Live data from Hacker News

VPNs are not the solution to a policy problem

asininetech.com

111–120 of 228 posts

Re: VPNs are not the solution to a policy problem

#111

Until a better solution is found, I think the way the recent IOT botnet stuff + this ISP privacy deregulation is portrayed in the media opens the opportunity for a startup that sells a secure, smart home router + VPN subscription plan.

And you would trust the startup with your traffic because...?

You have to trust someone at some point if you want to use the internet at all.

Do you trust any VPN providers? Or your ISP? Or the programmers of the browser that you're using? Or your CPU manufacturer? It's turtles all the way down.

Perfect is the enemy of good. If that protocol was open, it might foster a way to fold VPNs into the everyday person's internet connection, with the possibility to easily change VPN providers down the track.

Re: VPNs are not the solution to a policy problem

#112

Earlier quoted context omitted.

I just did a bunch of research at https://www.reddit.com/r/VPN -- looks like Mullvad is the most recommended / highest rated.

Sweden is a member of the EU [1]. It has a 6-month data retention law [2]. Much safer to route through Norway, Switzerland or even the United States. (I use PIA [3].) [1] https://europa.eu/european-union/about-eu/countries_en [2] https://www.purevpn.com/blog/data-retention-laws-by-countrie... [3] https://www.privateinternetaccess.com

Personally I would never use a US-based VPN.

Re: VPNs are not the solution to a policy problem

#114

Why aren't VPNs, and more broadly encryption, a solution to this problem? "Waving the wand of a technical solution," as the post pejoratively calls it, isn't such an unreasonable thing to do with an inherently technical problem. This problem only exists because of other technical wands we waved. Why solve this problem with policy? Policy is hard to get passed, hard to keep passed and even when it is passed often time…

Then the question is: are technical experts the only ones who deserve privacy? Are the strong the only ones who deserve safety? etc etc. While I also prefer a system which assumes no trust in government policy, it is still prefferable provide legal protections for the little guys whenever possible. In this case, the little guy is the vast majority of people who don't understand how the internet works.

It seems a lot more plausible to me that privacy technologies can be made accessible to the masses than that policies can be passed which protect the masses. After all the masses are only in this situation because other technologies which were once only accessible to experts became accessible to them. Does the government have a particularly good track record of protecting the little guys in your opinion?

Re: VPNs are not the solution to a policy problem

#115
What would be wrong with selling preconfigured routers to solve the problem?

The router could talk to a standard web api to get information to configure itself. The web service behind the scenes could set up and teardown digital ocean droplets as necessary running streisand. The web service IP's wouldn't be blocked because they'd only be used to periodiy get configuration.

So then you buy a non technical person this router, they create an account on the configuration website and as Ron Popeil would say, set it and forget it.

Re: VPNs are not the solution to a policy problem

#116

Does anyone sell a router for the home that has a VPN built in? So that I dont have to have every computer in my home hook into the VPN when I start it up. Just one account for my whole house? I imagine you could setup a linux box to do that for you, but I am lazy...

Pretty much all decent routers have a built-in VPN. Even old Apple Express routers have the feature.

Re: VPNs are not the solution to a policy problem

#117

Earlier quoted context omitted.

I went looking for a spreadsheet I once saw, apparently it's become a website. https://thatoneprivacysite.net/vpn-section/

France runs a warrantless mass surveillance program [1]. It is one of the countries our OpSec consultant specifically recommends taking clean computers to. It is labelled, by "That One Privacy Site" as NOT being an "enemy of the Internet" (whatever that means). Difficult to take the rest of its recommendations seriously. [1] http://www.cnn.com/2013/07/05/world/europe/france-surveillan...

[deleted]

Re: VPNs are not the solution to a policy problem

#118
post #102

There are a few schools of thought on where responsibility should lie in protecting user privacy. The first that it is a role of government and policy - in the same way the government sets standards for automobile and road safety they can set and enforce policies for user privacy. The second school of thought is individual responsibility. Users should take steps to protect their own privacy on a case-by-case basis, i…

But does the individual have any chance of winning the battle without at least some policy on their side?

Re: VPNs are not the solution to a policy problem

#119

Does anyone sell a router for the home that has a VPN built in? So that I dont have to have every computer in my home hook into the VPN when I start it up. Just one account for my whole house? I imagine you could setup a linux box to do that for you, but I am lazy...

I'm pretty sure you can do this with a router running DDWRT or OpenWRT.

Re: VPNs are not the solution to a policy problem

#120

Earlier quoted context omitted.

Especially if the VPN Provider is a shell company of the NSA or CIA!

On the contrary, Hanlon's razor could just assume good intentioned VPN hosts failing to secure their design by negligence or ignorance of broken protocols.

To the contrary, Ockham's razor means shell VPN companies set up by the multi-billion dollar three-letter agencies whose entire job seems to be to gather as much data as possible by any means. :-)
Post reply on HN