6 ms·
A heads up: theres a really nice project called Streisand[1] which provides a multi-protocol VPN with very little effort. You can launch one on a cheap cloud pr
by Goopplesoft 10y ago
A heads up: theres a really nice project called Streisand[1] which provides a multi-protocol VPN with very little effort. You can launch one on a cheap cloud provider (like DO, if their policy allows).
[1] https://github.com/jlund/streisand https://github.com/jlund/streisand
- ryanmarsh 10y agoI've had a few problems getting it running on AWS but setup was a breeze on GCE. So far it's been cheaper (and safer) than most VPN providers I've seen. YMMV
- pythonaut_16 10y agoCan you give a rough estimate of your monthly usage and the price on GCE? I've been looking at AWS and GCE but I'm having a hard time figuring out the actual bandwidth costs.
- wellpast 10y agoAny estimate on EC2 costs using this moderately?
- staticsafe 10y agoThat would depend on your traffic levels and which instance type you want to use. This should help figure things out: http://calculator.s3.amazonaws.com/index.html http://calculator.s3.amazonaws.com/index.html
- chrisper 10y agoYou would be better of putting it on a Digital Ocean and then create / destroy a droplet when you need it. It is what I do and my cost is like $1.50 per month (as opposed to $5).
- then00b 10y agoI second the idea of using Digital Ocean, though I just pay the $5 a month and leave it running.
- bdarnell 10y agoI've used streisand on DO (while traveling in China) and it worked well. There's also a similar project called algo[1] which provides a single protocol with maximum security, in contrast to streisand's multi-protocol flexibility (and increased surface area). https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- andreyf 10y agoWhy does he refer to OpenVPN as a "risky server"? Does it have a history of embarrassing security vulns?
- bdarnell 10y agoI think "other risky servers" may refer to the lesser-known servers that streisand includes, like shadowsocks.
- deleted 10y ago[deleted]
- analogist 10y agoI think a recurrent concern is OpenVPN's reliance on TLS, and its codebase complexity as a result of being built on OpenSSL--but with far less attention and resources and vuln hunting compared to say, actual browsers. Complexity + lack of auditing person-hours is never a good combo. (See https://twitter.com/tqbf/status/806646188158152705 https://twitter.com/tqbf/status/806646188158152705) Matt Green's audit of OpenVPN, when completed, may lead to more light on the matter. Otherwise, we're just relying on informed intuitions.
- bitexploder 10y agoExcept all the shenanigans with IPSEC. https://en.m.wikipedia.org/wiki/IPsec#Alleged_NSA_interference https://en.m.wikipedia.org/wiki/IPsec#Alleged_NSA_interferen... As a "security people" I think me and tptacek could split a great number of hairs and get not too far on this one, but I am open to new info. I know a lot can hide in the complexity of OpenSSL. Maybe the whole thing with IPSEC was to sway us toward OpenVPN likes. Regardless, I still lean slightly towards OpenVPN But honestly I am out to defeat ad networks. I only aspire to give nation states indigestion (at a mass scale). Individually if a well funded adversary wants any one of us I think they have us.
- drzaiusapelord 10y agoWhy not run a utility that visits random websites to drown the signal from the noise? Imagine this thing running 24/7 and visiting all sorts of sites, including all sorts of porn and fetish sites or whatever is taboo in your culture. Now its impossible to see what I'm actually visiting and you'd be foolish to not realize that these are generated url visits. A bit like how people used to copy and paste 'NSA keywords' into their emails and web postings. Not sure why anyone isn't proposing this. Far better than dealing with the hassle and performance issues with a VPN. Want my browsing data? Fine, how's 1 million URLs a day grab you?