3 ms·
For users who can afford it, routing a vpn through tor solves the captcha issue with cloudflare. Also adds an extra layer of security
by dev1n 11y ago
For users who can afford it, routing a vpn through tor solves the captcha issue with cloudflare. Also adds an extra layer of security
- amdavidson 11y agoCan you elaborate? I cannot imagine how Cloudflare could distinguish VPN traffic routed through Tor and standard traffic routed through Tor. The only difference is a hop on the front end, no change to what comes out the exit node.
- dev1n 11y agoif you setup an access point to route all of your traffic through tor, then connect to your VPN through that access point, your IP is the VPN IP, not the exit node.
- icebraining 11y agoWhat the point of doing that over connecting directly to the VPN? Seems like the benefit granted by Tor (avoiding leaking who connected to the VPN) would be negated by the fact that there are now payment records from you to the VPN.
- dev1n 11y agoIf you pay with BTC, prepaid gift card (paid for in cash) etc.. then there are no payment records from you to the VPN. The benefit of this is that the VPN provider doesn't know who you are because you are accessing the VPN through tor. Yet the VPN provides you a stable IP that won't be CAPTCHA'd like most normal tor exit nodes are. Edit: This is good if you are trying to maintain an Internet profile (i.e. Facebook, twitter etc.) that isn't tied to your true identity.
- jobbleobble 11y agoBut you are losing out on some anonymity here. The VPN provider may not know who you are but you are consistently making access with the same user ID and from the same IP. Your activity can be correlated to that account and that IP. If that's not your aim (like you say - being signed in to the same facebook account all day suffers you the same problem) then this isn't an issue. But this isn't what a lot of tor users want tor for.
- wfn 11y agoRight, but then (1) your VPN will have a browsing profile which aggregates your otherwise ephemeral, anonymized and un-correlated browsing sessions; and (2) it would be easy for adversaries to extract that very helpful profile. If your threat model does not include (2), (1) is still bad!