6 ms·
The TOR browsing experience is terrible and unreliable. If you're really so concerned, just pony up for a VPN.
by kishor_gurtu 13y ago
The TOR browsing experience is terrible and unreliable. If you're really so concerned, just pony up for a VPN.
- lotsofcows 13y agoVPN? Owned by whom? Which company / country can you trust? This discussion is about security and privacy, not avoiding content restrictions.
- ckozlowski 13y agoA VPN is not the same. A VPN will protect from a MITM attack, obscuring the resources you're accessing and the data exchanged to an observer. However, it does not anonymize you from the VPN provider, who can still disclose your information or be compelled to provide it. (you undoubtedly had to pay for that VPN with a legal name and payment information.) Tor not only protects against MITM, but obscures the requester such that if an interested party can either force information from, or controls the endpoint, they cannot discover who the requester is.* (* Provided that the requester is not divulging information in the form of cookies or other personally identifying information. If Mozilla were serious about providing native Tor functionality in Firefox, they'd no doubt provide it as part of the browser "Private" mode.) Edit: This link doesn't cover VPNs, but gives a good idea of how different services provide security at different levels. VPNs obscure the "site.com" along the route, while the location in all locations as shown as the VPN provider, and not the end user. However, because the VPN provider knows the identity of the user, it can potentially disclose this info. A Tor endpoint does not know this. https://www.eff.org/pages/tor-and-https https://www.eff.org/pages/tor-and-https
- Sanddancer 13y agoNope. I can walk down to the local (or not local) seven-11/walgreens/etc and get a disposable credit card for use in paying for my vpn provider, and provide them that I am Jake Blues and live at 1060 West Addison St, Chicago, Il.
- ckozlowski 13y agoI agree. I should have listened to the little voice telling me to change "undoubtedly" to some other "likely, but not definitely" term. I'd be curious to know how often that works. Regardless, I suspect most don't do that.
- clarkm 13y agoBut credit card companies maintain records of time and place sold, so unless you travel to a foreign country to make your purchase, you're still leaking your location.
- deleted 13y ago[deleted]
- drakeandrews 13y agoThen your bank still gets the time and place, unless banks are significantly worse in the US than the rest of the world.
- Sanddancer 13y agoThey'll learn those cards were purchased from a Walgreens on Market Street in San Francisco three months ago. If the clerk even remembers, the purchaser said something about being dragged to SF for business, and how they really wish they were back in New York with their kids. In other words, less than nothing.
- CompulsiveCo 13y ago>(you undoubtedly had to pay for that VPN with a legal name and payment information.) I used Bytesized-Hosting, which allows you to pay for their VPS with bitcoins. I only had to provide a username, password, and a junk email address. AirVPN, among other VPN providers, also allow you to pay with Bitcoins, which can be anonymized over TOR for that particular transaction. I am not sure how much it helps protect the conifdentiality of the user, but many VPNs also claim to delete their OpenVPN logs immediately after a session has ceased. Though, I suppose if a three letter agency wanted dirt on someone, this policy would be easy enough to circumvent.
- ckozlowski 13y agoThat is possible, yes. Not many VPN services do that, but as Sanddancer pointed out, there are ways. However, for most, it's an inconvenience that presents a barrier to entry. (Judgements aside.) As for logs, it would be great to believe that they would be true to their word. However, that requires placing trust in the service provider. While I would give the benefit of the doubt in that most probably are true to their policy, I wouldn't want the weak link in my security chain to be the faith that my VPN provider isn't logging. Regardless, since they are hosting the connection, they can discern the user. The capability exists, even if they promise not to use it. Removing the capability eliminates this source of worry. Going back to the original post and kishor's comment, he/she highlights the point that regarding the technical solutions available, there's a range between having the most security solution, and the fastest and most convenient. Tor, VPN+anonymized payment and other methods will provide a greater degree of protection than say, using your credit card to simply buy a VPN. At the end of the day, one needs to assess their security requirements against the degree of inconvenience they're willing to endure. Are they at risk of a nation-state ruthlessly pursuing them by any means? If so, then every protection is needed. If it just needs to be made difficult enough to protect against a cursory inspection, then a VPN might suffice. As with all security discussions, The likelihood and potential impact of the threat determines the degree of mitigations one needs.
- fnordfnordfnord 13y agoahem... "Show me all VPN startups in country X, and give me the data so I can decrypt and discover the users. *~These events are easily browseable in XKEYSCORE"* http://www.extremetech.com/wp-content/uploads/2013/08/xkeyscore-vpn-640x487.jpg http://www.extremetech.com/wp-content/uploads/2013/08/xkeysc...