6 ms·
I agree. A VPN should only ever be used for the following: - Shifting traffic over a VPN when using untrusted/sketchy wifi hotspots - Spoofing your geo-locati
by cyberlab 6y ago
I agree. A VPN should only ever be used for the following:
- Shifting traffic over a VPN when using untrusted/sketchy wifi hotspots
- Spoofing your geo-location to use geo-specific content
And that's it. If privacy is your goal, Tor is much more suitable since it's not a single-hop proxy like a VPN and compartments all your traffic. (But of course Tor is not a silver bullet and there are caveats).
- sodality2 6y agoWhat about avoiding copyright letters?
- cyberlab 6y agoIf someone is determined enough, they just subpoena the VPN and ask for logs. Since a VPN is a single-hop proxy, your real IP is trivially exposed. Even if the VPN provider claims they don't keep logs. There's no way of proving they don't keep logs, and you need to hope the server you connect to is not compromised in some way. And VPN providers are known to use cheap colocation servers/Virtual Private Servers which have questionable security.
- lordofgibbons 6y agoHave there been any known cases of someone being identified for copywrite violation while using a VPN service?
- StavrosK 6y ago> If someone is determined enough This sweeps the entire benefit under the rug. If someone isn't determined enough, a VPN solves your problem.
- ComodoHacker 6y ago- Routing traffic over untrusted home/office ISP - Censorship circumvention
- ignoramous 6y ago> Censorship circumvention In some countries, censorship circumvention usually require sophistication that not all VPNs provide. A few like getoutline.com, getlantern.io, and psiphon.ca specialize in that. In most countries, VPNs aren't even needed to circumvent censorship. Apps like getintra.org, GreenTunnel employ simpler techniques to bypass firewalls. > Routing traffic over untrusted home/office ISP With TLS v1.3 and DoH / DoT, I think VPNs may no longer be required if "hiding traffic" is the only need. Hiding IPs, however; (of both the client's from the server and the server's from the ISP) would continue to require the use of VPNs.
- hiq 6y ago> With TLS v1.3 and DoH / DoT, I think VPNs may no longer be required if "hiding traffic" is the only need. You, as a user, have little control over whether the servers you connect to support TLS 1.3 and eSNI / ECH.
- vehemenz 6y agoDepends on the VPN. ExpressVPN is HK/CCP owned, so I wouldn't worry too much about my privacy being violated for petty copyright infringements (BitTorrent).
- mistersquid 6y ago> ExpressVPN is HK/CCP owned Thank you for this callout. Had no idea. Comparing VPN services, I’ve found ExpressVPN to be highly rated. The aforementioned callout means ExpressVPN may not be the best service for me. In lieu of specific technical criteria regarding VPN services, who are the go-to (aka “top of mind” or “A list”) providers that privacy conscious, technically adroit (e.g. web dev with some sysadmin knowledge but little networking knowhow) users prefer? In other words, I’m looking for VPN recommendations but no longer trust my own Google-fu (advert rabbit hole) to discern what is a “good” choice.
- schmorptron 6y agoI've never used any vpn myself, but whenever I come across the topic in tech circles people seems to recommend mullvad. Can't vouch for them or anything, but might be worth looking into.
- imposterr 6y agoMullvad is probably the best choice for most. It's the company Mozilla is relying on for their VPN service as well.
- kaba0 6y agoI personally use ProtonVPN.
- voidmain0001 6y agoVPNPro doesn't list ExpressVPN as having Chinese ownership. Wikipedia[1] claims it operates in the British Virgin Islands, and Quora claims the same. That written, a comment on Quora claims that it's owned by the CIA. Ha ha! [1] https://en.wikipedia.org/wiki/ExpressVPN https://en.wikipedia.org/wiki/ExpressVPN [2] https://www.quora.com/Who-owns-Express-VPN https://www.quora.com/Who-owns-Express-VPN
- hnlmorg 6y agoWhat about tunnelling into a trusted network? That's what a VPN is really for. The other uses are more side effects exploiting the encryption and tunnelling properties of VPN rather than the original intended purpose of a VPN.
- croutonwagon 6y agoI think hes talking about VPN's in the context of these companies selling vpn services under the guise of "privacy" or "security". ProtonVPN, Nord, Mozillas, Mullvad and there are a ton others, many with less than stellar reputations and some that outright lie. Thats a bit separate from a road warrior, corporate vpn or even one that one may host on a VPS that they have full control over and are willing to allow the hosting provider still see the traffic. As in, they trust the hosting provider more than the transit provider. Think University/Campus networks, public gov networks, or even some ISP's or corp networks.
- hnlmorg 6y agoI got the context. My point is that the whole “privacy” VPN industry is snake oil and people miss the point of VPNs when they buy into these services.
- croutonwagon 6y agoI wouldn't go that far. There are some reasons that one could be useful. I dont personally have a use case cause I have other mitigations in place but i wouldn't consider a company like Verizon particularly trustworthy in general. Even Comcast has been known to inject ads. The core tenant of these VPN services is trust, with it they dont survive, but for an ISP with a de-facto monopoly thats a non factor. There are also plenty of sites and services that use IP tracking. Google is really bad but others are doing it behind the scenes and not telling you. Reddit 100% does. Amazon too. To the point that if i proxy my connection and try and login to one of my google accounts i sometimes have to verify or go through recovery. So in some cases its better than no vpn. And I wouldn't use any authenticated service over tor that i wish to keep. There are so many malicious relays and exit nodes. TOR is easily tracked at the nation-state level. China can axe tor traffic, even with bridges and OBFS4 configured. With a service like nord, you can get on and do your thing to bypass the great wall for the most part. And the the great firewall drops that connection you have a very large pool to choose from for your next. So there are definitely some reasons I could understand some would use them based on their own assessments/needs.
- qw3rty01 6y agoTor is explicitly not private, only anonymous. The end node can see all the traffic you send through it if it's not encrypted. If privacy is your main concern, tor is definitely not the right tool to use.
- cyberlab 6y ago> TOR is explicitly not private, only anonymous It depends on how you use Tor. For example, visiting your own personal homepage and then using the same relay to visit a NSFW site would be bad OPSEC. Also, Tor comes pre-installed with HTTPS Everywhere, and you can toggle a setting that disables all http traffic if you're worried about sketchy exit nodes analyzing your plaintext traffic. Remember: Tor can't read your mind. If you want true anonymity you have to go through extraordinary lengths to achieve it, and even then, you could make mistakes.
- qw3rty01 6y agoThe caveats you're mentioning are exactly why tor is a bad tool if privacy is your main goal. None of those concerns would be an issue with a service that focused on privacy. Also HTTPS everywhere isn't enough; you also need ESNI, which requires server support.
- xvector 6y agoAnd even if ESNI was ubiquitous, a malicious exit would simply perform a reverse DNS lookup and have very high certainty about which sites you’re visiting.
- hendersoon 6y agoYou're missing two major use-cases. 1) Piracy (the most common, I would imagine) 2) Evading content-blocking. For example, going to Facebook at work.