5 ms·
So how do you protect form such things? I mean is there a way to analyze all you outcoming traffic (from a specific machine for example) and route every connec
by q1t 11y ago
So how do you protect form such things?
I mean is there a way to analyze all you outcoming traffic (from a specific machine for example) and route every connection(like dns and similar stuff) though desired endpoint?
- amelius 11y ago> So how do you protect form such things? Tor?
- ams6110 11y agoUnless you believe Tor is a giant honeypot created by the NSA.
- c_c_c 11y agoThere are certainly honeypots inside the Tor network as there are on the internet in general. Tor itself is an invaluable network when used properly for a variety of people and purposes. Perhaps not a major point but I believe Tor originated out U.S. Navy and DARPA, not the NSA.
- bluedino 11y agoYou can use a VPN or ssh tunnel and send DNS queries through that tunnel or proxy - however, that just adds another layer for anyone who wants the information to go through.
- dreamfactory2 11y agoDo VPN providers know any less than an ISP?
- 0942v8653 11y agoNo.
- mindslight 11y agoNo, but they're (statistically) less interested, know less about you, and furthermore you're less beholden to them. Chaining VPNs multiplies the effect, with the end result looking a lot like TOR. Centralization is bad precisely because it concentrates the information, adds context to it (what you're doing relative to others), and amortizes the cost of building surveillance infrastructure and developing the business relationships for exploiting it.
- dreamfactory2 11y agoSo I guess VPNs centralise the traffic of people who care about spoofing geography and/or keeping their traffic private from their ISP
- mindslight 11y agoYeah, VPNs are certainly not a panacea. Although last mile wireline providers have surveillance in their genes, having descended from state surveillance organs (eg Ma Bell). They already make good money servicing warrant requests for IP address records, and preemptively keeping a record of customers' communications partners would be extremely cheap. And such "network intelligence" ties right in to fighting against the commodification otherwise driving profit margins on transporting bits to zero. I'd bet on the infrastructure-less provider that starts off only knowing my rough geographical location and what type of gift card I paid with, and that I can drop any time.
- mirimir 11y agoUS gift cards no longer work for non-US purchases. Bitcoins are currently the best option. At least for anything past the first VPN in a chain.
- mirimir 11y agoThere are many VPN services. So it's somewhat misleading to say that they centralize traffic.
- mirimir 11y ago
- ams6110 11y agoI don't use my ISP for DNS. Nor for email. Not sure that really protects anything but at least it sidesteps any log mining they're doing on their own servers.
- RKearney 11y agoI use my ISP (Comcast) for DNS mainly for 2 reasons: 1. No other public DNS is faster. 75.75.75.75 is 6 "hops" away at 15ms rtt. Google's 8.8.8.8 is 10 hops away at 25ms rtt. DNS adds about 3 ms of latency for both services. 2. It's my understanding that many services can use DNS to do geographical load balancing when Anycast isn't an option. When using Google DNS I would routinely get pointed to Akamai nodes in Chicago. I live in Nashville. After switching back to Comcast I know reach Akamai in Atlanta, which provides much lower latency and higher throughput. Just my two cents.
- narrowrail 11y agoIf you have the ability, you can run DNSmasq[0] locally (i.e. 1 hop or less) on your router. For the sites that you interact with frequently, it is quite helpful. [0]https://en.wikipedia.org/wiki/Dnsmasq https://en.wikipedia.org/wiki/Dnsmasq N.B. I say or less because you can run it on your machine as well.
- bluedino 11y agoThe other problem with using your ISP's DNS severs is they can hijack your request, or be slow/down all the time. 4/5 when the "internet doesn't work" it's just the cable company DNS not working and using Google or OpenDNS "restore service"
- cJ0th 11y agoOne (albeit small) thing you can do is to do much as possible offline. For instance you could download Wikipedia and use it offline only. The same goes for maps. For example, Open Street Map data can be used offline.