3 ms·
> Unencrypted web traffic? I don't know if you're aware, but basically all sites on the internet use something called SSL these days. However, SSL is useless i
by tmikaeld 3y ago
> Unencrypted web traffic?
I don't know if you're aware, but basically all sites on the internet use something called SSL these days. However, SSL is useless if you use a VPN that also provide DNS servers (which most do) - because the provider could listen in on all of your traffic by hijacking the handshake, DNS and traffic to and from any target server - making it much easier to create a user profile, because you're authenticated to the VPN.
Also, third party cookies are blocked in the mainline browsers by default, making VPNs even more useless.
Most if not all of the ISPs also use dynamic IPs, making it unlikely to be cross-site-tracked based on IP sources.
- moose44 3y agoWhat does that have to do with your ISP having access to this information and selling it? In addition to using public networks? Additionally, 3rd party cookies may be blocked but cross-site are not.
- tmikaeld 3y agoYou realize 3rd party cookies and cross-site cookies are the same thing?
- syntheticcorp 3y agoControl over a clients DNS doesn’t let the VPN provider view the contents of TLS encrypted traffic. However they can view unencrypted data from connections like SNI headers, DNS queries etc.
- tmikaeld 3y agoThe point here is that if you use someone else’s dns, they can redirect any domain to their server and sign the cert too since they also control the traffic.
- syntheticcorp 3y agoYou can’t serve a valid certificate chain to the client even if you control their traffic, because your malicious certificate isn’t signed by a trusted CA. And you can’t get a CA signature without demonstrating control of the domain to a CA.