Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

151–160 of 281 posts

Re: VPN – Very Precarious Narrative

#151
post #50

What VPN provider would you guys recommend?

For several years, I've been recommending AirVPN, Insorg, IVPN, Mullvad and PIA. So at this point, I can say that they've all been around for several years, and I've heard nothing bad about them. Ones I have heard bad things about are EarthVPN, HideMyAss, Proxy.sh and PureVPN. And although I've heard nothing bad about ExpressVPN or NordVPN, the fact that they've bribed so many review sites to recommend them annoys me…

I signed up for ExpressVPN before visiting China due to all sites recommending this (I badly wanted Google maps and Google to work). ExpressVPN does not work in China so either something changed very recently or a lot of people have been bribed to lie.

I would not trust ExpressVPN anymore for anything.

Re: VPN – Very Precarious Narrative

#152
post #66

Earlier quoted context omitted.

Oh come on now. The US Government forces tech companies to share information all the time. http://www.msnbc.com/msnbc/us-government-threatened-yahoo-bi... They certainly can, and will, go after any company they want to, without referencing any specific US legislation.

The demands mentioned in your link did reference specific US legislation: FISA section 702.

Before all this information got leaked, nobody knew about FISA section 702, nor had any idea how it was being interpreted and acted on by government agencies. I think it's quite clear that the secret courts in the US put huge demands on organizations to share and collect data on government behalf. Even worse, the organizations can not even publicly disclose information from the proceedings.

Until I see something to convince me otherwise, I assume any sizable organization that is operating within the United States shares any/all data requested. No loophole will protect them. If they don't collect the data, guess what, time to start collecting.

Re: VPN – Very Precarious Narrative

#153

Earlier quoted context omitted.

For several years, I've been recommending AirVPN, Insorg, IVPN, Mullvad and PIA. So at this point, I can say that they've all been around for several years, and I've heard nothing bad about them. Ones I have heard bad things about are EarthVPN, HideMyAss, Proxy.sh and PureVPN. And although I've heard nothing bad about ExpressVPN or NordVPN, the fact that they've bribed so many review sites to recommend them annoys me…

I signed up for ExpressVPN before visiting China due to all sites recommending this (I badly wanted Google maps and Google to work). ExpressVPN does not work in China so either something changed very recently or a lot of people have been bribed to lie. I would not trust ExpressVPN anymore for anything.

ExpressVPN works well in China, although there was a week in March where it was very spotty. I'm using it right now.

I agree that it's annoying how many review sites are getting paid to recommend them, but the service actually has been good for the last year.

I've tested several VPNs here, including Mullvad and Nord. ExpressVPN has the fastest speeds by a quite a bit.

However, self-hosted is much faster still. Unfortunately, it's less reliable.

Re: VPN – Very Precarious Narrative

#154
post #150

Earlier quoted context omitted.

He made this point explicit: > Networks like these make it easy for attackers to get a copy of your network data, and if you send something unencrypted, the results can be quite harmful. The web should be ideally end-to-end encrypted with HTTPS. But in case this assumption breaks down, VPN gives an additional headroom for security. Not much (as explained in the article, and thus should not be advertised so), but stil…

> The web should be ideally end-to-end encrypted with HTTPS. No. People designing public access networks should use encryption and AP client isolation.

They should, of course. And for when they don’t, a VPN can protect you. That’s what the article is saying.

Re: VPN – Very Precarious Narrative

#155
post #21
post #5

Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.

> b) A VPN has some incentive to deliver on privacy. Your ISP does not. Regarding this point, I think a good strategy here is to acknowledge that ISPs, like most organizations, don’t want to add to their workloads. Of course they aren’t privacy centric, but appeals to them oriented around _not_ having to store a bunch of logs or set up a bunch of processes can help to unite more people around initiatives to make thin…

Yes, VPNs might be unjustly talked about as a set-it-and-forget-it way to gain privacy online a bit, but what I find far more harmful is the blind trust people seem to have in their ISP. I often see the argument "You are just shifting trust from one company (ISP) to another (VPN).", yes, that might actually be the whole point.

ISPs can't be blindly trusted. I switched ISPs lately because my previous one started offering personalised TV-ads. This is a very scary topic and in Belgium it has already lead to some fishy things:

https://www.nieuwsblad.be/cnt/dmf20160913_02466535

Nice quote with regards to personalised tv-ads:

"Er komt ook een nog verdergaande versie waarbij ook het surfgedrag zal leiden tot gerichte tv-reclame. Daarbij wordt gemonitord naar welk type websites er in een gezin vaak wordt gesurfd, om zo interessepatronen te ontwaren die lucratief kunnen zijn voor adverteerders."

"There will be a far-reaching version in which browsing behaviour will also lead to personalised tv-ads. The websites visisted by families will be analysed in order to discover interest patterns that could be lucerative for advertisers."

Add this to the many cases where ISPs have fought for being allowed to use deep packet inspection to monitor what we do and you start to see that ISPs in fact think they have a right to collect and sell our data. Am I not already paying for internet and TV?

Re: VPN – Very Precarious Narrative

#156
The articles like this are disastrous. So many people are using VPN to bypass government restrictions, protect themselves from ISPs, which are no longer run by idealists dreaming about uncensored access to information, but by managers, that will share your information with any agency the minute request shows up in their inbox. And these people don't always have good knowledge of how security works, and who this article can greatly mislead.

I subscribed to a small VPN service 5 years ago for one reason: I needed static IP address for work, but my ISP at the time wasn't selling them to private individuals (freelance).

And I couldn't be happier! Wherever I go I don't have any issues with access to my resources or worries that local government will fine me for watching porn (check out UAE or Saudi laws).

Hell, even Skype is blocked by a lot of telecoms around the world since you don't pay roaming fees when calling through it. How ridiculous is that? On VPN it worked everytime.

HTTPS is great, but it is by no means private enough. ISP knows which service you are requesting, they can do SSL inspection and all kind of shady bullshit without your consent. With VPN they only see that I talk to 1 IP address somewhere in Netherlands and that is it!

Re: VPN – Very Precarious Narrative

#157
post #118

Earlier quoted context omitted.

But a VPS on DO, AWS or gcloud also has numerous services on the same physical machine. It's not like every request coming from that machine is from you or am I missing your point?

Sure. But each VPS has its own IP address. The VPS provider probably retains logs. And its ISP probably also retains logs. And everything involving that IP address is associated with you.

For incoming traffic yes, but outgoing traffic is heavily dependent on what you use. A lot of virtual spaces use the same outgoing IP

Re: VPN – Very Precarious Narrative

#158
post #50

What VPN provider would you guys recommend?

TOR browser, or TAILS in a vm are both far superior to a VPN if you actually care about privacy. It is less convenient than using a VPN though - so lots of people sacrifice privacy and money for convenience and the feeling of privacy.

I agree but your bandwidth will take a massive hit. I pay for my fiber so I can have fast internet, with TOR I would only be able to use a fraction of that.

Re: VPN – Very Precarious Narrative

#159

The articles like this are disastrous. So many people are using VPN to bypass government restrictions, protect themselves from ISPs, which are no longer run by idealists dreaming about uncensored access to information, but by managers, that will share your information with any agency the minute request shows up in their inbox. And these people don't always have good knowledge of how security works, and who this artic…

a) The unproven assumption you are making is that VPN providers are run by idealists, not by managers. There is no indication for this. b) The article outlines that using a VPN to bypass national censoring measures is perfectly valid. c) Your argument about the ISP knowing everything vs. the VPN provider knowing everything is exactly what the article is about. There is no indication to trust a VPN provider more than your ISP, for a number of reasons.

Re: VPN – Very Precarious Narrative

#160
post #125

Earlier quoted context omitted.

>most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? What percentage of (typically rushed) people at an airport will notice that a website is loading over http instead of https? SSLsplit is pretty useful.

Does your bank, or whatever, not use hsts?

Last time I checked, about 2 years ago, none of the Swedish banks used HSTS. And a couple of them used HTTP on their main page and and HTTPS on their internet bank which was put on some weird domain. Chrome's changes has since then forced them to move everything to HTTPS but I would be very surprised if they all use HSTS now.
Post reply on HN