Live data from Hacker News

VPNs are not the solution to a policy problem

asininetech.com

151–160 of 228 posts

Re: VPNs are not the solution to a policy problem

#151

Earlier quoted context omitted.

I strongly disagree. This policy fight isn't a fight to regulate the market (like the automobile regulations you mentioned). It's a fight for a fundamental right to privacy. Any technology improvement that can protect privacy can be made illegal, and enforced by a boot on the face (see China). If the government makes encryption without government key escrow illegal (not at all outlandish, has been discussed in many c…

> It's a fight for a fundamental right to privacy. Where did this right come from? and since when is this a thing? Don't mean to be condescending but "the right to privacy" isn't really a thing in this particular domain (legally speaking)

Sticking to a Western context, this is a pretty fundamental distinction between the US and the EU in the understanding (and, crucially, in the implementation/enforcement) of human rights.

I can't pretend to do justice to the long history of the concept, but we can at least say that for the latter, privacy has been considered an important human right since at least the UN declaration of 1948. This has been carried over into European law, see all the iterations on EU data protection laws. The UN statement is Article 12: "No one shall be subjected to arbitrary interference with his privacy, family, home or correspondence, nor to attacks upon his honour and reputation. Everyone has the right to the protection of the law against such interference or attacks."

For the US, this dimension of human rights did not deeply inform policy. Here discussion around a "right to privacy" really began in a different context with Brandeis and a right to be "left alone", largely meaning from the press. Many of the cases that inform privacy law in the US are oriented towards such scenarios and do not necessarily translate well to the context of data. See http://groups.csail.mit.edu/mac/classes/6.805/articles/priva.... There is rather a discussion on the accuracy of financial data about a person that stems from credit reporting.

The other area that would have to be discussed is of course wire-tapping laws, but leave that for another day... In sum, the question of a "right to privacy" has a long tangled history even just within the West, but is decidedly a thing in the EU.

Re: VPNs are not the solution to a policy problem

#152
post #102

There are a few schools of thought on where responsibility should lie in protecting user privacy. The first that it is a role of government and policy - in the same way the government sets standards for automobile and road safety they can set and enforce policies for user privacy. The second school of thought is individual responsibility. Users should take steps to protect their own privacy on a case-by-case basis, i…

> The second school of thought is individual responsibility. Users should take steps to protect their own privacy on a case-by-case basis, in the same way they look after their own home security or personal safety. > I personally believe in user responsibility for personal privacy and security, where you can't and shouldn't depend on policy to protect you and that all users should be aware of the issues and actively educated on how to protect themselves.

The problem is that while home security and personal security is something everyone understands on a basic level, the impact of personal information being public or being available to others is not.

Many people believe that whether other people, companies or government agencies or advertisers know some details about their private life doesn't matter much, but many don't understand the potential impact. Perhaps insurance policies go up inexplicably because you googled backache or headache remedies a few times. Perhaps certain political affiliation or opinions can be outlawed and put you on watch lists in the future (think of the McCarthy era in the US).

Many people also don't realize how much information can be derived from your network traffic, even if it is not explicitly present in the data itself.

Educating people on this kind of complexity and nuance is much more complicated than explaining what a fence does, or how curtains work. It would be expensive and hard, and many people won't understand the need for it anyway.

Re: VPNs are not the solution to a policy problem

#153
post #38

I had all sorts of VPN problems over the years with various Linux desktops OS. What I do instead is that I have a proxy server with just an OpenSSH daemon on port 443 -- if there's web traffic, add sslh to taste -- and then use the SOCKS v5 proxy built into OpenSSH client and then http://darkk.net.ru/redsocks/ I might be the weird case here but I found this infinitely easier to set up than any VPN.

SSH tunnels work in a pinch (OpenSSH is <3). However for coverage across devices such as smartphones OpenVPN works better long-term.

Unfortunately even recent versions of Android have some incompatibilites with OpenVPN.

When I tried again with Lollipop last month, the VPN's preferred DNS was not being set on the phone despite being sent from the VPN server, hence DNS lookups were leaking to whatever DNS server had been set before establishing the VPN. Quite a nasty gotcha. Workaround is to run a script to set the DNS, but that requires root privs which 'normal' users won't have.

Re: VPNs are not the solution to a policy problem

#154
post #47
post #28

Earlier quoted context omitted.

Because ISPs can't read your traffic

But now the VPN provider can just track you and sell all your browsing history instead of the ISP, so how is this better?

    > But now the VPN provider can
    > just track you
Find one based in a less offensive jurisdiction?

Re: VPNs are not the solution to a policy problem

#155

Earlier quoted context omitted.

I strongly disagree. This policy fight isn't a fight to regulate the market (like the automobile regulations you mentioned). It's a fight for a fundamental right to privacy. Any technology improvement that can protect privacy can be made illegal, and enforced by a boot on the face (see China). If the government makes encryption without government key escrow illegal (not at all outlandish, has been discussed in many c…

> It's a fight for a fundamental right to privacy. Where did this right come from? and since when is this a thing? Don't mean to be condescending but "the right to privacy" isn't really a thing in this particular domain (legally speaking)

Fair point. I certainly don't believe in natural law. I don't think we should fight for a right to privacy because it's inhenrently owed to us by the universe or some such.

I think we should fight for it because I think it makes life better and because I don't want to live under an oppressive government.

Re: VPNs are not the solution to a policy problem

#156

Earlier quoted context omitted.

I strongly disagree. This policy fight isn't a fight to regulate the market (like the automobile regulations you mentioned). It's a fight for a fundamental right to privacy. Any technology improvement that can protect privacy can be made illegal, and enforced by a boot on the face (see China). If the government makes encryption without government key escrow illegal (not at all outlandish, has been discussed in many c…

Maybe nitpicking, but: > a fight for a fundamental right to privacy Many don't consider this to be a fundamental right. > A tech that takes 100 years to develop can be made illegal in a day. As the recorded history goes, I think it was always the other way around - a new technological development suddenly invalidating a set of laws, and lawmakers playing catch-up with its use. I wish governments of the world got thei…

I partially agree with your points, but I still insist the policy fight is more pressing, because the tech is only possible to use with the right policy.

If the US and Europe change to be like China, all that tech is worthless because the spooks can come knock down your door if they suspect you're "hiding something."

Re: VPNs are not the solution to a policy problem

#157
post #102

There are a few schools of thought on where responsibility should lie in protecting user privacy. The first that it is a role of government and policy - in the same way the government sets standards for automobile and road safety they can set and enforce policies for user privacy. The second school of thought is individual responsibility. Users should take steps to protect their own privacy on a case-by-case basis, i…

> The second school of thought is individual responsibility. Users should take steps to protect their own privacy on a case-by-case basis, in the same way they look after their own home security or personal safety.

I think this is a bullshit argument. Nobody looks after their home security or personal security the way we expect users to be careful of their privacy, nor do we accept the amount of intrusions into our house or personal space as we are told is reasonable in information.

Imagine you could get a free pizza every week, you just need to let the driver go through your house and correspondence. Imagine if you had to sign over the risk that your house might be burgled if you signed up for a bank account...And the police didn't act on it.

These examples seem ludicrous, but that is not because I'm making them like this, it's because the premise that we all do "personal responsibility" is a myth.

We have police, laws, community rules, all of these things to protect our houses and personal security. If you leave the door unlocked, robbing it is still a crime. Likewise, if you walk around on an unsafe neighbourhood and get robbed, it would be ludicrous to hear "well, the city warned you that part is unsafe, so the police isn't going to investigate"

Re: VPNs are not the solution to a policy problem

#159
post #61

Lots of people seem to think the right answer is selling improved security. I disagree. It would be much more exiting to get the data coming from politicians homes, and the homes of their staff. It would be a fantastic way to generate news. Why is senator X's household researching cancer treatment? Will they step down this year? I can't help but think military bases would google their next deployment, that's another…

Well, pastebinning communication of a politician (or better - their kid) seems like such an effective idea, I wonder why this doesn't seem to happen? Is there a strong roadblock somewhere there? It's not like most politicians and their staff know much about Internet security.

Well in the UK they amended the law to exempt themselves: http://www.independent.co.uk/life-style/gadgets-and-tech/new...

Re: VPNs are not the solution to a policy problem

#160

Earlier quoted context omitted.

I strongly disagree. This policy fight isn't a fight to regulate the market (like the automobile regulations you mentioned). It's a fight for a fundamental right to privacy. Any technology improvement that can protect privacy can be made illegal, and enforced by a boot on the face (see China). If the government makes encryption without government key escrow illegal (not at all outlandish, has been discussed in many c…

> It's a fight for a fundamental right to privacy. Where did this right come from? and since when is this a thing? Don't mean to be condescending but "the right to privacy" isn't really a thing in this particular domain (legally speaking)

I really don't understand this line of logic on fundamental rights. If you're referring to the UDHR, it's a piece of paper put together by Eleanor Roosevelt a little over half a century ago. It's a human document of arbitrary concepts put together by people who believed enforcing those would improve the world in aggregate.

The idea of basing our sense of right on what is law, rather than basing the laws we write on our sense of right seems to be bafflingly common.

Post reply on HN