Earlier quoted context omitted.
> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?
It is my understanding that many ISPs and backbone providers sell or otherwise disclose full detailed packet metadata, including precision timestamps, and that there are companies that aggregate this data across the entire Internet. At which point your VPN becomes just another hop in the trace. VPNs, no matter how secure they themselves are, are effective for accessing lightly geo-locked content and defeating unsophi…
Infrastructure audit completed by Radically Open Security
101–110 of 290 posts
Re: Infrastructure audit completed by Radically Open Security
#102Earlier quoted context omitted.
Crimea is in Ukraine.
Yet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian. And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance. We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicat…
Re: Infrastructure audit completed by Radically Open Security
#103Thought experiment: design an architecture that passes this audit scope as written that allows for logging of user activity. I can think of at least one.
Thought experiment: build your own VPN company that doesn't log anything and try to convince people like you that you don't do any logging
actually a very interesting experiment
Re: Infrastructure audit completed by Radically Open Security
#104Earlier quoted context omitted.
You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.
if you want privacy on the internet you have options. VPNs give you privacy from your local network and ISP and a little bit from the destination service, and that's it. there are options to have privacy from additional kinds of parties. i2p, tor. whonix distribution of linux, tails…
Edit: Also, questioning trustworthiness of VPNs and them putting them forward as a solution is... a bit unorthodox.
Re: Infrastructure audit completed by Radically Open Security
#105any competent opinions on protonvpn vs mullvad vpn?
There is a pretty heavy bias against proton anything here, imo. They are seen as a marketing company is my interpretation of the sentiment.
Re: Infrastructure audit completed by Radically Open Security
#106Earlier quoted context omitted.
Is that an option? I've been paying 5 euros a month for a number of years and probably use it for 10 minutes a month, on average. I would love to just plunk down 20 euros and be good for the foreseeable future, if it was a couple cents per minute.
> I would love to just plunk down 20 euros and be good for the foreseeable future Simple, buy the number of gift vouchers on Amazon that meets your budget. There is no limit on the number of gift vouchers you can apply to a single account.
Re: Infrastructure audit completed by Radically Open Security
#107I really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers…
Re: Infrastructure audit completed by Radically Open Security
#108Earlier quoted context omitted.
Crimea is in Ukraine.
Yet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian. And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance. We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicat…
Re: Infrastructure audit completed by Radically Open Security
#109Earlier quoted context omitted.
You can't trust anything you have not built, incl. your laptop, keyboard, mouse, phone, car, even your teabag (what happens if they're randomly drugging your tea to test some pathogens, with a request from your government). Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible. So, the hole has no bottom.
To achieve true privacy, first you must create the universe.
I don't know whether I can trust the company which made it.
Re: Infrastructure audit completed by Radically Open Security
#110Earlier quoted context omitted.
It is my understanding that many ISPs and backbone providers sell or otherwise disclose full detailed packet metadata, including precision timestamps, and that there are companies that aggregate this data across the entire Internet. At which point your VPN becomes just another hop in the trace. VPNs, no matter how secure they themselves are, are effective for accessing lightly geo-locked content and defeating unsophi…
I don't understand this area well enough, I think. Doesn't a VPN encrypt the routing information that tells the packet where to ultimately end up? I.e. my ISP can see the traffic going to the VPN, but can't look inside it, and can't see where it goes from there?