Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

181–190 of 281 posts

Re: VPN – Very Precarious Narrative

#181
post #5

Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.

Not only does my ISP have no "incentive to deliver on privacy, my ISP is _legally required_ not to deliver on privacy. They are by law in the tinpot jurisdiction I live in, required to retain all "meta data" about my internet connection, and provide it to "law enforcement" which has turned out to include not just terrorist and serious drug crime divisions of the police, but also local council garbage services and the…

After reading the first sentence of your reply I (correctly) guessed which country you were talking about. It's a depressing state of affairs for sure.

Re: VPN – Very Precarious Narrative

#182
post #43

The slimy marketing around centralized VPN services is why I consider it a point of pride to include the following as a "feature" in the AlgoVPN readme ( > Anti-features > * Does not support legacy cipher suites or protocols like L2TP, IKEv1, or RSA > * Does not install Tor, OpenVPN, or other risky servers > * Does not depend on the security of TLS > * Does not require client software on most platforms > * Does not c…

> * Does not install Tor, OpenVPN, or other risky servers

What do you mean by "risky servers" here? I run OpenVPN on a few servers, is there something I should know?

Re: VPN – Very Precarious Narrative

#183
post #175

Earlier quoted context omitted.

How exactly is the airport supposed to offer a WiFi network that is encrypted and open without breaking usability and compatibility? This hasn't been possible until WPA3, which has barely started rolling out.

Many ways to do this. Make the password widely-known. Announce it over the intercom. Post it on the walls. Offer both encrypted and non-encrypted SSIDs. The non-encrypted SSID could even just be a captive portal with instructions to connect to the encrypted SSID. If you're feeling wild, use WPA2 Enterprise, and accept any credentials.

Doesn't the widely-known password render the encryption useless to anyone that has captured the 4-way handshake at the beginning of your WIFI-session? With the PSK and your session keys an attacker can decrypt your traffic if I remember it correctly.

Re: VPN – Very Precarious Narrative

#184
The reason people pay for these "VPN services" is trying to hide from the extortionists and even the law in some countries, when using BitTorrent to download the latest GoT episode?

All other problems aside, how successful defence against that is this? Article doesn't adress that as far as I could see.

Re: VPN – Very Precarious Narrative

#185
post #21

Earlier quoted context omitted.

> b) A VPN has some incentive to deliver on privacy. Your ISP does not. Regarding this point, I think a good strategy here is to acknowledge that ISPs, like most organizations, don’t want to add to their workloads. Of course they aren’t privacy centric, but appeals to them oriented around _not_ having to store a bunch of logs or set up a bunch of processes can help to unite more people around initiatives to make thin…

Yes, VPNs might be unjustly talked about as a set-it-and-forget-it way to gain privacy online a bit, but what I find far more harmful is the blind trust people seem to have in their ISP. I often see the argument "You are just shifting trust from one company (ISP) to another (VPN).", yes, that might actually be the whole point. ISPs can't be blindly trusted. I switched ISPs lately because my previous one started offer…

What's happening is the service providers are realising that a lot of lucrative billion dollar businesses have been built by selling ads on top of their last-mile services, they might as well do the same. In India, the companies that are ISPs are also Cable Providers and Mobile Network Providers. They have been caught MiTMing Https to inject ads. They do it cause they want their share of the internet ad revenue cake.

What's strange is that Belgium, in the post-GDPR world, has businesses with regressive behaviour wrt user profiling. What gives?

Re: VPN – Very Precarious Narrative

#186
post #5

Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.

People from the First World have no idea that porn and politically sensitive content is blocked in so many countries. Youtube is heavily censored - you won't be able to watch Charlie Chaplin movies or some lectures on Greek democracy in Thailand.

Also this censoring is poorly executed by some ISPs via simple DNS hijacking. As a result your connection is slow and with terrible jitter.

As for the proverbial airport/cafe WiFi - using VPN is not about not beeing tracked - it is about blocking easy access to your laptops filesystem by attacker on the same network.

Also if you do not trust commercial VPN provider just set up your own.

Re: VPN – Very Precarious Narrative

#187

> If you are using your device on a public network, VPNs can help you protect your data. I have a ProtonVPN subscription myself, just for those instances where I am sitting in an airport waiting for my plane Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine t…

I can't help but shake my head at this whole argument. For literally years I've been telling people that a VPN run by a third party does not enhance privacy or security, but because the consensus is "VPN = secure" it's a losing battle, and I sound like a tinfoil-hat-wearing loon. Most VPN services are not designed to provide privacy or security, and if you have a subscription to one, that's probably not the reason yo…

I don't think your analysis is complete.

Most VPN's raison d'être is providing privacy. If it's publicly known that they don't then that kills their business.

An ISP is tasked with connecting prior to the internet, they don't make claims about privacy, they can reveal information about clients without necessarily putting anyone off, most of the clients for large ISPs have probably never heard of a VPN.

If a VPN wanted to they could get audits by pen-testers to warrant their ability to provide secrecy.

A VPN provider that's been around a while and claims to offer a high level of privacy probably does.

Slight aside:

>My ISP can see the domain name of the result I click, and a VPN would mask that from them. //

There was a paper a little while ago, they directly identified pages by mitm-ing HTTPS by using meta-data (page size alone IIRC). Success was something like 80%.

Re: VPN – Very Precarious Narrative

#188
post #21
post #5

Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.

> b) A VPN has some incentive to deliver on privacy. Your ISP does not. Regarding this point, I think a good strategy here is to acknowledge that ISPs, like most organizations, don’t want to add to their workloads. Of course they aren’t privacy centric, but appeals to them oriented around _not_ having to store a bunch of logs or set up a bunch of processes can help to unite more people around initiatives to make thin…

If regulations require ISPs keep logs, or if they can make a profit from those logs then the workload is justified in reducing losses (fines from regulatory noncompliance) or increasing profits.

Re: VPN – Very Precarious Narrative

#189
post #20
post #5

Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.

So what protection does a foreign VPN provider have from the NSA? The answer: None.

A foreign provide surely has more, in the legal realm, than a domestic one?

Re: VPN – Very Precarious Narrative

#190

>However, the sad reality is, there is no such thing as a “no logs” VPN. Because running it would technically be impossible. PIA has told the feds in the US to fuck off multiple times when asked for logs. You can't provide what you don't have, and lying to the feds is a fast track to PMITA prison (PIA is based in the US). I feel pretty confident they're not risking prison to cover for Joe Blow subscriber. Other "no l…

What about European based/GDPR compliant VPNs? Wouldn't they require to truthfully disclose if and what they log?

For what it's worth, Poland is surprisingly good about this:

- as an ISP, you're required to retain data for a year that would let LEAs map an IP address you manage to a subscriber. If you're giving out public IP addresses to your customers, this can be just an excerpt from your IPAM.

- as an ISP, you cannot give out this data without a court order, and you will be in violation of data protection laws if you do do.

Source: the Warsaw Hackerspace is an ISP.

Post reply on HN