Live data from Hacker News

How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean

blog.hsp.dk

31–40 of 47 posts

Re: How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean

#32
this is not secure; it will leak your ipv6 address by default. use openvpn's ipv6 features to route ipv6 traffic as well[0]. using openvpn ipv6 is a PITA on digitalocean because they only provide a /124, when openvpn requires at least a /112. you can get around this using ip6tables to route a /112 address range you don't actually have access to, and the only consequence will be a loopback if you try to access one of the digitalocean IPs you are claiming to have in your available pool while connected to the VPN.

also, 1024 dh prime is unsafe depending on your threat model[1]. use 2048 if nation states bother you, or 4096 if truly paranoid or at high risk / performance isn't an issue. no reason not to bump up the RSA keys too.

0. https://community.openvpn.net/openvpn/wiki/IPv6

1. https://weakdh.org/

Re: How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean

#33

Using a socks 5 tunnel over ssh seems like an interesting ad hoc alternative for web browsing only: https://www.digitalocean.com/community/tutorials/how-to-rout... But crucially you'd want to make your browser use the tunnel for DNS as well: http://superuser.com/questions/103593/how-to-do-dns-through-... Careful if you're using this for something dangerous. I'm not a computer security expert by any stretch and I don'…

Yeah, I use SOCKS5 over SSH all the time, although I didn't follow that particular guide. I am also not an expert but after making sure DNS requests were tunneled, I wasn't able to see any cleartext at all using Wireshark. It is not a Tor replacement or anything. I think it should be effective at simple things like: masking personal browsing at work[0], masking browsing habits from your ISP. [0] Obviously if you use…

>masking browsing habits from your ISP

What I don't get is why people think that random VPS and VPN providers would somehow be better for your privacy than to let your ISP see the content of your traffic.

Re: How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean

#34
Interesting. I have set up a few VPN servers of various kinds (and other network trickery) in Virtual Machine hosting services, and ultimately gave up due to issues with TSO (TCP Segmentation Offload https://en.wikipedia.org/wiki/Large_receive_offload) interacting badly with PMTUD (https://en.wikipedia.org/wiki/Path_MTU_Discovery). The result was that TCP streams (often Downton Abbey, fwiw) inbound from a remote server, tunneled to me via the VPN, would stall and generally suffer from poor QoS.

I spent some time submitting support tickets to all the hosting providers I had tried (many). Every one of them told me that they had no way to disable TSO and the other common TCP offload features on their hosts.

So now I use Packet.net which gives me a honest to goodness actual bare metal machine (over which I have complete control), for much the same price.

Re: How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean

#36

Earlier quoted context omitted.

Yeah, I use SOCKS5 over SSH all the time, although I didn't follow that particular guide. I am also not an expert but after making sure DNS requests were tunneled, I wasn't able to see any cleartext at all using Wireshark. It is not a Tor replacement or anything. I think it should be effective at simple things like: masking personal browsing at work[0], masking browsing habits from your ISP. [0] Obviously if you use…

>masking browsing habits from your ISP What I don't get is why people think that random VPS and VPN providers would somehow be better for your privacy than to let your ISP see the content of your traffic.

Your ISP and your government have a strong interest in monitoring what you do, and they are more likely to take action against you if they don't like what you do.

A random VPS service (preferably in another country) only cares about you insofar as you pay them and don't cause any trouble to them. They don't have as much of an incentive to invade your privacy as your home ISP does, and I trust incentive structures a lot more than I trust boilerplate words on a privacy policy.

It can also be a matter of opportunistic encryption. Most public wi-fi is vulnerable to anyone in the vicinity, in addition to the usual ISP and the NSA. Use a VPN and now you're only vulnerable to the VPS service and the NSA. That's quite a bit of improvement.

You also have the freedom to choose a VPS service with good connectivity in a relatively less snoopy country, a luxury you often don't have in choosing your home ISP.

Re: How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean

#37

This seems a bit pointless to me. If your aim is to hide your traffic from third-party networks you might be on (free wifi, school, hotels, etc) then a yearly VPN subscription is almost certainly cheaper than the cheapest DigitalOcean droplet. If you get a good provider (I use PIA but am not affiliated with them) then you get unlimited traffic, multiple clients, endpoints all over the world, tech support, all without…

I trust Digital Ocean much more than I trust PrivateInternetAccess. I also don't want to be associated with the other traffic going through PIA or similar VPNs.

Curious, why don't you trust PIA? Have they done anything shady?

Re: How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean

#38

This seems a bit pointless to me. If your aim is to hide your traffic from third-party networks you might be on (free wifi, school, hotels, etc) then a yearly VPN subscription is almost certainly cheaper than the cheapest DigitalOcean droplet. If you get a good provider (I use PIA but am not affiliated with them) then you get unlimited traffic, multiple clients, endpoints all over the world, tech support, all without…

Rolling one's own often makes sense, and not just from an audit perspective.

Where I am for example almost all VPN vendors are blocked, so there's not much choice other than to roll your own. And once you've figured out how to do it on one provider you can pretty much do the same anywhere.

Re: How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean

#39

Earlier quoted context omitted.

Yeah, I use SOCKS5 over SSH all the time, although I didn't follow that particular guide. I am also not an expert but after making sure DNS requests were tunneled, I wasn't able to see any cleartext at all using Wireshark. It is not a Tor replacement or anything. I think it should be effective at simple things like: masking personal browsing at work[0], masking browsing habits from your ISP. [0] Obviously if you use…

>masking browsing habits from your ISP What I don't get is why people think that random VPS and VPN providers would somehow be better for your privacy than to let your ISP see the content of your traffic.

I live in a country where metadata is recorded at the ISP level for government perusal. More than 60 agencies want access this data without a warrant [0]. Why does the Taxi Services Commission need to know my web browsing history? Or Greyhound Racing Victoria?

There's also a law specifically making it a crime to post any information about government actions deemed a "special intelligence operation" [1], which makes me think that they're recording this data in bad faith.

So fuck 'em. Fuck the government that seeks to monitor everyone in order to entrench their power structure. Fuck them for lying to us, by claiming it's about terrorism. Fuck them for indicating a willingness to prosecute anyone who shines a light on their shady actions.

That's why I use a VPN, running on a VPS I have provisioned myself. No, I don't trust the VPS provider, but they have no power to imprison people, nor have they demonstrated a desire to expand their power over others.

[0] http://www.abc.net.au/news/2016-01-18/government-releases-li...

[1] https://www.theguardian.com/commentisfree/2014/sep/26/journa...

Post reply on HN