Live data from Hacker News

Attackers can decloak routing-based VPNs

leviathansecurity.com

221–230 of 238 posts

Re: Attackers can decloak routing-based VPNs

#221
post #199

Earlier quoted context omitted.

>Regardless what police or governments want, they have to abide by laws I can't tell if this person actually believes what they wrote, or if it is some kind of attempted public social pressure technique meant to adjust the Overton Window from a rational place. Be it 2024 or 1624, to assert that one trusts the gov to "not fuck them over" takes a special type of naivete. It certainly takes a general obliviousness to th…

I believe what I wrote. Do note that this applies to Western Europe (more precisely: the Netherlands). And do note that "to be f#ed over" is rather broad and personal. While one person might feel they are truly "f#d" by police" when they get a ticket driving their bike without lights at night, that's obviously not what I mean. I am by conviction an Anarchist (though certainly not libertarian), and I do see the times…

> those are cases where the government, through democratic mandate, made (extremely) bad laws

Yes, due to democracy.

You think more democracy is the answer?

Re: Attackers can decloak routing-based VPNs

#222

Earlier quoted context omitted.

You are missing one valid use-case: avoiding three-strikes letters being sent to your ISP by the MPA. Unless you're part of a release group, the complaints from the MPA never rise to the level of actual legal action, so your VPN provider is free to bin them, whereas your actual ISP would almost certainly act on them.

Yes of course, if you're engaged in low level criminal behaviour, then even these low levels of obfuscation will keep some pressure off your back. But since copyright law is somewhat of a grey area in the EU, you technically don't even need a VPN for that. You could run a VPS somewhere and get the same results much cheaper. But this kind of use case is not something VPN providers can advertise with anyways, so my poi…

You can get a good VPN for $5/month. I don't think you can get a decent VPN with enough bandwidth to use as a tunnel for the same price.

And as for infringement being grey in the EU, not really it goes by country. Nothing grey about it in Denmark for example.

Re: Attackers can decloak routing-based VPNs

#223

Earlier quoted context omitted.

Yes of course, if you're engaged in low level criminal behaviour, then even these low levels of obfuscation will keep some pressure off your back. But since copyright law is somewhat of a grey area in the EU, you technically don't even need a VPN for that. You could run a VPS somewhere and get the same results much cheaper. But this kind of use case is not something VPN providers can advertise with anyways, so my poi…

You can get a good VPN for $5/month. I don't think you can get a decent VPN with enough bandwidth to use as a tunnel for the same price. And as for infringement being grey in the EU, not really it goes by country. Nothing grey about it in Denmark for example.

You can literally get a VPS with gigabit connection for free these days.

Re: Attackers can decloak routing-based VPNs

#224

Earlier quoted context omitted.

>I’m not aware of any Western government that has so far gained the power to force its companies to affirmatively lie about whether they have shared logs with the government Do you see the problem with this statement?

Depends on what things you think are likely to be true in secret or judicially determined in the future without an intervening legislative change. My impression of the law in most Western countries is that the courts would overturn any requirement to compel a company to affirmatively lie to the public through explicit speech of some kind, even in the national security context. Orders compelling silence or non-removal…

>My impression of the law in most Western countries

Apparently you still didn't get it, so let me spell it out: Your entire point hinges on your own impression that your government won't abuse its power. An impression that will always be heavily influenced by PR and propaganda, no matter where you live - and one that seems eerily off considering the fact how often surveillance programs and attempts at destroying what privacy we have left make it to the surface. This kind of blind trust in your superiors is the straightest way to a 1984-esque dystopia.

Re: Attackers can decloak routing-based VPNs

#225

Earlier quoted context omitted.

As I said above, a simple court order can destroy any attempt at privacy. All (serious) VPN providers claim they don't store logs. But that does not mean that a court can't force them to do so. When combined with a gag order you can have someone collecting all your traffic without you even realizing it. And that's just the VPN provider, which usually doesn't own any datacenters. The datacenter providers can also rece…

> All (serious) VPN providers claim they don't store logs. But that does not mean that a court can't force them to do so. When combined with a gag order you can have someone collecting all your traffic without you even realizing it. And that's just the VPN provider, which usually doesn't own any datacenters. The datacenter providers can also receive the orders to either monitor traffic or even install hardware to do…

>None of this really matters unless you are doing something illegal enough that the government is interested in you

The issue here is that how "illegal" something is depends heavily on where you live. In some places speaking against the government can get you killed [1]. In others, hosting movies can get your house raided by police helicopters [2].

[1] https://www.unesco.org/en/safety-journalists/observatory

[2] https://www.youtube.com/watch?v=KmIPVrkN1hA

Re: Attackers can decloak routing-based VPNs

#226

Earlier quoted context omitted.

You can get a good VPN for $5/month. I don't think you can get a decent VPN with enough bandwidth to use as a tunnel for the same price. And as for infringement being grey in the EU, not really it goes by country. Nothing grey about it in Denmark for example.

You can literally get a VPS with gigabit connection for free these days.

Link?

Re: Attackers can decloak routing-based VPNs

#227

Earlier quoted context omitted.

> All (serious) VPN providers claim they don't store logs. But that does not mean that a court can't force them to do so. When combined with a gag order you can have someone collecting all your traffic without you even realizing it. And that's just the VPN provider, which usually doesn't own any datacenters. The datacenter providers can also receive the orders to either monitor traffic or even install hardware to do…

>None of this really matters unless you are doing something illegal enough that the government is interested in you The issue here is that how "illegal" something is depends heavily on where you live. In some places speaking against the government can get you killed [1]. In others, hosting movies can get your house raided by police helicopters [2]. [1] https://www.unesco.org/en/safety-journalists/observatory [2] http…

> The issue here is that how "illegal" something is depends heavily on where you live.

The context of the discussion was the EU.

And the point stands. For 99% of people VPNs offer privacy even against the government, that would need to meet a high burden of proof and require a warrant to break that privacy.

Re: Attackers can decloak routing-based VPNs

#229
post #77
post #73

Earlier quoted context omitted.

What would be the opposite approach, to make sure all traffic goes through VPN, and only VPN, even if user didn't start the VPN connection (default to no connectivity)? Is there better approach then just disabling all other network interfaces?

AFAIK Wireguard will always listen in the default namespace, thus you need to isolate everything else. A fun way of doing it though is to do an ip rule that uses the VRF table, and matches on the user id. That way all traffic from certain users will always end up in the same routing table. You can go further and match on everything except the Wireguard endpoint. With iptables you can MARK the traffic you want to be d…

Cool, thank you!

Re: Attackers can decloak routing-based VPNs

#230

Earlier quoted context omitted.

>None of this really matters unless you are doing something illegal enough that the government is interested in you The issue here is that how "illegal" something is depends heavily on where you live. In some places speaking against the government can get you killed [1]. In others, hosting movies can get your house raided by police helicopters [2]. [1] https://www.unesco.org/en/safety-journalists/observatory [2] http…

> The issue here is that how "illegal" something is depends heavily on where you live. The context of the discussion was the EU. And the point stands. For 99% of people VPNs offer privacy even against the government, that would need to meet a high burden of proof and require a warrant to break that privacy.

I said nothing that goes against the context. Again: When you are actually scared of getting cought for something, a commercial VPN very likely doesn't help. That goes for all jurisdictions.
Post reply on HN