6 ms·
Always using VPN has really made using Internet a lot nicer place, I can use any Wifi without any fears, don't have to care about ISPs doing funny things with m
by wmt 11y ago
Always using VPN has really made using Internet a lot nicer place, I can use any Wifi without any fears, don't have to care about ISPs doing funny things with my traffic, and if I get country blocked content I can just quickly route my traffic to another exit node.
Of course then the VPN provider is the single point of failure, but if it's trustworthy enough only folks with proper court orders should have access to my traffic. And it's an extra ten bucks per month or so.
- retube 11y agoAren't you then just effectively shifting your choice of trusted provider from ISP to VPN? Is it possible to run your own VPN on a VPS host, digitil ocean or linode or similar?
- userbinator 11y agoNot just VPN, but it really becomes whatever ISP the exit node of the VPN is connected to.
- scintill76 11y agoYeah, but at least there haven't been any (high-profile) abuses, yet. Meanwhile Verizon and now Comcast have been caught tampering with their customers' traffic, and those are probably just the well-publicized cases. Maybe I am just blissfully unaware of VPNs' shenanigans.
- djent 11y agoCox injects HTML into your HTTP connections. I've recieved popups on pages saying they've spotted traffic from a botnet server over my connection, and that my computer may be infected. I talked to Cox support and they view it as a feature.
- jakeogh 11y agoI saw that once, not sure how common it is because I surf without JS by default. http://www.cox.com/residential/support/internet/article.cox?articleId=a31ff300-bc03-11e2-caa8-000000000000 http://www.cox.com/residential/support/internet/article.cox?... Will happily cancel my service if it continues.
- netheril96 11y ago>Is it possible to run your own VPN on a VPS host, digitil ocean or linode or similar? Yes. I run several types of VPNs and shadowsocks on a VPS host. I mainly use it to bypass GFW though. Of course, trusting the VPS provider and its ISP is no different than trusting a VPN provider and its ISP.
- bigiain 11y agoOn the other hand, while your VPN or VPS provider may be no more trustworthy than your local ISP, it's _much_ easier to switch VPN providers - and you can arrange to have them in a different jurisdiction as well - If my net connection is through a proxy server in the Netherlands run by a company from Germany in a datacentre owned by a Japanese firm and I'm in Australia browsing websites in the US - there's a lot of legal hoopjumping needed to get to me.
- Nyr 11y ago> Is it possible to run your own VPN on a VPS host, digitil ocean or linode or similar? It's possible and very easy: https://github.com/Nyr/openvpn-install https://github.com/Nyr/openvpn-install Disclaimer: I'm the script creator.
- laumars 11y agoI know I'm being unfairly picky when I should be thanking you for building a helpful install script; but your install instructions seem very counterintuitive given the privacy argument of running a VPN: wget git.io/vpn --no-check-certificate -O openvpn-install.sh && bash openvpn-install.sh Aside the lack of https scheme in the URL, you're also deliberately disabling the certificate authentication and then directly running the output into bash. Granted the double ampersand offers some protection, sadly it's still little better than the often criticized: curl http://example.com/install.sh | bash Plus the address you supplied is a shortened URL so the user has to trust that the file it redirects to is the same Github hosted file that's in the referenced repo. I do appreciate the work you've done. But given the security and privacy expectations of VPN, it might be worth having a little more transparency in your install instructions - even if that means splitting your instructions into 2 lines.
- crumpled 11y agoI find these points very valid. But, I always feel a little annoyed when people complain about piping curl into bash. If you know enough to see the danger, you also know enough to avoid it. Just curl to a file and read it, or open the web page and read it. Take some responsibility. I'm with you on the https and the short link, though.
- Nyr 11y agoAs you can imagine, this has already been discussed many times. For example: https://github.com/Nyr/openvpn-install/issues/24 https://github.com/Nyr/openvpn-install/issues/24 https://github.com/Nyr/openvpn-install/issues/66 https://github.com/Nyr/openvpn-install/issues/66 > given the security and privacy expectations of VPN The security and privacy expectations are that the network for the server is not compromised. If that's not the case, why would you want the VPN hosted there in the first place?
- malka 11y agoyes it is. Then you trust DO as an ISP though. imo they are far far more trustable than any comcast.
- deleted 11y ago[deleted]
- buro9 11y agohttps://github.com/jlund/streisand https://github.com/jlund/streisand " Streisand sets up a new server running L2TP/IPsec, OpenSSH, OpenVPN, Shadowsocks, sslh, Stunnel, and a Tor bridge. It also generates custom configuration instructions for all of these services. At the end of the run you are given an HTML file with instructions that can be shared with friends, family members, and fellow activists. " It's effortless.
- k_vi 11y agoIt is possible to run VPN on a host using a socks proxy. It is easy with something called "ssh tunneling".
- richmarr 11y ago> Aren't you then just effectively shifting your choice of trusted provider from ISP to VPN? Yes, but that's okay. Privacy is part of the VPN market's value prop; companies in that space compete on it, unlike ISPs.
- lsaferite 11y agoEven the $10/month Linode plan has 2TB of data transfer. If you use it as a VPN you'll have to halve that since you are using it as a conduit. You still get 1TB which is 3x the Comcast data limit. I say VPN everything. I tried doing the same with my mobile but it either eats my battery alive or kills instant notifications. I HATE that tracking tag that mobile carriers are adding.
- Vendan 11y agoLinode only counts download towards the data transfer, so you can pump 2TB through, as they only count the data one time, as it's heading out of the VPS.
- michaelcampbell 11y ago> Aren't you then just effectively shifting your choice of trusted provider from ISP to VPN? Sure, but the issue at hand is js/html injection, which a VPN more or less (generally more) obviates.
- knodi123 11y agoYou're shifting your trust from A.) a dumb-pipe retailer, who you may not have freely chosen, and who has no motivation to respect privacy, to B.) a privacy provider who is easily replaceable and whose entire business is based on quality and integrity. Seems rational to me.
- ck2 11y agoYou realize it is possible to just intercept the connection to the VPN over wifi right?
- netheril96 11y agoWhat? VPN connection is encrypted and (hopefully) authenticated. You can't inject data into that stream. Or you can, and completely break the connection.
- ck2 11y agoYou just middleman the vpn authentication via wifi - by spoofing the wifi router you THINK you are connecting to, but it's not really because its just emulated with a stronger signal so your device thinks everything is fine.
- bottled_poe 11y agoThat won't work if the encryption certificate is signed by a trusted authority.
- NoGravitas 11y agoI don't know about all VPN technologies, but OpenVPN does authentication with client and server certificates. Just spoofing the WiFi router is not going to let you spoof that.
- Wilya 11y agoThat's not how it works on a decent VPN system. If you try to do that, the VPN client will notice that the spoofed server isn't presenting a valid certificate or doesn't use a valid key, and refuse to connect. Same reason you can't "just" middleman an HTTPS connection. Besides, there's no need to spoof. The point of the VPN connection is to protect against the wifi router (even the legitimate one!) reading the traffic. By spoofing, you're just replacing a dodgy wifi router with another dodgy router.
- 11y ago
- akerro 11y agoIf anyone is interested, you can get TigerVPN lifetime for 30$ (one connection slot) or find online (I found one on reddit) TorGuard 50% coupon for 2 years service, but 5 slots and more endpoints. I use both from UK, and Internet is clear over there.