12 ms·
Personal VPN services are snake oil
- tim333 2y ago[dead]
- rsync 2y ago"One massive problem with personal VPN services is that they are working to fail open. If the connection fails, your connection is not “protected” anymore. Some premium VPN providers sell “kill switch” functionality, but I am sure less than 1% of the users use this properly." There's a very, very easy way to solve this problem: vpn_command ; ip link set ens160 down ... or whatever ... this way, if the VPN exits you are immediately bringing your network down. Very simple and robust. A 'network slug'[1] is an even more robust - and network-wide - mechanism for enforcing your VPN. If you are serious about avoiding misconfiguration or opsec failures you should have a network slug as a physical choke in your PHY. [1] A "slug" is a layer-2 bridge, with no IP address configured, that still enforces a TCP/IP whitelist. So it does not "use" a hop on the network route, and you can't see the device, but as it bridges traffic it enforces a (very simple) ruleset: https://john.kozubik.com/pub/NetworkSlug/tip.html https://john.kozubik.com/pub/NetworkSlug/tip.html
- chadsix 2y agoThis is generally true. These VPN services are security theater as tracking has moved beyond IP address. They are likely masking other more nefarious use cases; and in many cases, deliberately and willfully aiding and abetting therein (for example forwarding BitTorrent traffic to other "Non-Copyright/DMCA Participant" countries, forwarding users through faux residential IPs for 'streaming', etc.).
- ethbr1 2y agoURL would be funnier if owner also owned the actual URL, but redirected everything to the extra one. And it's unregistered! https://www.namecheap.com/domains/registration/results/?domain=dotzoltanbalazs.com https://www.namecheap.com/domains/registration/results/?doma... Edit: Per below, missed the last dot. zoltanbalazs is registered. https://www.namecheap.com/domains/registration/results/?domain=zoltanbalazs.com https://www.namecheap.com/domains/registration/results/?doma... Also, what would be more interesting: a financial breakdown of how an average free VPN provider makes money. I assume ad injection + selling traffic data, but does that make enough to offset the cost?
- jsheard 2y agoI believe at least one of the business models for "free" VPNs is to turn their users machines into exit nodes, and the real business is in selling those to people who want to spread their traffic across many residential IPs for usually dubious reasons (e.g. scalpers trying to scoop up concert tickets or limited edition sneakers or whatever without tripping bot detection).
- bpfrh 2y agoafaik some free vpn providers use your own connection to offer residential ips for scrapping services or other vpn users. I know I read a article about one where they at least routed some other traffic through the vpn app, but I can't find the article anymore.
- twisteriffic 2y agohttps://thebestvpn.com/118-vpns-logging-policy/ https://thebestvpn.com/118-vpns-logging-policy/
- dantyti 2y agoholavpn was exposed by trend micro as a botnet for rent (best source I could find since the original white paper from trend micro seems to be gone: https://www.vice.com/en/article/pga9yk/your-tool-to-access-netflix-content-abroad-is-hijacking-your-internet-connection https://www.vice.com/en/article/pga9yk/your-tool-to-access-n... ) facebook used their vpn onavo to mitm users of snapchat, amazon, youtube: https://techcrunch.com/2024/03/26/facebook-secret-project-snooped-snapchat-user-traffic/ https://techcrunch.com/2024/03/26/facebook-secret-project-sn... – somehow I had missed this, I was only aware of the much older scoop about facebook using it to track underaged users: https://techcrunch.com/2019/01/29/facebook-project-atlas/ https://techcrunch.com/2019/01/29/facebook-project-atlas/
- gruez 2y ago>facebook used their vpn onavo [...] It's worth pointing out that while it operated as a VPN (so it could capture traffic), it was ostensibly marketed as a "security" app (ie. scanning your web traffic for threats). It's not really a good example of shady VPNs.
- beefnugs 2y agobaby's first regex! oh so cute, here let me feed you more periods
- lucb1e 2y agoI just noticed newlines are rendered on Algolia: https://hn.algolia.com/?query=regex%20feed%20periods&type=comment https://hn.algolia.com/?query=regex%20feed%20periods&type=co... This can be useful when people attempt bullet point lists Anyway is this comment a reference to the domain? I don't understand what you mean
- bhaney 2y ago> When to use a personal VPN? > - Geofence bypass > - Piracy > - Soft network block/censorship Among all the people I know who use the kind of VPN services talked about here, these are exactly their reasons for using them. Obviously advertisements are going to shy away from these angles.
- jsheard 2y agoYou may not even need a VPN to get around censorship, ISPs implementing legally mandated site blocks often only bother to enforce them at the DNS level so you can trivially bypass them by using an encrypted DNS resolver.
- pc86 2y agoEncrypted DNS resolvers aren't trivial[0] for the ~99% of people who don't even know what they are, though. [0] https://news.ycombinator.com/item?id=8863 https://news.ycombinator.com/item?id=8863
- bhaney 2y agoDoesn't Firefox default to eDNS these days? I don't think it can get much more trivial than that
- LaLaLand122 2y agoIn the UK, at least, it isn't the default (because of "the children"/"terrorism"). But it's still just a setting in Firefox/Chrome to change (and I guess in Edge too).
- gruez 2y agoChanging the "secure dns" option on their phone/computer is probably easier than installing a VPN app, tbh.
- taneq 2y agoEven just using a different DNS can be enough. A certain popular movie uploader is/was blocked by my ISP at the DNS level but worked fine once I changed to OpenDNS.
- paulgb 2y agoThe problem is that they are sold as a security/privacy product, because they can’t mention the more illicit uses (which the author mentions under “when to use a VPN”), which are the real use cases people buy them for. It’s kind of like when shops selling bongs would market them as “tobacco accessories”, but there was a wink-and-nudge understanding about how they would really be used.
- elorant 2y agoI buy them so I can have country specific ips
- EGreg 2y agoYou mean like vibrating massagers? Did you know the original vibrator was a medical device by doctors to automate treatment of Hysteria?
- zaroth 2y agoHaha, lookup what “hysteria” was and the medical “treatment” devised to “cure” it. We might have a long way yet to go as a species, but we’ve sure come a long way.
- jiggawatts 2y agoWe still have chiropractors and Chinese herbal medicine dispensaries.
- toast0 2y agoI've never seen a whole lot of value in personal VPNs; it's basically trading one network that can observe you for another. Often with unverifiable claims about not observing you. But, it can be helpful to trade one network's routes for another, in cases where direct routing between you and your desired peers is poor for whatever reason. And it's clearly useful for circumventing geographic restrictions (as long as those imposing the restrictions dont' care to identify and restrict access through VPNs)
- ls612 2y agoMullvad and Proton at least have had their no logs policies court tested so I believe their claims.
- mmsc 2y agoIn general I agree about it not providing security benefit, but they can reduce the exposure of eavesdropping like DNS leaking browsing patterns, and so on. Sure, you’re now leaking your DNS traffic to the VPN server, but in my opinion it’s better to leak that to somewhere external than somewhere close by (e.g. to companies or individuals directly related to your network that will use it for monitoring and monetisation) https downgrade attacks and the like (html injection on http pages) can also be thwarted (unless they are done on the vpn->service path ofc),
- al_borland 2y agoWouldn’t switching to something like Cloudflare’s 1.1.1.1 DNS mostly solve the DNS issue without going the VPN route? The user’s DNS provider would no longer be their ISP.
- mschuster91 2y ago> The user’s DNS provider would no longer be their ISP. Only if the ISP doesn't do DPI to transparently route any outgoing DNS traffic to their (censoring) servers. There have been enough cases of that.
- yjftsjthsd-h 2y agoDoes that work anymore with DNS over HTTPS? I think the real leak is that until we get Encrypted Client Hello your HTTPS connections expose the domain in plaintext so DNS is kind of a moot point.
- WirelessGigabit 2y agoIt does not. DoH and DoT is a real lifesaver for the privacy-minded people. And it's hell for the security minded people. Before I could do DNAT on my router to redirect everything to my Pi-Hole, even the Google Mini that staunchly ignored the handed out DNS, but used 8.8.8.8. But soon they'll start using DoH and I can't do anything anymore at all. I believe IMDb on iOS already uses DoH.
- CPLX 2y agoIt’s not that deep. People want to download shit and watch Netflix
- pyrolistical 2y agoThe author calls it snake oil then lists legitimate reasons to use a VPN at the end
- tensor 2y agoNo better way to get traffic than rage baiting I guess.
- lionkor 2y agoSay I sell snake oil, and I say it will cure cancer. Then Peter comes and buys it because he lubricates his discumbulator machine with it. It has a legitimate use, and maybe I even know that, but I still sell it as a cancer cure (which it isn't). Its still snake oil.
- deleted 2y ago[deleted]
- kelsey98765431 2y agoArgument is based on the assumption that "probably only one percent of users correctly use a kill switch", and in general shows a low level of understanding of threat models and the swiss cheese security model. Author assumes to know the intentions of VPN users and asserts users are dumb, also throwing unnecessary barbs at "wannabe hackers". Unprofessional article, bad advice, no differentiation between nonlogging services and services like nordvpn that bundle google analytics and tracking into their application. My take? Do a threat assessment, build a threat model, know your adversary be it your own ISP selling your data or protection against hostile state entities when traveling overseas. There are many valid uses for the various types of commercial VPN and instead of an objective look at these services the author walks in with an assumption that they are all the same and never provide value to their customers, then bends over backwards to attempt to make weak arguments against a vast category of service.
- rfl890 2y agoYep, HN is definitely not the article's target audience.
- blablabla123 2y agoI think this is one of the biggest misunderstandings about security that there's one linear scale and that every solution can be assigned a generic positive/negative delta on that.
- datadrivenangel 2y agoAuthor is correct that TOR has better privacy than a better VPN because TOR means you are truly anonymous (assuming the network is not majority compromised). However, bandwidth and latency on TOR suck, and in many cases the endpoint IPs are blacklisted to hell due to abuse. A VPN is a nice middle ground where your can put another entity between yourself and your traffic, which is valuable against most opportunist adversaries. If a TLA wants me and can get a warrant, not even TOR will save me, but a VPN keeps the ISP from selling my traffic and the media trolls from sending me grumpy letters because the neighbors keep using my wifi to watch free content.
- bsza 2y ago> assuming the network is not majority compromised There is no such guarantee AFAIK, as long as a bad actor controls all the nodes in YOUR route, they can deanonymize you.
- malfist 2y agoEveryone is pointing out that the article shoots itself in the foot by giving three very good reasons for VPNs and dismissing them. But I think there's a fourth reason that isn't mentioned: The US doesn't have reasonable privacy laws and I don't trust my VPN to not sell my browsing history to anybody with two pennies to rub together. Yeah, I can (and do) use DNS over HTTP, but the ISP still knows what IPs I am connecting too. It's trivial to find out what domains are hosted there.
- DanielBen6 2y ago[dead]
- PlutoIsAPlanet 2y agoAn issue is that they're sold as a way to stop your ISP tracking what you're doing. But why would I trust a random company with this information over an ISP, who yes aren't always angels, but at least are somewhat accountable.
- moffkalast 2y agoFurthermore, they use their VPN clients as proxies and sell access to their network to scrapers and botnetters. Usually the rule of thumb is that if you're not paying, you're the product, but in this case they manage to double dip. That's where the real funding comes from. https://oxylabs.io https://oxylabs.io
- perplexa 2y agoIf they claim to be operating an ethical service one more time I might start to believe it.
- Ekaros 2y agoIt is really question do you trust your ISP or do you trust your VPN provider? And if you are doing something your state might have interest in. Well VPN options might also be questionable. Either in some adjacent state, or other ways scrupulous...
- SV_BubbleTime 2y agoMy ISP is Comcast and my VPN is Mullvlad. Guess.
- sss111 2y agoMullvad and it's not even close haha
- gruez 2y ago>But why would I trust a random company with this information over an ISP, who yes aren't always angels, but at least are somewhat accountable. ISPs often have captive markets and have enough political sway to grant them said captive markets. VPN companies have none of that, and live or die based on their reputation, so they arguably have more of an incentive to behave well. Meanwhile some ISPs have even admitted to selling your traffic for marketing purposes or are forced by the government to keep records. There's plenty of shady VPN companies out there, and not all ISPs are scummy and sell your info, but there's quite a bit of range between the scummiest ISP and the best VPN, and for a subset of people using VPNs definitely makes sense.
- diego_moita 2y agoA lot of people have VPNs for single temporary reasons. * In the Bible Belt (a.k.a. Chistianstan) and some Muslim countries it is to access porn. * In Canada and Mexico is about accessing what Netflix doesn't provide to their countries. * In hybrid offices it is about the second job that they do remote and hidden. They want something simple for a couple of months and then just discard it. VPNs are good for that.
- BrandoElFollito 2y agoThere are some states in the US that restrict access to porn?
- wishfish 2y agoYes. Via the new age verification laws which require any site with a considerable amount of 18+ content to verify their users are 18+. This has passed in a few states. Leading Pornhub, and some other porn sites, to block access from those states. The age verification laws are written pretty broadly and could be used to target a wide variety of content. Not just porn. Anything the state deems 18+ would require age verification. These laws are facing some court challenges. If we're lucky, the laws will not survive.
- ementally 2y agoAuthor linked to privacytools.io. >even better, a browser built with privacy in mind which is full of VPN ads https://www.privacytools.io/privacy-vpn https://www.privacytools.io/privacy-vpn. Browse https://www.privacyguides.org/en/vpn/ https://www.privacyguides.org/en/vpn/ better.
- pompino 2y agoVPN or not, the biggest MiTM threat to privacy on the web is Google. They may not be actively malicious and steal your bank info, or do other nefarious stuff, but they will always oppose end-end encryption. Google's stance is to lock out the competition under the guise of "protecting" users, so only they can spy on user data.
- shoaki 2y agoAlthough i agree with the overall message, there are privacy concerns with OCSP[1] which are mitigated by using a VPN. When trying to use the web privacy conscious, it might actually be beneficial to your privacy. This is a very edge case though. [1] https://en.wikipedia.org/wiki/Online_Certificate_Status_Protocol#Privacy_concerns https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
- TZubiri 2y agoFuck that is a good domain name
- FireBeyond 2y agoBack in the 90s, early 2000s, in Australia, there was an ISP called Dot, IIRC. In an attempt to be edgy, their website was at: triplew.dot.net.au "triple w dot dot dot net dot au"
- rwiggins 2y agoThere's a fourth use-case: occasionally, gaming. I play Final Fantasy XIV, an MMORPG - apparently, supposedly, the peering connection between AT&T and FFXIV's US ISP (NTT) was particularly bad. [1] This manifested as pretty severe connection issues for AT&T customers playing FFXIV. Except, it was a chronic issue that would only flare up when that particular connection point was stressed. One of the easiest workarounds? Hop on a VPN. That's one example. Anecdotally, I have a few friends that toggle VPNs on and off when they encounter "network weather" in games. Personally, I'm a bit skeptical they're truly so often mitigating problems by toggling a VPN (instead of, say, just waiting a couple minutes), but hey, they swear by it. [1]: https://forum.square-enix.com/ffxiv/threads/482155-Bad-lag-again-with-NTT-s-NA-server-network/page2 https://forum.square-enix.com/ffxiv/threads/482155-Bad-lag-a...
- netfortius 2y agoTry to travel the world and access financial or governmental institutions, then tell me about usefulness / uselessness of VPN.
- gruez 2y agoIt's baffling that banks/governments that do geoip based risk assessments (ie. the ones that would lock your account if you tried logging in from a random country) wouldn't flag logins from a VPN/datacenter IP. Those basically tell you nothing about where the user is actually logging in from, and they should therefore treat them as if you're logging in from a random country.
- iambateman 2y agoIt’s true that their privacy promises are dubious…but they’re great for IP switching. I run a low-volume scraper which benefits a ton from keeping the IP address fresh. So I guess, in a sense, I’m grateful that enough people are paying for ~nothing to make the service pretty great.
- zaroth 2y agoDigital Ocean droplet and Tailscale?
- shoaki 2y agoThe author specifically excludes "Company VPNs" and VPNs to "phone into your home network" from the scope of the article.
- gruez 2y agoThe "DIY VPN" is worse for 3 reasons: 1. it's more expensive than commercial VPNs, which you can often get for <$3/month, or even less with promos/cashback sites 2. you're limited to one region, which means you can't use it as effectively for geoblock evasion purposes. 3. you get less anonymity because you get a static ip that's assigned to you only, as opposed to a commercial VPN provider where you can connect to hundreds/thousands of servers each of which are used by probably hundreds of users.
- coppsilgold 2y agoIf a VPN provider doesn't keep logs and if their routes to you are not being tapped for packet timing correlation then they are superior in privacy to DIY VPNs due to them laundering your connections/packets with multiple other people.
- zoklet-enjoyer 2y agoI need a VPN to do a lot of stuff with crypto now because websites are blocking Americans. $5 a month and having to use it is annoying, but I'd have missed out on thousands of dollars of income if I wasn't using one.
- mschuster91 2y agoThere is a fourth use case for VPNs: evading traffic shaping and censorship on public wifi hotspots. Many hotels block not just porn sites but also legitimate news pages (e.g. Torrentfreak), and most drastically throttle YouTube, Netflix and other streaming-heavy sites. A fifth use case is related: evading bad peering. Deutsche Telekom was infamous for years to "double dip", i.e. requiring that other (backbone/regional) ISPs pay them for peering, and so DTAG customers that tried to access Hetzner servers were throttled as the Hetzner-Telekom link got saturated in the peak traffic times. [1] https://www.golem.de/news/hetzner-und-netzneutralitaet-extrakosten-fuer-bessere-anbindung-an-telekom-kunden-1511-117711.html https://www.golem.de/news/hetzner-und-netzneutralitaet-extra...
- oynqr 2y agoThe link to AWS was/is really bad as well, since that has to go through Telia.
- mschuster91 2y agoFor real, this is the only case where I wouldn't mind AWS to actually use their market size firepower. Throttle all of DTAG on a single 1 GBit/s link and tell them, either you peer with us for free like everyone else, or you'll have to deal with annoyed users.
- pelasaco 2y agoMy use case: - In Hotel, Airport. VPN can be used to bypass DNS based captive portal. - Yes true hopefully all website are encrypted with ssl, but still an attacker can easily fingerprint me through my internet usage, even though everything is ssl, there are still a lot of plain-text data flying around. So yeah, ProtonVPN, ftw.
- gruez 2y ago>Yes true hopefully all website are encrypted with ssl, but still an attacker can easily fingerprint me through my internet usage So an "attacker" can figure out that you browse hacker news. Who cares?
- blackeyeblitzar 2y agoI care, and my feeling is that more people do each day as they become aware of how tracked they are. Why does anyone need to know anything about me - it feels like a violation. There are all sorts of possible costs to that, but I think many of us value privacy on its own. But as for an attacker - maybe they discover something about you from one compromised service and correlate it to something else. Or maybe they extort you in some way. Who knows - there are many possibilities and it’s safer to reduce exposure.
- yjftsjthsd-h 2y agoYeah, no. > OK, but what about my DNS and TLS records being exposed to everyone so they can follow what I am doing? In a public place, anyone can look at your display already. Or, if you are worried about your ISP selling your traffic data, there are better options for you. Use DNS over HTTPS, for example. You have to use a VPN provider you trust better than your ISP/Wi-Fi provider. Also, as Encrypted Client Hello is about to start soon, it will be exponentially harder for eavesdroppers to figure out which sites you are trying to visit. Encrypting DNS is a nice start, but the ISP can still see the IPs you're connecting to, which is enough for a lot of sites, and Encrypted Client Hello is about to start soon is a lot of words to say "today, your ISP can see the domain on every HTTPS connection you make". So no, distrusting my ISP is absolutely a compelling reason to use a VPN. (And lest you say "but do they actually spy on you?", I literally got a letter from AT&T informing me that they were going to start monetizing information mined from my connections.) > But if you care about privacy, the answer is always ToR, ToR browser or Tails, and never VPN. Except in cases where you first have to hide your ToR usage using a VPN, which is a rare exception among users. If you don’t understand why you would need that, you probably don’t need that complexity. Tor Browser uses uncountable techniques that prevent tracking your browser. And if your privacy is essential against local Wi-Fi attackers, your ISP, why is the ad industry not in scope? Adblockers are only half the solution against tracking. I mean, yeah I also use uBlock, but TOR makes harsher tradeoffs than are necessarily needed (multiple hops is really safe but also really slow). I'm just hiding from my ISP's prying eyes; I explicitly don't include the NSA in my threat models and lesser methods are Good Enough™ for websites tracking me.
- woofcat 2y agoECH is not starting soon. CloudFlare haven't rolled it out to everyone and good luck finding a constant setup for it. There are some experimental servers for it, but basically not supported anywhere.
- healsdata 2y agoThe article appears to be written by a technical person who doesn't understand (or want to acknowledge) how bad end-users can be at security. We're still trying to get users to not reuse passwords on multiple sites and not click on links in SMS messages. Meanwhile, the author is suggesting you contact every website you use and ask them to add HSTS. Some end-users need straight forward advice like "Use a password manager" or "Use a non-free VPN on open WiFi connections". The rest is going to get thrown out with the bathwater.
- wmf 2y agoFor people with bad security practices... VPNs still have virtually no benefit.
- VeejayRampay 2y agoI wanted to use one to watch Gardener's World from the BBC and it doesn't even work (I'm in France and the program is UK-only for a reason that no one really understands) same goes for watching Netflix from other countries, VPN are badically useless
- tempaccount1234 2y agoWatching BBC Iplayer via VPN is hard, mainly because it’s in the interest of the BBC to avoid eating the cost of serving the world for free. And VPN traffic is easy to spot, if you’re looking for it. I’m assuming the BBC invests a lot of resources to fence of non paying foreign viewers. But this is a BBC specific problem, most of the other European geofencing is quite weak and getting access to most other public broadcasters works just fine with a proper VPN.
- VeejayRampay 2y agoit's sad, cause it's a GREAT program (which I have to watch on YouTube where people upload episodes)
- miki123211 2y agoI'd add: 4. Making all your traffic look "neutral" to your ISP, in places (think corporate / college campuses, cellular data, hotels and boarding schools, not countries) where net neutrality isn't enforced and certain traffic (most often torrenting, video streaming and/or gaming is deprioritized. I guess this could be classified as blocking or censorship, but deserves a separate category IMO. 5. Places where the networking hardware messes about with your data. I've seen places that would add their own iframes to unencrypted HTML content, which broke some software because their algorithms to detect what was HTML weren't very good.
- diebeforei485 2y agoSome college campuses (like the University of Texas system) block tiktok on wifi, so people are using VPN. (They could use cellular data instead, but that is often slower than campus wifi with VPN).
- aborsy 2y agoWouldn’t a VPN help protect against a targeted attack? Like an attacker could push bad JavaScript or app update to the user of a particular IP address. On DNS, it’s plaintext by default, and almost always not signed via DNSSEC. Such user could slightly benefit from a VPN from a security perspective. VPNs also usually do ad blocking, and some limited malware scanning. On privacy, there are many situations where a private IP address may be desirable, some of which mentioned in this post. VPN hides the traffic from the ISP, but also the user from the destination. On the latter, for instance, the websites could log IPs and that information could be sold or leak in the future.
- deleted 2y ago[deleted]
- privacyking 2y agoIn my country ISPs are legally required to store metadata for all traffic so using a VPN protects me from that
- rbut 2y agoYes in AU this, and so websites don't know my real IP, are the only reasons I use a VPN. I don't ever do anything illegal, I just don't like being tracked.
- pg5 2y agoPlex does not work for me on my AT&T fiber - some peering issue (or intentional throttling?!) that makes movies fail to playback 50% of the time as if I'm on dialup or something. Got a cheap VPN to get around the issue and it works perfectly.
- sedatk 2y agoYes, AT&T throttles Plex traffic. I don’t know if they could if FCC hadn’t killed Net Neutrality.
- bazil376 2y agoHeartened to see that porn consumption is one of the few recommended use cases for a personal VPN
- yegor 2y agoI run a commercial VPN service (Windscribe). Here are my thoughts on this. At its core, a basic VPN is a trust shift service, nothing more. Do you trust your ISP less than an some anonymous shell company owned by Siberian forest dwellers? In many cases, the answer is no. That being said, depending on where you are and if you choose the "right" VPN, the answer could be yes. Here are some reasons why you may want to use a good commercial VPN, which goes beyond just the ability to tunnel your traffic through a remote endpoint: - You are in Russia, China, Iran or other countries with heavily censored Internet. Over 3 billion people live in such places, or nearly 50% of the world's population. - If you don't live in such places, laws in certain US states criminalize certain behaviors. This will only get worse, even in "western democracies". Using a quality VPN service is much better than barebacking the Internet. - You want your traffic to be "lost in the crowd", something you cannot achieve with your Digital Ocean droplet, no matter how well you configure it. Changing your IP does absolutely nothing, safe a few exceptions (piracy, or keeping an alter ego if your opsec is good) - Additional features: server side DNS filtering / blocking. Yes you can use uBlock origin, but not on mobile, and not outside the browser. Yes you can run Pi-Hole, and setup WG tunnels to your homelab. 99% of people won't. - Advanced features: Companion browser extensions that block ads, trackers, malicious domains, mess with your browser settings to reduce chances of fingerprinting. Yes you can install 5+ different extensions to do that. Most people won't. TLDR; If you're an elite haxor, you can do everything yourself. You will spend time, and money doing so. Most people will not bother or not be able to do these things, and a quality commercial VPN service can check a lot of the boxes I mentioned above. Just avoid the ones that advertise heavily, those are marketing / snakeoil sales companies, as the author suggested.
- croemer 2y agoI use speedify to channel bond wifi and mobile when the wifi is not super reliable. It works great when walking around outside and eduroam works for 20m at a time.
- hintymad 2y agoI thought many people used VPNs so that they could connect to a host in Canada or Mexico to use BitTorrent to download videos in the US.
- constantcrying 2y agoThe article itself refutes the claim in it's title. VPNs have legitimate use, where they are the most attractive option to complete a certain goal. The article itself is listing thse use cases. But yes, VPN advertising preys on people's unfounded fears.
- tomxor 2y agoIn terms of privacy, there is one aspect you can gain: Privacy from your ISP and government. Even the UK now mandates ISPs collect data on user behaviour "just in-case" (snoopers charter), and it has been confirmed one of the big three mobile networks has implemented this, but not which. It's bad enough trying to put up with big tech.
- remram 2y agoCannot use Torrent on my ISP. Can use Torrent on VPN.
- deleted 2y ago[deleted]
- nieve 2y agoThe thing I never hear mentioned is when your home ISP (or say your favorite cafe's) is known to use your traffic data for marketing purposes or sell it outright. I trust Mullvad farther than I trust my ISP. I could switch ISPs, but my only option is Comcast and they're even sleazier.
- 01nate 2y agoI don't necessarily disagree that there's a lot of people being sold a VPN that probably don't need it, but VPNs still can be a legitimate tool. Even outside of the "well known" VPN uses like piracy, privacy (in a 'I trust it more then my ISP' fashion), and getting around geo-fences there's still uses for them. A couple of quick examples: Getting around blocks or monitoring on networks like work WiFi. No need to tell my work I'm on Indeed, and for a little while they seemed to block my email provider (Proton) and reading my email is handy to be able to do. For use as a network tool. For example, I was recently helping my brother set up a website, and with port forwarding he was able to really easily VNC into my VM I was working on it with. VPNs can also be handy for the 'slightly suspicious stuff' that's not illegal. You know, things like an internet search about something you saw on TV or were just curious about that's not illegal to research, but you're worried it could be a suspicious search. Or maybe I want to use wget to grab an offline archive of a website, but don't want to raise alarms and get my IP banned.
- Havoc 2y agoI view it as more moving the problem. Instead of police kicking down ISP doors they kick down VPN runners doors. Sorta ambivalent towards them overall. Just don’t have a big use for them
- 1oooqooq 2y agonobody going to point out that using a vpn for region bypass gets you blocked on Wikipedia, banned on your banking, shown captcha left and right by cloud flare... but Netflix and Disney+ all works perfectly? :pondering emoji face
- DanielBen6 2y ago[dead]
- 1vuio0pswjnm7 2y ago"Also, as Encrypted Client Hello is about to start soon, it will be exponentially harder for eavesdroppers to figure out which sites you are trying to visit." Exponentially? Can we see the data on that. Perhaps this word as used here is just a figure of speech. "Tor Browser uses uncountable techniques that prevent tracking your browser." Tor Browser has a number of popular browser "features" removed/disabled by default. As such the browser user does not need to do anything, no fiddling with poorly-documented options via about:config, user.js or whatever. IMHO, modifications like these would be useful even when not submitting requests through the Tor network. The question I have is why is there not a Firefox version that is like Tor Browser but without the Tor integration. Perhaps the answer is because Mozilla is trying to perpetuate online ads, i.e., surveillance, data collection and tracking, as a "business model", such as the model adopted by Google. Mozilla is wholly dependant on financial support from Google. If Google's online ads business fails, Mozilla is out of options. NB. I would never use Tor Browser. I am a text-only browser user and I prefer netcat and other TCP clients through one or more localhost-bound proxies for making HTTP requests. When I experiment with Tor, I use tor binary I compiled myself without relay module. In front of the tor SOCKS proxy, I use socat for requests to .onion sites that use HTTPS and tinyproxy for requests to .onion sites that use HTTP.^1 1. If anyone can explain why some .onion sites use HTTPS instead of HTTP, I would be interested to know the anwser. AFAICT, most .onion sites use HTTP. Tor reminds me of the early public internet. Submitting a request like an Archie search and having to wait seconds for a response. Also the number of .onion sites is relatively small. I like the uniformity of .onion addresses and the general absence of "vanity" names. And the search engine for it reminds me of the web pre-Google: like AltaVista, thousands of results are accessible. That's the way I like it. None of this collecting data from searches and trying to "guess" what someone is searching for (as Google does).
- ImpostorKeanu 2y agoAnother interesting point is that VPN providers have access to server-side keys and, obviously, the processes. This just makes the VPN provider the new ISP. There's no guarantee that VPN traffic isn't being decrypted and inspected "just trust us, bro. look at our popsec influencer approvals, bro."