5 ms·
If you’re worried about your VPN provider but you can trust your VPS provider, try an SSH Tunnel. https://joeldare.com/ssh-tunnels-my-vpn-alternative-for-priva
by codazoda 1y ago
If you’re worried about your VPN provider but you can trust your VPS provider, try an SSH Tunnel.
https://joeldare.com/ssh-tunnels-my-vpn-alternative-for-privacy-on-the-go https://joeldare.com/ssh-tunnels-my-vpn-alternative-for-priv...
- Theodores 1y agoThanks for the link. How does this work on the server side? It gets packets on 8080 and then what? The article needs to explain the server config, even if it is just how to install ssh-server. I have tried setting up OpenVPN on my own VPS and I didn't get very far with it. I have also had to use OpenVPN in the day job and I much prefer just using ssh without some extravagant OpenVPN layer. My experience of failing to configure a VPN of my own (primarily for testing GeoIP) led me to try a few VPNs and the amount of junk adverts and whatnot made me wonder if it was time to fdisk my computer and start over due to the virus-vibes I was getting from a VPN. This was in the days before VPN adverts on lame YouTube channels, so I presume the product has improved since then. In theory, someone smarter than me can rent a VPS and get OpenVPN on there, or, better still, a remote desktop so that only the screen image goes over the internet from the VPS to the PC, X-Window style but better. This could be further obfuscated by using 443 and one's own special ROT13 'encryption'. Presumably a skilled person that knows what they are doing could get it all setup in an hour, to write concise instructions that 'civilians' can work through in pretty much the same time. If you were highly invested in porn, watching Netflix in foreign countries and with even worse stuff to hide, you would think that some investment in getting a proper VPN with your own VPS would be the way to go, but no. Cost isn't the problem if you are deeply into something worth hiding, so why do so few people roll their own VPN? The reality is that the typical product is marketed with FUD and the goal is to turn you into a 'sleeping giant'. A 'sleeping giant' is a customer that has a standing order or other payment arrangement that is for a service that is not used, and for that to not be noticed on bank statements. Everyone wants you to be a 'sleeping giant', including some 'worthy' charities, dating websites and every software subscription service. They aren't using FUD marketing though. The commercial VPNs have mastered the art of selling a product that deserves technical knowledge to understand to the masses, so you have got to respect the hustle.
- londons_explore 1y agoVPS's that you can easily spin up for an hour or two tend to charge $$$$ for egress bandwidth, which makes them an unattractive option for streaming video over.
- flexagoon 1y agoThere are very simple options to selfhost a VPN nowadays. For example, Amnezia allows you to just type your server ssh credentials into their mobile app, and it will automatically set up AmneziaWG on your server and add it to the app. You can then create Amnezia or plain WireGuard config files from extra devices right from there.
- harvey9 1y agoThat sounds like I'm putting a lot of trust in an app. Also giving it control over my server, which I guess is not a big deal if the server is a disposable VPS
- flexagoon 1y agoIt's all open source though, so you can verify the scripts it's using, which are all here https://github.com/amnezia-vpn/amnezia-client/tree/dev/client/server_scripts https://github.com/amnezia-vpn/amnezia-client/tree/dev/clien... But even without that, there are solutions like wg-easy that let you spin up a WireGuard server with a single Docker container
- sciencejerk 1y agoI too recently tried to set up OpenVPN on a VPS and it was a huge pain in the @ss, even while following a (very long) tutorial. If I figure out an easier way to do this I'll message you in this thread
- CaptainOfCoit 1y agoOpenVPN is just really complicated, which makes sense because of the context and history. But even me who've done plenty of OpenVPN setups through the years, found Wireguard a lot simpler and easier to both learn and use effectively. So if you haven't tried Wireguard, give it a go, the simplicity is pretty nice.
- idatum 1y agoThis is the way: SOCKS5 via SSH You do need some minimal technical understanding and some scripting. Pick any cloud provider that can give you a VM with SSH access. Read up on doing this on your local device or another device on your LAN: ssh -NT -g -D 10001 -o UserKnownHostsFile=/dev/null -o ConnectTimeout=5 -i your_ssh_private_key your_cloud_login@any_cloud_provider_ip Change 10001 to whatever. Now read up on how your browser points to a SOCKS5 proxy. For Firefox, I create a separate profile. For chromium based, I use the command line. You are now virtually located to whatever region you chose for your VM. I mentioned some scripting. It's simple enough that I have a /bin/sh script to spin up the VM, set up the SSH SOCKS5 proxy, launch the browser, then spin the VM down when the browser exits.
- praveen9920 1y agoMajor issue I faced in this method is the network egress costs the cloud providers charge. I had to remind myself not to accidentally land on YouTube or some other video streaming sites. Are there any cloud providers who don’t charge for network egress?
- lxgr 1y agoMany! OVH has unmetered plans, for example.
- CaptainOfCoit 1y ago> Major issue I faced in this method Biggest issue regular user might find with this is that basically all the VPS host' IP ranges are known, and plenty of websites give you a different (worse) experience compared to when using residential addresses, or straight up block you. Personally I found the hassle to great, compared to using existing VPN services.
- giobox 1y agoExact same experience here. In the 2010s I ran my own VPN exit node on a dirt cheap VPS so I could access streaming content in my country of birth. Worked great for years, but nowadays so many sites simply block non-residential IP ranges that I gave up ages ago now. It's a shame because deploying WireGuard was a simple two command process: git checkout followed by a `docker compose up -d` for me etc on a fresh VPS instance.
- kmarc 1y agoThis, and FoxyProxy for domain-based proxy settings is my go to when connecting to some websites (self-hosted bit bucket/confluence, etc) behind Corp intranet boundaries.
- vaylian 1y agoVPS tunnels have their place, but they have one major downside: Your outward-facing IP address will (most likely) be static. And because you are the only one using that VPS, it is easy to link your internet activity across different sites. If you want to use this method to protect your privacy, then you need to frequently discard your VPS and pick a new one.
- commandersaki 1y agoI like to use dsvpn: https://github.com/jedisct1/dsvpn https://github.com/jedisct1/dsvpn Seems to have triggered the netsec community on reddit though.