Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

101–110 of 281 posts

Re: VPN – Very Precarious Narrative

#102
post #21
post #5

Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.

> b) A VPN has some incentive to deliver on privacy. Your ISP does not. Regarding this point, I think a good strategy here is to acknowledge that ISPs, like most organizations, don’t want to add to their workloads. Of course they aren’t privacy centric, but appeals to them oriented around _not_ having to store a bunch of logs or set up a bunch of processes can help to unite more people around initiatives to make thin…

[deleted]

Re: VPN – Very Precarious Narrative

#103
post #79

Earlier quoted context omitted.

Of course one has to wonder how much of that "poor OPSEC" is actually just parallel construction. The linked article doesn't sound like it. But on the other hand with the way mass market VPN software generally works, how many people are going to be absolutely sure that all of their traffic definitely went out the tunnel? The FBI having access to an NSA-provided tool that takes some IP addresses and returns other "ass…

Sure, a lot of it may be parallel construction. We do know that the NSA shares with the FBI and other TLAs. If your threat model includes the NSA or the like, VPN services are at best a minor hindrance. Possible options include Tor and "anonymously" using WiFi hotspots. I only know of one fundamental fail for Tor: the relay-early bug that CMU exploited. The others have involved Firefox and Windows bugs. People using…

The quip about someone being sure absolutely no traffic went out their access IP is that without extreme confidence, they won't be pushing their lawyer/team to scrutinize the chain of custody for the server logs, hinging their case on procedural grounds. Someone diligent enough to setup proper firewall rules is probably also forethinking enough to not go cracking random newspaper websites for fun.

And yeah in regards to criminal activity, I think it would be prudent to consider the NSA, specifically bulk processing of dragnet surveillance, part of the threat model in the modern age. It's very easy for the public narrative to focus on a guilt-implying needle in a haystack, regardless of how that needle was actually found.

Re: VPN – Very Precarious Narrative

#104
post #9

Earlier quoted context omitted.

Who cares if they log now? They can be forced to log --- and are in fact running businesses the practically beg the DOJ to force them to log.

> They can be forced to log There is no legislation in the US that can be used to do this [1]. Some very misguided companies may voluntarily log, but those that care about privacy or, at the least, realize that holding people's data is a liability, won't make poor decisions like that. [1] https://en.wikipedia.org/wiki/Data_retention#Failed_mandator...

Nah, he's right. The Core Secrets leak said the FBI was using some secret method to "compel" domestic targets to do the "SIGINT-enabling" of their networks. It might have been just fines and jail threats under the secret court (FISC). On top of that, the Patriot Act let them hold people indefinitely, they were kidnapping folks at airports for "extraordinary rendition" (torture), and there's the old civil forfeiture laws on top. That's the extreme stuff.

Less extreme, Lavabit was hit in court. Lavabit said giving their private key to the government would expose all their users' data. They said it would be bad for their business. The FBI countered that there would be no damage if nobody knew they did that. So, they just wouldn't tell anyone what the judge had ordered. Judge went along with that idea. So, that's how legislation and liability in the U.S. works. Especially when there's secrecy orders.

Pro tip: don't host anything that's supposed to be private in the U.S.. It's a surveillance/police state slash plutocracy disguised as a democracy. Anything that might be private can be ordered to not be private secretly with immunity.

Re: VPN – Very Precarious Narrative

#106
post #93
post #79

Earlier quoted context omitted.

Sure, a lot of it may be parallel construction. We do know that the NSA shares with the FBI and other TLAs. If your threat model includes the NSA or the like, VPN services are at best a minor hindrance. Possible options include Tor and "anonymously" using WiFi hotspots. I only know of one fundamental fail for Tor: the relay-early bug that CMU exploited. The others have involved Firefox and Windows bugs. People using…

> Possible options include Tor I thought most folks believe that the NSA/CIA/some other TLA has control of more than 50% of the exit nodes, which should be enough to reconstruct the sources of most traffic.

Some people do. If that's true, all hope is lost ;)

Re: VPN – Very Precarious Narrative

#107
post #88
post #23

Earlier quoted context omitted.

They all have anti-abuse mechanisms, but that doesn't mean logging. Why couldn't you have a flagging system in real-time that shuts down accounts but doesn't save the data to disk?

>Why couldn't you have a flagging system in real-time that shuts down accounts but doesn't save the data to disk? That's what I described with the deep packet inspection. You could hook up an IDS and block users based on the IDS output, but like I said, the sort of people who like no log VPNs will not like that. At one point I set that up at my VPS company a long time ago, (of course, I was very up front about it and…

>PIA absolutely does not keep any logs, of any kind, period. While this does make things harder in some cases, specifically dealing with outbound mail, advanced techniques to handle abuse issues, and things of that nature, this provides a high level of security and privacy to all of our users. Logs are never written to the hard-drives of any of our machines and are specifically written to the null device, which simply acts if the data never existed.

From https://www.privateinternetaccess.com/helpdesk/kb/articles/d...

They don't say they aren't using deep packet inspection, and it acknowledges that makes it more difficult to handle abuse.

Re: VPN – Very Precarious Narrative

#108
post #50

What VPN provider would you guys recommend?

For several years, I've been recommending AirVPN, Insorg, IVPN, Mullvad and PIA. So at this point, I can say that they've all been around for several years, and I've heard nothing bad about them.

Ones I have heard bad things about are EarthVPN, HideMyAss, Proxy.sh and PureVPN. And although I've heard nothing bad about ExpressVPN or NordVPN, the fact that they've bribed so many review sites to recommend them annoys me.

And yes, I have written stuff for IVPN.

Re: VPN – Very Precarious Narrative

#110
post #82
post #50

What VPN provider would you guys recommend?

Also interested in this! Also why VPN vs just setting up one yourself on digitalocean or something like that? (The reason why I'm not with a VPN yet is because it would compromise my speed. Am I overestimating the impact?)

If you setup your own VPN on some leased VPS, then you're the only user. So there's zero help re anonymity. And re privacy and security, you need to trust the VPS provider.

No free lunch :(

Post reply on HN