5 ms·
Using the internet in general is a false sense of security. If you want total security crush all of your technology and go live in the woods. The point of cybe
by moose44 3y ago
Using the internet in general is a false sense of security. If you want total security crush all of your technology and go live in the woods.
The point of cyber security tools like VPNs is to limit tracking, data sharing and reduce the potential for malicious actions to be taken against you.
You can't honestly say not using a VPN is better than using one. What's the alternative? Unencrypted web traffic? Your ISP harvesting your web data and selling it? Exposure on public networks?
- tmikaeld 3y ago> Unencrypted web traffic? I don't know if you're aware, but basically all sites on the internet use something called SSL these days. However, SSL is useless if you use a VPN that also provide DNS servers (which most do) - because the provider could listen in on all of your traffic by hijacking the handshake, DNS and traffic to and from any target server - making it much easier to create a user profile, because you're authenticated to the VPN. Also, third party cookies are blocked in the mainline browsers by default, making VPNs even more useless. Most if not all of the ISPs also use dynamic IPs, making it unlikely to be cross-site-tracked based on IP sources.
- moose44 3y agoWhat does that have to do with your ISP having access to this information and selling it? In addition to using public networks? Additionally, 3rd party cookies may be blocked but cross-site are not.
- tmikaeld 3y agoYou realize 3rd party cookies and cross-site cookies are the same thing?
- syntheticcorp 3y agoControl over a clients DNS doesn’t let the VPN provider view the contents of TLS encrypted traffic. However they can view unencrypted data from connections like SNI headers, DNS queries etc.
- tmikaeld 3y agoThe point here is that if you use someone else’s dns, they can redirect any domain to their server and sign the cert too since they also control the traffic.
- syntheticcorp 3y agoYou can’t serve a valid certificate chain to the client even if you control their traffic, because your malicious certificate isn’t signed by a trusted CA. And you can’t get a CA signature without demonstrating control of the domain to a CA.
- okamiueru 3y agoIs it limiting tracking, or potentially exposing a untrusted middleman with knowledge of all your traffic, and who it belongs to? What is the difference between the ISP knowing this and being a problem, but the VPN sitting with the exact same information, also knowing it?
- lowbloodsugar 3y agoI mean, sure, it really depends on who is providing the VPN. With Proton, you're already using them for your email, so if they were a bad actor, you're basically fucked already. If you have ProtonMail, then the choices are 1/ No VPN, so your ISP will collect this data, 2/ a popular VPN provide who will collect this data, or 3/ Proton who say they won't and they've already got you email too if they are liars. Option 3 is the lowest risk of event if they are good actor, but also the potential damage of an event, if they are bad actor, is much higher since they have more data including email based 2FA.
- moose44 3y agoLike I said above, the best option is to not use technology at all. If you want to use it, you play the odds and attempt to limit nefarious activity against you.
- moose44 3y agoISPs knowingly collect it and sell it. Proton (at least according to them) do not collect it. You must choose your VPN carefully.
- Tijdreiziger 3y agoThat’s a pretty strong statement to make about all ISPs in the world.
- moose44 3y agoIt's true. In fact, in the US they even lobbied congress to do so: https://techcrunch.com/2017/03/28/house-vote-sj-34-isp-regulations-fcc/ https://techcrunch.com/2017/03/28/house-vote-sj-34-isp-regul...
- gtvwill 3y agoAm my own isp.... I rarely use a VPN. Fixed ip and all. Your VPN doesn't protect against squat when it comes to the agencies that might be watching. Hell it doesn't even protect much against marketers fingerprinting your movement around the internet. You leave a plenty big breadcrumb trail that isn't just IPV4. Honestly VPNs have been a great marketing example of the last 5 years. You all buy something without needing it or knowing why t f you have it. Yes using internet without one is better. Why? It's cheaper for starters.Auth. faster! No relay slowing down your connection! VPN best use isn't on consumer end. It's on orchestration end as another tool to guarantee you are who you say you are via another layer of auth.
- Tijdreiziger 3y agoThere is one specific case in which using a VPN is faster: if your ISP has bad peering in general, but good peering with your VPN provider.