16 ms·
There’s a lot of gross stuff that your ISPs (which includes your mobile phone provider) do to further monetize your relationship with them, and having a VPN can
by edw 6y ago
There’s a lot of gross stuff that your ISPs (which includes your mobile phone provider) do to further monetize your relationship with them, and having a VPN can negate that.
ISPs can observe your DNS lookups to their servers and assemble a profile on you based on the domain names you look up, and put you into a series of audiences that marketers can then use (for a fee) for ad targeting.
ISPs can also observer your DNS lookups to Google’s or anyone else’s public DNS servers.
ISPs can snoop on your unencrypted traffic, proxy it, and inject headers into HTTP responses to facilitate (you guessed it) the creation and sale of audience data to advertisers.
ISPs can transcode (and downsample) multimedia content to decongest their pipes or airwaves.
If you are a spy or a member of a disfavored political group, you should almost appreciate the scummy practices of ISPs, as it drives a bunch of non-spies and people not associated with disfavored political groups to adopt privacy-enhancing technologies.
If I worked at the NSA or CIA or FSB or Mossad or wherever, I would highly encourage lawmakers to enact laws to protect consumer privacy in order to drastically reduce the perceived need for people not in the above groups (et alia) to adopt VPNs and other technologies; there would be fewer “boring” people using such technologies, giving the needles a lot less haystack to get lost in.
- Kelamir 6y ago> ISPs can also observer your DNS lookups to Google’s or anyone else’s public DNS servers. edw, could you elaborate on that, please? I thought changing to public DNS servers like OpenDNS provides some security from ISP tracking.
- stuuuuuuuuu 6y agoTraffic between you and the public DNS servers isn't encrypted, so your ISP can still read it. (I suppose this is one of the problems that DNS-over-HTTPS is designed to fix.)
- Kelamir 6y agoThank you for the answer, stuuuuuuuuu! I'll look into it. ... DNS-over-HTTPS can be enabled in Firefox via Network settings, turns out.
- _jal 6y agoIn addition to the lack of encryption mentioned, some ISPs transparently intercept DNS requests and reply to them with their own. Test your own ISP: try something like nslookup news.ycombinator.com 1.2.3.4 If you get a response, your ISP is gaslighting you.
- lifthrasiir 6y agoSome ISPs even tried to replace NXDOMAIN replies with their own "services". That was particularly popular in the last decade, though I haven't seen any recently.
- systematical 6y agoGood thing we don't willingly give that data to anyone.
- dastx 6y agoA VPN can negate that but now you're putting your trust in the VPN company's hand.