5 ms·
How to find a trustworthy VPN service
- hprotagonist 9y agoI've been pretty impressed with https://github.com/trailofbits/algo https://github.com/trailofbits/algo so far.
- problems 9y agoAlgo and self-hosted VPN in general is only good for some applications though. - IPSec will be blocked on many places where port 443/TCP isn't and OpenVPN or similar could work. So it's not ideal for free wifi, enterprise or school networks. - You will still get DMCA takedowns from your datacenter or cloud provider if you don't choose one carefully - You're limited to a single IP so if you're using it for a scraper and get blocked, you have no option of just clicking next IP. Commercial VPN providers are often able to hit all these points.
- tptacek 9y agoAgree. It's a pretty bad idea to use centralized commercial VPN services.
- danieldk 9y agosshuttle is also great if you want an ad-hoc VPN and you have some SSH server somewhere: https://github.com/apenwarr/sshuttle https://github.com/apenwarr/sshuttle Virtually no configuration. Saved the day when my ISPs DS-Lite (IPv4 over IPv6) was broken. Just sshuttled to a IPv6-capable server and I was up and running again.
- deleted 9y ago[deleted]
- nthcolumn 9y agoAlex Sotirov.
- davepeck 9y agoMy general advice to people looking for VPN service is to use Algo if you have the skillset. If not, and you decide you want a centralized service, it effectively comes down to trust signaling. I have six criteria I look for in these cases, which I end this blog post with: https://davepeck.org/2017/04/16/why-its-hard-to-choose-a-vpn-provider/ https://davepeck.org/2017/04/16/why-its-hard-to-choose-a-vpn...
- josho 9y agoThe only use case I know of for a vpn service is to hide illegal torrenting from your isp. Why else do people route all of their traffic to a third party?
- thresh 9y agoTo overcome nation-wide blacklists.
- msh 9y agoUsing public wifi networks
- baldfat 9y agoEspecially when banking
- Ajedi32 9y agoI never really understood that one. Don't pretty much all banks use HTTPS these days? Wouldn't that make banks the type of site you'd be _least_ likely to need a VPN for? I'd be more concerned about using a VPN when browsing other, less secure sites that don't support HTTPS.
- bobjordan 9y agoChina. Get yourself in a place where every other page you try to visit is blocked and then you'd be a lot more thankful for VPN service.
- starky 9y agoInterestingly, I was just in China. Most of the things that used to be blocked worked perfectly fine for me. I barely used my VPN because even Facebook was working. It does seem to vary quite a bit, I've always found that Shenzhen is a bit more lax with the firewall than even neighbouring Dongguan.
- atentaten 9y agoThis article makes Mysterium Network's upcoming decentralized,zero-knowledge, trustless VPN service more interesting: https://mysterium.network/ https://mysterium.network/
- goodroot 9y agoI currently use cryptostorm. It's "more difficult" to use than most, but it seems trust worthy. ProtoVPN, their service, looks interesting. Perhaps worth checking out, but it would need a solid flock of regions in order for me to consider it.
- nthcolumn 9y agoOn the free tier there are about 8 udp and tcp ovpn I think with different EU endpoints.
- nthcolumn 9y agoDefine 'trustworthy'. Protonmail are now offering ProtonVPN free tier and paid subscriptions for higher speeds. Under Swiss law they are now required to store logs. The only trustworthy solution is your own OpenVPN server on some cloud provider (not difficult to setup). Even then it is debatable whether it would remain private long. Probably draw attention if anything but you won't get your logs sold to Target. It's hilarious how many 'VPN providers' don't even encrypt the traffic.
- ryanlol 9y agoNot OpenVPN, use Algo or soon wireguard. ¹: https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- Ajedi32 9y ago> Under Swiss law they are now required to store logs. Source? Their website [claims][1] they don't store logs. > ProtonVPN is a no logs VPN service. We do not track or record your internet activity, and therefore, we are unable to disclose this information to third parties. [1]: https://protonvpn.com/ https://protonvpn.com/
- marcopol 9y agoYes, they don't. Check their statement on the new Swiss law here: https://protonmail.com/blog/swiss-surveillance-law/ https://protonmail.com/blog/swiss-surveillance-law/
- johnpython 9y agoVPNs are for privacy, not anonymity. Confuse the two are your own peril - the Grugq The only trustworthy VPN service is one that you operate yourself. There are plenty of Github projects that will deploy a personal VPN for you: https://github.com/jlund/streisand https://github.com/jlund/streisand https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- bjt2n3904 9y agoWhat's to stop digital ocean / AWS from enumerating small servers that are listening on VPN ports and nothing else, then doing the same thing Comcast and Verizon are doing? Further more, what makes you think they aren't?
- LastZactionHero 9y agoMaybe they are, but I suspect they have different incentives. If I discover that they're singling out my $5/mo VPN server for monitoring, the rest of my $1500/mo is moving to another company.
- sr2 9y agoWhat's to stop someone renting an offshore VPS, like say, in somewhere like Hong Kong[0], and that isn't part of the 'fourteen eyes' spying alliance? [0] https://privacytoolsio.github.io/privacytools.io/#vpn https://privacytoolsio.github.io/privacytools.io/#vpn Also what's to stop someone stacking anonymously-bought VPNs on top of each other (proxy chaining) similar to how onion routing works, and creating their own homebrew Tor? If the VPN provider is peeking at the logs (which it shouldn't be doing), then all they see is another VPN IP. VPNception! (Something like the SHALON[1] technique is useful for this, for example): ------------ > Abstract—In this paper, we introduce a novel lightweight anonymization technique called Shalon. It is based on onion routing, aims to reduce complexity, and delivers high bandwidth. We have, compared to the widely known approach Tor, slightly reduced the level of security in favor for greatly increased performance. > The most significant advantage compared to other approaches is that Shalon is fully based on standardized protocols, which makes our approach highly efficient and easy to deploy. It also makes Shalon easier to understand for normal users, eases protocol reviews, and increases the chance of having several implementations of Shalon available. In this work, we provide a description of the design and implementation of Shalon, a performance and anonymity analysis, and a discussion on the scalability properties. [1] https://pdfs.semanticscholar.org/6f30/f14ff4972ddd787bf7e8590bfcdaf8df3414.pdf https://pdfs.semanticscholar.org/6f30/f14ff4972ddd787bf7e859...
- duozerk 9y agoThere's a pretty good (and, in contrast to most such lists, independent from any provider) comparison of VPN services here: https://thatoneprivacysite.net/vpn-comparison-chart/ https://thatoneprivacysite.net/vpn-comparison-chart/
- davepeck 9y agoIt's good if you're savvy, perhaps. But I also think it can lead people astray. I wrote more about it on my blog: https://davepeck.org/2017/04/16/why-its-hard-to-choose-a-vpn-provider/ https://davepeck.org/2017/04/16/why-its-hard-to-choose-a-vpn...
- Magnets 9y agoWhenever I see any article discussing which is the best VPN provider it's usually written by someone who is benefiting from the recommendation of a particular company. This article is no different
- _qbxp 9y agoI'm not super knowledgeable in this field, so maybe somebody can set me straight regarding VPNs. I have always assumed that VPN services like PIA, AirVPN, etc. are useful for, among other things: 1. To make the content you are viewing private from your ISP, employer, public WiFi, etc. 2. To make it more difficult for some remote host/website/actor to link your activity on their site with you. Isn't point (2) negated if you host your own VPN on AWS? In the sense that if you're in a country with a nefarious government, wouldn't it be easier for them to subpoena AWS than to get info from some VPN service over in ________ country that doesn't store logs, and has a million other users using the same IP? An example situation might be the RIAA notices that an IP is downloading Janet Jackson MP3s, and all they need to do is subpoena AWS if you're hosting your own VPN which has a unique IP, versus tracking down some Caribbean company who has given you an IP that's shared among thousands of users and has a public reputation for trustworthiness to hold?
- sr2 9y agoThere's a useful guide[0] if you're going to use a VPN and you should take it seriously. Personally I think a VPN is only ever useful for routing traffic over hostile networks (like at shady cafe wifi) and spoofing your geolocation to access geo blocked content. [0] https://gist.github.com/joepie91/5a9909939e6ce7d09e29 https://gist.github.com/joepie91/5a9909939e6ce7d09e29
- candu 9y agoMy current solution: ssh -v -C -D 1080 {server_i_own}, then set application proxy settings to localhost:1080. (I’m aware this isn’t really the same as a VPN, but for my current purposes it’s Good Enough.)
- sharjeelsayed 9y agoThis creates an Auto closing SSH Tunnel (Tunnel will close if Chrome exits) to a remote ssh server and redirect to localhost on port 7070 and launch Chrome Portable using local port 7070 as socks 5 proxy The following command is for cygwin on Windows.Can be customised for Mac OS or Linux ssh -o StrictHostKeyChecking=no -C -f -q -D 7070 username@servername sleep 10 ; "/cygdrive/c/PortableApps/GoogleChromePortable/GoogleChromePortable.exe" --proxy-server="socks5://localhost:7070" &