3 ms·
Tor has limited value. Lots of things are blocked (search, for example), and it's slower than dialup. The security of the exit points is also questionable, and
by oskapt 7y ago
Tor has limited value. Lots of things are blocked (search, for example), and it's slower than dialup. The security of the exit points is also questionable, and this is about trust.
Pushing all traffic through a VPN only moves the problem. Now I have to trust some unknown entity in some other country to respect my privacy. I don't want my traffic to bounce from Chile to Norway and then back to Chile when I do online banking. I run a VPN endpoint in Chile for my own traffic, but I don't need to push all of my home traffic through it....yet.
All useful traffic runs over HTTPS already, but metadata is still valuable. My ISP could snag SNI headers and know sites, but I don't think they're actively sniffing 100% of the traffic that goes across the wire. No, I think they want to be Verisign/Comcast/OpenDNS and redirect NXDOMAIN responses to ad pages or inject false responses to "unauthorized" queries.
- teddyh 7y ago> Tor [is] slower than dialup. That was true years ago, but nowadays I rarely percieve any speed difference at all when comparing browsing using Tor and non-Tor. > Pushing all traffic through a VPN only moves the problem. Now I have to trust some unknown entity in some other country to respect my privacy. But, and here’s the crucial difference: with VPNs you have a choice. A wide variety of choice. With ISPs, especially in the US, not so much. > All useful traffic runs over HTTPS already, but metadata is still valuable. My ISP could snag SNI headers and know sites, That’s due to be fixed with ESNI. Just wait for a technical fix. > but I don't think they're actively sniffing 100% of the traffic that goes across the wire. No, I think they want to be Verisign/Comcast/OpenDNS and redirect NXDOMAIN responses to ad pages or inject false responses to "unauthorized" queries. That is true today, but when DoH and/or DoT happens, the ISPs will certainly switch to doing whatever still works. They are merely sniffing and proxying DNS traffic today because it still works, but the second it no longer works, they will switch to whatever does work. You can’t just work around the current mechanisms, you have to look a few more moves ahead.