4 ms·
Use a VPN While Traveling?
A while back there was an HN discussion[1] in which I asked whether there's a consensus that it makes sense to use a VPN while traveling and using public wi-fi in places like airports. The answer I received was pretty consistently that there's no point.
But the NSA has released a document that says: "Accessing public Wi-Fi hotspots may be convenient to catch up on work or check email, but public Wi-Fi is often not configured securely. Using these networks may make users’ data and devices more vulnerable to compromise, as cyber actors employ malicious access points (Masquerading [T1036]1), redirect to malicious websites, inject malicious proxies, and eavesdrop on network traffic (Network Sniffing [T1040])."[2]
So, I'm still unsure about it. For instance, suppose I accidentally use a malicious public wi-fi service masquerading as the one supplied by an airport. I try to go to https://www.somewebsite.com. Would the malicious wi-fi service be able to supply a phishing version of www.somewebsite.com that also uses https? If not, why not?
[1] https://news.ycombinator.com/item?id=28643650#28643995
[2] https://media.defense.gov/2021/Jul/29/2002815141/-1/-1/0/CSI_SECURING_WIRELESS_DEVICES_IN_PUBLIC.PDF
- aborsy 4y agoThe traffic is mostly encrypted these days. But if WiFi network is malicious, there are some attacks that could be deployed. If you run a VPN at home or on a VPS, it’s preferred if you VPN into the home or VPS network. If you use a VPN from a provider, the opinion is divided as seen in the link you posted, but I think a VPN still improves the security in a public WiFi.
- pid-1 4y ago> Would the malicious wi-fi service be able to supply a phishing version of www.somewebsite.com that also uses https Yes it would. But a browser would show a giant red warning. The real issue is many protocols, like DNS, are not encrypted. Also if you're a developer chances you use a non encrypted protocol are much higher.
- eternityforest 4y agoI just trust TLS. Anything to do with finances or Facebook messages or email is already using TLS, and I don't particularly care about metadata spying.
- dontbenebby 4y agoI trust but verify. I have a separate contain for my email, banking, and "news". If something shows up outside it's little container... that's a red flag. And you should be more worried about metadata spying. It's not what you know, it's who, and metadata has less protections, is easier to collect legally, and is easier to store for VERY long periods :-) But yeah, if you want to frustrate an attacker that aside from being on "example.com" they have no idea what you're doing, it's great but too many sites use excessive subdomains rather than after the slash. (Maybe I should write an essay titled "Excessive use of subdomains considered harmful" and troll a bit later this evening)
- dontbenebby 4y agoOP I did a master's thesis on censorship circumvention. What's your threat model? Just on vacation looking for love (but not getting robbed or murdered?) Industrial espionage? Or are you in that special set of folks who has to wonder if some literal bitch from the Stasi or whatever is gonna show up to your date with a cute little .25 ACP to cap you with because you made the wrong choices in the primary? What happens when you use Tor over that VPN and taint your anonymous traffic with the rest?[0] I know of at least one case this is probably how he was caught, but he was a literally pedophile who was busted for uploading child abuse imagery to the darkweb and in the same "friend circle" as Matthew Falder. (I worry I gave out to much advice public boards over the years as I did my... OSINT... so no citations today so go enjoy the challenge if you wanna piece that one together) Anyways, to get back on topic: if you are worried about DNS sniffing, tweak your firefox so it uses 1.1.1.1 and https only[1]. Cloudflare skeeves me out because it's a central location and every time I talk Mike Nelson, he says something incredibly offensive about women, claims he can't talk long because he is driving... then shits his pants. (It's really bizarre he has such a prominent position with behavior like that.) Back when I last... Delved... into these topics someone questioned my integrity and refused to help me set that up -- eventually I spoke to their help desk (Township I think? Maybe county?), who realized I wasn't trying to hack their infrastructure and guided me through the issue with their captive portal, but for future reference if some of your terminals are still running goddamn Internet Explored or... laughs Netscape... I'm the least of your problems and you should just say yes sir, no sir or resign on the spot if you're going to even give the slightest HINT you are not my ally in an actual emergency, hence the Mike Nelson meme) Anyways to get back to VPNs: HTTPS is a thing now so use Firefox HTTPS only mode since the EFF sucks at auditing their own code and in general you want to simplify your extension rig to reduce fingerprintability. (Fuck HTTPS everywhere) (And if anyone reading this is still thinking you're obstructing people you know nothing about is some kind of cool unicorn riot style act of protest and reading these posts: Congrats! You obstructed a domestic violence victim tracking down the worst people on the planet at their township library during breaks studying for an OSCP attempt made with the last of their emergency fund, you deserve to watch WPXI every morning and go white as a ghost regardless of race, creed, or social class because folks like me are spending the holiday weekend in all black debating if we should leave the country as our code compiles) [0] https://web.archive.org/web/20211120193211/https://matt.traudt.xyz/posts/vpn-tor-not-mRikAa4h/ https://web.archive.org/web/20211120193211/https://matt.trau... [1] https://support.mozilla.org/en-US/kb/https-only-prefs https://support.mozilla.org/en-US/kb/https-only-prefs