4 ms·
The bottom line is, in 2019 if any of my relatives asked me which VPN to use I would first outline the history of VPNs as a vector for malware/adware and explai
by ben_jones 7y ago
The bottom line is, in 2019 if any of my relatives asked me which VPN to use I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider as a MITM to ALL your internet activity. Only then would I highlight the benefits of VPNs in regards to internet freedoms and circumventing bad content blocks where users want to pay to access content but are arbitrarily denied.
VPNs are not the type of consumer product you EVER want to have acquired by ANYBODY. Not by Google, or Facebook, a US company, a Russian company, a Japanese company, NOBODY. Was this not extremely obvious when the deal started to form?
You've made a lot of promises that nothing will change, but those are empty promises given the history of post-acquired companies, as well as the vpn market as a whole. You have a lot of work to do following up on those promises, and until you do you will not have the same level of trust as you once did.
- mikorym 7y ago> I would first outline the history of VPNs as a vector for malware/adware and explain to them the supreme level of trust you must have with a VPN provider I'm not your great-grandfather, but I also didn't really know (or think of) this. I kinda always thought about VPNs as intranets. I also assumed that browsers are easy enough to hack that you don't need to do a full MITM on the entire network. I also assumed most normal people don't use VPNs. What would the most common attack vector through a VPN be? My guess would be targeting people that use pirate streaming sites / streaming through proxy IP.
- ben_jones 7y agoI believe the most common case would be selling the user traffic, assuming the VPN knows who you are (through billing for example although given your traffic their are a variety of ways even if you did an anonymous signup), they could then say "Hey Ben reads a lot of technical blogs and spends a lot of time on console.cloud.google.com, Triplebyte you should plaster him with ads because that will totally work".
- everdrive 7y agoIt modifies who your targets are. You can try to attack people with malicious websites, but in that scenario you can only attack people who manage to visit your malicious site. (this example should be considered to include advertising iframes and such.) A VPN provider, however, has a captive audience and can be certain who they are attacking.
- nickpsecurity 7y ago"VPNs are not the type of consumer product you EVER want to have acquired by ANYBODY." That's why I encourage these types of things to be set up as public-benefit companies, non-profits, etc chartered to do the good things and not do the bad things. At least, the obvious ones that keep recurring. General principles plus a pile of specifics as examples of them.
- jeltz 7y agoNot if you use the packages for OpenVPN or Wireguard from your package repo. Then you only have to trust Wireguard/OpenVPN and your distro to not MITM you. Your VPN cannot do any MITM attacks other than those your ISP can as long as you do not install their client.