4 ms·
The term “VPN” has become a bit overloaded. It can mean, among other things: 1) a corporate VPN you connect to in order to gain access to corporate resources.
by anderiv 4y ago
The term “VPN” has become a bit overloaded. It can mean, among other things:
1) a corporate VPN you connect to in order to gain access to corporate resources. Cisco AnyConnect, OpenVPN, IPsec/L2TP are examples of this type.
2) An overlay network that allows seamless (and secure) access to systems on disparate networks. Wireguard (and thus Tailscale), ZeroTier are examples of this type.
3) A way for individuals to obscure their internet traffic by tunneling it to a VPN provider. Mullvad, PIA, Nord are examples of this type.
All of the sponsorships you see are from companies in category #3. It is my opinion that there are very few circumstances where using a VPN (#3) is useful or needed. HTTPS is ubiquitous, and browsers have various mechanisms for MitM prevention and other anti-spoofing/anti-tampering mechanisms. Taken together, these provide a high degree of protection that wasn’t necessarily as widely-deployed just a handful of years ago - a time when using a VPN was more useful.
Are there situations where using a VPN (#3) is warranted? Yes, for sure. However, these content creators who are taking sponsor money from VPN providers are doing their viewers a disservice by making them think they need a VPN. 99% of the public does not, and should not waste their money on it.
- Izkata 4y agoI think your terminology is a bit mixed up: OpenVPN and WireGuard are technologies that can be used for any of those three purposes. For example, Mullvad/PIA/etc are hosted vpns that you can use OpenVPN or WireGuard to connect to.
- YPPH 4y ago>Are there situations where using a VPN (#3) is warranted Anonymity and therefore privacy. An ISP-assigned IP address reveals a lot of information about you. With a court order it can be traced back to you. Suppose a dissident wants to publish information adverse to the government, there's a situation.
- armitron 4y agoDissidents should use Tor (best done in a RAM-only environment that’s not running on their own computer) and not fuck around with VPNs because it’s go to jail or worse. There are countless ways for someone, even an expert, to hang himself using a VPN.
- imwillofficial 4y agoUnfortunately, these days fingerprinting is pretty advanced, a VPN offers you almost no protection. Even tor, if not used very carefully.
- bruce511 4y agoThat's one, but a bigger one is accessing out-of-region media. Most (all?) streaming services are geo-locked, and do not contain the same libraries in different markets (if they are available at all.) So VPNs are a common way of accessing streaming which would otherwise be unavailable. While this is "piracy of a sort", it does imply an actual paid subscription, albeit in the wrong territory. So its more-honest than the alternative (plex etc)
- raunak 4y agoPiggybacking off of this comment, I’d be very curious to know the HN sentiment on piracy as a whole Net good, net bad, somewhere in between?
- bruce511 4y agoAs one who makes a living selling software, I'm against piracy, and would prefer people to be honest. I prefer not to pirate myself if it's avoidable. That said, I'm aware my stuff is pirated, for various reasons, and I pretty much ignore that. Pirate users might turn into customers one day. I make minimal effort to prevent piracy, mostly to make sure the experience for paid users is as simple and streamlined as possible. I prefer to consume my media via paid channels, and that is easy and convenient (and cheap) to do (now) so that's much easier to do now than it was 20 years ago. My attitude to open source licensing is the same. I'll happily integrate MIT licensed material into commercial offerings, but I respect the rights of GPL authors, and I understand that is off the table. I believe authors have a right to choose the license they want, commercial, open or free, and it's up to me to respect that right.
- throwoutway 4y agoThe only thing left outside HTTP that the average person must worry for is unencrypted DNS requests .. but progress is being made there