4 ms·
> Is it possible to run your own VPN on a VPS host, digitil ocean or linode or similar? It's possible and very easy: https://github.com/Nyr/openvpn-install htt
by Nyr 11y ago
> Is it possible to run your own VPN on a VPS host, digitil ocean or linode or similar?
It's possible and very easy: https://github.com/Nyr/openvpn-install https://github.com/Nyr/openvpn-install
Disclaimer: I'm the script creator.
- laumars 11y agoI know I'm being unfairly picky when I should be thanking you for building a helpful install script; but your install instructions seem very counterintuitive given the privacy argument of running a VPN: wget git.io/vpn --no-check-certificate -O openvpn-install.sh && bash openvpn-install.sh Aside the lack of https scheme in the URL, you're also deliberately disabling the certificate authentication and then directly running the output into bash. Granted the double ampersand offers some protection, sadly it's still little better than the often criticized: curl http://example.com/install.sh | bash Plus the address you supplied is a shortened URL so the user has to trust that the file it redirects to is the same Github hosted file that's in the referenced repo. I do appreciate the work you've done. But given the security and privacy expectations of VPN, it might be worth having a little more transparency in your install instructions - even if that means splitting your instructions into 2 lines.
- crumpled 11y agoI find these points very valid. But, I always feel a little annoyed when people complain about piping curl into bash. If you know enough to see the danger, you also know enough to avoid it. Just curl to a file and read it, or open the web page and read it. Take some responsibility. I'm with you on the https and the short link, though.
- Nyr 11y agoAs you can imagine, this has already been discussed many times. For example: https://github.com/Nyr/openvpn-install/issues/24 https://github.com/Nyr/openvpn-install/issues/24 https://github.com/Nyr/openvpn-install/issues/66 https://github.com/Nyr/openvpn-install/issues/66 > given the security and privacy expectations of VPN The security and privacy expectations are that the network for the server is not compromised. If that's not the case, why would you want the VPN hosted there in the first place?
- laumars 11y agoYou cannot control what happens beyond your own hosted infrastructure. Even the most trusted networks are still at the mercy of external DNS servers, web servers and routing equipment. Hence the entire point of trusted signed certificates. Just because a persons hosted VPS might be trusted it doesn't mean that: 1. The git.io redirects to the expected location. Anyone could clone your git repo then put a malicious script in a different shortened URL 2. Nor that someone couldn't MITM between the the user and the git.io 3. Nor similar MITM attacks between git.io and github Security is only as good as the strength of your weakest link.
- Nyr 11y agoYeah, so? If the server network is MITMed, you are fucked at so many levels that it doesn't even matter anymore.
- laumars 11y agoNot if you're running HTTPS you're not. You cannot have code injected into a HTTPS connection like you could with plain text HTTP. And even in the worst case scenario where the entire connection is re-routed to a rogue server: you would get a nice big warning that your connection isn't secure and the download would fail. Thus again preventing the malicious code from running on the users VPS. You're also still ignoring my first point as well. I really don't get your careless stance here. Github already comes with an SSL cert and you don't actually need a URL shortened for the type of link you're publishing. So all of these complaints people are making are so very easy to solve. But instead you are intentionally following bad practices. Frankly, if this is your attitude towards security then I really don't think you're the sort of person who should be writing installers for VPN servers to begin with.
- Nyr 11y ago> Not if you're running HTTPS you're not. Yes, you are. If your adversary can MITM a datacenter, it's likely that a rouge cert can also be obtained from a trusted CA. If your threat model includes this kind of adversary, please don't use my script. You should also consider how funny would be to host a VPN and route your traffic like this in a network which you don't trust. > You're also still ignoring my first point as well. What would an adversary accomplish pointing a DIFFERENT short URL to a malicious script? I don't understand. I'm only using/listing git.io/vpn, so whatever someone does with other URLs is not my problem. There is some fork using git.io/ovpn for example. > I really don't get your careless stance here. I'm not careless. You can either run the one-liner which clearly states --no-check-certificate or download and examine the script as long as you want. The choice is on you. > Github already comes with an SSL cert But minimal distro images don't come with trusted CA certificates, so it's useless. Yes, I could install them. No, I don't want to.