30 ms·
I sort of thought that https was sufficient for most things on unsecured connections, so a VPN wouldn't be necessary to prevent things like password sniffing. O
by TTPrograms 12y ago
I sort of thought that https was sufficient for most things on unsecured connections, so a VPN wouldn't be necessary to prevent things like password sniffing. Or is that wrong?
- teamhappy 12y agoAt home TLS is fine. If you're connected to a public wifi using a VPN on top of that is a good idea because you only have to trust one VPN provider (or your own server) instead of every hotel chain, coffeeshop, etc. > sufficient for most things on unsecured connections WPA2 + good TLS encryption (i.e., good cyphers) should be.
- mkinitcpio 12y agoAre you worried about parts of the TLS handshake being intercepted, or something? Because even then that's non-sensitive information like public keys and cipher lists and stuff, no? Or are we worried about side-channel attacks, or weak ciphers being chosen? Just curious about your reasoning for why TLS alone isn't sufficient.
- marcosdumay 12y agoHe's probably worried about those places looking at the sites he connects to, data sizes and other kinds of metadata. But also, there are plenty of sites around with broken TLS that can be intercepted by a man in the middle.
- stu_k 12y agoSpeaking of which, can anyone recommend a good VPN provider?
- TheOtherHobbes 12y agoTorrentFreak has a regular round-up of VPNs: http://torrentfreak.com/which-vpn-services-take-your-anonymity-seriously-2014-edition-140315/ http://torrentfreak.com/which-vpn-services-take-your-anonymi... The comments are probably as useful as the main content. Personally I use AirVPN. They're not expensive, the client is open source, and performance seems good enough for casual use. I'm not sure I'd trust any of the usual VPNs if I needed Snowden-level security. But I don't, so casual use is fine.
- teamhappy 12y agoI've used blackVPN and IPredator in the past. Running openvpn on your own box is pretty easy too (if you've ever set up something like a HTTPS server.)
- IvyMike 12y agoPIA has never done me wrong, it's cheap, they support a ton of VPN protocols and OSes, multiple simultaneous clients (up to 5?), and at least one of the guys who runs it is a HN regular. More in this thread: https://news.ycombinator.com/item?id=6345520 https://news.ycombinator.com/item?id=6345520 Not affiliated in any way, just a happy customer.
- breakall 12y agoRun your own for a few bucks a month! Here's a guide to setting OpenVPN up on an Ubuntu machine: https://www.digitalocean.com/community/tutorials/how-to-set-up-an-openvpn-server-on-ubuntu-14-04 https://www.digitalocean.com/community/tutorials/how-to-set-...
- Buge 12y agoYou often cannot control which sites use https.
- kaybe 12y agoThere are addons for this: https://www.eff.org/Https-everywhere https://www.eff.org/Https-everywhere
- TTPrograms 12y agoSo hypothetically if you didn't care about people sniffing your non-https traffic there's little to be gained from a VPN? Besides various metadata collection and DNS queries.
- Buge 12y agoLike they say it works for "many major websites". It only works if the servers of the site support https, but don't advertise it.