well ,, why change it ? Looking @ the task manager now I have 3x nwjs processes blacked out and 1x nwjs red or green when connected. I have been using PIA for years , this is the 1st time I see this process ! What is it and why I have so many running? Then there's 2x PIA manager plus Open VPV and 2x Ruby Interpreter running as well . Also , I can not access settings to check on stuff while connected.. why? This is a Windows 8.1 64 bit laptop... would be grateful if someone offered a solution and/or explanation ! TIA
    Hey, i have the same problem when it comes to excessive processes. I have currently 8 running and they are the exact same ones as you. I sent a debug report to asanjeev and blue23 i'm guessing they are the designers or coders of the new app 9 days ago and have not had any response from them yet or update on my issue. I know how you feel, its frustrating to suddenly have so many processes. If you look back at when the new app was in beta it did say improved app performance and significant reduction in disk usage. I see no difference in app performance and the disk usage is higher than it was before. I dont know whats going whether they are working on the problem or not but this is taking way too much time. I wish i could help you but i'm waiting for a solution to this as well.
  • After previous failures I have managed to get v61 installed and working on my linux unstable system---Yipppeeeeeeeeeeeeee
Sign In or Register to comment.