5 ms·
Or you could pay an additional $5/month for a decent VPN. In fact, I have a number of close contacts who work in the industry who tell me that this type of prac
by kenthorvath 12y ago
Or you could pay an additional $5/month for a decent VPN. In fact, I have a number of close contacts who work in the industry who tell me that this type of practice is of heavy interest and routine on the wireless end of things. Companies are tracking not just your browsing habits but your location data based on cell tower triangulation.
This is why we need to decentralize the ISPs and move to local mesh networks.
- digitalengineer 12y agoPersonal (non-company) VPN still doens't fully work on smartphones. It needs to be manually activated each time, making 'all-traffic-behind-vpn' impossible for now. It is possible for coporate VPN's so we know iPhones can do it. A choice by Apple HQ?
- computer 12y agoDo it on your router, so that all devices that connect over wifi are automatically router through your VPN.
- lazerwalker 12y agoI don't know how they're accomplishing it technically, but http://getcloak.com http://getcloak.com manages to auto-enable my VPN on my iPhone every time I connect to a non-whitelisted wireless network.
- autodidakto 12y agoiOS 7 opened up some APIs for it. GetCloak's app uses it (and has a lot more niceties, I read), and so does the ugly but generic OpenVPN app. I'm guesses that they're not able to block all traffic before the VPN is set up though. I'm not sure. And I'm certain the OpenVPN app doesn't fail safe/closed. Anyone know of a portable, travel wifi router that supports VPN and fails closed?
- jeff_tyrrill 12y agoI'm a Cloak user. Connect on Demand in iOS has a great design, but unfortunately it's buggy. About once a week, I will catch it not using the VPN (and not blocking traffic nor trying to reconnect). I even connected my iPhone to Apple's desktop utility that allows reading the device logs and I correlated the behavior to certain log errors. This problem started in iOS 7.0 and remains up to 7.1.1 (iOS 6 was fine). As a result of this bugginess, I'm no longer willing to use untrusted wi-fi networks even with VPN. It's really too bad that Apple is not fixing this, because it renders the Connect on Demand feature useless from a security point of view, and it nullifies the functionality of Cloak. Cloak is otherwise an awesome app and service, and it's not their fault as they can't control this code.
- nodata 12y agoI just checked my phone, and Android 4.4.2 supports always-on VPN.
- redsparrow 12y agoAndroid added always-on VPN in 4.2.
- ingenium 12y agoWorks fine for me with OpenVPN on Android (4.4.2 on a Galaxy S4 and Nexus 7). It will only prompt to accept the VPN the first time it's run. If you leave it running in the background it will re-establish the connection whenever it needs to. That being said, I also have an Xposed module to get rid of the confirmation prompt entirely (I use Tasker to enable the VPN automatically when my phone connects to unsecured wifi networks). I can't speak to how Apple does it, so maybe it's just an OpenVPN vs IPsec thing. If you setup your own IPsec VPN you could possibly have it activated automatically. There was a post on HN a few months ago with a script to basically setup an IPsec VPN automatically for you.
- r1ch 12y agoYou'd probably end up paying a lot more than $5/mo for a VPN that is actually able to keep up with gigabit internet speeds and downloading habits.
- Fuxy 12y agoYou know your ISP is crap when you have to pay another ISP(VPN) to keep your connection secure and private.
- kenthorvath 12y agoYes. We can generally all agree that ISPs in the United States are effectively monopolists with no incentive to do what's right for their customers. Now, let's talk solutions.
- logfromblammo 12y agoEveryone run some fiber to your nearest neighbor in each of the 4 cardinal directions. Go to MIT, find one or more of the kids that already figured out to make all that work, and read their theses. Launch an open-source project for the required network hardware and its firmware, and manage to sell as many as you can produce at $30 each. My pipe dreams are about a series of tubes.
- justizin 12y agothis is how all networks work. there are no special MIT theses. get an ASN and use BGP. Fiber hardware at $30 each is probably not happening, since we barely get ethernet hardware in that price range, and certainly not of any quality.
- logfromblammo 12y agoI was actually referring to the [implied] part where the person installing it doesn't need to know anything other than how to plug everything in. You're not going to get a usable network out of this if it requires the people using it to know anything at all about their hardware, or if they have to get their own identifying numbers from ICANN. It really needs to be something where they plug in a box and hot and cold running Internet comes out when they open the faucets. And if you thought disruptions were bad when some country "misconfigures" their BGP to route the entire Internet through their spy agency's offices for 15 minutes, wait until a thousand Joe Bagadonuts are doing it truly accidentally, all the time.
- jessaustin 12y agoOr you could pay an additional $5/month for a decent VPN. TIL another reason why Ma Bell doesn't like neutrality. If they get their way we can expect performance on unobfuscated VPNs to suffer.
- mnw21cam 12y agoITYM obfuscated?
- jessaustin 12y agoA standard VPN doesn't try to hide, and will look like a VPN to the ISP: all packets contain encrypted material, destination doesn't vary, etc. This is what I mean by "unobfuscated", and this would be easy for an ISP to throttle. One can imagine ways to tunnel VPN traffic over ISP-approved traffic, but that arrangement might have other drawbacks.
- mnw21cam 12y agoOkay, sorry, thought you meant unobfuscated as in unencrypted. Yes, you could tunnel VPN traffic over an HTTPS connection. I have built VPNs using ppp over ssh tunnelling before, and that works fine.
- jessaustin 12y agoNo worries! Actually I wonder if just tunneling over TLS would be enough if the ISP were determined. I mean, after they see me pushing and pulling GBs from the same host for an hour, they might just GET it themselves. If they see a "how to configure your VPN" page, that address could go on a slow-list.
- wlesieutre 12y agoPutting it over HTTPS won't necessarily stop them. The caveat mentioned in the article is that they won't track your HTTPS web browsing. But they can still slow it to a crawl if they don't like you doing it.
- spacefight 12y agoI don't get why people are pushing folks towards VPN. If you use one, you shift your endpoint from Provider A to Provider B. And you have absolutely no guarantee ever, that the upstream link of provider B or that provider B itself (accounting, user association etc etc) is not rigged... True, a VPN in hostile environments might be a good idea. If the termination endpoint is secure, is another question.
- mbreese 12y agoI think it has more to do with the network peering arrangements of the VPN host more than privacy. At least that would be the benefit from my point of view. If my ISP has a poor path to (for example) Netflix, but my VPN provider has a good (unsaturated) path, it could be advantageous. But this requires my ISP to have a good connection to my VPN provider.
- johnpowell 12y agoI have a Plex server in Canada with OVH and on my local connection it worked fine for years to stream movies and TV. Even 1080p stuff worked fine. Then it appears that CenturyLink started shaping port 32400. So I got a 5 dollar droplet on Digital Ocean (SF) and now use that for a VPN. Plex works fine. I can switch the VPN on and off and it makes a huge difference. Without the VPN it is constant buffering.
- Havoc 12y agoI had a discussion about this with one of the guys from PIA VPN...you can pay via bitcoin and the info required for sign-up is kinda uhm spartan. No chance of pushing any serious traffic through a VPN though unless you control it. Unfortunately, in my case a VPN would probably put me on weaker legal ground. My ISP is not legally entitled to monitor my traffic...once it hits the VPN provider the local laws apply & I can do without US laws on the privacy front.
- BryanB55 12y agoDoes anyone have any recommendations on a VPN that can keep up with gigabit speeds?
- blueskin_ 12y agoAll sorts of VPS providers to choose from; main issue is that most 'budget' plans will be 100mbit.