11 ms·
Poor man's VPN (pay for only what you need)
- StopHammoTime 5y agoI'm suprised no one has mentioned Outline (https://getoutline.org/ https://getoutline.org/) which provides full capability to setup a VPN easily on any major cloud providers with 1-click. It also provides mobile apps to use as well. A great experience, and I'd say it just works.
- azalemeth 5y ago> Motivation: Lately due to GDPR many websites are blocking access in the EU. For me, I cannot order medicines back home via netmeds.com Blaming GDPR for this is a bit like blaming a lead mine for getting shot. Yes, it's involved but it's not the reason. It only seems to be certain large US websites that carte-blanch refuse to serve EU visitors over GDPR, mostly those with large, tendril-filled advertising networks that have no "easy opt-out". Some sites (healthcare ones that tended to be SEO'd to the max when I searched for drug names as well as more mainstream ones like, iirc, the Washington Post) carte-blanch refuse to let you browse them without accepting unnecessary cookies; this is a direct breach of the legislation and yet they still want your traffic. If someone won't sell you something because of GDPR -- legislation that protects your privacy, and in particular considers medical information as especially sensitive -- then you perhaps have to think rather carefully about if you wish to do business with them. (For what it's worth, from a Danish IP, the site listed in the github repo works perfectly on my home network which admittedly contains a pihole-provided dns-level adblocking. It blocks tor and I don't have an easy way of testing it otherwise).
- mosseater 5y agoOn the other side of this, depending on the breadth of your data, it can be non trivial to run pipelines to redact someones information. It takes man hours to verify, and processing time ($$). Plus, what if they don't have that process in place? They will need to do it manually, and take up more time from someone. Plus you need to communicate with the requestee and verify their identity as well as give them updates when they ask. This is fine if not abused. But if a mountain of redactions came in, I could see a company just deciding it wasn't worth it to serve the EU. Not to mention the fact that there are a non-zero amount of people that will make GDPR redaction requests and hound the company down in hopes of suing them if they don't follow the law to the letter and/or can't process the redaction in time. If a company doesn't already have that process in place, it could be a momentous task to initially process. I'm 100% for user privacy. But it can be tricky with the way the GDPR law works, so I understand why companies outside of the EU don't bother with it.
- dinvlad 5y agoI think in CVS's case likely yes, they probably hired underpaid folks to implement their site, and now those folks are probably long gone so no one would even know how to remove all those advertising domains without which the site doesn't work.
- mindslight 5y agoThere are two easy answers for this: 1. Don't create surveillance files on people in the first place. It's not like the lack of privacy legislation means there are legitimate reasons to be performing surveillance. It's just that the illegitimate ones have not yet been made illegal. 2. US states should start adopting the GDPR verbatim (with no corpocratic handouts), so there is only one law to follow.
- canadaduane 5y ago> perhaps have to think rather carefully about if you wish to do business with them This seems to be precisely what happened--and the thinking involved invention--a way of circumventing what prevented acquiring the needed medication. (I assume that alternatives were considered, and found wanting for one reason or another).
- dinvlad 5y agoWell, this reminded me of the situation right here in the US. The other day I couldn't place an online order at CVS because it was repeatedly "having technical difficulties". Turns out I had to unblock half a dozen (!) advertising domains in my Pihole (incl. the ones I've never heard of) to finally place an order. I don't know how to treat it as "I have a choice whether to do business with them" ;-) I guess the only way to protect my privacy in this case is to risk going to the physical store with other sick people atm.
- mindslight 5y agoI handle this pragmatically by using different VMs with assorted browsers, browser configs, and exit addresses. For the context of buying from CVS (realworld nym, heavy surveillance), I'm running NoScript and slowly enable domains until the site works. Doing this for some sites actually speeds them up considerably (eg Home Depot).
- dinvlad 5y agoThe problem is in this case, no amount of blocking will work, because the site was completely broken without those, at least for me :-) Though I can reduce the amount of divulged info for sure, but the very fact they're using them means my order details likely go to third-parties, and it's impossible to prevent that because it relies on that reporting in the chain of logic (i.e. order won't proceed until a successful response from the advertising APIs). The only technical way around that I can think of is to implement Signal's and other's API proxies and let it return back fake info to the site. But I'm not that obsessed about this issue :-) Another over-the-top way is to place the order directly against CVS APIs, using their cookies etc. Again, not worth spending time on..
- TedDoesntTalk 5y agoWhy not just avoid CVS and use another pharmacy (online ordering). I use valisure because they also test the medications they sell for impurities, but there are plenty of others… like even supermarket pharmacies have online ordering now with home delivery or pickup.
- syshum 5y agoBusiness and people will take the path of least resistance. If only a small part of my traffic / business comes from the EU yet I am going to incur huge costs, and have to fundamentally change the way my business runs to comply with GDPR guess what, the EU is getting blocked, as make not sense to do it. My current company does not really collect user info, does no business at all in the EU or is even consumer facing in the US but looking at our internal processes it would be almost impossible to comply with GDPR with out changing MASSIVE amounts of internal processes and procedures.
- smoyer 5y agoAnd circumventing that block violates the CCFA (at least here in the US) so instead of the GDPR turning me into a criminal, SO users who visit my site are the ones violating the law.
- goodpoint 5y ago> Business and people will take the path of least resistance. No, this is malicious compliance.
- tzs 5y agoIf a non-EU site finds itself subject to GDPR because of Article 3(2), they need to then worry about whether or not Article 27(2) applies to excuse them from Article 27(1). If not then they have to deal with the hassle and expense of hiring a representative in the Union. If they are indifferent to EU visitors but happen to get enough of them that 27(2) won't excuse them from 27(1), then it may be worth blocking EU visitors to try to reduce the chances that 3(2) applies. Article 3(2) is somewhat objecting, relying on whether you intended or not to offer goods or services to people in the Union so blocking is a way to make your intent clear. IP addresses are considered to be personal data under GDPR, so a site that is doing nothing other than serving content with no advertising or targeting but that has the default Apache logging enabled could end up with an Article 27 obligation.
- sokoloff 5y agoJust reading this comment makes me inclined to block visitors from the EU from my hobby sites. (Work is compliant; hobby/personal stuff isn’t worth the bother of even reading what Article 3(2) is.)
- andai 5y agoI feel the same, and I live in the EU. The silver lining of my aversion to collecting user data is that it aligns nicely with my beliefs about privacy and minimalism (ie. coming up with ideas for web applications that don't even need a backend).
- tzs 5y agoArticle 3(2) is short. Here it is: > 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to: > (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or > (b) the monitoring of their behaviour as far as their behaviour takes place within the Union. Recital 23 includes an elaboration on (a): > In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union. Probably nothing to worry about for a hobby site.
- ctime 5y agoTo be fair, both of the sites he mentioned are Indian (netmeds.com and makemytrip.com) I’m sure there are sites in the US, however, that block access from GDPR countries.
- arihant 5y agoIs there a study on comparing number of people actually selecting cookies on the pop ups vs. number of users who already had Adblock? Because unless you have that info, GDPR cannot be claimed to protect any privacy. How many people who never had Adblock are selecting which cookies they want on these pop ups? And it’s not only the US websites, the website OP mentioned is one of the three largest medicine websites in India. There is no reason for them to comply. And EU laws are incredibly confusing. Follow GDPR and respect privacy, while saving customer IP address for years when EU needs VAT.
- jmercouris 5y agoOr you could just use sshuttle with far less steps: https://github.com/sshuttle/sshuttle https://github.com/sshuttle/sshuttle
- 0xCMP 5y agoAgreed. You're already setting up SSH and deleting it soon so why bother setting up the IPs, adding your public key, getting the server's public key, configuring iptables, and configuring wireguard locally when you could just SSH? Only benefit I'd see is wireguard would be easier to use on a mobile device, but the setup requires the ability to run ansible and do ssh already so... that's not really practical.
- yjftsjthsd-h 5y ago> why bother Last I checked, wireguard had much better performance than sshuttle. May or may not matter for your use case, but it's a reason.
- NavinF 5y agoYes! Last time I used sshuttle (bypassing content blocks in India by tunneling to a server in the US), my bandwidth dropped from 10mbps to 1mbps. Back then wireguard didn’t exist, but IPSEC could easily saturate the 10mbps link. I suspect it’s a combination of TCP-over-TCP and a horrible default buffer size that makes sshuttle unusably slow.
- ignoramous 5y agoYou don't need VPNs to bypass censorship blocks in India. Well, at least in my experience. Apps that manipulate TCP packets locally to break fingerprinting [0] like GoodbyeDPI (Windows) [1], GreenTunnel (cross platform CLI) [2], Intra (Android) [3] have been adequate. [0] https://nitter.net/vinifortuna/status/1304189371688660992 https://nitter.net/vinifortuna/status/1304189371688660992 (https://twitter.com/vinifortuna/status/1304189371688660992 https://twitter.com/vinifortuna/status/1304189371688660992) [1] https://github.com/ValdikSS/GoodbyeDPI https://github.com/ValdikSS/GoodbyeDPI [2] https://github.com/SadeghHayeri/GreenTunnel https://github.com/SadeghHayeri/GreenTunnel [3] https://github.com/Jigsaw-Code/intra https://github.com/Jigsaw-Code/intra
- mainwater0803 5y agoHow does this compare to Algo[1]? [1] https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- aaronsdevera 5y agoLove algo. hard to imagine another project comes close to the ease of setting up an algo server...
- gmac 5y agoIt only does IKEv2, but this script (mine) cuts out Ansible and is intended to be even easier: https://github.com/jawj/IKEv2-setup https://github.com/jawj/IKEv2-setup
- aizatto 5y agoAnother cool tool to easily launch a VPN of your choice (WireGuard, OpenVPN, SSH) in a cloud provider. I tried it out before just to test it out, it's pretty cool. https://github.com/StreisandEffect/streisand https://github.com/StreisandEffect/streisand
- danrochman 5y agoLooks like it was a cool project, but the last commit was 2 years ago. I’d suggest looking at Algo (https://github.com/trailofbits/algo https://github.com/trailofbits/algo), which is similar, but actively maintained.
- nefitty 5y agoWoah. I'm glad you revealed this to me before I stumbled into a year-long yak shaving session.
- j1elo 5y agoSince basically always, I'm still using PiVPN https://www.pivpn.io/ https://www.pivpn.io/ Is that out of favor nowadays, given new technologies like Wireguard have become mainstream? Would I be better off using this, or the Algo scripts that another commenter mentioned? (https://github.com/trailofbits/algo https://github.com/trailofbits/algo)
- wfriesen 5y agopivpn now supports both wireguard and openvpn, with wireguard as the default.
- somerando7 5y agohow do you grab new IPs for your pi?
- gorjusborg 5y agoI bet he sneaks into Evil Corp and disguises it as a thermostat.
- julienb_sea 5y agoMy cyberghost vpn is under 3$/mo and has unlimited usage. It's hard to imagine any pay-as-you-go scheme coming even close from a cost perspective.
- feupan 5y agoIndeed. From the title I imagined a setup that launched an EC2 machine and then shut it down after disconnection. That’s the only way to pay cents per month assuming you’re not connected to a VPN 24/7 Managing your own server at 5$/month does not make sense from any perspective other than “privacy” if you believe that.
- mihcsab 5y agoyou can get a performant 4 core arm64 vps from oracle for free, had no speed impediment with wireguard on it. It's free 24/7... the affordability of arm...
- Osiris 5y agoI used to use a very cheap NAT VPS as an OpenVPN server but after it got terminated I found CyberGhost. It is a lot more flexible and usable across multiple devices with the downside of not being able to open incoming ports.
- throaway46546 5y agoThe only downside is VPN provider endpoints are blocked by many services.
- bccdee 5y ago`ssh -qND localhost:8080 user@ip` sets up a SOCKS proxy at localhost:8080. In your browser connection settings (at least in Firefox) you can set it up to route your traffic through the connection. It's not as good as a proper VPN for prolonged use, but for a quick one-off, it'll do the job.
- karmahunting 5y ago[dead]
- dghughes 5y agoI followed a guide and made my own using OpenVPN on AWS Lightsail not (Digital Ocean). But once my AWS Lightsail trial was over the cost crept up and was quickly getting out of hand. I had to stop it and even delete everything since I was still being charged for a powered off VM! It is an interesting project and it looks good on your resume if you're just starting out in IT.
- shepherdjerred 5y agoNothing will ever beat Tailscale (it is by far my favorite piece of software in this space)
- rmkrmk 5y agoTailscale is just great! It's so easy to use, I have it running on all my devices and servers, so I can connect to them from wherever I want, and with the "Exit Node" feature you can also select a system to route all traffic through (and switch easily between them, at least on mobile).
- sascha_sl 5y agoTailscale still takes some rather drastic measures to make itself work magically which have occasionally broken other things. For instance, I can't connect to a work VPN (vpnc) properly while tailscaled is running because Tailscale hijacked my resolver entirely. It does that even on resolved.
- LiamMcCalloway 5y agoConcurring with Tailscale's ease of use, though for mobile clients I found it was more reliable to have a wireguard accessible tailscale peer rather than rely on Tailscale's app.
- vondro 5y agoThank you for pointing out Tailscale. It seems like it's exactly what I was looking for, with free tier being completely sufficient. I set up smarthome network (zigbee2mqtt running on orangePi) and also endpoint in neighbouring country.
- goodpoint 5y agotailscale is closed source and paid for deployments with more than one user.
- hda111 5y agoGood point. The software in this space should be open source. This is the only way you can trust it.
- gibs0ns 5y agoI've generally considered an SSH tunnel as a poor man's VPN. If you're going to the effort to spinup a machine, and use SSH anyway, i find it much easier to use `ssh user@server.com -D 4444` then I can set my browser's proxy settings to use localhost:4444 as a SOCKS5 proxy. For those apps that don't have native proxy support, I use proxychains to force them over a proxy connection. Ofcourse this is only useful for a single user, and for devices that can use ssh and proxies.
- daxuak 5y agoSecond this. I haven't tried proxychains. iptables with redsocks[1] for redirection works pretty nice. [1] https://github.com/darkk/redsocks https://github.com/darkk/redsocks
- deleted 5y ago[deleted]
- rkeene2 5y agoThat is a SOCKS5 proxy (as you said), however SSH can pass IP packets or Ethernet frames: https://rkeene.org/viewer/tmp/ssh-ip-tunnel.txt.htm https://rkeene.org/viewer/tmp/ssh-ip-tunnel.txt.htm
- anotherhue 5y agoDoesn't this have all the usual TCP over TCP issues?
- ajsnigrutin 5y agoyep, fragmented packets and double confirmations, but if you're using it to order pills and read some US news, it doesn't really matter.
- deleted 5y ago[deleted]
- suifbwish 5y agoHaha I came here to say just that. Using NAT and routing you can setup the machine initiating the client ssh connection to act as an internet gateway for the clients that have its IP set as their gateway. Did this with a raspberry pi before.
- nvr219 5y agoUse Algo!!! Extremely easy to set up with dummy-proof instructions.
- jijji 5y agoit depends what your use case is, but if you are trying to mask you public IP, I'd been using Squid Proxy [0] for decades and even have production networks using it for scraping activity in a load balanced way [0] https://en.m.wikipedia.org/wiki/Squid_(software) https://en.m.wikipedia.org/wiki/Squid_(software)
- henning 5y agoCould this be turned into a bash script without loss of functionality? I'm not trying to denigrate the work or Ansible as a tool in more complex scenarios.
- 0xbadcafebee 5y agoIf you're spending $5 on a VPS, aren't there actual VPN services that cost $5 or less that you don't have to manually set up and destroy? If you're just doing it for fun (kinda like "hosting your own mail") I recommend setting up an IKEv2 IPSec VPN. It might be the hardest VPN to set up? But you learn a good deal about VPNs and networking. Most OSes ship with a native IPSec VPN implementation, and most "enterprise" VPNs are some variation of IPSec. Mobile devices, internal firewalls, internet gateways, enterprise AWS tunnels, etc. You can keep getting fancier by adding VLANs, GRE, BGP, certificates, RADIUS.
- linuxandrew 5y agoOP mentions DigitalOcean as a compute provider. Is there much info on which compute providers will ban you for, say, P2P or BitTorrent activity? Presumably this is against the ToS for most providers.
- darkryder 5y agoWhile it does not yet exist as an end to end solution, BlindTLS[0] is a technique which perfectly fits the description of a "poor man's vpn". You pay the vpn provider for a tiny fraction of the traffic, and you can safely route the rest directly through your own ISP. This should work around most censorship techniques or geographic blocking. It doesn't promise privacy though. [0] https://dl.acm.org/doi/abs/10.1145/3473604.3474564 https://dl.acm.org/doi/abs/10.1145/3473604.3474564
- sneak 5y agoI wonder what percentage of VPN users use a VPN for censorship/regionlock circumvention, and what percentage of VPN users use it for privacy.
- KronisLV 5y agoHeh, right now i use WireGuard for exposing some of my homelab servers to the internet and to work around my ISPs NAT setup, WireGuard is really pleasant to use and simple to set up! I recall using OpenVPN a few years ago for a similar use case in my university dorm, it was comparatively way worse - the configuration parameters were unclear, some of the documentation was out of date and even when using the faster (but less secure) methods of encryption, i found myself having a VPS that was overwhelmed and had almost 100% CPU usage (on its single core, since VPSes are generally expensive) whereas the client couldn't get much past 10 - 20 Mbps when the connection speed itself was closer to 100 Mbps. Nowadays, for a VPN, i just use Time4VPS https://www.time4vps.com/virtual-private-network/?affid=5294 https://www.time4vps.com/virtual-private-network/?affid=5294 (affiliate link so i get discounts for signups, i also use them for most of my VPS hosting) because they're affordable and have more locations than i can get VPSes in those locations for comparable amounts of money. It seems like their offering is OpenVPN based which is surprising, since it works pretty well - makes me think that either i royally screwed up my own config back in the day (though default config should never hit 100% CPU usage like that, which happened to me), something was wrong with the system packages, or they just have beefier servers behind it, despite many users.
- danlugo92 5y agoI'm getting 182mbps with my VPS, (600 without). South America 600mbps > Atlanta VPS
- mihcsab 5y agoyou can get a 4 core 24gb ram arm64 for free on oracle free tier(not a trial), install wireguard, it's really fast too.
- framecowbird 5y agoWhat's the cheapest and easiest way to set up a VPN that authenticates with G-Suite OAuth? Asking for a friend...
- codethief 5y ago> Make sure you can ssh into the machine […] This is the tricky part. SSH gets blocked in some LANs, so then you would have no way to spontaneously deploy your VPN server. So better deploy it ahead of time.
- 12ian34 5y agoThe author's use for this is to circumvent geographical jurisdictional restrictions. If that is the aim (rather than privacy), then I don't understand how a $5 (per month) VPS along with all of the config and steps required (read: non-negligble time cost) is the "Poor man's" solution. Surely using any of the free forever unlimited VPNs would do the job at near zero cost?