EnglishFrenchGermanPolishSpanishTurkishRussianItalianDutchDutch

Preguntas más frecuentes

See also the
"How to" video

Generales

¿Qué es SecurityKISS Tunnel?

SecurityKISS Tunnel es un programa y un servicio que te permite acceder a Internet a pesar de censura y limitaciones locales. Además, el programa hace tu conexión segura y impide que otras personas vean tus actividades de visitar páginas, mensajes instantáneas, descargas, información de tarjetas de créditos y cualquier otra cosa que envías por la red.

Técnicamente SecurityKISS Tunnel es una implementación de la red privada virtual (VPN) que crea una VPN entre tu portátil y nuestro gateway de seguridad de modo que todo tu movimiento en línea va por un túnel impenetrable y no transparente.

¿Es totalmente gratuito?

Ofrecemos la versión gratuita y la versión de pago. En la primera opción tanto el programa como el servicio son completamente gratuitos con el uso diario limitado.

La versión de pago tiene un alto límite de uso en el ciclo mensual y otras funciones. Ve los paquetes.

¿El servicio continuará siendo gratuito o será cobrado un cargo en el futuro?

Siempre habrá una versión gratuita del servicio.

My ISP provides me the Internet link with 10 GB per month. If I use your JADEITE plan, will my montly limit increase to 50 GB ?

No. SecurityKISS is not Internet provider and we cannot add an extra Internet link to your PC. If you ISP's monthly limit is 10 GB you will not be able fully use the quota of the JADEITE plan so it makes more sense to order the cheaper OLIVINE plan with 20 GB/month instead.

Thanks to the fact that SecurityKISS is using compression before data is encrypted and transferred. it is possible that the total data sent and received may be larger by about 10 or 20 percent depending on the type of traffic. So while there is no way to increase the 10 GB limit of your ISP, you may slightly increase the amount of user data transferred (for example to 11 GB).

¿Cómo puedo obtener una cuenta gratuita para usar vuestro servicio? ¿Tengo que mandar mis datos personales?

No necesitas cuenta. Simplemente descarga el programa y úsalo. Tu programa instalado está identificado sólo por ID de cliente.

Respetamos tu privacidad y tu tiempo, así que no nos hace falta saber tu nombre y tú no tienes que perder tiempo para completar formularios innecesarios.

¡No más nombres de usuarios y contraseñas!

¿Cuánto tiempo hay que esperar para activación de la cuenta?

Las cuentas de clientes son activadas inmediatamente después de que recibimos el pago (normalmente esto dura unos segundos)

¿Qué sistemas operativos son compatibles?

El SecurityKISS Tunnel gratuito, que todos los usuarios pueden descargar, se soporta en Windows XP, Windows Vista y Windows 7.

Clientes de JADEITE y EMERALD pueden usar programas VPN integrados de la mayoría de sistemas operativos para conectarse a servidores PPTP de SecurityKISS..

Can I run SecurityKISS Tunnel on 64-bit operating system?

Yes, it works on 64-bit Windows

Does SecurityKISS work with Windows 7?

Yes, both 32-bit and 64-bit versions of Windows 7 are supported

Where are VPN servers located?

While the company is based in Ireland the VPN servers (security gateways) are in the UK, US, Germany, Switzerland, Canada, Poland, Sweden and Netherlands. We are setting up new servers in other locations.

Are you planning to offer more servers in other countries?

Yes, we will publish locations of the servers once they are ready

As this software is very good to keep the system secure so please let me know why are you providing this software free of cost?

We make the software available for free to present the quality and reliability of our service to everyone. We also offer paid packages, however we will maintain a free version of the service all the time.

We believe in the formula:

Satisfied User = Potential Customer

Free users can still avail of the benefits of SecurityKISS Tunnel but they need to manage their limits judiciously.

When will the usage limit be dropped? I want to run this tunnel all the time...

The usage limit will be increased but never be dropped.

For free users it is possible to use SecurityKISS Tunnel all the time if they manage their limit carefully while we provide paid versions of the service with full support and high usage limits. You can view the paid packages here

For free users we increased the limit to 300 MB/day

¿Cuántos ordenadores pueden usar SecurityKISS? ¿Pueden estar en línea al mismo tiempo?

Con un ID del cliente (con la misma instancia del programa) se puede conectar de muchos PCs. La limitación es que sólo un cliente puede estar conectado al mismo servidor al mismo tiempo.

En la versión de pago tienes más de 15 servidores así que te puedes conectar del mismo número de PCs.

Se dice que la velocidad de conexión alcanza los 100Mbit/s pero ni siquiera puedo llegar a la mitad de esta cifra.

Los 100Mbit/s es el límite superior de ancho de banda del vínculo al que los servidores están conectado al mundo exterior. Sin embargo, esto no significa que será posible seguir estando conectado al máximo ancho de banda, porque la velocidad depende de muchos factores que se mencionan a continuación.

I have looked at the status on the Tun/Tap adapter and it says it is running at only 10Mbit/s.

"The Tun/Tap adapter will run at whatever speed the hardware and network will support - the 10Mbps you see in the interface properties doesn't really mean anything - it's really just a Windows artifact from the days when ethernet interfaces were always hardware and never virtual." By James Yonan

La velocidad de conexión en el túnel es más baja que mi conexión común a Internet.

La velocidad de conexión de túnel nunca será tan alta como tu conexión común a Internet porque:

Para aumentar la velocidad se puede:

Is there any speed difference between plans?

The primary difference is between the free GREEN plan and other plans. In the free version the bandwidth is controlled in order to prevent traffic congestion when the large number of free users connect.

On the other hand in the paid plans the connection speed is limited only by the 100Mbit bandwidth of ethernet link of our server, your Internet link bandwidth and the time needed for data to travel between your PC and the server.

The same rules apply for OLIVINE, MALACHITE, JADEITE and EMERALD plans so the speed should be the same for all paid plans however, in the high end packages you get more servers which are underloaded (since only high end plans customers can use them) so most of the bandwidth is available to you.

How can I upgrade my current plan?

If you bought 1 month plan and exceeded your monthly data allowance before expiry date, just buy another package and your account will be upgraded immediately. In order to upgrade your existing 3 month, 6 month or 12 month plan please contact Support

Manual

¿Dónde puedo encontrar mi ID del cliente?

Encontrarás instrucciones aquí.

¿Cómo funciona el contador de límite de SecurityKISS?

Encontrarás instrucciones aquí.

Can I change servers I am connecting to?

Yes. SecurityKISS system has servers in many locations and you can change server at any moment. If you don't select a server from the list before connection the program will connect to a random one.

When you need a server in particular location you can select server manually from the list.

¿Dónde está la lista de servidores?

La lista de servidores abre en una dedicada ventana de diálogo. Puedes llegar a ella de la barra de menús o haciendo clic en el botón del panel inferior. Ve capturas de pantalla

How to change the server?

Once you open the server list select the server you want to connect and click 'Apply'. If you are connected via tunnel, disconnect and connect again. After clicking 'Disconnect' wait a few seconds before reconnecting to let your operating system return to stable state.

After successful connection the bottom panel should display the new IP address and corresponding country flag.

See the full instruction here

¿Qué significa la columna 'Customer Only' ('Sólo para clientes') en la lista de servidores?

Servidores sólo para clientes no son usados por usuarios gratuitos y por eso no están sobrecargados, sus direcciones IP no son públicamente conocidas por todos y tienen mejor reputación en la mayoría de sitios web que usan supervisión de IP o filtrado.

I had to reinstall my Windows. The SecurityKISS Tunnel link from the activation email does not work anymore. How can I install SecurityKISS on the new system?

If you lost your SecurityKISS Tunnel installer or you want to install it on a new PC, you can download individually generated software from the client area panel at any time:

https://www.securitykiss.com/panel/

Please go to the Download tab and your operating system subtab. Generating the software usually takes up to 30 seconds and it includes security certificate and up to date server list for your client ID.

¿Cómo se usa Panel de Aréa de liente?

Encontrarás la instrucción aquí

Seguridad

¿Este programa tiene un registrador de pulsaciones de teclas, malware, virus o spyware? Cuando intento instalarlo el sistema muestra un mensaje de advertencia.

No, el programa es totalmente seguro. Es la propiedad de SecurityKISS.com y ha sido escrito con el uso de la tecnología de código abierto. Esto significa que el programa no contiene ningún componente de terceros que sea un blackbox, lo que pueda presentar un riesgo potencial.

La advertencia es causada por la instalación de un TUN/TAP controlador que estimula un dispositivo de Ethernet. Tu sistema operativo muestra la advertencia porque es una operación de bajo nivel. El código de TUN/TAP controlador es una parte del proyecto Open VPN y es completamente seguro, probado y usado por millones de usuarios.

SecurityKISS Tunnel ha sido certificado por Softpedia como '100% LIMPIO'.

Más abajo se presenta la nota original de Softpedia:

'SecurityKISS Tunnel fue probado en los laboratorios de Softpedia usando varias soluciones de seguridad líderes y fue encontrado absolutamente limpio de componentes adware/spyware. Estamos impresionados por la cualidad de su producto y les animamos a mantener estos estándares tan altos en el futuro.'
Lee más en Softpedia

Mi software anti-malware reporta un virus en vuestro programa. ¿Qué significa esto?

Esto puede significar que:

En primer lugar, por favor asegúrate que has bajado SecurityKISS Tunnel directamente del nuestro sitio web.

Existe una probabilidad marginal del ataque intermediario (Man-in-the-middle), es decir, alquien entre tu ordenador y nuestro sitio ha reemplazado la secuencia de datos de manera que has recibido un archivo infectado. Esto puede ser especialmente cierto cuando estás usando servicios proxy anónimos.

La tercera posibilidad es la más probable pero por si acaso comprueba el archivo con otro software antivirus, por favor.

Algunos programas antivirus son bien conocidos por muchos ‘falsos positivos’ (AVIRA y EMSISOFT son ejemplos infames). Un falso positivo es una situación cuando un programa antivirus reporta archivos legítimos y normales como virus. Puedes encontrar más información en Wikipedia: Wikipedia: False Positives

SecurityKISS Tunnel puede ser erróneamente clasificado probablemente porque contiene el código a www.securityKiss.com para recibir el mensaje de bienvenida y la lista actual de las direcciones de gateway de seguridad (servidores VPN).

Este problema es causado por unos productos anti-malware que suelen llamar la atención de usuarios que piensan 'Cuantas más amenazas detecta el antivirus, mejor', lo que es una conclusión falsa.

Puedes examinar archivos SecurityKISS Tunnel subiéndolos a servicios en línea que usan varios programas antivirus.

Recomendamos los servicios mencionados más abajo porque no requieren instalación de ningún software en tu ordenador:

www.virusscan.jotti.org
www.virustotal.com

Los informes del examen incluyen resultados de aproximadamente 40 diferentes programas antivirus.

Como acceso directo adjuntamos el informe de Virus Total del examen de SecurityKISS:

Informe del examen de SecurityKISS Tunnel en www.virustotal.com

Claro que para volver a comprobar puedes usar otros servicios antivirus de este tipo.

Mi tráfico saliente es muy sensible. Temo que cuando la conexión VPN de SecurityKISS caiga de repente, la línea y mi PC simplemente continuarán enviando información usando conexión estándar no cifrada.
¿Cómo puedo bloquear el tráfico automáticamente? ¿Hay una solución a este problema?

La solución es Exclusive Tunneling. En cuentas resumidas Exclusive Tunneling elimina la ruta predeterminada para conexión subcayente de modo que ningunos datos pueden ser enviados fuera del túnel.

Why am I always assigned the same IP address from a particular server? Is it based on my client ID? This would seem to have the potential to compromise my security.

Assigning the same IP is an OpenVPN feature - it is the underlyig technology SecurityKISS Tunnel use. It is based on client ID and not on external IP address. The mapping is only stored internally on our server.

The 'static IP' is an option in OpenVPN but it is a default option and there is no reason to change it as it is fully secure.

The local IP you can see in SecurityKISS application is the IP address of virtual network created inside the tunnel so it is completely opaque for third parties. This IP does not appear outside of the tunnel as it makes no sense for external world (it is in a non-routeable address pool).

When I'm connected via SecurityKISS Tunnel and testing the connection using Internet Vulnerability tools like Shields Up I can see that the following ports are open: 22, 80, 443. Isn't it a security threat?

When connected in SecurityKISS Tunnel, the server you are connected to is scanned instead of your PC.

Port scanning tools like the one from Shields Up are designed to test open ports on Internet users' PCs and it generally makes no sense to run port scan tool for the server because it is normal mode of operation for a server to open ports to 'serve' the content and part of its nature.

It is a general principle of the client - server architecture that the server side must open a port to make communication possible. An average Internet user works as a client so usually they don't need to open any ports that's why the negative Shields Up scanning test result may be an indication of some vulnerability. However, testing the server in the same way is like trying to apply the same standards to completely different network entity. What is good for the goose is NOT good for the gander here. While for PC workstation exposing open ports is not very common, for the server it's perfectly normal to have many ports open.

To explain WHY the mentioned ports are open:
port 22 is an SSH console for administration, port 80 has many applications, port 443 is one of the VPN server software.

None of these open ports is a security threat. Additionally they are protected against attacks with adaptive firewall rules.

Can I be absolutely sure that data uploaded/downloaded is completely secure?

The tunneled connection is very secure - it is even resistant to 'man in the middle' type of attack.

The thing that can make the whole solution less secure is the ends of the tunnel, especially on the user's side.

Using SecurityKISS Tunnel your data is very well protected once it leaves your PC but if your PC is infected with virus, trojan or the Internet browser sends too much information then SecurityKISS Tunnel will not help much. That's why having a good antivirus program apart from SecurityKISS is so important.

Troubleshooting (Solución de problemas)

¿Cómo iniciar el programa en el modo de solución de problemas?

Encontrarás instrucciones aquí.

He instalado SecurityKISS Tunnel pero no puedo conectarme

Asegúrate que has bajado SecurityKISS Tunnel del nuestro sitio web. No uses un programa descargado de otros sitios web. No funcionará. La copia del programa que has recibido de tu amigo tampoco funcionará.

Comprueba en tu configuración de firewall si la conexión está abierta para SecurityKISS Tunnel (TCP 80, 443 y UDP 123)

También puedes comprobar si cliente DHCP está siendo ejecutado. Encontrarás instrucciones aquí

I can establish the tunnel but connection is slow and hangs up often

Please check your firewall for some advanced options that may cause problems with tunneled connection.

For example the Comodo firewall has 'Block Fragmented IP Datagrams' option which is turned on by default (Comodo -> Firewall Behavior Settings -> Advanced).

Since tunneling is about wrapping one packets into others some of them may be fragmented and blocked by the firewall because of that.

Issues of this kind are particularly difficult to track down so in case of unstable connection it is recommended to turn off firewall for a short time and observe if there is any difference.

Cuando en el túnel, mi programa cliente de correo electrónico no puede conectarse para recibir o enviar mensajes

En la versión gratuita enviar y recibir email directamente de programas clientes de correo electrónico como Thunderbird u Outlook está bloqueado para evitar el envío de spam u otro abuso. Por favor, ve también nuestra oferta que lo explica en detalles.

When SecurityKISS Tunnel installation completes and I'm trying to run it I get another dialog from AVG antimalware software saying that a threat was detected. After selecting 'Ignore the threat' I still don't have access to the program.

When AVG software complains about the SecurityKISSTunnel.exe file you actually need to select the AVG dialog box option to 'Ignore the threat' but it is not enough.

You can find additional info in the 'Ignore the threat' AVG dialog box, which says that the program can still be blocked by AVG Resident Shield. It means that Resident Shield does not respond to the 'Ignore the threat' command.

To fully enable the program you need to configure AVG manually: in the AVG application open Tools --> Advanced Settings, find the Anti-Virus --> Resident Shield --> Exceptions form, and add SecurityKISSTunnel.exe into the list of exceptions for Resident Shield. (Thanks to Bill Rodgers)

I can't connect from Android or iPhone/iPad

Privacidad

¿Proveedores de Internet (ISP) son conscientes de particulares descargas/cargas o solamente de su tamaño?

Tu ISP es consciente sólo de una conexión con gateway SecurityKISS y su volumen. Ningún tipo ni protócolo de tráfico encapsulado es visible para terceros.

¿Guardáis registros de tráfico por vuestro túnel?

Por razones de seguridad recopilamos información sobre la dirección IP del usuario y la duración de conexión.

¿Qué tipo de información es guardado en registros y cuánto tiempo son almacenados los registros?

Almacenamos registros que contienen la hora de conexión/desconexión, dirección IP y también volumen de tráfico para controlar el uso de cada usuario.

Registros detallados son eliminados automáticamente después de 10 días y la única información que es guardada por mucho tiempo es el uso total.

I am concerned about the amount of information stored about the users using your VPN. What information do you keep? Websites visited, usernames, passwords, etc?

As a completion to previous response - we do not store logs with information about traffic type or content. Your data is decrypted and sent directly to destination.

I am still worried about security of personal information because you store my IP address and connection time.

This is the minimum of information that we must store in order to make the service running.

Please note that comparing to the amount of information captured by an average website it is a drop in the ocean. Normally every website can store visitors IP address and register users activity, guess their preferences based on the time spent on a particular page and on the click order (needless to say about cookies).

We do not require registration from free users - there are no login names and passwords so they cannot be associated with your IP address. Such a design primarily has had users privacy in mind.
This is a very important point of our philosophy - we protect you from the third parties but we also want to protect you from ourselves.

We don't want to be another Big Brother Google who knows your next step before you even think of it. We are here to come to grips with this Orwellian dystopia that becomes a reality nowadays.

I'm connecting from Italy to SecurityKISS server in Chicago. When i use Firefox and surf to Google homepage I can see Italian version! Is this correct? I would expect English version for United States?

If you had connected to Google website before using SecurityKISS Tunnel, Google is able to recognize you as an existing user and display Italian language version instead of the US version. It is possible because Firefox (and any other Internet browser) is storing a small piece of information locally on your PC when connecting first time to a website. This piece of information is called Cookie. Cookie can be turned off in your browser settings but it may limit functionality of many websites. Every time you open the website again the browser sends Cookie back to that website what allows to identify you as a returning visitor. Thanks to that the website can also display the language version saved when you connected first time.

There is also another phenomenon possible. Google tries to assign default language settings to the IP address the user is connecting from. This assignment is based on the language the search queries are submitted. It may happen that many Italian users connect via SecurityKISS Tunnel server to Google and submit search queries in Italian so Google algorithm identifies SecurityKISS server as Italy based and Italian version is displayed by default regardless of the real server location. We have experienced similar issue with our Manchester server where Hong Kong Google version was displayed by default because there were many SecurityKISS users connecting from that part of the world.

Finally it is possible that IP geolocation is wrong. Websites are trying to guess from what part of the world you are connecting from. Based on tbe IP address they try to match the country however, there is no such thing like official IP-country matching central service. All these guesses come from approximate databases built on empirical data and it happens they are wrong in some cases. It has already happened that the most popular geolocation databases were identifying one of our UK servers as located in Ireland and Germany server as located in Italy.

Would your software cause my computer to not have full access to various sites like ebay.com or youtube.com or amazon.com, etc.?

No, website providers do not block traffic outgoing from our security gateways. Remember however that SecurityKISS Tunnel does not prevent sending cookies from your browser to websites. This is potential opportunity to block users by website providers.

Integration

In the paid version I tried to use VoIP (2 different providers: Fastvoip and Voipalot) both using SIP protocol but I couldn't establish a call. Why are you blocking VoIP/SIP traffic?

We don't block VoIP/SIP traffic for our customers. We have tested Fastvoip and Voipalot services and experienced many connection problems even on raw (non-tunneled) connection. When starting Voipalot in Ireland the program is failing when trying to find voipalot.com server.

Our conclusion is that those services are not reliable enough and also they may find it difficult to traverse NAT (Network Address Translation) which is an inherent part of local home networks and VPN services such as SecurityKISS.

It may be worth to look for other VoIP alternatives. Although we do not recommend using non-transparent technologies like Skype we have tested it with our service and it works well with SecurityKISS Tunnel.

Is there an option to set up forwarding ports, to fully set up something like emule to work as efficiently as possible?

No, we do not support port forwarding. It is not technically possible on a shared server IP.

Técnicas

Why does your geolocation data differ from the WHOIS data?

There is a different purpose and meaning of WHOIS data and geolocation service.

When you check a server or your computer IP address on our geolocation service you are getting the best estimate of actual location of the device with this IP address. The estimate is based on traffic analysis and information from users.

WHOIS query identifies the person or company to which the address has been delegated. Usually it shows the address where the ISP is registered on. Additionally large ISPs tend to cover wide geographic areas and in WHOIS database they are allocated to the same city and country.

¿Vuestro VPN está usando OpenVPN o PPTP?

El software de SecurityKISS Tunnel (Windows sólo) está usando OpenVPN mientras que también hay una opción PPTP (todas las plataformas) para clientes.

What is the difference between OpenVPN and PPTP?

It is explained in this article.

What is the encryption strength of your tunnel?

We use 128-bit Blowfish algorithm for session encryption. For the session keys exchange we employ 1024-bit RSA certificates. Session keys are renegotiated once per user per hour.

¿Porqué SecurityKISS Tunnel es más seguro que otros proveedores VPN?

Cada programa SecurityKISS descargado del nuestro sitio web es diferente. Cada usuario recibe una única aplicación generada individualmente con un par de claves de 1024 bits firmadas, generadas secretamente: pública y privada.

La idea es que la clave privada debería ser conocida sólo a ti y nosostros destruimos la clave privada RSA de cliente justo después de la descarga del programa. No almacenamos la clave privada porque debería ser conocida a ti solamente y no es necesario para el servidor para establecer un túnel seguro. Como cada usuario tiene una clave diferente, ellas son verdaderamente secretas y el túnel establecido es resistente a todos conocidos tipos de ataques incluso ataques intermediarios (a condición de que no reveles la clave privada).
Debido al hecho que cada usuario tenga una clave diferente, hay una ventaja más – no necesitamos nombres de usuarios ni contraseñas para identificar usuarios.

Otros proveedores VPN proporcionan solo una instancia de programa VPN que tiene el mismo par de claves RSA para todos los usuarios.
¡Esto significa que la clave supuestamente privada es conocida públicamente!

Esos proveedores VPN identifican usuarios a través de nombre de usuario y contraseña, lo que significa que la seguridad entera se basa en la contraseña que se convierte en la clave real en el canal de comunicación. De hecho, clave RSA de 1024 o 2048 bits o incluso la seguridad de 128 bits de sesión individual está reducida a seguridad de 8 – 40 bits, dependiendo de fuerza de contraseña.

What is the technical difference between Pause and Disconnect? Which one is better and for what?

Disconnect turns down the tunneled connection, so in order to restore the complete connection establishment with authentication and other security procedures must be performed.

Pause changes only the routing table on the user's machine, so the tunnel is alive but user traffic is not redirected to it so it sits idle.

From practical point of view Pause is for fast on/off switching.

I don't want my DNS queries to be resolved by Internet Service Provider's (ISP) servers, which may result in the ISP being able to log data. Does SecurityKISS offer anonymous DNS servers?

Yes, by default every SecurityKISS server has its own DNS software server which resolves users' DNS queries when they are connected in the tunnel. These DNS servers operate on the local tunneled network 10.x.x.x and are not accessible from outside. All DNS queries travel encrypted inside the tunnel. We don't log DNS traffic.

When using SecurityKISS Tunnel, is DNS still done the 'regular' way outside the tunnel, or does SecurityKISS do it for me?

When connected with SecurityKISS Tunnel, the DNS queries and responses are sent inside the tunnel.

It means that DNS info is protected in the same way as every other data transmitted in the tunnel - completely opaque to a third party.

I went to the website dnsleaktest.com and did a test. The test concluded that SecurityKISS DNS servers were leaking. Can you explain?

There is a lot of misunderstanding about DNS leaks so let's clarify the basics first.

DNS leaks may happen on Windows and it is related to the known Windows vulnerability (no global DNS settings + closed source => hard to predict how DNS queries are routed). This is not 100% fixable by the third party software like SecurityKISS. It is just a design and implementation flaw in Windows. The best advice we can give to users experiencing this is "Please use a decent operating system instead".

Many SecurityKISS users reported DNS leaks after visiting the dnsleaktest.com website. They were concerned that the test shows various DNS server locations so we investigated these cases.

Fortunately all the reported incidents to SecurityKISS were not actual DNS leaks but only the "smoke and mirror" alarming results from such websites like dnsleaktest.com and ipleak.net. The DNS servers displayed on dnsleaktest.com are the servers in the DNS hierarchy that are trying to resolve the domain. This is how DNS system works and there is nothing wrong with it. Normally these servers don't know your real IP address. Queries are proxied by VPN server so they are anonymized like the rest of the traffic.

Only if dnsleaktest.com shows your real location, it might be worrying and deserve investigation.

In most cases there is nothing to worry about but it's confusing to users and the DNS leak websites incite fear and draw wrong conclusions.

Even if it is not the real problem we had to address this issue because users don't know whom to trust and it is quite complicated matter to be explained in one sentence. We updated our servers so that certain DNS queries are not forwarded upstream to external DNS servers. It should prevent displaying confusing results on dns leak testing websites.

Can you briefly explain the difference between using TCP vs UDP servers?

SecurityKISS Tunnel can use TCP or UDP protocol to connect to the servers.

TCP was designed as a stateful, reliable protocol with error checking, retransmissions, connection and congestion control.
UDP is lightweight, connectionless (each packet is handled individually) and faster.

SecurityKISS Tunnel supports both methods to give users option if one of the protocols is blocked in their network however, it is recommended to use UDP as it is slightly faster.
It may happen that UDP is blocked on Internet Provider firewall so then TCP is the alternative option. Usually TCP's performance penalty is very low and connection speed is almost the same as in UDP.

What are the advantages and disadvantages of using TCP 443, UDP 123, UDP 5000 or UDP 5353?

In most cases it does not matter. Multple options are given in order to enable users who are behind restrictive firewalls and some protocol (UDP/TCP) and port (443, 123, 5353, 5000) combinations are blocked. If randomly selected option works there is no need to worry about. Otherwise it's worth to check a different combination.

Should I compress the data before sending in the tunnel?

No. It will give you no advantage in speed because we use compression anyway.

The compression factor depends on the type of data you are sending and whether you use our OpenVPN client or PPTP (available in paid packages only).

Can you provide tls-auth file for OpenVPN configuration?

We don't use tls-auth. The tls-auth option uses a static pre-shared key (PSK) which is shared between users and the server.

It is often used if two peers connect over VPN as an additional line of defense. In the commercial VPN multi-user setup it makes no sense because the key is no longer secret. It is shared among users, everyone knows it so it does not offer any security (although it may mitigate some Denial-Of-Service attempts against server).

Otras

May I distribute your software?

There is no point in doing it since every downloaded instance of SecurityKISS Tunnel is a different binary.

Please do not share copies of downloaded binaries nor make them available on sharing websites. The shared binary is not going to work. Moreover it is in your interest not to share downloaded program because it will stop working for you. If you want to recommend it to someone - share the news and redirect people to our download website where they can get software for free.

Your software is one of the best ideas I've ever seen. Excellent work.

Thank you. You can help to improve it by sending suggestions and issues you found. Also any suggestions related to the website and its content are welcome.

We are going to expand the Articles section so if you have any ideas or texts you would like to publish - let us know!

Especially we are interested in making it as intelligible as possible since we want to reach a wide audience.