4 ms·
So, should we, or should we not use a VPN? If most sites nowadays are on HTTPS, is vpn still needed for daily use I think the only reason now to use a vpn, is
by systems 4y ago
So, should we, or should we not use a VPN?
If most sites nowadays are on HTTPS, is vpn still needed for daily use
I think the only reason now to use a vpn, is to login to a site as if from a different location, if the site blocks your region, or sensor some of its content
Any other good reason to use a vpn
- irrational 4y agoI was wondering the same thing. How would my ISP even know that I am using a site like z-library if everything is over HTTPS?
- devmor 4y agoDNS for one, if you're using theirs.
- Laaas 4y agoHost names are commonly unencrypted. See [0]. IP addresses also tell a lot. They can check what domain names map to that IP address. [0]: https://www.cloudflare.com/learning/ssl/what-is-encrypted-sni/ https://www.cloudflare.com/learning/ssl/what-is-encrypted-sn...
- Ekaros 4y agoIP addresses? DNS queries? Later if you either use ISP provided DNS servers or unencrypted DNS. You can identify host from queries and IPs and then match it to TLS connection.
- SV_BubbleTime 4y agoThey still likely get your DNS info, and also they know you are connected to x ip address which is likely y service. All HTTPS does is make sure they can’t see what you are transferring. There is still meta data to whom. Why do you think google runs 8.8.8.8? It’s not out of kindness.
- ed_mercer 4y agoDo I care that can see metadata? If they don’t know what was transferred, how is that useful to them? Data-mining?
- rafael09ed 4y agoBecause the base URL isn't encrypted. The packet still needs to be able to be routed
- ivann 4y agoBy looking at the SNI [0] if the connection does not use TLS 1.3 and ESNI. [0] https://en.wikipedia.org/wiki/Server_Name_Indication https://en.wikipedia.org/wiki/Server_Name_Indication
- Ekaros 4y agoI suppose there is also governmental and ISP filtering and firewalls. So not too many scenarios.
- lalopalota 4y ago- limit amount of browsing data collected by ISP - untrusted networks (public wifi) - normalize usage of privacy preserving practices
- frakt0x90 4y agoCorrect me if I'm wrong, but origin and destination are still visible to your ISP and any snoopers on your network. The content is encrypted, but not the origin and destination of the request. I use Mullvad because they seem to be a company with insanely good ethics and it's only $5/month. Mozilla VPN uses the under the hood I think.
- ramzyo 4y agoThat's right, origin and destination are still visible. Even if you use encrypted DNS to hide hostname to IP lookups, your actual traffic has to be routed somehow by someone. Whether that's your ISP or a VPN provider + their ISP.
- GTP 4y agoYour ISP doesn't get the full URL: they can tell which website you're visiting, but not the specific content you're accessing. The amount of information that is leaked by this, depends on which kind of site you're visiting. In the end, I occasionally use a VPN only if I'm connected to a public hostspot.
- hannob 4y agoWith a VPN your origin and destination are visible to your VPN provider. You're just moving the point where your metadata can be grabbed. I don't particularly trust my ISP, but I don't see a reason to trust any VPN provider any more.
- soiler 4y agoI mean, I generally trust Mozilla + Mullvad a lot more than Spectrum. The only reason Spectrum wouldn't be selling or otherwise mishandling every bit of data about me they can is if they're too incompetent to realize they have the data. Mozilla has a good track record; they could always become compromised or make other mistakes, but Spectrum fucking sucks.
- DeathArrow 4y ago>So, should we, or should we not use a VPN? If most sites nowadays are on HTTPS, is vpn still needed for daily use It's good for hiding metadata like sites you access. In my country there's a recent law demanding ISP to record metadata and allowing many agencies to access it without warrant.
- nokcha 4y agoI imagine a VPN is sometimes still useful when torrenting, to avoid copyright complaints to your ISP.
- galleywest200 4y agoI use my VPN when connecting to WiFi networks I have less trust in, such as a coffee house or "guest wifi" at a hotel.
- koolba 4y agoOr if you don’t want your ISP to know the host names of the specific porn^Wnews sites you frequent. HTTPS covers the content, but for most people the DNS lookup would still be in plaintext.
- ramzyo 4y agoPosted this on another thread about VPNs a few weeks ago. Reposting here since I think it applies. I've recently been describing what a commercial VPN provides to non-technical friends and family as a type of "global virtual Internet cafe" subscription - the pros and cons of using a physical Internet cafe mostly apply. An Internet cafe isn't inherently (i.e. due to technical benefits of underlying technology) any more or less secure than connecting to your home or work wifi/network, and the Internet cafe knows who you are and what websites you're visiting, but your ISP/employer doesn't (since you're "at" the Internet cafe, not on your home/work network). Of course, your ISP/employer does know that you're visiting the Internet cafe, and in the case of work (and some ISPs) can stop you from doing so. If you visit a website from an Internet cafe, the website may still be able to figure out who you are, just like they can when you bounce between different networks normally. And of course, if you login to your account on a website or put your shipping address or something in when buying something, you're self identifying (unless you have throwaway accounts or forwarding addresses or whatever). And finally, if someone really wants to figure out who you are to a high degree of confidence, they will. I find this lands pretty well and is close enough to being technically correct without getting into the details that non-technical people would start glazing over if I got into.
- k_bx 4y agoI'm using VPN to pay for the movies that are blocked for me otherwise (as a Ukrainian viewer).
- karaterobot 4y agoTorrenting without a VPN gets you a nasty letter pretty quickly. Someone at my IP address downloaded a single episode of The Last of Us with the VPN turned off, and I got an email that same day. No idea who would do such a horrible thing, but I think I saw some hacker-looking guy parked on the street stealing my wifi.
- ashirviskas 4y ago>Torrenting without a VPN gets you a nasty letter pretty quickly. Only in some countries ;)
- lucb1e 4y ago> If most sites nowadays are on HTTPS, is vpn still needed for daily use Let's say every website is still on HTTP (not S). How does a VPN for daily use help you at all? Your traffic traverses the Internet unencrypted anyway: either from your ISP to target server, or from the VPN's ISP to target server. It shifts the responsibility from one party to another, but it doesn't reduce the unencrypted path. Instead of trusting your ISP, you now have to trust a shady operator that often promises not to comply with local laws when the police comes with a warrant. They often also don't have assets to seize, so little reason to be legit. And it's not like you can stop paying the ISP that you are so distrustful of. It only costs you more money.