4 ms·
If you host your own VPN on a CPA, couldn't the authorities simply link your VPN IP (the VPS IP) to you via billing? Or am I not understanding how it works?
by _qbxp 10y ago
If you host your own VPN on a CPA, couldn't the authorities simply link your VPN IP (the VPS IP) to you via billing? Or am I not understanding how it works?
- i336_ 10y agoUnfortunately not sure what you mean by CPA, haven't heard that acronym before and Google only came up with "Cost Per Analysis" :P Theoretically speaking you're completely correct. The main mitigation in practice is to find providers in different countries which are unlikely to be cooperative given the context - for example most countries will look down heavily on picture sharing of certain kinds (if you get what I mean :( ), while different countries have different policies on torrenting. I've (solely anecdotally) heard good things about UrDN (used to be Ukraine, now Sweden); Feral Hosting runs in the Netherlands, a country often used for VPN type things (and if I understand correctly, you can get up to - big asterisks - 10Gbps-20Gbps with them, without bazillions of $/mo); and I understand Switzerland's laws are torrent-friendly, so getting hosting there is expensive but kind of the gold standard. As I said before, the VPN industry/scene is artificially inflated. Getting OpenVPN up and running is actually a lot easier than you might think, I had it on my todo list for months (getting a VPN running on a VPS for a friend) and I ended up getting OpenVPN itself AND per-application tunneling going on FreeBSD in about 2-3 days, with resilient client- and server-side autoconfiguration scripts stabilized after about a week. There aren't really any tutorials but it's all fairly easy to do. Unfortunately Windows doesn't do per-app tunneling that well, if at all, I don't think. I'd recommend playing with OpenVPN between for example two local machines/VMs, or ideally a local machine and a VPS somewhere (even one you're not planning on using for whatever the VPN would be for). This is because your LAN will always be more forgiving and responsive than the Internet, and also because "oookay, so now I can reach my laptop from 192.168.0.3 and 10.0.1.15" isn't as interesting (to me) as "my laptop is 10.0.1.15 and my VPS is 10.0.1.16!". If you're familar with VM networking or can accept the additional load of learning about that concurrently then go for it with VMs, but I wouldn't recommend it otherwise - your goal is to set up OpenVPN between a remote host and your local computer, not to specialize in networking two VMs together. There's also the possibility of tethering one computer to your phone for one end of the network (with your phone using its data), and using your existing internet for the other end of the network. That's if your cellular ISP allows VPN traffic. I wouldn't advise using your phone's VPN client for initial experimentation/setup, its debugging will not be nearly verbose enough to diagnose any issues.
- wakkaflokka 10y agoSorry, that was a weird autocorrect, I meant VPS, not CPA lol. I see what you're saying now. Choose a VPS provider who does not store your information or is not cooperative with legal requests. In terms of privacy, what's the difference between trusting a VPN service (i.e. iVPN) versus trusting a VPS service? Or are we talking the benefit is solely in the decreased cost of runing a VPN on a VPS?
- i336_ 10y agoNo sweat. > I see what you're saying now. Choose a VPS provider who does not store your information or is not cooperative with legal requests. Not storing information (eg, accepting Bitcoin) is mildly rare, I think, and the ones that Google easily turns up are categorically going to be expensive (since they're the ones fielding inquiries from who-knows-who with who knows what agendas). Places that aren't interested in info and are cheap on top of that are edging into the hens' teeth sector; they exist, but they take a truckload of digging (usually asking around) to find. UrDN aren't everything but they're an entry-level example of such a host. FWIW I learned about them from someone I was talking to on IRC (for other reasons, the conversation got to VPSes and they mentioned them). > In terms of privacy, what's the difference between trusting a VPN service (i.e. iVPN) versus trusting a VPS service? Or are we talking the benefit is solely in the decreased cost of runing a VPN on a VPS? Looking at the tables on http://vpngate.net/ http://vpngate.net/ (headsup: practically 30KB/s :P) you can see "Logging Policy: 2 weeks" ad infinitum. That's one example of nice transparency that I can recall. The only time I setup a VPN it was on top of a VPS so I don't actually have any sort of idea about the VPN market per se, in particular where to find concrete logging info. That said, speaking from a security standpoint, let's say someone wanted to exchange pictures/videos in the "exceptionally unsavory" category, they hop on Google, find a VPN that says "Logging: None!!", say "great!" and use that VPN for whatever cuz it won't be tracked. ....Nope. Not realistic. So, IMHO, from a good infosec standpoint, any VPN provider that says "no logging" is doing so solely to be a honeypot, or at least I would hope they are actually still logging! If they actually aren't that's heinous laziness. Of course, these providers are used as tunnels for torrent traffic on a daily basis, logging policies notwithstanding. If you've ever used Wireshark (or have a quick look at what it does), you can get an idea of packet capturing. It's trivial to do this on a central gateway or router for any network (or Internet)-connected server/service, and you can log all throughput to a machine without making any changes to that machine. The main two questions are storage and processing. If you have say a dozen 100Mbps machines you want to log, that's (assuming continuous 100Mbps throughput the whole time; unlikely but possible) (((1024^2)12)(246060)*12)/(1024^4) =13.04TB of data after 24 hours. If those 12 nodes get 1Gbps connectivity that becomes 135.89TB of data, and if you have 1000 1Gbps nodes you have 11.32PB of data to store. But once the data is stored, assuming a 24 hour window it must be completely processed within that window because it will be completely discarded afterward (literally overwritten). Need to go to sleep, can elaborate further in a few hours