Some of them are valid concerns. But the article should have touched on _how_ one would actually achieve the privacy levels that the VPNs claims to offer. For example, using TOR rather than a VPN is a much better guarantee of privacy against IP based tracking (and what the draw-backs of TOR is - such as accidental real-ip leaks via javascript). A lot of users simply trust the marketing of VPN providers - because it's…
VPN – Very Precarious Narrative
161–170 of 281 posts
Re: VPN – Very Precarious Narrative
#162The articles like this are disastrous. So many people are using VPN to bypass government restrictions, protect themselves from ISPs, which are no longer run by idealists dreaming about uncensored access to information, but by managers, that will share your information with any agency the minute request shows up in their inbox. And these people don't always have good knowledge of how security works, and who this artic…
Re: VPN – Very Precarious Narrative
#163The slimy marketing around centralized VPN services is why I consider it a point of pride to include the following as a "feature" in the AlgoVPN readme ( > Anti-features > * Does not support legacy cipher suites or protocols like L2TP, IKEv1, or RSA > * Does not install Tor, OpenVPN, or other risky servers > * Does not depend on the security of TLS > * Does not require client software on most platforms > * Does not c…
FSM == Flying Spaghetti Monster?
Re: VPN – Very Precarious Narrative
#164There is a lot of marketing, agreed. However, those messages do serve a purpose - they make it clear you configured that particular VPN correctly and that it works.
> IP addresses for user identification
Yes, there are more factors than just IP. Clear cookies, use uBlock Origin and HTTPS Everywhere, and know you can be tracked anyways, especially if you log in to the sites you have ever used without a VPN. For stronger privacy protections, use Tor Browser over Tor - Tor is better in terms of privacy, but due to Tor being heavily abused, a lot of services outright block Tor IPs or put you into reCAPTCHA hell, so it's not really suitable for day-to-day browsing, unlike a VPN you can set up and leave it turned on all the time.
> Location leaking
It's not always the case that the IP provides inaccurate information. Out of curiosity, I disabled the VPN, and went to https://www.privateinternetaccess.com/pages/whats-my-ip/. The guessed location was within 120 meters of an actual location, on the same street, in a big city. Sure, it doesn't point to an actual building, but it is dangerously close.
Just to be clear here, I don't use PIA as my VPN, they have a good demonstration of an issue however.
> “Network Encryption”
This is accurate. Part of why having HTTPS everywhere improves the security. Keep in mind however that SNI and the IP you are connecting to is not encrypted. This may change however soon (while you cannot really "encrypt" IP, a lot of websites are using services like Cloudflare, essentially preventing anyone on a path from guessing the website you are connecting to).
> What about “DNS leakage”?
The thing about DNS is that if you are using your ISP DNS while using a VPN, you are leaking an information about your ISP. To prevent DNS leaks, you should be using a DNS provider not provided by your ISP, and if you don't have any idea which DNS to pick, many VPNs provide their own DNS.
> The “no logs” thing
The article is arguing that paying with a payment card will leak your identity. This is true. Pay with cash, gift cards, or cryptocurrency (although this is a complicated subject, Bitcoin is tricky to pay privately with, I use Monero myself for VPN payments).
About logging, this is a complicated subject. The answer is: you have to trust the VPN. Read the privacy policy to tell how serious they are about "not logging anything". Generally, avoid any VPN that over-promises what it can do, a VPN is not "100% effective" whatever that means. Look out for conflicting messages in privacy policy, anything that goes "we don't log" and then later "except we log" should be avoided.
As for trusting your ISP - look, most ISPs don't promise "not logging", and in fact, where I live, they have an obligation to log.
In the end, don't rely on "no log" policy. It should be here, but assume the VPN is actually logging.
> Using a VPN does not make you anonymous.
Yes. If you violate the law, unless you are really careful, the law enforcement will find you. The police may be able to ask Google to provide details of an e-mail account using this IP address (from your VPN). VPN will however protect you people finding your IP address, contacting your ISP claiming to be a copyright owner needing user's details for a lawsuit - most ISPs will just give the details with this simple attack, and it doesn't matter whether you have downloaded or not, "no logs" VPNs won't.
In short, a VPN won't magically protect your address if you send it over the Internet. It cannot do that.
> Security issues in VPNs and their clients
Yes. All software can have vulnerabilities, this is nothing new. To improve your security, don't use the official VPN client but use an OpenVPN/WireGuard configuration file - if a VPN doesn't provide it, then don't use it.
> VPNs are a central point for attackers
So is your ISP. All software can have vulnerabilities.
Re: VPN – Very Precarious Narrative
#165I see people commenting ‘I use company X, they are great’ seemingly ignoring the fact that they have no real clue as to what Company X is actually doing.
Re: VPN – Very Precarious Narrative
#166Here's why I think using a VPN makes sense:
1. ISPs cannot track and mitm you. ISPs have MiTMd https [1].
2. Circumvent censorship, esp DNS manipulation attacks.
3. Prevent use profiling: traffic meta-data analysis (what IPs you connect to, what protocols you're using and so on) [2].
4. A lot of propaganda is targeted at a demography in a particular location. Tunneling traffic through a VPN might mask your location unless the app or website had access to it prior, and fingerprinted you already [3].
Sophisticated actors can still do all of the above VPNs or not.
The trackers have it too easy and use IP addresses as a signal. Masking IP address is one signal less. Then, up the stack at the application layer, it's up to the end user to make saner choices. That isn't on a VPN provider or Tor.
VPNs could def do better:
1. Firewall known trackers server-side. Similar to how how browsers today block known rouge websites that have been caught phishing or spreading malware.
2. Stripe traffic over multiple exit IPs. Much like Firefox's multi-account containers.
3. Let the end user analyse their traffic client-side, and help them take control over what the client should send and not send.
4. Open-source their stack, and provide ability to inspect what's running on the servers.
5. Provide technically better internet experience by accelerating traffic over uncongested paths, provide better connectivity over lossy networks [4][5].
If VPNs aren't improving the experience and if IP masking is all you need, then remember, Tor is free [6], and is pretty decent in terms of speed and latency these days.
--
[0] https://trac.torproject.org/projects/tor/wiki/doc/Transparen...
[1] https://news.ycombinator.com/item?id=495830
[2] https://news.ycombinator.com/item?id=11278784
[3] https://panopticlick.eff.org
[4] https://blog.cloudflare.com/1111-warp-better-vpn/
Re: VPN – Very Precarious Narrative
#167Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.
They are by law in the tinpot jurisdiction I live in, required to retain all "meta data" about my internet connection, and provide it to "law enforcement" which has turned out to include not just terrorist and serious drug crime divisions of the police, but also local council garbage services and the taxi commission.
All I need from a VPN service is for it to be slightly more difficult to request all the data invading my privacy than the mandatory legal disclosure of it that I'm subject to anyway. Anything beyond time-zone slowness and paperwork incompetence is just a bonus. I prefer VPN providers based in France or Finland or Iceland - on the perhaps vaguely over reliant on bad stereotypes theory that they'll put English language requests at the bottom of the pile, and that the Sydney Taxi Commission won't have an Icelandic speaker on hand to ask them for my internet date records...
Even if they keep all traffic logs, and even if they happily turn it over without a fight to anyone who can fake a plausible looking LEO email address from Australia, I'm still ahead in at least some important waays privacy-wise over not running a VPN at all... If they really don't keep logs, or really will push back against LEO requests without proper warrants, even better. But not doing that doesn't;t make them useless...
Re: VPN – Very Precarious Narrative
#168> If you are using your device on a public network, VPNs can help you protect your data. I have a ProtonVPN subscription myself, just for those instances where I am sitting in an airport waiting for my plane Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine t…
Re: VPN – Very Precarious Narrative
#169> If you are using your device on a public network, VPNs can help you protect your data. I have a ProtonVPN subscription myself, just for those instances where I am sitting in an airport waiting for my plane Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine t…
Because the Internet is more than the stuff that lives on port 443?
What does the author do about UDP packets?
It’s interesting that you mention email. SMTP can use TLS of course but I know of plenty of POP3 email providers that still send unencrypted and even if it were, it’s not using HTTPS.
What about DNS requests too? Those are still often sent in cleartext.
Even with actual HTTPS with a browser, the domain itself is visible.
In short - the Internet is not just the web.
Re: VPN – Very Precarious Narrative
#170> If you are using your device on a public network, VPNs can help you protect your data. I have a ProtonVPN subscription myself, just for those instances where I am sitting in an airport waiting for my plane Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine t…
For literally years I've been telling people that a VPN run by a third party does not enhance privacy or security, but because the consensus is "VPN = secure" it's a losing battle, and I sound like a tinfoil-hat-wearing loon.
Most VPN services are not designed to provide privacy or security, and if you have a subscription to one, that's probably not the reason you bought it either. They're designed to provide the minimal amount of traffic hiding required to allow you to pirate TV/movies/video games without getting in trouble or hitting blocked URLs. And it works, or you wouldn't still have the subscription.
Now, as both the buyer and the seller need a non-shady cover story, they describe hiding your suspect downloads as "security and privacy" - it's not utterly inaccurate, but it implies far more than what's happening.
The problem with the narrative is that it makes laypeople think they are "more secure" when using a VPN, when in reality, the opposite is true.
As an example, when I perform a Google search, my traffic is encrypted over SSL, so my ISP can't see that. My ISP can see the domain name of the result I click, and a VPN would mask that from them. But now a new third party (the VPN provider) can see that instead. This makes sense if you're downloading pirated media (as the VPN service doesn't care), but the buyer is in effect trading:
1) An ISP, which is in most western countries heavily regulated, with legal commitments to auditing and your privacy (just not from law enforcement).
for:
2) Some computer somewhere that is run by an utterly unregulated company or individual that may or may not know how to configure OpenVPN correctly and that you don't know anything about, other than they run a shady business based on allowing you to download pirate files on the internet. Also they're not at all regulated or audited, and may not even be in a jurisdiction that requires them to protect your data at all.
Given this trade-off, trusting a VPN to do a better job of protected your privacy than an ISP seems like madness to me, given that they could easily sell whatever information they have on you on and there's nothing you can do about it (and you'd likely never find out). It may not even be a crime depending on where they're located.
There's arguments for VPN in preference to unsecured Wi-Fi, but in reality, how often is that an issue? How many scenarios are there where you can't use mobile data instead? (And even where/when you can't, you still have all the downsides above which may or may not be better).