11 ms·
This seems like bad advice because it doesn't address the legitimate need for keeping your browsing history private from overzealous, data-mining ISP's [1]. An
by infodroid 9y ago
This seems like bad advice because it doesn't address the legitimate need for keeping your browsing history private from overzealous, data-mining ISP's [1].
And even in the case of a known-hostile ISP that engages in invasive practices like supercookies or ad injection, it's unrealistic to ask users to set up and maintain their own VPS servers.
For the average internet user, a "glorified proxy" service that is hassle-free to set up is a simple and effective means of protection against such a menace.
[1] https://techcrunch.com/2017/03/29/everything-you-need-to-know-about-congress-decision-to-expose-your-data-to-internet-providers/ https://techcrunch.com/2017/03/29/everything-you-need-to-kno...
- rsync 9y ago"it's unrealistic to ask users to set up and maintain their own VPS servers." I think that sshuttle[1] changes that calculus. sshuttle allows you to make any ssh server a VPN endpoint. So you don't need to configure IPSEC or make an SSH tunnel or anything like that - you just need a login on an ssh server somewhere. [1] https://github.com/sshuttle/sshuttle https://github.com/sshuttle/sshuttle
- GordonS 9y agoAFAIR, it doesn't work for Windows clients, which are a rather large user segment. Still, it is impressively simple to use for Linux and OSX users.
- rsync 9y ago... and it works for FreeBSD and as of our (rsync.net) sponsorship of work done last year, has DNS support in FreeBSD with ipfw as the backend.
- __jal 9y agoIt was addressed, indirectly, at the end - "You are on a known-hostile network". In my case, one of my links is Comcast, a known-hostile network. I agree it should have been much more prominent, because this is exactly why I use one, and why many folks I know use one.
- thsowers 9y agoThis gist was also written in 2015, I think the knowledge of ISPs data-mining is more public now (even though it was likely going on then anyways in some format)
- hug 9y agoIt seems like bad advice because it is, frankly, just bad advice. Nearly all of his arguments fall down, even within his own post. He says that VPN providers don't provide more security. They do, and he mentions this himself when it comes to the public wifi argument. He says that VPN providers don't provide more encryption. They do. Another layer of transport encryption is another layer of transport encryption.[1] He says that VPN providers don't provide more privacy. They do. Turns out a lot of networks do things like log DNS, which a decent VPN client can tunnel.[2] He says there are two use cases for VPNs: There are a lot more. He says that tunneling all of your traffic is a worse case for obfuscating your identity to a third party service. It's not, or at least I can't imagine how it would be. He says that instead of a VPN, you can use a VPS with a VPN: That's just a VPN. It does all of the same things, including being outsourced to a third-party provider, except you lose a ton of the functionality of a real VPN service like geographical redundancy and spread. He asks why VPN services exist, if for any other purpose than stealing traffic or data, but fails to understand any way in which a VPN service could be useful. The entire piece is just the opinions of someone who is failing to see that other people have significantly different use-cases and threat models than he does. - [1] Especially if you think of "local -> internet" as easier to intercept than "somewhere internet -> otherwhere internet". Which it usually is. One involves something dumb simple like ARP poisoning. Another involves compromising a telco or the VPN provider itself, which is a teensy bit harder. All of this is even sillier if you consider the hostile-network scenario as well. [2] Yes, you are offloading 'trust' that the VPN provider doesn't also log your DNS. There's more chance that they don't when they say they don't, than your corporate network doesn't when they say they do.
- raides 9y agoThere is less of a chance that the Colo or shell account you are using to run psybouncer will hand over anything to anyone before you wipe the machine than there would be directly connecting to a VPN service. I think this is addressed to average Joe Americana who clicks the protect button in Facebook.
- kurthr 9y agoHe's apparently never been to China... or he'd already understand "Why VPNs".
- yorby 9y agoVPN providers have just as much insight about your traffic as your ISP... it's just a matter of time before they monetize it... and they both know who you are (unless you are very very very careful, which is almost impossible).
- lagadu 9y agoNegative on that: all a VPN provider knows about me à priori is my IP (and all that comes with that, like ISP and rough location) and which monero payment ID I used to pay it with (which is entirely useless). In contrast an ISP knows everything: my address, name, bank account, contracted service, fiscal number, etc. If either of them is going to use my traffic data against me, I'd rather it be the former, who I can easily replace within minutes and has less information about me.
- rphlx 9y agoIt does not totally invalidate the benefits you mentioned but from what I've heard there are mature commercial services that map consumer IPs to meatspace IDs (name, phone number, address, household income, credit score, etc). The ad industry is both a consumer and a producer of these databases for obvious reasons. Highly likely that multiple levels of law enforcement have access to them as well.
- sk5t 9y agoVPN providers are replaceable in ways in which last-mile ISPs are not, so they have more of an incentive not to trash their reputations.
- bigiain 9y agoAnd (for some of us) even regular/non-malicious but law abiding ISP's - who're now required by law to keep logs of your "metadata" aka: which websites you visit... https://www.ag.gov.au/dataretention https://www.ag.gov.au/dataretention
- anonytrary 9y ago> doesn't address the legitimate need for keeping your browsing history private from overzealous, data-mining ISP's I think the point of the article is that an arbitrary VPN provider is really no different than an overzealous, data-mining ISP. Unless people can trivially join some sort of anonymized, decentralized mesh network, they are going to be forced to trust a third party at some point.
- rbcgerard 9y agoWho do I trust more Comcast (ISP) or F-secure (VPN)? Pretty easy answer...
- irundebian 9y agoNone of them?
- bjoli 9y agoYeah. M ISP has sold data on customers before which is why I uses VPN. I chose one which seems moderately high profile (where a court case could ruin their reputation), and they are apparently planning on supporting wireguard later on. Seems I picked the right one :)
- c16 9y agoHave you ever considered it would be easier for the government to pay the VPN providers a large sum to hand over the data, avoid a big public lawsuit, and silently mine all the data without having to break the encryption?
- bjoli 9y agoThe ISP an the VPN providers are already mandated by law to hand over my data at any goverment request, but a VPN provider is not required to store data for 6-24 months. That is not what I'm afraid of. I just trust my VPN provider more than my ISP. The data policy of my VPN is much better: they cannot legally sell my data,whereas my ISP make no such promises.
- c16 9y agoDon't get me wrong - I pay for a VPN subscription too for when I'm travelling/public wifi, but it's much easier to quietly hand VPN providers a nice sum of money for them to just hand over the keys. Everyone leaves happy. Based on that, I believe if you want an extra level of security for every day use, then go for a big VPN co. If you're doing highly sensitive style stuff, then there's probably better software and services out there. It's all about your threat model I suppose.
- bjoli 9y agoI am using mullvad.net, which I would consider large enough. They operate in a jurisdiction where I can actually hold them liable and where I know which of their claims are leally binding.