10 ms·
Why are these VPNs even a thing? The only reason i would use one is to get cheaper steam keys from brasil and for that i can get a free one. From a security s
by LordHeini 6y ago
Why are these VPNs even a thing?
The only reason i would use one is to get cheaper steam keys from brasil and for that i can get a free one.
From a security standpoint it is awful because you increase the number of providers you have to trust.
Apart from your ISP and the server you connect to, you got a third party involved for no reason.
And VPNs can not that trustworhty as shown by the leaks of logs and what not.
Maybe someone can enlighten me why these services exist and what usecase they have?
- kevincox 6y agoMostly because of their FUD marketing. Almost all of the VPN ads imply, if not outright state that accessing your bank account is unsafe without a VPN. I mean sure, if you want to sell Netflix access sure, but their security claims are way off.
- Ekaros 6y agoIf your ISP is realistic vector for your bank details, anyway you have much bigger problems. Geoblocking I see, but other stuff without knowing exactly who you get VPN from and who is your ISP is extremely murky... And I think there is very few who can make educated decision on these. And they are running their own or using tor...
- LiberatedLlama 6y agoTheir marketing is the sketchiest shit ever. Any VPN that advertises like that is dead as far as I'm concerned, particularly NordVPN. They are the worst offender; listening to a few different jackasses on youtube pitching their product and hearing each one repeat the same talking points, it's obvious the FUD comes from NordVPN themselves, telling people to say it.
- s1rech 6y agoIf you are using the network of a hotel or a train station, for instance. Assumption is that you trust that VPN provider of course.
- Hamuko 6y agoWouldn't you be better served by your own VPN server?
- J-Kuhn 6y agoNot everyone can setup their own web/mail/vpn/whatever server.
- yjftsjthsd-h 6y agoThen you're the only person coming from that IP; a commercial service lets you hide in the crowd.
- seppin 6y agoYes but deploying a vpn to digitalocean for example made the web unusable. Too many "spam" catches when simply trying to browse the web
- muststopmyths 6y agoexactly. I have at least some trust in Mulvad, but I'll be damned if I'm getting on the hotel WiFi in a US hotel chain without VPN. Let alone while travelling in foreign countries. I frequently access my bank info etc. on such trips. With a VPN at least I have fewer random threat vectors to consider on a network.
- BoumTAC 6y agobut every site nowadays use https. Doesn't it prevent issue with public wifi ?
- rasguanabana 6y agoNot all traffic is http.
- djrogers 6y agoWhat ‘bank info etc.’ are you accessing that isn’t TLS encrypted already? Adding IPSEC on top of that isn’t helping much, if at all…
- ence 6y agoPirating copyrighted material.
- LordHeini 6y agoWell afaik seeding on public torrents is just about the only way, where you would get in trouble for pirating. Just don't do that, use a private tracker and use Tor for small stuff like ebooks.
- TillE 6y agoThere's nothing magical about a "private tracker", those are regularly infiltrated too.
- LordHeini 6y agoI may be completely wrong on this one but... This is not much of a problem, because you are seeding to "friends" making the whole thing non commercial and a private affair in some legislatures. Not sure if the laws have changed but what.cd used to have a certain number of users which was capped by the number of friends some judge thought to be reasonable. If i recall correctly that whas around 200k meaning that you could run a private tracker and in case of a bust claim to know everyone. Back in the day i had a what.cd account and when they got busted (took them many years) nothing happened to the users. I think they shredded the servers before the cops could seize them.
- monocasa 6y agoNone of that helps in the US.
- LiberatedLlama 6y agoGetting onto many private trackers is a real pain in the ass, involving lurking on some IRC channel for who knows how long, begging and sucking up to people until somebody gives you an invite (assuming the tracker is even open to new applicants at the time.) Then, even with an invite, often the admins want to interview you to see if you answer probing questions like a pirate or a lawyer. The whole thing is a pain in the ass. These days I just say YOLO and use public trackers.
- blondin 6y agoyoutube ads is the reason i am most familiar with. especially with nordvpn. so, essentially, even the most knowledgeable people on youtube tell you that nordvpn is a must have thing. and they "use it all the time". what do you want people who don't know better to do? that's the sad online world we live in.
- fencepost 6y agoIt moves the source of threat from local (eg someone around you on shared wifi) and the local(ish) ISP to remote and abstract and possibly uncaring (foreign company and whoever has the resources to monitor their firehose). It doesn't eliminate threat, but it changes it in ways that may be relevant - eg with a VPN the people around me can't see that I'm surfing midget porn, and my ISP can tell that I'm torrenting but can't tell what or from where. Other torrent watchers (eg whoever goes after pirates these days) will also have a hard time isolating me back to an IP with which they might be able to get account holder information - and entities with the resources to monitor what's coming out of the fat pipes at the VPN provider probably don't care about me.
- astura 6y agoI suppose Geounblocking is a big feature - I use PIA to watch in-market MLB games.
- yjftsjthsd-h 6y ago> From a security standpoint it is awful because you increase the number of providers you have to trust. No, a VPN replaces an ISP in most threat models (by shifting who can see your traffic). For some people, this is a good trade (ex. me: my ISP has straight-up admitted to analyzing people's traffic for marketing info).
- beermonster 6y agoISP modifying DNS responses, or at the least potentially logging them. A good reason to use DoH/DoT. ISP logging traffic anyway in UK in order to comply with, say, Snoopers charter. ISP providing out-of-date router hardware with unpatched firmware that most people connect directly to their WiFI networks instead of isolating.
- mikeiz404 6y agoOne reason is to help reduce some identifying information Ad networks and the like might collect since a common IP is shared among many users. There are disadvantages too but this is something you won’t get with self hosting. Also ISPs in the US are able to sell your browsing history (https://protonmail.com/blog/private-browsing-history/ https://protonmail.com/blog/private-browsing-history/) but I believe this can be mitigated by DOH.
- mikeiz404 6y agoLooks like the host name may still be leaked in HTTPS connections even when using DOH — https://www.cloudflare.com/learning/ssl/what-is-sni/ https://www.cloudflare.com/learning/ssl/what-is-sni/ And HTTP will always reveal the host name with or without DOH.
- LorenPechtel 6y agoGetting around censorship such as the Great Firewall. I have relatives in China, we visit most years. Without the right VPN (most don't do a good job against the Great Firewall) you lose things like Google (thus your Gmail account), Facebook (no great loss), Dropbox and it's siblings, pretty much any major news site. Last time I was over there I was having some trouble with my VPN (it's always a cat-and-mouse game between the VPNs and the Firewall) and the only search services that worked were Bing (which saw my Chinese location and did a much worse job than normal) and Baidu (which is China-focused and thus did a horrible job of serving up results in English.) Both engines were more likely to cough up a mixed-language page that vaguely matched over an English-only page that would be a much better match. Note that I was using a machine with the language set to English and not one bit of Chinese in the queries.
- viseztrance 6y agoI moved last year back to my home country from the uk, and did the final trip on my motorbike. Midway I realized I was missing an offline map of a country I was about the be passing through the next day. I had an unlimited data plan with traffic abroad included, and despite this, it didn't allow me to download the maps for my gps (everything else worked!), even after fiddling around with third party dns. So I downloaded a vpn app, and managed to get everything sorted out.
- tgsovlerkhgsel 6y ago1) people believing long-outdated guidance about not using open WiFi networks without a VPN 2) protecting your browsing traffic from being observed by your ISP (where you may not have much choice), at the risk of it being observed by the VPN company (which you trust). 3) Torrenting without having to worry about fines, nastygrams and other annoyances 4) Bypassing geoblocking 1 + 2 is what the VPNs advertise, but I think 3 + 4 are what people actually use them for.
- lliamander 6y agoWait,, what's wrong about 1?
- cube2222 6y agoAlmost everything is over https now, and with it, the wifi network security doesn't matter much.
- Aldipower 6y agoWifi isn't only browsing the web..
- kevindong 6y agoBut web browsing is the vast majority of network usage now. The only big exception I can think of that don't go through standard HTTP/HTTPS rails is email. And even then desktop email clients are pretty rare now and they're pretty universally encrypted now.
- tgsovlerkhgsel 6y agoNo, but HTTPS isn't only browsing the web either. Very little that the average person will do on the go doesn't use TLS (or other effective encryption) in some form.
- LiberatedLlama 6y ago> 1) Open wifi networks still exist. When last I was at my public library (a year ago... covid) they still had an open wifi network for public use. I think for them it's a matter of principle, since it means nobody has to ask permission to use it.
- jariel 6y agoProbably the #1 reason by far is geoblocking. Security interests are niche compared to people wanting to watch 'xyz program' or 'xyz super game'.
- 12ian34 6y agoI'll just leave this here as food for thought https://schub.wtf/blog/2019/04/08/very-precarious-narrative.html https://schub.wtf/blog/2019/04/08/very-precarious-narrative....
- beermonster 6y ago> Maybe someone can enlighten me why these services exist and what usecase they have? Because there are lots of people that can't create their own VPN even though these days you can spin up a lightsail instance for $3.50 pcm and be up and running with Wireguard in minutes. And for those people that cannot, their threat model changes to now needing to trust a single entity after they are up in minutes. As you say, those providers have oftentimes been proven to not be so trustworthy. But how many CAs have been shown to be not trustworthy in the last couple years?
- upbeat_general 6y agoAlso many websites will block cloud services IPs. This can also happen with 3rd party providers but in my experience it’s much less common because some vpn providers will buy residential IPs. It also can be nice to get a new IP more or less whenever you want by just connecting to a different, already setup server.
- ficklepickle 6y agoThe only websites to block my AWS IP are streaming providers like Netflix. I don't believe VPN providers are buying residential IPs. They use a p2p architecture and route traffic through their customers, usually without informing them. If I do use a commercial VPN service, I prefer to use the openVPN client rather than their proprietary client.
- gambiting 6y agoIn the UK your ISP has to store your entire browsing history for a year. Multiple agencies have access to this data without a warrant. So my usecase is simply preventing my ISP from knowing what I browse and from keeping this record. I'd much rather take my chances with a VPN company than my ISP and the British government.
- laurent92 6y agoI never understood the details of it: So if you download 2GB from SSH, does it have to store it, encrypted, as is? Or just the IP packet headers, i.e. where from and where to, in which case it is practically useless?
- gambiting 6y agoCorrect, it's just a log of IP addresses that you "visited" which is why I really struggle with it. Visiting any website can hit hundreds if not thousands of IPs, without your knowledge or any intent behind it.
- glenneroo 6y agoMy bank blacklisted me from their online banking portal because of a "suspicious IP". After submitting a number of automated requests to my bank's new security website (a company in another country and only available in a different language), I found out that my IP was marked as dangerous because I ran a Tor service at some point in the past. I hadn't been running it for months but they still had my IP tagged as potentially malicious which was enough for my bank to distrust my ip. I should also note that I also had a static IP back then, which due to this ban, I subsequently disabled. In the mean time I've moved all my external facing (mostly Raspberry Pi) services to VPN and plan to finally re-activate static IP.