3 ms·
Tunnelbear[0] has Vigilant mode[1] that blocks all outgoing connections until you have connected to the VPN server. It was one of the main reasons to start usin
by foliveira 11y ago
Tunnelbear[0] has Vigilant mode[1] that blocks all outgoing connections until you have connected to the VPN server. It was one of the main reasons to start using it.
[0] https://www.tunnelbear.com https://www.tunnelbear.com
[1] https://www.tunnelbear.com/updates/vigilant/ https://www.tunnelbear.com/updates/vigilant/
- elithrar 11y agoSimilar to Cloak's (https://www.getcloak.com/ https://www.getcloak.com/) "OverCloak" feature that blocks all outgoing connections until the VPN connects. I use it religiously when traveling since airport WiFi is often a huge risk.
- metasean 11y agoI love Tunnelbear, but I assure you their vigilant mode is far from perfect. In particular, I take a train to and from work. When the network goes down, and it goes down several times every trip, sometimes Tunnelbear goes into vigilant mode, but it frequently doesn't - i.e. I can absolutely connect to sites from the open wifi while the Tunnelbear icon is spinning up a fresh connection but before it has fully secured the tunnel. My very convoluted solution has been to use my phone and PDAnet [1] for the actual connection, instead of the public train's wifi (they go down with similar frequency). When my phone connection goes down, it requires a hard reset (unlike the public train wifi). Before I actually initiate the hard reset, I use Pauser [2] to manually stop my main browser, then I open my secondary browser and verify I can connect to one of several different generic sites, while Tunnelbear is active. Once I know Tunnelbear is active, I'll un-pause my main browser and go back to work. In other words, (A) I avoid the public wifi, (B) I manually have to pause my main browser when I loose connection, (C) I have to ensure I'm not using me secondary browser for anything secure, and (D) I have to manually ensure Tunnelbear has fully secured my connection before restarting my main browser. I'm sure this still leaves me open to attack, but less so than not using this process. [1] http://pdanet.co/ http://pdanet.co/ [2] http://sdunster.com/project/pauser/ http://sdunster.com/project/pauser/
- tokenizerrr 11y agoI looked at PDANet and I don't realy understand... My Android phone (galaxy s6) can do all that by default under Settings->Tethering and Hotspot. I do live in Europe though and I've never heard about a "tether plan". Is that some American weirdness maybe?
- metasean 11y agoI wasn't aware that it was an American weirdness, but phone carriers here can, and mostly do, charge us to tether our phone to another device [1]. There is at least one legal exception, where consumers whose data is transmitted via the 700 MHz frequency band can not be charged for tethering [2] [1] https://en.wikipedia.org/wiki/Tethering#United_States_of_America https://en.wikipedia.org/wiki/Tethering#United_States_of_Ame... ; It looks like the U.K. has similar tethering charges [2] https://en.wikipedia.org/wiki/United_States_2008_wireless_spectrum_auction https://en.wikipedia.org/wiki/United_States_2008_wireless_sp...
- tokenizerrr 11y agoThat's really weird. It's just data?
- metasean 11y agoYes, and tethering charges are basically charging consumers twice for accessing that data. I ethically disagree with it, but it is the standard practice here and with one legal exception, it is a legally supported practice.
- rsync 11y agoI requested this feature from the current maintainer of sshuttle ... I think I referred to it as "failsafe" mode, meaning that if sshuttle crashes or has not yet started, the default firewall rules that it installed allow no traffic to flow. Not sure if it's been acted on.