4 ms·
could you please explain why a self-hosted vpn is a nightmare for privacy? i am running a streisand server and the disk is fully encrypted
by nowherecat 10y ago
could you please explain why a self-hosted vpn is a nightmare for privacy? i am running a streisand server and the disk is fully encrypted
- vox_mollis 10y agoBecause you're moving the "exit" from your non-anonymous local ISP to your non-anonymous colo provider. If you want to hide your traffic or at least make your adversary work a little to determine who you are, shared VPN endpoints are better.
- philsnow 10y agoHow is that any different? ISPs don't let just anybody know who the subscriber is at a given IP (though if you do reverse lookups, many ISPs so leak a lot of locality information, so still a good idea to use some VPN instead of no VPN). My Streisand hosted on AWS looks to the outside like anybody else's Streisand hosted on AWS, doesn't it? Similarly, my f-secure egress looks like anybody else's f-secure egress, so what's the difference? I don't really know, I don't use a VPN. Really asking.
- vox_mollis 10y agoISPs don't let just anybody know who the subscriber is at a given IP They certainly let law enforcement and intelligence agencies know, often without a warrant. Please read my comment as if the threat model includes panopticon governments, not common skids running aircrack-ng.
- philsnow 10y agoAnd reputable VPN vendors resist efforts by nation states to procure information about subscribers? I would expect to have to pay a handsome fee for that. (I'm not saying you're wrong; again I've not really thought about having to thoroughly anonymize my own traffic.)
- halomru 10y agoWith a VPS-self-hosted VPN all your connections to the outside originate from a static, unique, unshared IP, making it trivial to track and correlate your behavior across all protocols. Instead of containable identifiers like cookies, your IP has become a guaranteed unique identifier. To leverage this, it's fairly easy to detect you're on a self-hosted VPN: your IP is in an IP range assigned to a hosting/colocation provider, is not a TOR proxy (there is a public list of those) and doesn't belong to any remotely popular VPN (easy to enumerate for a little money, lots of lists exist). In exchange for that you have eliminated your ISP (or public wifi) as a threat but instead added the hosting provider to the list of threads. And for any adversary that stands above the law, the routing infrastructure of your hosting provider is already a valuable target.
- nowherecat 10y agothanks. so basically there is no way to hide the addresses i access through my vpn from the provider of my dedicated server? would it help if i used non logging encryped dns server?