6 ms·
It comes down to statistics. Using a VPN you are using 1 entity, so all a state actor needs to do is view that one entity's traffic. This may be time consuming
by beardog 5y ago
It comes down to statistics. Using a VPN you are using 1 entity, so all a state actor needs to do is view that one entity's traffic. This may be time consuming and legally challenging if the entity is trustworthy and has servers spread across the globe, but there is still only 1 point that they need to monitor - I suspect many VPN service users are not randomly switching servers. You said "self hosted" VPN which if you are doing that at home it provides no anonymity (which i'm assuming is the point of the comment since the context is Tor). If you host it at a server you are anonymously renting (good luck doing that without opsec failure), it is still only your traffic there, you have no benefit of blending in with others.
With Tor, you can be assured that your attacker needs to monitor more than some % of the network (which can be done either by running nodes themselves or having a wide view of netflow data). Alphabet soup agencies are capable of this, but these attacks are expensive and non-trivial which is why historically the FBI and such use browser exploits the most. You shouldn't rely on Tor alone to protect your life if your adversary is highly skilled or funded, but chalking it up to a VPN is completely discounting the benefit gained from a larger anonymity set in the world's biggest onion routing network.
- masterof0 5y agoThank you.