20 ms·
Don't Use VPN Services
- jacques_chester 7y agoThese arguments all assume that ISPs are more trustworthy than VPN providers. One of these markets involves competing on security and privacy. One of them involves colluding on influencing FCC policy. So even if a particular VPN provider is inept or corrupt, my expected return on the investment is higher than trusting TWC.
- daxelrod 7y agoYour threat model should also include your VPN provider's ISP.
- leetcrew 7y ago> One of these markets involves competing on security and privacy. one of the points raised in the article is that it's difficult to evaluate whether the VPN actually follows its logging policy. if they say they don't log, you pretty much have to take their word for it until information to the contrary somehow goes public. it's entirely possible that LE could be using a VPN as a honeypot and forcing everyone they catch to stay quiet through a plea deal. you'd never know until someone broke ranks. the VPN company could just as easily log your traffic and sell your usage data. unless they're sloppy about it, how would you find out?
- lugg 7y agoMaybe logs vs definitely pipes your GETs straight to Utah. Figure it out.
- joepie91_ 7y ago> One of them involves colluding on influencing FCC policy. That is an extremely US-centric view. Aside from that, physical ISPs have something to lose, as they have a very real infrastructural investment; whereas becoming a "VPN provider" literally does not entail more than "rent a few servers, run OpenVPN, buy a billing system license, hire a marketing guy". It's entirely viable for a VPN provider to just disappear overnight and set up shop under a different unrelated name at virtually no cost to them, if their old brand gets burned. That significantly changes the trust equation, and not in favour of VPN providers.
- derefr 7y ago> physical ISPs have something to lose Unless they're a (natural or artificial) monopoly, like... pretty much every ISP in North America is. Comcast has the reputation of, well, Comcast, and they're doing just fine. > Becoming a "VPN provider" literally does not entail more than "rent a few servers, run OpenVPN, buy a billing system license, hire a marketing guy". Yes, that's a good thing: it means that VPN providers, unlike telcos, are under selection pressure. Which means that for VPN providers, unlike telcos, reputation actually means something; the top VPN provider is striving much harder for your dollar than the top telco is. Certainly, don't pick a VPN provider at random, but you wouldn't anyway.
- joepie91_ 7y ago> Unless they're a (natural or artificial) monopoly, like... pretty much every ISP in North America is. Comcast has the reputation of, well, Comcast, and they're doing just fine. Once again, that is an extremely US-centric view. > Yes, that's a good thing: it means that VPN providers, unlike telcos, are under selection pressure. Which means that for VPN providers, unlike telcos, reputation actually means something; the top VPN provider is striving much harder for your dollar than the top telco is. Except that isn't how the industry works, at all. Virtually all "reputation" that VPN providers have originates from paid product placements (see: the myriad "VPN reviews" that are chock full of affiliate links, YouTube ads, etc.), and providers are assumed legitimate unless shown otherwise by default. This means that said "reputation" is 100% reproducible under a new brand without ever having a single long-term customer vouching for you. There's no competition on quality; the competition is on marketing only. Exactly why the industry has turned out that way and doesn't follow the "competition breeds quality" narrative that people on here love to put forward, is left as an exercise to the reader.
- RandomTisk 7y agoI would guess that it's because higher quality is pretty hard to achieve relative to most services. You can only offer a few things, stability, speed, perceived security and given the ease of use of the cloud, providing all three of those is relatively simple. The smattering of new VPN services are a little like altcoins in that respect. Going from perceived security to demonstrable security will require a strong demand and right now it seems ignorance is blunting that demand for individuals, where companies just roll their own servers they know they can trust and have access to.
- Angostura 7y agoOne of these markets involves specifically trying attract customers who have be worried about sensitive information or activity.
- throwaway13337 7y agoThis is silly. Most people use VPNs to get out region restrictions. These are getting more and more common due to local governments making laws that affect the whole internet - think GDPR - that individual site owners do not want to abide by so they block IPs. VPNs solve this very real problem for those still wanting access to the content. They're also used for subverting content region licensing. For example, with Netflix.
- fireattack 7y agoOr using it to tunnel to a more torrenting-friendly region.
- chii 7y agoI can't believe VPN can give you acceptable speeds for torrents tho...
- diminoten 7y agoWasn't this already recently posted? Also, it's a terribly constructed article, genuinely terrible. Completely wrongly assumes a specific threat model that isn't accurate for the target audience.
- causality0 7y agoNot to mention the author is all over the comments making an ass of himself by accusing his critics of being trolls.
- vesche 7y agohttps://thatoneprivacysite.net/#detailed-vpn-comparison https://thatoneprivacysite.net/#detailed-vpn-comparison Sure, you're always trusting a VPN at their word that they don't log, the above gives a detailed analysis of which ones you probably shouldn't trust. You can always host your own: https://github.com/n1trux/awesome-sysadmin#vpn https://github.com/n1trux/awesome-sysadmin#vpn You can also VPN chain (l2iptables), tunnel over TLS, etc. That gist post is pretty dumb imo
- Topgamer7 7y agoThe post is targeted to those who are not sufficiently technically adept to know of these techniques.
- Mirioron 7y agoHow many non-technical people read things on github? I'm seriously wondering, because whenever I see a link to something posted on github I always assume that it's intended for an audience with some technical understanding. I know that some laws and what not have put up onto github to provide easier access, but it never seemed like that non-technical people started using it.
- lucasmullens 7y agoI think if someone shared it to their facebook, a non-technical user wouldn't be much less likely to read it than say a medium article. Non-technical users don't really care about the domain. Certainly most readers of github are technical, but that doesn't necessarily make it less suitable for non-technical people.
- unicornfinder 7y agoThis post makes good arguments, but there's a very real reason to use a VPN provider over your own server - plausible deniability. With a VPN your traffic is mixed in with many, many other users', whereas with your own server, any traffic coming from that IP can safely be presumed to be yours.
- savethefuture 7y agoWhen the vpn company is subpoenaed because someone saw suspicious traffic coming out of their servers, regardless of the number of people, the logs and connections would point directly to you.
- juped 7y agoThis only applies if their claim to keep no logs is false; some have demonstrated in court that their claim is true.
- chiefalchemist 7y agoIs there a list of these somewhere that's maintained?
- bdibs 7y agohttps://thatoneprivacysite.net/detailed-vpn-comparison-chart-for-the-color-blind/ https://thatoneprivacysite.net/detailed-vpn-comparison-chart...
- chiefalchemist 7y agoThx. Maybe I missed it but I'm looking for a column: "Has proven in court they don't log."
- geofft 7y agoWhy not use Tor? Isn't its whole purpose to solve this problem in a trustworthy way?
- deleted 7y ago[deleted]
- drdrey 7y agoSeems to be from 2015
- mandukya 7y agoVery nice and informative. I wonder who's logging all the Tor data
- kryogen1c 7y ago>Because a VPN in this sense is just a glorified proxy. The VPN provider can see all your traffic, and do with it what they want - including logging. This is a tautology. If you use it as a proxy, then its a proxy. VPNs arent for this, and so are bad at it. VPN use case is either to securely leave a network (hotel Wi-Fi, airport wifi) or to securely get to a network (home resources, corporate resources). If you want a proxy, find a proxy.
- ignaloidas 7y agoProxy is securely leaving the network. There is no real difference in the principle of operation besides the protocol(SOCKS vs OpenVPN, etc.)
- deleted 7y ago[deleted]
- zamadatix 7y agoI think the crux is you consider "VPN use case is either to securely leave a network (hotel Wi-Fi, airport wifi)" a core VPN use case when the author considers that a proxy use case. I side with the author on this one, a virtual private network is meant to mean multiple private devices on a single network segment virtualized over some transport. Using it as the place you connect to to shove your internet traffic through a relay definitely fits the secure proxy use case/definition way better.
- jen_h 7y agoCan't easily configure a proxy for a mobile (ATT, VZ, et al) network connection (on iOS, at least), VPNs are easy-peasy to connect, so I use a personal, private VPN as proxy -- it obscures my traffic, blocks ads and malware...and I wouldn't say it was "bad at it" at all...
- Havoc 7y agoI don't get how using a VPS is any better than just going without anything? It's got the exact problem as the VPNs...just shifts the end point. Would there be any benefit in using a number of VPS round robin style? I've got access to a handful...
- bojo 7y agoI think the author is implying that you have some level of control versus none.
- Havoc 7y agoI'd prefer anonymity over control. Cause VPS box still has my name on it
- ignaloidas 7y agoWell, you now control the endpoint and have a lower probability of your traffic being snooped, as major VPN's have a concentrated stream of "interesting" traffic while random VPS's don't.
- savethefuture 7y agoSimply layers obscurity, it would be harder to subpoena multiple companies than a single vpn service. (Plus you "own" the vps and can quickly delete or create new services whenever) Before you browse, create a new vpn box, browse..., then delete the box after use. What logs, what box?
- Havoc 7y agoDoesn't really get me any anonymity - first VPS box in the chain still has my name on it (credit card history etc). Not that it matters - fortunately my traffic isn't all that exciting
- savethefuture 7y agoWell if you are really after anonymity, you have to also keep in mind your isp and browser fingerprinting and the million other things that can expose you online. :)
- lugg 7y ago"unless you are on a hostile network" Which I consider my ISP.. no, I can't just change ISP, I live under five eyes. I don't get a choice. This article is rediculous. It's just a clickbait title and a whole bunch of ranting saying the exact opposite.
- sjy 7y agoCan (2015) be added to the submission title? This hasn't been substantially updated since then.
- tptacek 7y agoWhy would it need to be?
- sjy 7y agoThe opinions expressed in the article aren't new to me, but I thought the fact that I saw them on the front page of HN implied that they were becoming increasingly popular or there was some new development (eg. confirmation of certain VPN providers being honeypots). If I had realised this was just a link to a discussion that happened a few years ago and had no real impact on the general consensus among IT experts, I wouldn't have clicked on it.
- alkonaut 7y agoI use a VPN because I want a proxy, and for e.g iOS it seems a VPN is the easiest way to set up a proxy. The article lists several reasons to use VPNs but isn’t the biggest one these days simply to circumvent geographical content limitations for online services such as video streaming? Nearly everyone I know has used a VPN service at some point, and if you asked any of the non-technical ones what it is they might say ”a think that lets me watch the game broadcast when I’m in another country”. People want proxies and the VPN providers provide VPNs that work like proxies. I can’t really see the downside to using the VPN as a proxy?
- juped 7y agoThe primary reason people use VPN services, which articles like this always fail to address, is best illustrated at this URL: https://iknowwhatyoudownload.com/ https://iknowwhatyoudownload.com/
- zamadatix 7y agoCurious if this actually lists anything accurate for anyone else. For me: Home - US, dynamic IP but unchanged in a year: nothing. Colo - US, static IP for 5 years: 7 things I haven't downloaded and can't find any history of on my disks or backup software. Seedbox - EU, static IP for 3 years: nothing. Home probably has <12 downloads, the other two should have thousands from various sources.
- juped 7y agoIt's very limited but tends to show normies some popular movies (and, crucially, embarassing pornography) they've torrented, which makes the overall point
- scandinavian 7y agoIt just scrapes public trackers. If you don't use public trackers, you wont show up.
- benhurmarcel 7y agoAt home it shows me ~20 downloads which I didn't do, and none of the ones I did. Not sure why.
- throwaway_bad 7y agoPretty impressive. Every anime I torrented off nyaa.si / horriblesubs was listed.
- sincerely 7y agoOkay, so I just checked this out, and there is a non-zero amount of child porn on the list. Is my roommate downloading CP? Is there any other explantion?
- p0cc 7y agoThe title is misleading because the article focuses on using VPN providers to obfuscate traffic when this is one use case of VPN technologies. The gestalt types of VPN usage are: * Remote Access VPN: Connect to resources on your corporate network. An example of this is you're in a coffee shop on holiday and need to access a corporate resource. * Site-to-Site VPN: Connect networks on two sites together. An example of this is you're in a branch office and need to connect to a resource in HQ. Note that VPN providers give you a limited Remote Access VPN to their network, which they control. They can do whatever they want to your now-decrypted traffic before they send it out to the internet. If you want to obfuscate your traffic, Tor is a better candidate.
- ignaloidas 7y agoQuote: > Note: The content in this post does not apply to using VPN for their intended purpose; that is, as a virtual private (internal) network. It only applies to using it as a glorified proxy, which is what every third-party "VPN provider" does.
- p0cc 7y agoI agree with you - the gist does have a caveat. The title is still misleading as VPN Services is too broad for the gist's content.
- joepie91_ 7y ago"Service" here refers to a service in the "company" sense, not in the "system daemon" sense. Legitimate VPNs are typically run on one's own network, not outsourced to a third-party service.
- dang 7y agoOk, we put anonymity in the title above. If someone has a better suggestion we can change it again.
- agwa 7y ago
- rhacker 7y agoUse a VPN and a proxy.
- devy 7y agoThe title should be renamed to "Don't Use 3rd Party VPN Services".[1] On-prem VPN deployments with solutions like AlgoVPN[2] from TrailOfBits is still very useful. Let alone mass majority of the the corporate IT's internal VPNs that is required for some workforces to perform their jobs remotely on public Internet. [1]: https://gist.github.com/joepie91/5a9909939e6ce7d09e29#gistcomment-2197521 https://gist.github.com/joepie91/5a9909939e6ce7d09e29#gistco... [2]: https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- tptacek 7y agoThe article specifically discussed that (using Streisand as the example rather than Algo, though Algo is what you should in fact use).
- hello_moto 7y agowhy Algo instead of Streisand? out of curiosity.
- tptacek 7y agoAlgo is designed not to install risky VPN software, or to use risky configurations, by subject matter experts.
- hello_moto 7y agoThank you for the insight (esp coming from security expert :)).
- jplayer01 7y agoI’ve seen a complete lack of arguments for why anybody should use Algo or Streisand. I don’t see the point. If you don’t trust VPN's, why trust literally anybody you choose to host a VPN, especially if there is arguably even less anonymity to be had.
- 7y ago
- nly 7y agoI use a third party VPN service to get around the fact that my residence comes with broadband that hijacks all DNS and routes all HTTP (port 80) connections through a Squid... I also feel sharing an IP with many other users adds to the level of anonymity.
- oil25 7y ago> I use a third party VPN service to get around the fact that my residence comes with broadband that hijacks all DNS and routes all HTTP (port 80) connections through a Squid... You could set up a local resolver to NXDOMAIN specific IP address replies. Dnsmasq has an option for this. Regarding Squid, what makes you sure your VPN services doesn't do the same? > I also feel sharing an IP with many other users adds to the level of anonymity. Can you explain how you feel this adds anonymity? There is still potentially a record of you using that shared IP at a certain time to do a certain thing, so what is your threat model in which the VPN helps anonymity?
- deleted 7y ago[deleted]
- S-E-P 7y ago> And remember that it is in a VPN provider's best interest to log their users - it lets them deflect blame to the customer, if they ever were to get into legal trouble. Hmmm? If you don't have record of it, the courts don't do much, at least in the US. If they subpoena you, and you don't have logs, nothing ever comes out of it. Outside of fines and things of that nature. > The $10/month that you're paying for your VPN service doesn't even pay for the lawyer's coffee, so expect them to hand you over. How do you think insurance works, or why airlines habitually overbook? A trivial word problem if you will: If you had 10,000 users, you were subpoena'd and only 100 users did anything worth prosecution, that's what. For one lawyer, drinking a $10 coffee (or two $5 dollar) every week day for a month. that's 20 days, $200 a month. $2,400 annually. Assuming in this example only 1% of your users need defending, that's 99% of your coffee budget you don't have to worry about! For 10,000 users, a yearly subscription pulls in about $1,200,000 (we aren't doing any adjustment for taxes and all that garbage). If 99% of your users are behaving themselves.. or at least not doing something bad enough for the courts to take notice (which in the digital age, things like piracy are white noise) that means you still have $1,188,000 to help you in those, typically blanket cases (i.e. a court case in which 20 of your users were downloading illegal movies, and MGM got really upset). Since if you aren't logging, these infractions are dealt with in aggregate usually, since it can't be quantified. So number of lawsuits < bad users. That's not bad, if all your lawyers needed was coffee monthly, then you could support, with 99% of your users cash, 495 lawyers coffee for a year! more than enough coffee to defend your business. Don't forget you can still use the "blood money" you got to buy them coffee! The basic principle behind my oversimplified, and somewhat tongue-in-cheek example was to remind you that insurance is a lucrative business. I wonder how they survive if your monthly cost for liability (up to $500,000) isn't $500,000 per month!?!
- thothamon 7y agoWhile it's true that your VPN provider _may_ be lying about their "no logging" policy, at a minimum, you get additional layers of protection. Your source IP is masked. A subpoena would be required to reveal your source IP, and perhaps your VPN provider is telling the truth about not keeping logs. If your VPN endpoint is in a different country than your network endpoint, then the legal obstacles get even higher. Surely you shouldn't depend on that alone. Tor would be a wise additional layer of protection, if applicable. But to suggest that you get no privacy benefit at all from a VPN is like saying your host may be compromised, so you might as well use regular telnet rather than SSH.
- bureaucrat 7y agoThey _were_ also not disclosing that they were hacked last year. https://web.archive.org/web/20180504001844/https://8ch.net/b/res/7948898.html#7950919 https://web.archive.org/web/20180504001844/https://8ch.net/b... Yes, people would rather give their entire packet to a hacker than five eyes, wouldn’t they?
- Zush8phoog 7y agoNordVPN, according to this leak https://web.archive.org/web/20190603203749/https://ghostbin.com/paste/azk4r https://web.archive.org/web/20190603203749/https://ghostbin.... was logging client connections as recent as 2018 despite claiming they do not log https://nordvpn.com/features/strict-no-logs-policy/ https://nordvpn.com/features/strict-no-logs-policy/ see openssl/server.cfg it should contain special lines to disable logging https://www.lowendtalk.com/discussion/107379/how-to-disable-logging-on-openvpn-server https://www.lowendtalk.com/discussion/107379/how-to-disable-...
- Izmaki 7y agoThis. If we always assume the worst, we may as well stop using passwords or strong ones anyway, because we can assume that our machines per definition are hacked and local network infiltrated. Not happening, right? That’s what i thought...
- chinhodado 7y ago
- baby 7y agoI agree with the content, but I would recommend dsvpn instead of the suggested solutions. https://github.com/jedisct1/dsvpn https://github.com/jedisct1/dsvpn
- xaduha 7y agoIt's great, but has no Android support atm. Gotta stick with Wireguard for now.
- tomxor 7y agoI mention this every time this comes up but it's info worth spreading... "sshuttle", make any server into a VPN without VPN server-side software, this takes the pain out of doing your own VPN, gives you far more obscurity, lots of flexibility and in my experience it also performs much better - which I believe is due to the TCP deconstruct-reconstruct vs traditional VPN which does TCP over TCP. The only disadvantage is it's only for TCP (no UDP or multicast). For routing all your internet it's as simple as this (on the client only, no server setup): sshuttle -r user@1.2.3.4 0/0 That's it... server requirements are met by almost anything, you don't need root access, but it does need python, which most distros have by default. Now you can use your own little obscure server, yes it's not invulnerable a VPS provider can still look at you if they wish, but it's far less of a target than a purpose built consumer VPN provider. It's also far more powerful for slicing up and mixing subnets or only routing specific targets ... for example unblock a specific site, but don't re-route other traffic: sshuttle -r user@1.2.3.4 sci-hub.tw [edit] Minor issue worth mentioning, not to disappoint people trying this out - it's currently necessary to use the -x option to exclude the server itself from being routed on Linux, I think this is due to a kernel bug? which is a little annoying, hoping this will go away eventually. This is not relevant to BSD or Mac, although on Mac you have other kernel bugs to worry about in XNUs network stack. sshuttle -r user@1.2.3.4 -x 1.2.3.4 0/0 [edit] As "icelancer" has pointed out bellow, please note that using your own server ties your activity to your identity more definitively if you are the only one using the server and you pay for the server in your name. Not being a purpose built consumer VPN makes it a less likely target through significant obscurity, however in the event it IS targeted, it's uniqueness will make it easier to associate activity with you via the VPS provider. > This also ties your identity to a provider definitively. That's fine, as long as you tell people that's what is happening. A good consumer VPN that isn't a garbage one offers plausible deniability.
- chias 7y agoOkay so this is shockingly impressive. For those of you who are thinking "eh, I like my `ssh -D8080 user@1.2.3.4` solution", sshuttle has the following two advantages: 1. no need to configure your SOCKS proxy in your applications 2. it works even when dynamic forwarding is disabled on the host you're connecting to
- danShumway 7y agoReposting the last response I gave when this article came up. ---- > Your IP address is a largely irrelevant metric in modern tracking systems. I don't believe this for one second. Your IP address on its own is not sufficient to identify you. That doesn't mean your IP address is not helpful in identifying you. If you have Javascript disabled, it is a heck of a lot easier to identify you with a combination of an IP address, user agent, and OS than it is to identify you without the IP address cutting down the pool of potential visitors. On top of that, if you're targeting me and do a geo-location of my IP address, it will get you within 5 miles of my house. That's close enough that you'll know which county I'm in, which with a few other easily-obtained pieces of information will let you pull up my voter registration, which will give you my exact street address. Of course, you could mitigate this by setting up your own VPN on something like Linode, but unless you're regularly rotating IP addresses, you've just traded a pseudo-identifier that multiple people/devices share for a persistent identifier. This argument comes up all the time, and I have never heard anyone explain it in a way that passes my sniff test. If you want me to stop using a VPN, you need to do a lot better than just claiming that IP addresses don't matter -- you need to show some kind of evidence to back that up. ---- Broadcasting your IP address to every website you've ever visited is a completely valid concern that gets hand-waved out the wazoo whenever this subject comes up. I've sent bug reports to sites that publicly tied IP addresses to comments/accounts so anyone could track your movement patterns over time. Yes, that info can be useful to an attacker trying to deanonomyze you. Yes, that info can be used to link users together. Yes, that info can be used to narrow the pool of potential visitors so other fingerprinting techniques are more powerful. It is blanketly ridiculous to claim that an approximate county-level geolocation isn't a useful data-point to attackers. If IP addresses weren't useful, the Tor project wouldn't be going to such lengths to hide them.
- ogeiczvm 7y ago> Of course, you could mitigate this by setting up your own VPN on something like Linode, but unless you're regularly rotating IP addresses, you've just traded a pseudo-identifier that multiple people/devices share for a persistent identifier. This actually happened to me. I'm using a persistent VPN (50% to access my private infrastructure and 50% because I have a hostile ISP). I mostly don't use any Google services (maybe one google search a month and the occasional google map search but I avoid when I can) and I was very surprised when once I did a google search and saw my postal code at the end of the page. The IP address was for a VPS (in the same city but with a different post code). I found it unusual but didn't pay too much attention. A few months later I moved places (different post code) and after a while google had my new post code at the end of their search page. That's when I found it troubling and assumed that a family member's iPhone was using Google Maps and based on the 'directions' usage they figured out that that IP address has a home address for those GPS coordinates. (The iPhone in question is reasonably 'hardened' with background updates off and location services only 'when app opened' and disabled for most system services). That was the only plausible correlation between IP address and location google could have done automatically - neither I nor the said family member no longer login to old google accounts we had many years back. That's when I started rotating IP daily (which is trivial in my case as I use lightsail, I issue a shutdown from a different server and then a power on, AWS rotates the IP automatically out of a very large pool - so far I haven't gotten the same IP twice). The only problem I have with lightsail is that I often get a 'dirty' IP so I rotate 4-5 times before getting a good one (I test this by going a curl on a website that sends google captcha on dirty IPs but lets the 'good' ones straight in).
- TomMckenny 7y agoIt would be nice if there were an independent auditing organization that could confirm an ISP's claims.
- readhn 7y agoone thing that was not mentioned- your ISP logging your data. Too much of my data in my ISP's hands is not a good thing. I'd rather tunnel out through a "trusted" 3rd party server then give all my data traffic to Comcast or whatever.
- to-too-two 7y agoI’m way out of my element here, but would it be plausible in the future for say, Firefox, to offer a simple and free VPN like service? Something in the vein of incognito mode (it’s UX simplicity).
- miles 7y agoFirefox is testing a VPN, and you can try it right now https://www.theverge.com/2019/9/11/20861381/firefox-testing-vpn-mozilla-private-network-test-pilot-program https://www.theverge.com/2019/9/11/20861381/firefox-testing-... Mozilla tests Firefox VPN service to help protect your privacy https://www.cnet.com/news/mozilla-tests-firefox-vpn-service-to-help-protect-your-privacy/ https://www.cnet.com/news/mozilla-tests-firefox-vpn-service-...
- mike00632 7y agoOpera Browser offers a free built-in VPN.
- icelancer 7y ago"There is no way for you to verify that, and of course this is what a malicious VPN provider would claim as well. In short: the only safe assumption is that every VPN provider logs." This is demonstrably false; look at any VPN provider that was subpoenaed and unable to produce documentation.
- user4142 7y agoNow, with DoH, VPNs will be nore relevant if you don't trust our IPS. Today, if you change you DNS to another resolver, your IPS won't bother because majority will not change and you can pass under their radar. With DoH, IPSs will be forced to log filtered/mapped IP requests so they can keep doing whatever they're doing today with DNS queries. So, when DoH matures, IPS won't see your DNS queries but it won't matter for them any more as they will be seeing all other requests
- jchw 7y agoAlthough I agree with the general notion, social proof and a good track record are not bad indicators. I will always recommend Mullvad if you are looking for a VPN service that is trustworthy. I think VPN services that advertise a lot are a little sketchier, though surely some of them must be decent... maybe PIA?
- pnutjam 7y agoI use pia, they are inexpensive with plenty of traffic to blend with.
- tootahe45 7y agoBefore anyone buys a vps from Lowend talk like he recommends, most of the providers on there are trash-tier and massively over-sell their services which is why they seem cheap but performance ends up very poor. And why would i trust a vps vendor with 10 customers over a VPN provider?
- linsomniac 7y ago"... because the provider can see all your traffic!" However, if you don't use a VPN: Your ISPs (Broadband, coffee shop, whatever) can see all your traffic! 20 years ago I passed ALL my traffic on my laptop through a VPN, I just happened to run my own. But back then much less of the standard traffic was encrypted. Now, pretty much all web traffic is encrypted. So that makes the VPN less of a concern, IMHO. Depends on what you're doing though... There was this one time I went to Defcon. Installed a scratch laptop for it. The firewall on it would only allow DHCP and OpenVPN on the physical interfaces.
- Johnny555 7y agoExactly - I trust my VPN provider not to use or abuse my traffic data (websites visited, DNS queries, etc) more than I trust my ISP (Comcast)
- kgwxd 7y agoVPN companies are explicitly built on reputation for not doing that. ISPs don't give a damn about reputation and are usually a monopoly, or the other options are just as bad.
- azinman2 7y agoWhat reputation? Where is the dispensing of knowledge? And how do you know violations are evening coming back to the surface? With the ease of starting a new service, and the typical anonymity of who is running it, I don’t believe one bit in being able to let the decentralized world determine is trustworthy here. The space is full of shady operators.
- sjy 7y agoWe don't know that all violations are coming to the surface, but we can be pretty sure that if there are VPN honeypots then they are either obviously sketchy services or part of an expensive, sophisticated, secret and therefore targeted attack. Based on their website and other public information (like their WireGuard advocacy), I think Mullvad is more trustworthy than the average ISP, which in turn is probably more trustworthy than the average fly-by-night VPN operation.
- linsomniac 7y agoI've always been amazed at the prices I see for the VPN services, they seem improbably low. Which makes me wonder where they make their money.
- pnutjam 7y agoBandwidth is cheap.
- otakucode 7y ago>There is no way for you to verify that, and of course this is what a malicious VPN provider would claim as well. In short: the only safe assumption is that every VPN provider logs. If the VPN provider has been ordered by a US court to produce log information, and they have appeared in court responding that it is not possible for them to do so as such logs do not exist, and the court has accepted this as true, that is adequate 'proof' in my eyes. It is something which puts them in the position of being extremely legally liable for in a way that advertising 'no logs' does not, since prosecution for false advertising is a joke.
- 0xcoffee 7y agoI know I'm going fully into the realm of conspiracy theories here, but history has shown secret court orders are a thing. VPN's are the perfect honeypot for law enforcement agencies, they wouldn't want to lose this every time they bust someone. So put on a nice show that they can't get the logs, then secretly order them to log.
- linsomniac 7y agoAside: 15 years ago all of our employee laptops passed all of their traffic over our own VPN. One of my employees wanted to quantify how much having all our traffic go to our server space was slowing it down. He ran a series of tests comparing latency and throughput of directly visiting sites on his home Comcast connection, vs. the VPN. Generally, the VPN was significantly faster. I wasn't entirely surprised by this. Our facility had multiple high quality connections (Level-3, InterNAP), and one of those traffic optimizers that would add intelligence beyond just BGP.
- jrockway 7y agoThat is my experience today. My Linode is a lot closer to things on the Internet than my Spectrum connection. For example, if I ping the US/Central Overwatch server, it's 50ms from my home connection and 20ms from my Linode (which is 11ms away from home). It is sometimes as much as 26ms to the first hop after my router, though, which is pretty amazing. That's enough time for light to travel 5000 miles.
- hansdieter1337 7y agoIf you want privacy use TOR+VPN. TOR for anonymity, a VPN for a “clean” breakout IP. Oh, and make sure to pay for the VPN using a form of anonymous payment. And, make sure that your devices won’t give up your identity. Anonymity is actually pretty hard...
- mantap 7y agoVPN is just fine if you want to avoid dragnet surveillance, though choose a less popular one. If you are actually the target of a nation-state level adversary then yeah install Tails and use Tor but know that you're probably fucked.
- cracker_jacks 7y agoA terrible summary of why VPNs are useful. Goes on and on about privacy with no mention of bypassing censorship. It must be nice living in a place where you don't have to worry about access. There's no point in privacy without access.
- peterwwillis 7y agoI need an IPSec VPN a couple times a year to get around network issues. Trouble is, when I need it, I can't connect to it to buy it, and I don't want to pay for it year round. Pay-as-you-go IPSec would be great.
- octorian 7y agoThis actually reminds me of an episode that happened to me many years ago. Back then, it was "web anonymizers" (not VPN providers) that were all the rage. These programs would maintain a database of open proxies, and route peoples' web activity through those proxies. Well, I had Apache misconfigured just long enough to get picked up by one of these apps. For years afterward, my server logs were chock full of attempts at logging into various accounts via HTTP. I seriously had thousands of Yahoo! username/password pairs just sitting in plaintext inside my server logs.
- breatheoften 7y agoOff topic but — anybody know a good/recommendable vpn service that supports MacOS without requiring third party software and which allows inbound access to the external ip associated with the service ...? I need to ssh back to my laptop frequently because of some annoying restrictions with a service provider I use (heroku). I _can_ do shenanigans with ssh tunneling on a publicly accessible server I control - but it’s actually pretty annoying to work that way in my scenarios. I’ve tried a few vpn services that offer “static ips” but the services I’ve tried filter inbound connections to that ip ... does anyone know a good vpn service that can effectively gives me a public IP address so I can make inbound connections to my developer machine while I’m random shitty coffee shop WiFi ...?
- terrycody 7y agoThis is BS, VPN is an legitimate service and many people rely on such services to do their things, it may pose some potential security issues, but in most cases, it won't cause big harm to you even when your credentials leaked. Just try to use a very random username and password, payment can set to pay as a VCC or one time method.
- unrealcube 7y agoLocal keepass database :)
- exabrial 7y ago> ... with increased adoption of CGNAT and an ever-increasing amount of devices per household, it just isn't a reliable data point anymore. I know this is not a popular stance on HN, but ipv4 has built in casual anonymization, whereas ipv6 had built in casual identification. Both systems are defeatable, but what bothers me about ipv6 is that the invasion of privacy is the default. Coincidentally, Google, Facebook, et all are pushing ipv6 very hard.
- systematical 7y agoThe biggest value I've seen from VPNs is when certain networks block SSH. This happens to me all the time when staying in hotels. For my work I need SSH. I've also had edge-cases where I need to obscure my country of origin. For instance, I couldn't stream Game of Thrones via Hulu/HBO Go this Summer while in Mexico. For some reason, Mexico is blocked. My VPN solved that. For security? It's unlikely to help unless I am on an unsecured wireless network or something like that. Good read nonetheless.
- sarah180 7y agoThe author admits in comments that this is clickbait. Not much to see here except "the providers you trust might not be trustworthy."
- bitL 7y agoHow about when you get a VPN from a country that has strong privacy laws due to bad experience with local snitches and which doesn't have intelligence-sharing treaty with any other country (including US) - like Romania. Wouldn't that be safer?
- bArray 7y agoOther reasons you might want to use a VPN: * Geoblockers - Much media content is blocked based on geolocation, specifically geolocation based on your IP. (Netflix, Youtube, etc.) * IP blacklist - I know a few people that have inherited a blacklisted IP simply through unlucky ISP IP allocation. * ISP logging - So not a hostile ISP, but one that actively tries to log your data. (If you live in Europe, this is almost definitely happening. Apparently in the US ISPs even sell this data.) * Speed - A few people report being able to get a faster network connection. (I'm not entirely sure why this is the case, but I can imagine there being edge cases where this is possible.) Setting up your own VPN is NOT solution to every problem mentioned here, especially if you want to switch server location on a whim or are not technically minded.
- sjy 7y agoI often get really slow download speeds from the GitHub CDN, which my ISP must not peer with or something. My ISP has faster routes to most of the rest of the internet, including some VPN endpoints, so a VPN can be used to cut out the bottleneck and allow me to download large binaries off GitHub at 2 MB/s instead of 80 KB/s.
- bArray 7y agoYeah I've heard some gaming folk say that their latency also goes down. I guess it all depends on the pipes your particular ISP has rented and their connecting places.
- oefrha 7y agoGithHub uses S3 for artifacts. If your typical S3 download speed is ~80KB/s, I suspect it would be a similar story for Cloudfront, in which case a huge part of the Internet would be painful to use...
- bArray 7y ago< 80kB/s is what a large majority of the internet experiences with page viewing times is excess of 30 or 60 seconds...
- johnjungles 7y agoWhat about just setting up your own VPN on a cloud provider or a raspberry pi? You’d still be responsible for the traffic flowing through but at least you wouldn’t have ISP logging, get around geoblockers, keep a secure connection in public WiFi’s, fantastic for devops people who want to have local connections for debugging networking things on aws/gcp/cloud providers, etc... I think you mean that you shouldn’t think of a VPN as an anonymous traffic tool like they advertise.
- benhurmarcel 7y agoWhere do you connect that raspberry pi? At home, you're using your own IP and ISP still.
- dontbenebby 7y agoBeing able to use airport wifi (or other public wifi) is actually a pretty big deal IMHO. I really value not having to constantly leave my phone on, blasting my location to anyone who cares to ask. https://www.vice.com/en_us/article/nepxbz/i-gave-a-bounty-hunter-300-dollars-located-phone-MicroBilt-zumigo-tmobile https://www.vice.com/en_us/article/nepxbz/i-gave-a-bounty-hu... (I self host my VPN, so I'm fairly confident the provider isn't going to jeopardize their entire business model to add extra analytics. Sites I visit get the IP of the VPN, and conversely my ISP sees my traffic going to a random server in Denver. It's win-win.)
- jotto 7y agoHow often do you rotate the IP on the box you're proxying through?
- dontbenebby 7y agoIt's for security, not anonymity. I use Tor if I want anonymity.
- Iv 7y agoI wholeheartedly agree and I am surprised to not see Tor mentioned as an alternative.
- badrabbit 7y agoUse to have this view,now conceded that a vpn provider with good reputation and accountability is best. Your local ISP sell whatever data or inject whatever content thet desire,and your rights mean little if your contract stipulates they can sell this access to a 3rd party and this 3rd party can then resell analyzed or raw data to anyone including your own government. If you perform methodical risk analysis,you will find having the ability to damage reputation of your first-hop provider is an ideal leverage. Never negotiate from a position of weakness (e.g.: ISP or Tor exit nodes)
- jaimex2 7y agoFantastic post. I've long given up trying to explain this to morons paying for NordVPN and similar products.
- computerex 7y agoWhat a myopic viewpoint. ISP's can and do sell customer data: www.cnbc.com/amp/2017/03/28/congress-clears-way-for-isps-to-sell-browsing-history.html It's doesn't take a logical leap to infer that a company whose entire purpose and business model is to provide anonymization as a service is less likely to sell out its own customers than the ISP's. Yes VPN's can log despite claiming they don't. But the well known ones are highly incentivized to do as they claim because lying would destroy trust and would ultimately destroy their business. Governments are also more likely to target giant national ISP's than some VPN provider whose servers are in some very liberal and consumer leaning countries outside the US. Also securing your own VPS on the internet and managing it without getting pwned is well outside the expertise of most people and is probably not recommended.
- mcnichol 7y agoIf it is necessary Run....your....own....vpn
- sidcool 7y agoIs 1.1.1.1 a dependable VPN?
- smurda 7y ago“remember that it is in a VPN provider's best interest to log their users - it lets them deflect blame to the customer, if they ever were to get into legal trouble” Disagree. It is always easier for the legal team to say, “sorry we don’t store the logs” as a way to absolve themselves.
- davedx 7y agoThis reminds me of the “don’t use sms for 2fa” arguments.
- ru999gol 7y agothat's an astonishingly idiotic argument, most of what he talks about also counts for your ISP too. They might log everything too and not tell you about it, but at least my ISP never made their whole business case around protecting my privacy. And also what exactly would be their incentive in building up their infrastructure to facilitate this logging, do you have any idea how much storage space each VPN node in their network would need just to log everything? And even if they were to log everything you are still sharing a IP with hundreds of other people making you less identifiable to at least the websites you are visiting. 100% FUD
- sarim 7y agoSays a person living in a free democratic society...
- mrweasel 7y agoThat's a fair point of cause, but if you need a VPN to hide from your government, then you need to be extremely careful about which VPN provider you pick. Potentially your VPN provider could be forced to, or voluntarily, hand over data to your government, without your knowledge, leading to a dangerous false sense of security. You certainly shouldn't be running your own VPN either, because that would be much easier to track, seeing as your traffic isn't mixed in with that of others. Those of us in free democracies have little need for VPN providers. For those who do not, I'm not sure that I'd trust a VPN provider how targets gamers via YouTube ads.
- ComodoHacker 7y agoDo random routing features like SecureCore of ProtonVPN add some value? I think they do in terms of anonymity.
- badsavage 7y agoHehe, at least someone is talking about it. Online privacy is a dream in the 2010s
- cookie_monsta 7y agoA slightly less breathless analysis from Krebs (2017): https://krebsonsecurity.com/2017/03/post-fcc-privacy-rules-should-you-vpn/ https://krebsonsecurity.com/2017/03/post-fcc-privacy-rules-s...
- bloody-crow 7y agoEven if you assume that VPN provider is listening and analyzing all your traffic, it's still preferential to your internet service provider doing the same thing. Fost starters, the internet provider just knows more about you. You probably have a contract with them, they know your exact physical location and they have your SSN. A malicious actor from within internet provider having access to all this information could potentially blackmail you by revealing your porn logs to your spouse, or your unsavory private reddit history to your employer etc. Second, your VPN provider could be in a different country, and that would make data mining your traffic slightly less interesting to them. It'd also make data acquisition via subpoena of some sort from your country slightly more bureaucratic. Third, if you have reservations about your VPN provider, you can just cancel your account and go to a different one. Changing VPN providers takes 5 minutes, while changing internet service provider can take months, or in some cases might not even be possible.
- neumann 7y agoThis is focused purely on people who think VPN is for privacy/security. I use a VPN to get around geo-fencing - in Australia there is a lot of media agreements that mean you can't watch stuff here that is free elsewhere without paying for cable or a local streaming company. A small VPN with multiple exits so I can watch content that is free in the US and EU markets.
- unrealcube 7y agoI prefer using free and open VPNs on free and open networks like Xfinity hotspots, Libraries, Cafes, etc with mac and hostname randomization... Someone can correct me if this is not good anonymity but I think it is. The problem with Xfinity hotspots is finding authorized Mac addresses though lol