10 ms·
Don't Get Pwned on Public WiFi: Use Your Own VPN
- molecule 13y agosubscribing to a VPN provider is typically easier, cheaper and provides more options than rolling your own on EC2 http://netforbeginners.about.com/od/readerpicks/tp/The-Best-VPN-Service-Providers.htm http://netforbeginners.about.com/od/readerpicks/tp/The-Best-...
- bensedat 13y agoDefinitely true that cheaper is definitely possible, but a DigitalOcean droplet or an EC2 micro can be pretty cheap and you don't have to worry about the other VPN clients as much.
- joelhaasnoot 13y agoIt is hell though - recently setup this on a droplet, but getting all the settings right and diagnosed on Ubuntu and some Ubuntu and Android clients was complicated. It never seems to work the first time...
- spindritf 13y agoL2TP/IPsec is hell. OpenVPN is not more difficult to set up than a web server. Of course, you need L2TP if you want to use the built-in clients on Android, IPhone, Windows...
- CedarMadness 13y agoBack in the 2.3 days, Android had OpenVPN support (or maybe it was just a CyanogenMod feature). I wish that would come back.
- dschep 13y agoIt was (and still is, IIRC) a CM feature.
- bensedat 13y agoYeah, mobile support was a bit tricky to set up for us as well, but we managed it with just OpenVPN. The OpenVPN app for iPhone at least was able to be configured without too much headache, although it only supports a subset of the OpenVPN options. It should be compatible with the config in the article.
- joelhaasnoot 13y agoFor Android, there's an OpenVPN app too - it uses the very handy and neat Android VPN API and besides needing certificates in the right format (not the text versions), it works well.
- joelhaasnoot 13y agoTrue, that was my first try, and it failed miserably.
- chewable 13y agoI install something called OpenVPN-AS on a DigitalOcean droplet and it works like a charm...the first time out. Here are step-by-step instructions: https://www.digitalocean.com/community/articles/how-to-install-openvpn-access-server-on-ubuntu-12-04 https://www.digitalocean.com/community/articles/how-to-insta....
- krallin 13y agoOr you can just dynamically launch an EC2 instance just when you need a VPN : )
- jessaustin 13y agoCan you do that securely without the VPN? b^)
- fantnn 13y agowith something like puppet, yeah
- alexchamberlain 13y agoHow does it provide more options?
- michaelt 13y agoIf you don't trust a public wifi hotspot with your cleartext traffic because of passive snooping, why would you trust a VPN provider with your cleartext traffic? A lot of these torrent-anonymously consumer VPN services look pretty dodgy.
- agwa 13y agoUse a non-dodgy VPN service, such as https://www.privatetunnel.com/ https://www.privatetunnel.com/ (run by the OpenVPN people) or https://privacy.cryptoseal.com/ https://privacy.cryptoseal.com/ (run by HN's rdl). You may be trusting them with your cleartext traffic, but that's really no different than trusting e.g. Comcast with your cleartext traffic when you're at home.
- Scramblejams 13y agoGood writeup, but why does this piece recommend running the VPN over TCP? Tunneling TCP over TCP, which will be the end result, is known to provide terrible performance in the presence of even minor packet loss.
- bensedat 13y agoGood point! I made the change when using the VPN at DefCon but haven't updated the post. I'll do that now.
- Scramblejams 13y agoCool. I was looking around a few weeks ago for a good howto on setting up an OpenVPN server, but didn't find anything straightforward enough for the time constraints I was under. Thanks for writing this up, it'll come in handy for me.
- Wilya 13y agoI've seen many networks blocking udp entirely. An openvpn on a HTTP tcp port (article says 80, I would say 443 is better) is much less likely to be blocked (openvpn also knows how to go through an HTTP proxy).
- agwa 13y agoRun two instances of OpenVPN - one TCP, one UDP. Always try the UDP one first. I've done performance comparisons and the difference is striking.
- scotty79 13y agoI wonder why this is so convoluted. NAT used to be like that but since long time it's just `apt-get install ipmasq`
- chrismonsanto 13y agoI use a VPN for much of my private traffic. Here is where I differ from the article's recommendations, and why: - I don't recommend rolling your own on EC2: pick a VPN with a good reputation and a policy of not retaining logs. See: http://torrentfreak.com/vpn-services-that-take-your-anonymity-seriously-2013-edition-130302/ http://torrentfreak.com/vpn-services-that-take-your-anonymit... (you don't have to use torrents to need a VPN, btw!!) - I recommend using a Debian VM w/ OpenVPN for your private traffic. That way, 'am I using my VM?' is a quick test for whether your traffic is private or public. - I can't stress this enough: _be sure to firewall your VM from any traffic not to your VPN provider_. If OpenVPN drops its connection, it will fallback to sending packets normally! At least if you firewall, your connection will just die, instead of potentially sending private traffic in the clear. The article doesn't mention this, and it should. - Be sure not to log in to your usual services on your VPN, or there is a possibility that someone can connect your real traffic and your VPN traffic. I use LastPass with random passwords to manage all of my accounts, so I solve this problem by simply not installing LastPass on my VM, which makes logging in a very deliberate action on my VM.
- IvyMike 13y agoI agree with the "don't roll your own" VPN suggestion--I personally signed up with Private Internet Access and haven't looked back since. But I have a question about this: "be sure to firewall your VM from any traffic not to your VPN provider." Is there a good generic way to do this on Windows? I've looked around and it's never very clear. I think the PIA client has a "VPN kill switch" that should effectively do the same thing, but not all VPN providers have a client.
- chrismonsanto 13y agoIf you are using a VM like I suggested, you can do this inside the VM instead of messing around with Windows. See this post: https://news.ycombinator.com/item?id=6285837 https://news.ycombinator.com/item?id=6285837 Unfortunately I don't use Windows, so I don't know how to firewall from it.
- 13y ago
- slig 13y agoAnyone have experience setting up a VPN on a Raspberry Pi? I'm guessing that it would cost less than $5/month on energy and I have one sitting on a drawer. Also, I don't live in the US and proxying all my data through the US and back would introduce unwanted lag.
- alexchamberlain 13y agoGrab a Kimsurfi dedicated machine in France! Only £3 a month.
- slig 13y agoWell, I'm not in Europe and VPNs/Dedicated servers in my country are tad expensive.
- vetinari 13y agoI'm running my VPN (Strongswan) on a home/soho router (Netgear WNDR3700 with Openwrt). So using Raspberry Pi is definitely an option.
- bluedino 13y agoGoing from your cable/DSL ISP to your house and then back to the ISP adds quite a bit of lag as well, compared to a server sitting in a DC somewhere. I've made a beefy VM or even used a spare server at the office on a 100/10mb pipe and a $5 VPS is much more responsive. Especially noticeable with things like an IRC shell.
- ja27 13y agoI'm VPNed into a Raspberry Pi back at my house right now. Works fine. I just followed a tutorial or two but if I remember correctly, it wasn't much more than "apt-get install openvpn" and a few configuration steps. It's actually running on my XBMC Pi that's already always on and connected to a TV.
- mhurron 13y agoYou know what would be great - The ability to do this automatically, especially on Android. I would love to see the ability to specify 'safe' or 'trusted' WiFi networks and if you connect to a network other than these, the VPN gets initialized and used. Setup on the phone is once and usage of the VPN happens automatically after that.
- mef 13y agoIf you run a Linode, they have similar instructions for each of their Linux images: https://library.linode.com/networking/openvpn/ubuntu-10.04-lucid https://library.linode.com/networking/openvpn/ubuntu-10.04-l...
- spindritf 13y agoIronically, Ghostery prevents the article from being displayed and there are nine trackers detected on that page.
- taf2 13y agoit's good information - did you think it was going to be free ;-)
- bensedat 13y agoOops, a lot of that looks to be coming from the article share links. Sorry!
- pokoleo 13y agoIronically, Ghostery is owned by Evidon who sells GhostRank data to businesses.
- pyrocat 13y agoCan you expand on this? I use Ghostery all the time. What exactly is being sold to businesses?
- pokoleo 13y agoThe wikipedia article[1] of Ghostery gives a quick & fast overview of what they do. MIT Technology review posted[2]: > Evidon sells two main services based on the data it collects. One allows website operators to see which tracking code, from which companies, is active on their site and how it affects the speed with which its pages load. The other provides ad companies with figures on how common the tracking code from different companies is around the Web. [1] https://en.wikipedia.org/wiki/Ghostery#History_and_use https://en.wikipedia.org/wiki/Ghostery#History_and_use [2] http://m.technologyreview.com/news/516156/a-popular-ad-blocker-also-helps-the-ad-industry/ http://m.technologyreview.com/news/516156/a-popular-ad-block...
- fixanoid 13y ago
- dotBen 13y agoFor this audience, one would assume this isn't anything new. The next level of 'detail'/risk to consider here is the fact that so many apps, and even browsers, will bind to the "on connection" event of connecting to a wifi hotspot - before you can initiate your VPN your twitter client* has already sent your authenticated token over the wire, etc. I've tried to hack something together with iptables but that doesn't work either in airports/etc where there are splash screens to negotiate, etc. ( = yes, you could use a better client, but then the reason we need VPNs in the first place is that so many apps and sites don't use https)
- mitchty 13y agoA lame workaround would be to close all apps prior to putting your laptop to sleep, then engaging the vpn and only afterwards restarting the apps. Shouldn't be too big of a deal now that tabs/sessions are mostly saved in chrome/firefox no? And well not like losing your twitter credentials is a big deal anyway. (i'm not a huge twitter fan btw :D)
- michaelwww 13y agoSomebody could probably sell me a solution that does all this automatically without distracting me from I'm supposed to be thinking about.
- theandrewbailey 13y agoI like to use an SSH SOCKS proxy to my home server. It didn't seem to be as much work to set up as this.
- ef4 13y agoIf you're planning to run a VPN server on Amazon EC2, be forewarned that lots of sites are going to block you. For example, Yelp, Craigslist, the StackOverflow family, Hulu, and Bank of America.
- skrebbel 13y agoAny idea why they do that?
- jlgreco 13y agoI heard before that stackoverflow does it because of scrapers, or something like that.
- jacquesm 13y agoAnti-bot / anti-griefer measures.
- borski 13y agoBecause often, EC2 is used by spammers, botnets, and the like. Turns out when you make starting a box really simple, evildoers will use your service as well. Craigslist & Co. dislike EC2 in general, for that reason.
- ef4 13y agoIn the case of things like Hulu, it's an attempt to enforce their geographic boundaries (so that Europeans don't buy cheap EC2 instances to watch America-only licensed content). I assume most of the others are trying to block scrapers that copy all their content and republish it.
- post_break 13y agoThe easiest defense against a pineapple is to create a wifi network titled "Pineapple Connected ALERT ALERT" or something similar to that. No security, no keys, and set it to your highest priority of networks to connect to if you have automatic joining enabled. As someone who has used these lovely devices to prank others it's a good idea to do so.
- dotBen 13y agoI'm confused, does the Pineapple device create an additional SSID called this? Sorry, not familiar with the devices.
- post_break 13y agoYour computer asks "Hey is ____ SSID available?" and pineapple says "Yep! That's me!" Now your computer connects to the pineapple. Well if you set the "Pineapple detected" SSID in your computer as the top priority, you'll connect to that when the pineapple is around. You're just putting in a dummy network on your computer to warn you that you've just joined the network f*&%ville, and you're not the mayor.
- dotBen 13y agoOh I see. So anyone running a pineapple should alter the code not to respond to any SSID client probe containing the string "pineapple" and just wait for the next probe, and latch on to that as that will result in the MITM'ing of a high-value target.
- borski 13y agoThis is brilliant. We'll start recommending this, I think.
- post_break 13y agoNo problem, it's a hell of a lot easier (and safer) than trying to run a VPN through one of these things. I'm not saying a VPN is pointless, but think of how many services on your computer connect before you can hit that VPN button.
- mapgrep 13y agoDoes anyone know why this is better than a simple SOCKS proxy, which can be set up with one SSH command to your VPS and a quick visit to your system settings? I use sheepsafe to pull these up automatically when I'm away from a trusted network https://github.com/nicksieger/sheepsafe https://github.com/nicksieger/sheepsafe
- bensedat 13y agoThis answer possibly explains some of the differences between the two: http://superuser.com/a/423615 http://superuser.com/a/423615
- mapgrep 13y agoAh thanks. The TLDR seems to be "VPN can handle UDP and other non TCP connections, e.g. for YouTube".
- dschep 13y agoSimpler, more vpn-like solution can be done via Sshuttle[0] or (albeit less simple afaict) with `ssh -w local_tun[:remote_tun]` [0] https://github.com/apenwarr/sshuttle https://github.com/apenwarr/sshuttle
- bluedino 13y agoYour apps have to support SOCKS proxies for one.
- beagle3 13y agoMuch more practical on Linux/OSX: https://github.com/apenwarr/sshuttle https://github.com/apenwarr/sshuttle No root/admin privileges required on your "VPN server" - just the ability to ssh. It solves the tcp-over-tcp issue. It just works. It only does TCP (with a specific hack for DNS, but no general UDP or IP). But it works exceptionally well, and just needs an sshable account on the server.
- nly 13y agoThe article doesn't mention IPv6 where things can be a bit more tricky. The Android clients don't let you use TAP (layer 2 tunneling), so if you're going to be accessing your VPN from an Android device you'll have to configure IPv6 NAT, or hack around with scripts to add IPv6 addresses dynamically.
- archagon 13y agoIf you're too cheap to shell out money for a VPN, proXPN has a limited free tier. I've been using it for banking while travelling and it works great!
- newman314 13y agoI'm still looking for a good config for a raccoon roadwarrior config to a VM behind dd-wrt (as dd-wrt does not come with IPSec support). Amazingly, there is very little information about this despite what would seem to be a pretty common desired config. Or maybe my google-fu just sucks. At this point, I can get a tunnel established but it fails to correctly route after the tunnel is set up. Frustrating.
- smtddr 13y agohttps://github.com/apenwarr/sshuttle https://github.com/apenwarr/sshuttle Easy solution and system-wide, if your OS supports it and you can ssh to a trusted server. My personal plan-B tool when a simple ssh -D and firefox's socks-proxy isn't enough. (BTW, why doesn't Chrome have socks-proxy like Firefox yet?)
- ihaveaq 13y agoI have a Chromebook (whose security is limited to HTTPs Everywhere, which doesn't lock much at all). How do I set up a VPN for it?
- bensedat 13y agoLooks like Chromebooks may support it right out of the box: https://support.google.com/chromeos/answer/1282338 https://support.google.com/chromeos/answer/1282338
- thomc 13y agoBut their OpenVPN support is awful and limited, unless you enable developer mode and set it up manually. Prevents Chromebooks from using VPN in our office.
- rmrfrmrf 13y agoIf you have a decent internet connection at home with reliable uptime, you can also just set up a VPN at home and connect that way. My router comes with OpenVPN on it, so I don't even need to have extra hardware running.
- davepeck 13y agoHi folks. I'm one of the three guys who runs Cloak (https://www.getcloak.com/ https://www.getcloak.com/). Cloak is a super simple VPN where both the back-end service and front-end apps are tightly integrated. (We think of it as the "Dropbox of VPNs" in the sense that, like Dropbox, it's so easy to use.) Basically, it's the VPN service+applications I wanted for myself when I started looking around and couldn't find anything (1) easy enough and (2) non-sketchy. Right now Cloak supports OS X (10.7+) and iOS (6+). We've been around for a while and I know there are a number of happy customers here on HN. In any case, please let me know if you have any questions, and please do give it a spin. Cheers! (EDIT for clarity, and because X of Y descriptions are not always loved.)
- computer 13y agoThe "Dropbox of VPNs"? What does that even mean?
- davepeck 13y agoWe think Dropbox is great because it's so easy to use and "just works". We designed Cloak with that thought in mind.
- chrischen 13y agoWhile Dropbox is simple to use, it's hardly the first thing that comes to mind when you make a comparison to Dropbox. I'd change that phrase because it's very confusing.
- deleted 13y ago[deleted]
- newman314 13y agoI see that Cloak uses racoon under the hood for iOS in what I assume to be a roadwarrior config. Do you mind sharing an appropriately scrubbed config so that I can compare to see what I'm doing wrong in my setup? There seems to be a dearth of viable configs out there and this would be immensely helpful. Thanks in advance. FWIW, this is what I have so far. http://superuser.com/questions/553193/how-do-i-configure-dd-wrt-to-forward-ipsec-traffic-to-an-internal-server-to-supp http://superuser.com/questions/553193/how-do-i-configure-dd-...
- Nux 13y agoI too use (open)vpn for 99% of my traffic because terrorism etc. I can't recommend it enough, the damn thing is super stable and secure, works via NAT via NAT via NAT etc and super flexible (push routes, push dns, proxy and other settings), works in routed mode, bridged mode and so on. I recommend you get a server or a VPS somewhere "nearby" and install openvpn software on that. I can't trust VPN providers that they do not monitor or log my traffic and neither should you.
- gurbelmann 13y agoOf course, you have a problem when the owner of the wifi explicitly prevents anonymisation services. For example, when I was at Birmingham airport, I couldn't connect to my VPN because they blocked domains of well-known VPN providers and even hijacked all my DNS requests so I couldn't circumvent so easily it. I guess running your own local DNS server which has your typical requests cached would solve this problem though.
- borski 13y agoWell, if you're running your own on, say, an EC2 or Rackspace or DigitalOcean droplet, they likely won't have it blocked.
- Wicher 13y agoI like Tinc VPN (http://www.tinc-vpn.org/ http://www.tinc-vpn.org/). It's multiplatform and open source, just as OpenVPN is, but I prefer it for its simplicity and its mesh feature. It doesn't try to do too much (which means you'll have to set up routes yourself). See http://www.tinc-vpn.org/documentation-1.1/tinc_4.html#How-connections-work http://www.tinc-vpn.org/documentation-1.1/tinc_4.html#How-co... to get an idea of the mesh feature.
- car54whereareu 13y agoOnce your vpn is established do you post to HN, inject SQL, download torrents, or is there something else exciting to do? I'm not in a fraternity (or sorority) so that's out.
- chakalakasp 13y agoBTW, for what it's worth, the (very inexpensive) Synology NAS models out there will all act as an openvpn server. It requires a hit of tweaking to get it to work they way you'd expect, but it's nothing beyond what the typical reader here can do.
- holri 13y agoI am using a NoMachine NX remote session to a my server through ssh for this purpose.