6 ms·
Can't trust any VPN these days
- jrvieira 2y agoThese days?
- endymi0n 2y agoHad the same thought from the headline, but the punchline is that he's using the VPN he completely built himself and can't even trust that one.
- isoprophlex 2y ago... which is entirely a PEBCAC-type error in this case, as he never tested if his configuration worked as expected.
- udev4096 2y agoWhich is not surprising because according to him, all it takes is running a simple bash script
- exitb 2y agoHe most likely wouldn't have this problem if he used a VPN product for clueless users. It has nothing to do with trust towards a class of technology and all to do with the fact that computers are hard.
- jbverschoor 2y agoRun your own exit node for tailscale or zerotier somewhere
- nofunsir 2y agoor bog-standard ssh server + bitvise local client. EDIT to clarify because i feel many might not be aware how easy it is: 1) enable port forwarding in your sshd config (implies you can't just do this on a server which you don't admin and which has this disabled) 2) point bitvise's socks5 proxy server feature at the ssh server 3) point anything that needs to be tunneled at the bitvise client's port (default 1080) e.g. firefox. 4) voila, packets leave and return via the ssh server's public IP.
- letters90 2y agoor just a portable mingw coming with an openssh and a dynamic proxy there you go with an easy socks5 proxy.
- ndheebebe 2y agoSo I open say Firefox and it routes it all through that. No gotchas?
- nofunsir 2y agofirefox > about:preferences > Network Settings (at bottom) > Manual proxy configuration > SOCKS v5 (enter details and your password if you set it up in bitvise) > also check "Proxy DNS when using SOCKS v5" at bottom
- justonenote 2y agoDoes Firefox route WebRTC through a socks proxy? Does it leak your locally configured IP when WebRTC is initiated? Even if the specific case of Firefox can be configured correctly and you have the source to verify that's it only sending traffic over the socks proxy, manually configuring every app to use a socks proxy is brittle and error pone, and for some apps just won't work. Much more straightforward to just have a system wide VPN as the only available route for outbound traffic so that all apps use it transparently.
- nofunsir 2y agomedia.peerconnection.enabled = false also, this sounds like fud.
- justonenote 2y agoso you gave 3 steps to get it working for firefox but forget one step that results in an IP leak. so not fud, it's a more brittle way to do it.
- 2y ago
- anakaine 2y agoGreat write up! Do you have any plans to create your own Arch Linux installer that bundles all your steps together so other users in your situation might be able to have a simpler time getting all the mechanics operating if they're Linux users but not as skilled as you?
- axegon_ 2y agoI have honestly never trusted VPN providers in any shape or form. I had a university professor back in the early 2010's who said something very accurate: "Proprietary services providing anonymity provide everything but anonymity". I'm far more comfortable running a vps somewhere when I need to. And even then, VPN is kind of an exception since I hate fiddling with the setup(as easy as it may be). For most of my usage, an SSH tunnel as a socks proxy does it all and when I'm done, kill the vps and move on.
- anakaine 2y agoThe article doesnt quite match the headline in the way your reply suggests. Trust, in this instance, is more about accidental leakage and installers not tailoring the OS to have Up and Down watchers to apply DNS changes. It's not about whether the VPN provider can be trusted.
- axegon_ 2y agoOn the contrary: an accidental leakage is one of the many reasons a VPN provider cannot be trusted. Say I want to hide myself temporarily - which is safer - a VPN provider, having no idea how they handle data, logs and whatnot, or a tiny vps somewhere for half an hour while you need it, get your job done and then nuke it out of existence. The latter would be infinitely harder to compromise if you know what you are doing as opposed to a service that is running 24/7 and having no idea how data is retained.
- alias_neo 2y agoYou're missing the point. OP _is_ running their own VPN, the title is misleading, and the article has nothing to do with VPN providers and trusting them. To quote: > I have my own VPN () - in other uncool words, I set up OpenVPN on a VPS ... The title should be "I configured my home rolled (Open)VPN server incorrectly and it leaked DNS".
- mr_mitm 2y agoSetting up a VPN using my FritzBox at home together with the Android app wg-tunnel was dead simple. I was really surprised how easy it was. A few clicks in the routers web interface and then scanning the QR code it gave me was all I needed. wg-tunnel has a whitelist of wifis where I don't need a VPN and turns on automatically on all other wifis. A VPS is not necessary in this (and OP's) usecase.
- Etheryte 2y agoI would say that the title is misleading. The author set up their own VPN, but didn't delve into what the config options they used actually do until they ran into problems. Everything else follows from that.
- sbt567 2y agoNice writeup. I'm wondering though. If the block is on DNS level, isn't it easier and cheaper to use dns-over-https or dot instead?
- martheen 2y agoIf it's just DNS, yes. But more and more countries start using SNI filtering for blocking, which can be bypassed by locally running obfuscation tool, but at some point one can get annoyed enough and just use a VPN entirely.
- arcade79 2y agoThe tragedy here is that expectations differ. I would expect my laptop to use my local DNS server if the VPN is up. My local DNS server is the one I have on my home network. The rest of my traffic, I would expect to go through the VPN tunnel. Problem of course is that VPNs used to be expert-level stuff. This kind of "avoid government blocks" use of VPN wasn't even common when I started fiddling with OpenVPN around 2001/2002.
- BSDobelix 2y ago>I would expect my laptop to use my local DNS server if the VPN is up No, a correct configured VPN-tunnel is tunneling all data from one point to another (zero exceptions) if vpn is de-connected no data should be transferred (aka interface down). If you want something else work with per-application proxy's. >Problem of course is that VPNs used to be expert-level stuff. And it still should be that way, VPN's where made so you can securely work inside your enterprise/home network while sitting anywhere in the world, all services are provided from local servers and if external, go through the enterprise-firewall (traffic-audit, IDS, and maybe other VPN-tunnels to other external locations subnet's etc).
- mmsc 2y ago>Your exceptions are wrong, a correct configured VPN-tunnel is tunneling all data from one point to another (zero exceptions) if vpn is de-connected no data should be transferred (aka interface down). >VPN's where made so you can securely work inside your enterprise network Discord.com is not your enterprise network.
- BSDobelix 2y agoYourLocation VPN-> EnterpriseFirewall/VPN-Gateway Lan-> LocalNetwork(DNS,NTP,SMB/NFS etc) Lan-> EnterpriseFirewall HTTPS-> Discord.com Ok?
- mmsc 2y ago>EnterpriseFirewall/VPN-Gateway Lan-> LocalNetwork(DNS,NTP,SMB/NFS etc) Lan-> EnterpriseFirewall HTTPS This does not seem to agree what you previously said: "VPN's where made so you can securely work inside your enterprise network" If you're connecting to the internet, route to the internet. If you're connecting to "inside your enterprise network", route through the VPN. >EnterpriseFirewall HTTPS If you're talking about forced https interception, then it sounds like an excellent way to make something secure (https) insecure.
- botto 2y agoClickbait title, author didn't use a VPN provider, used own OpenVPN solution and didn't configure things correctly.
- deleted 2y ago[deleted]
- mmsc 2y agoClicking the link, it bought this was going to be about the issue identified in Mullvad discussed here; https://news.ycombinator.com/item?id=41856883 https://news.ycombinator.com/item?id=41856883 but this isn't even a bug or about trust. A VPN (in this context) is hardly a VPN if it doesn't traffic dns requests, and it's probably the false advertising by the "you need a vpn to securely access the internet" companies that misinformed OP what type of VPN they were setting up. The title should be more like "can't trust not reading the manual these days", or "can't trust sane defaults"
- thelastparadise 2y agoYou can trust it if you configure it correctly.
- WmWsjA6B29B4nfk 2y agoWhat if the the author simply used 1.1.1.1 / 8.8.8.8 / any other public DNS outside of their country for all traffic? It's an easier solution (yeah, with some drawbacks)
- ndheebebe 2y agoThey tried that. I guess it didnt stop the leak.
- mmsc 2y agoIt would be intercepted at the ISP level and the false results would still be received. There are lots of DNS intercepting tools ISPs buy these days. DNS isn't authenticated.
- WmWsjA6B29B4nfk 2y agoI understood they have been simply accessing their ISPs DNS through the tunnel.
- mmsc 2y agoNo: >Okay, at that point I was clueless. I tried changing the DNS settings of OpenVPN (i.e. dhcp-option DNS 1.1.1.1) but it didn't work. After a couple of iterations with ChatGPT, it finally led me to the correct path.
- WmWsjA6B29B4nfk 2y agoThis line was no-op until the author started using the `up` script as they describe later. > The OpenVPN server can push DHCP options such as DNS and WINS server addresses to clients (some caveats to be aware of). Windows clients can accept pushed DHCP options natively, while non-Windows clients can accept them by using a client-side up script which parses the foreign_option_n environmental variable list. It's still not clear to me what the experience would have been if the author had only 1.1.1.1 set at the system level, not touching any OpenVPN options.
- deleted 2y ago[deleted]
- deleted 2y ago[deleted]
- Jnr 2y agoMaybe a bit off-topic, but genuine curiosity - why would anyone go for OpenVPN these days, when there is Wireguard available? It makes sense if UDP is blocked, but in this case OP is clearly using UDP for OpenVPN.
- mr_mitm 2y agoUnrelated to OP's story, but besides tunneling traffic over TCP or even an HTTP proxy (which OpenVPN supports OOTB): plain Wireguard doesn't support 2FA, which is a requirement in some places. Unless there is an open source 2FA VPN solution built on Wireguard that I haven't heard about yet, in which case I'm interested.
- dongcarl 2y agoI believe Tailscale has 2FA? Headscale is an open source implementation: https://github.com/juanfont/headscale https://github.com/juanfont/headscale
- wruza 2y agoIs there a oneliner for setting it up on a ubuntu box akin to https://github.com/angristan/openvpn-install https://github.com/angristan/openvpn-install ? How does it work with iphone, android, windows? Can a regular person set up a client by receiving a single profile file? Idk about wg, but ovpn ticks all these boxes.
- mr_mitm 2y agoThere is this by the same author: https://github.com/angristan/wireguard-install https://github.com/angristan/wireguard-install Mobile users simply scan a QR code and are good to go.
- wruza 2y agoThank you very much, I’ll try it soon! My relative has an android device that can’t run ovpn but may work with this.
- nofunsir 2y agobog-standard ssh server + bitvise local client = VPN 1) enable port forwarding in your sshd config (implies you can't just do this on a server which you don't admin and which has this disabled) 2) point bitvise's socks5 proxy server feature at the ssh server 3) point anything that needs to be tunneled at the bitvise client's port (default 1080) e.g. firefox > about:preferences > Network Settings (at bottom) > Manual proxy configuration > SOCKS v5 (enter details and your password if you set it up in bitvise) > also check "Proxy DNS when using SOCKS v5" at bottom 4) voila, packets leave and return via the ssh server's public IP. 5) For stubborn apps, check their config files, or use tsocks
- yaris 2y agoWhile there is some useful info in the post, the title is hugely misleading. The author tried one (single) VPN solution which they set up themselves, without full understanding of the things or even reading documentation upfront (although "it's right there under the DNS section"). It feels more like "I was unable to correctly setup VPN even using the very detailed instructions, but I can't blame myself, can I?"
- Hikikomori 2y agoAlso not a privacy focused vpn that requires extra steps to be so.
- wruza 2y agoHas nothing to do with VPN or OpenVPN (almost). “You can’t trust” “Linux” in this case. Its network stack is still not mouse-friendly in general and requires some thought. Quoting key points from TFA: - (DNS leak happens) - The DNS changes are not automatically applied by the OpenVPN client on Linux. - You need to configure up and down scripts for managing the DNS updates. - The recommended script is update-resolv-conf, which modifies DNS settings when the VPN connects and restores them upon disconnection. - That script consists of a bunch of arcane bash commands that I don't understand. Iow, OpenVPN decided to not mess with system scripting. For Linux, the OpenVPN client can receive DNS host information from the server, but the client expects an external command to act on this information. No such commands are configured by default. They must be specified with the up and down options. There are a few alternatives for what scripts to use, but none are officially recognised by OpenVPN, so in order for any of them to work, script-security must be set to 2. The down-root plugin can be used instead of the down option if running as an unprivileged user. Otoh, it could at least signal that somehow in the ui/cli. Does it not? I’m pretty sure there’s no dns leaks on my kubuntu boxes with ovpn profiles, but can’t test right now. If so, it’s probably an even narrower Arch + network manager problem.
- vetinari 2y agoThis is something I always wondered about: why so many linux users always take the hard way? They have two options: a) use the mouse-friendly way in NetworkManager to configure their VPN client (yes, it handles VPN DNS too; if you have systemd-resolved, it can also do split-horizon DNS over specific links) or b) funble around with tools and scripts they have no idea how they work, complain how complicated it is, and either get lucky so it works somehow or break their system entirely. With a current desktop linux system, they should take the option a). They can use command line if they insist, nmcli is also here.
- udev4096 2y agoExtremely misleading and vague title. Also, the author should seriously consider using wireguard. It's way faster than OpenVPN
- ritcgab 2y agoJust use wireguard.
- deleted 2y ago[deleted]