7 ms·
I don't understand why go after the VPN, I think most people don't use a VPN correctly. What good is a VPN when multiple apps on your computer are phoning home
by pedro_hab 3y ago
I don't understand why go after the VPN, I think most people don't use a VPN correctly.
What good is a VPN when multiple apps on your computer are phoning home?
If the law has a suspect IP, couldn't they just ask google, microsoft and facebook what accounts were accessed with that IP?
To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to hide?
- Kuinox 3y agoTo watch movies that are not licensed in your country, on legals platforms.
- peer2pay 3y agoWhen tunneling through a VPN ideally thousands of users will share the same exit IP. So even if all your apps "phone home" identifiable information there is no way to prove that whatever traffic "the law" is trying to pin you on actually originates from your machine. Unless of course if the VPN keeps detailed traffic logs which is why that’s generally frowned upon.
- sdrinf 3y agoBriefly, law requires establishing probable cause, that _one_ specific person has done specific things, to underwrite search warrant. VPN IPs are shared between users, meaning any one of the ~X00 users sharing a single ip could be doing any number of things at the same time.
- formerly_proven 3y agoBriefly, non-US jurisdictions are not US jurisdictions and have different standards and procedures.
- fareesh 3y agoIf an app phones home at 11:00 AM and the illegal act is at 11:01 AM wouldn't it narrow down the list of suspects considerably?
- robjan 3y agoNo, because at the same time x number of users have their apps phoning home with what appears to be the same IP
- ementally 3y agoHow can you be sure that you are the only one in your country not connected to the same IP address provided by a VPN server?
- therein 3y agoWell if they have ISP flow logs, that'll be trickier because it will enable very granular inspection of the traffic and the timings of that traffic. However if they are trying to cast a wide net and inquire Google and other service providers for it, that will lead to a lot of collusions and they won't be able to tell it is from country A because it is from the VPN.
- fareesh 3y agoAre you sure x is sufficiently large?
- terhechte 3y agoUse the VPN from a VM. You can also configure Mullvad to use socks so that it can only be accessed from Firefox (which has OS independent socks settings)
- metadaemon 3y agoI was under the impression the socks feature no longer works, are you currently using it?
- pulpfictional 3y agoI am, through the mullvad add-on.
- metadaemon 3y agoTIL, thanks!
- therein 3y agoTake their wireguard config, change allowed IPs to include only the IP of their SOCKS gateway. And then use the SOCKS proxy over Wireguard while nothing else on your system is routed through it. That's the only way you'll get Mullvad "split tunnel" on OSX. Edit: Should have replied to the sibling comment but I guess this will do.
- S201 3y agoIt works the same as always for me on Linux with SSH port forwards.
- jaystraw 3y agoyou can start chrome-based browsers with a flag from the commandline with os independent proxy settings
- can16358p 3y agoMy country blocks many websites and I'm pretty sure spies users' traffic too. I can use VPN to access the web freely and while VPN provider can also log my traffic, I trust it MUCH MORE than my country's government.
- ementally 3y agoIf your ISP suspects your IP address (can see your are connected to specific VPN server) they can just contact top websites, example: twitter, facebook or google and ask them if there are any users connected with the same IP at given specific time.
- woofcat 3y agoThis is a confusing take to me. So my ISP which has my billing information is trying to find out who I am by calling Google? They know who I am. The inverse is what you're trying to prevent. Service ABC has malicious activity and calls Google to ask which accounts are accessing from that IP address. However this has two main problems. a) Why would Google give this info over willingly. b) Most VPN's assign the same outbound IP address to multiple users. So it's not a 1-1 mapping. c) People who are using a VPN for something malicious are not also signed into Google.. I'd think.
- kijin 3y agoa) This is why you go through the legal system instead of asking Google directly. Report malicious activity to a three-letter agency of your choice, and let them do the dirty work. b) You can reduce the list of suspects significantly by correlating activity on multiple services from the same IP address around the same time. c) You'd be wrong... especially since Google never really forgets who you are, even when you are not signed in.
- ementally 3y agoa) If they are unable to identify the user by any means then this is their only resort and google is going to happily hand it over. b) Depends on the country you are in. You might be the only one connected to a specific VPN server at specified time, this also answers point c. c) Would be surprised. Have a read of this recent Affidavit https://s3.documentcloud.org/documents/23723268/pompourin-affidavit-govuscourtsvaed53554220.pdf https://s3.documentcloud.org/documents/23723268/pompourin-af...
- autoexec 3y agoIt's not a 1-1 mapping but it can narrow things down to you and maybe a handful of others. If you're doing something like file sharing repeatedly over several days/weeks they can pull data for all of that time and when your IP is the only constant they'd know it was you. If they have only a handful of people it could potentially be, and they care enough they can seize and search the devices of everyone to find the person. Also, you don't have to be logged into google for google to know who you are. If you're using windows, your OS is also phoning home constantly with identifying data. If you use steam, it's also phoning home. Run wireshark sometime and see how much your computer is sending to random servers without you doing anything or being "logged in".
- KronisLV 3y ago> To use a VPN correctly wouldn't have to use a fresh OS and absolutely not login to any accounts connected to the IP you are trying to hide? Even then fingerprinting would still present an issue, even without explicitly logging in, with most browsers. For example: https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/ Also have a look at this: https://www.amiunique.org/ https://www.amiunique.org/ So you might need to have a browser that lies and presents configuration information that is common enough not to be unique, probably an OS inside of a VM might be one of the possible starting points. Outright denying access to some of that might actually help identify you, but pretending to be a common setup might not even work that well. I'm frankly not sure whether privacy on the web is even truly possible nowadays, at least without a lot of effort. Even with a VPN, I treat the web as something that is more or less "spying" on me regardless, in the metadata collection and storage sense.
- jenadine 3y agoI believe the "a fresh OS" makes fingerprinting useless.
- akyuu 3y agoNot really. Modern web browsers expose a lot of information, such as your language, time zone, screen resolution, CPU and GPU details (number of cores, vendor, model...), etc. There's even <canvas> fingerprint which depends on your GPU driver version. If you use a custom built desktop computer, you're going to have a pretty unique browser fingerprint because few people will use the same exact hardware configuration. On the other hand, if you use Apple hardware you'll look the same as other Mac/iPhone users. The other option is to use Tor Browser or Tails OS, but I don't think that's feasible for everyday browsing. As other people have said, it's suprisingly difficult to have privacy on everyday browsing today. Personally, I blame Google. I believe they purposefully pushed modern web standards into maximum user data exposure for their own profit.
- steve1977 3y agoSo, one could think a solution would be to not use modern browsers. But then this alone makes you stand out again I guess. Maybe VPNs should start to offer “browser anonymization” as a service.
- mindslight 3y agoI personally use a bunch of VMs for web browsing, all with different exit IPs. And yes, a lot of people use VPNs but don't use them correctly. But I'd rather help them to use them more effectively, rather than shout down that VPNs "don't work". And even when they're not used correctly, most people don't have particularly omniscient threats. And even imperfect use still helps everyone else by creating cover traffic, a fluid market for VPN services, and more evidence to websites that (IP-based) nagwalls hurt legitimate visitors.
- aborsy 3y agoYou use Qubes OS? Otherwise, a lot of ram, CPU and storage might be needed.
- mindslight 3y agoActually no, just home-rolled with virt-manager. I can definitely see the advantages of Qubes, but at this point it feels like it would be a lot of learning and changes for what is mostly a similar system. And I don't think it would work for the servers/daemons I run either.
- aborsy 3y agoYeah, even getting that beast installed on a typical machine may not be straightforward. It has very specific hardware requirements.
- miohtama 3y agoYou want to use VPN in places like United Arab Emirates and China where there are issues with Internet traffic - WhatsApp calls and such are blocked, you force to use the local crappy app by the local ruler’s cousin otherwise - They will outright send a re-educator to visit you if you browser the web about the sensitive topics
- autoexec 3y ago> They will outright send a re-educator to visit you if you browser the web about the sensitive topics This also true if you post the wrong things to social media in Canada (https://northernontario.ctvnews.ca/sudbury-ont-police-say-youth-13-charged-after-hate-filled-song-lyrics-posted-to-social-media-1.5666980 https://northernontario.ctvnews.ca/sudbury-ont-police-say-yo...) and in Australia (https://www.youtube.com/watch?v=vWZ06UThHas https://www.youtube.com/watch?v=vWZ06UThHas) and in the UK if you post something offensive they'll outright arrest you. I'm sure I read an article at some point about someone in the US being questioned by police for posting a movie quote to social media, but I can't seem to find anything about it now, just finding tons of examples of police in the US getting in trouble for posting racists things.
- lofaszvanitt 3y agoYou put the vpn on a physical device (router), so there is no way to circumvent it on the os level.
- troad 3y ago> don't use a VPN correctly People have different use cases for a VPN. I use one because I travel a lot, and spend a lot of time on dodgy public Wi-Fi. Not because I’m living some Jason Bourne fantasy.
- kleene_op 3y agoThat's what Jason Bourne would say.
- causi 3y agoYeah. A commercial VPN that's demonstrated its record-keeping policy under subpoena is reasonably safe if your objective is pirating media. HN commentators act like the VPN target market is Sino-Iranian freedom fighters who split their time between rescuing Uyghurs and searching for a way to cure their magical curse that makes them dissolve into dust if Google can tell they did a search for good restaurants in the area. Most people are just trying not to get a scary letter from HBO.
- autoexec 3y ago> Most people are just trying not to get a scary letter from HBO. It's safe to assume that VPN company operating in the US is compromised but I figure that three letter agencies aren't going to spoil their honeypot over some kid downloading movies and TV episodes, which just gives you an added layer of protection against raids while also preventing your ISP from selling your browsing history and avoiding DMCA letters which unfortunately can get you perma-banned from your ISP based on nothing but unproven accusations from unreliable 3rd parties.
- jorblumesea 3y agoIP != user. You'd only narrow it down to 10k suspects or something.
- nextaccountic 3y ago> What good is a VPN when multiple apps on your computer are phoning home? The point of a VPN is that whenever an app phone home, they will do so through the VPN. Standard VPN configuration (which I supose the Mullvad client performs?) is to entirely disallow any traffic that doesn't go through the VPN
- deleted 3y ago[deleted]
- Root_Denied 3y agoYou're missing the reason this is important - the companies that run those apps (spotify, facebook, steam, discord, etc.) will be able to correlate your VPN connection with your non-VPN connection, and tie those both to an app account that identifies you. It means unless you've got a dedicated download/seed box running your torrent downloads, one that doesn't have anything else on it and never connects to anything without a VPN connect, it's possible to track you down way more easily than you would think.
- kelnos 3y agoAnother easier option is to run the VPN client and torrent client in a Docker container, with networking separate from the host machine. Then the only thing using the VPN is the torrent client.
- tadfisher 3y agoThe point of a VPN-as-a-service is that many thousands of connections originate from that same IP, making it difficult to correlate individual connections to an identity.
- autoexec 3y agoYou're right that this is a huge problem with modem OS/software that's constantly phoning home, and people would be wise to avoid using those programs/operating systems when using a VPN to hide their identity. but many VPNs offer plausible deniability by assigning many people the same IP. A request to MS asking for who had a given IP address at a certain time could return multiple devices in different countries/states/cities. Narrows things down significantly, but not always a dead give away.
- deleted 3y ago[deleted]