8 ms·
Every time this sort of question comes up, I reflexively link people to this page: https://gist.github.com/joepie91/5a9909939e6ce7d09e29 https://gist.github.com
by CiPHPerCoder 9y ago
Every time this sort of question comes up, I reflexively link people to this page: https://gist.github.com/joepie91/5a9909939e6ce7d09e29 https://gist.github.com/joepie91/5a9909939e6ce7d09e29
Most of the time what people think they need a VPN for, a VPN won't actually help them much. They have a narrow use-case in privacy contexts, in which case you're better off using Tor.
- jakehm 9y agoI think the most popular use case is torrenting which a VPN will help.
- blfr 9y agoIf you want to torrent, turn one of the low end boxes into a seedbox rather than a VPN server.
- jerheinze 9y agoThat isn't great privacy wise as it's still privacy by policy. The best way to torrent is to use i2p which - unlike Tor - encourages that activity. (Short tuto: the default Java i2p bundle already comes with I2PSnark, a torrent client. To download a torrent, search through known i2p trackers such as the Postman Tracker: http://tracker2.postman.i2p http://tracker2.postman.i2p )
- dfrey 9y agoThe content owner could still request your information from the VPN provider and the VPN provider might provide it (even if they say they won't). I think the main benefit is that there are so many individuals torrenting copyrighted material that aren't using VPNs that it means you aren't the "low hanging fruit" so you're considered not worth the effort by the content owners.
- tensor 9y agoYes, but there is a big difference between "this provider might be lying about not storing traffic, and they also might give the data to someone" and "this ISP is 100% storing traffic and routinely gives that data to others."
- jerheinze 9y agoWhy base your privacy on wishful thinking ("provider is probably not lying") instead of using privacy by design solutions? (e.g. i2p for torrenting)
- prophesi 9y agoEven then, setting up your torrent client to use a proxy is just as simple and effective.
- untog 9y agoThat github note doesn't really disagree with the article, which points out that you need to trust your VPN provider. My general position is this: I don't trust my phone provider. At all. Just a week or so ago there was an HN post demonstrating how an ad provider can get your full name, cellphone plan details etc just by calling an API from a page rendered on your phone. But I also don't really have a choice - AT&T or Verizon or T-Mobile, they're all different flavors of the same crap. Do I trust my VPN provider unequivocally? No. But I trust them a hell of a lot more than my phone provider, and they can't sell my personal info against my browsing history because they don't have it. A VPN isn't the answer to everything, but nor is it useless.
- tptacek 9y agoNo, hold on. The two articles disagree very much. The one Scott just cited explains that you can't trust a commercial VPN provider.
- untog 9y agoThe Mozilla post says: > Are VPNs truly private? > Unfortunately, no. The VPN provider can still log your browsing data. You are essentially putting your trust in your VPN provider. Will your provider hand over info when pressed? Will they log your browser data and sell it at a later date? Which is basically also saying you can't trust a commercial VPN provider. I suppose it does differ in that it says it's still an option, though.
- bearbearbear 9y agoWhy do you trust your VPN provider more than your phone carrier? What have they done to earn your trust?
- untog 9y agoPartially, at least, they don't need to earn my trust as much. They don't have my name, address, date of birth and social security number/credit data, like my phone company does. The only positive point of trust a VPN provider has is that no-one has exposed them selling browsing data. Definitely not great, but also better than my phone company by default.
- criddell 9y agoI trust most VPN services more than I trust my ISP. If what you are trying to do is avoid your ISP collecting your surfing data for advertisers, throttling Netflix traffic, or adding a super-cookie to headers, then a VPN might make sense. My ISP choices are limited to two companies that are both terrible. A VPN is a nice way of limiting what they can do to you.
- jerheinze 9y agoYou don't get any additional privacy, the only way to really _guarantee_ that you get additional privacy is to use a solution that provides privacy by design rather than by policy.
- ghostly_s 9y agoHow do you not get any additional privacy?
- jerheinze 9y agoAs I mentioned using privacy by design solutions (Tor, i2p, ...)
- criddell 9y agoI'm not looking for a guarantee. Probably getting additional privacy is good enough for me.
- jerheinze 9y ago> I'm not looking for a guarantee. Probably getting additional privacy is good enough for me. I think we can both agree that wasting your money on wishful thinking ("maybe provider doesn't log") instead of using free open-source privacy-by-design solutions is a bad idea.
- deleted 9y ago[deleted]
- __sha3d 9y agoI feel like this is dated, because in 2017 this: > You are on a known-hostile network is true for every network in the USA. You can be sure they ae all being snooped on by 1. the ISP collecting traffic data for profit and 2: the gov. because they get it all anyways.
- iak8god 9y agoThe title of this should be "Don't expect VPN to magically protect your privacy," not "Don't use VPN services." Here are some reasons I've used, and continue to use, VPN: * When I am on a network that uses an idiotic blacklist to block certain types of content. The network might even be run by my employer and I might be accessing content that is necessary for my work, but there might be no way to appeal the idiotic blacklist. * When I am on a network that INJECTS content into HTTP responses (a certain paid airline WIFI used to do this). * When I am on a network that might allow other users on the network to snoop on / mess with my traffic. * When I want to access services that I have paid to access but are only available to IP addresses in a specific geographic region, and I happen to be in another geographic region. Etc.
- Pigo 9y agoI used to be employed at a place that was so restrictive I couldn't even access asp.net (the website). I think it was something to do with it being in the cloud and looking like it was being hosted in the middle east. Most people probably don't know what it's like to work in a company with the extremely power hungry network admin that want someone coming to them for everything.
- scott_karana 9y agoThree of your four points are explicitly addressed in there as reasons to use a vpn.
- Skunkleton 9y agoFor now, I am running my own VPN on Linode. The only real benefit of this is now my traffic is mixed with non-similar traffic. The hope is that this makes it less valuable to monitor the contents of my traffic. Of course, this just security through obscurity, and nothing more than a half measure. The internet is not designed for privacy, and privacy does not benefit the majority of commercial stakeholders of the internet. This is probably why most privacy solutions feel like shoving a square peg through a round hole. My personal feeling is that we should combat commercial bulk surveillance through legislative means.
- CiPHPerCoder 9y agoObligatory: https://twitter.com/tqbf/status/700798735190601729 https://twitter.com/tqbf/status/700798735190601729
- simonh 9y agoA confusing, content-less, arbitrary recommendation against Linode with no clear justification or reasoning given anywhere in the tweet stack is obligatory? I'm confused. Are there any actual reasons not to use them?
- erikbye 9y agoHis "recommendation" stems from a DDoS incident, and possibly, a hack. https://news.ycombinator.com/item?id=10998661 https://news.ycombinator.com/item?id=10998661
- jerheinze 9y agoYour last paragraph ignores the existence of many privacy by design solutions such as Tor or i2p. Yeah, they can't protect against a global passive adversary - as any other low latency anonymity system in existence, but that's totally different from saying that there's no way to have privacy on the Internet.
- Skunkleton 9y ago
- sametmax 9y agoMost people I know want a VPN to pirate stuff without consequences. So I'd say, Tor would not cut it.
- CiPHPerCoder 9y agoTor is emphatically not meant for piracy, especially BitTorrent.
- jerheinze 9y agoAs I mentioned in another comment about using VPN for torrents: > That isn't great privacy wise as it's still privacy by policy. The best way to torrent is to use i2p which - unlike Tor - encourages that activity. (Short tuto: the default Java i2p bundle already comes with I2PSnark, a torrent client. To download a torrent, search through known i2p trackers such as the Postman Tracker: http://tracker2.postman.i2p http://tracker2.postman.i2p )
- sametmax 9y agoUnless stremio and other pop corn time like can work transparently with i2p, it won't help.
- jerheinze 9y ago> Unless stremio and other pop corn time like can work transparently with i2p, it won't help. What? i2p is a self-contained network and not really meant for clearnet browsing.
- sametmax 9y agoYou need to look up what stremio (https://www.strem.io/ https://www.strem.io/) is and understand the value proposal for the casual non tech saavy end user. This is the face of torrenting now. Not magnet links. People don't know what a URL is anymore, don't expect them to understand a classic torrent client or i2P.
- aquova 9y agoI'm fairly new to whole world of increased internet privacy, so I'm curious of the benefits of using a VPN or Tor. I'm not a political activist or engaging in illegal activity, I just want my personal data being passed around as little as possible (preferably by spending little to no money to do so). Is using Tor worth the effort? What are the benefits? Or do I simply use Chrome and resign to my fate like nearly everybody else?
- jerheinze 9y ago> Is using Tor worth the effort? Definitely. > What are the benefits? Because of its 3-hop design, a non global passive adversary (GPA) would need to control both your entry node and the exit node to de-anonymize one of your Tor circuits. In addition, Tor circuits generally last for 10min only. Also using the Tor Browser you get stream isolation meaning that you get different Tor circuits for different websites. You can also setup your own non-exit node and connect to it to ensure that no single point in your Tor circuit controls both the entry node and the exit node.
- derefr 9y ago> a non global passive adversary (GPA) would need to control both your entry node and the exit node to de-anonymize one of your Tor circuits That's not a benefit, that's a feature. A benefit involves a use-case. What does a person gain from not having their traffic de-anonymized? The described user is someone who doesn't have any particular activities they need to keep secret or risk jailtime. So, for them, what's an example of something that could happen differently in their real life if they used Tor vs. if they didn't? (This wasn't a rhetorical question; there are such use-cases. I'm just commenting to prod you into zooming out a bit from "privacy is its own end" to thinking more about what regular people care about and how privacy helps them get it.)
- sam_goody 9y agoFor starters, don't use Chrome. Chrome sends a whole lot of data to Google (and possibly to their data-sharing partners) such as, at the least, what sites you visit and how long you are on each. When combined with Analytics, cookies, profiling and whatever G services you use, and the fact that Chrome is a program (not a site) connecting that all, you have pretty much lost any legitimate hope to privacy before you begin. Use HTTPS everywhere is a no-brainer, as at least the middle steps won't see the data. IMO, using a commercial VPN is just not that difficult and the speed is close to native, so its a lot easier than TOR.