Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

231–240 of 281 posts

Re: VPN – Very Precarious Narrative

#231
Has anybody evaluated whole-network hardware filter+VPN solutions that filter cookies ( such as Winston https://winstonprivacy.com/ ) in the context of this article? I was planning on testing Winston at some point at my home, but Winston requires a separated modem and router as opposed to the combo box I have.

I think the declarations in the article do confuse the issue a bit - some of the benefits of a VPN such protecting against DNS logging are real but are probably not as useful to VPN marketing people as a "pitch", because they're a bit tougher to explain to laypersons.

Re: VPN – Very Precarious Narrative

#233
post #210
post #202

Earlier quoted context omitted.

What would you consider the best/easiest way to setup your own?

I am running strongswan[1] with IKEv2 on cheap (10$ per year) VPS in Amsterdam, Netherlands. Or you can google for how to set up your own VPN on AWS/Google Cloud free tier. [1] https://wiki.strongswan.org/projects/strongswan/wiki/UserDoc... [2] https://medium.com/@tatianaensslin/how-to-create-a-free-pers...

IKEv2 is solid, fast and secure. And major OSes have native VPN clients, including iOS - no need to use 3rd party client software.

Re: VPN – Very Precarious Narrative

#234

> If you are using your device on a public network, VPNs can help you protect your data. I have a ProtonVPN subscription myself, just for those instances where I am sitting in an airport waiting for my plane Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine t…

Im actually glad that the author pointed out that once you log in somewhere that will track you, that connection is associated with you. A vpn is not a cure-all. It is only as private as you're willing to make it. If you want to pirate movies and chat on facebook at the same time, you're probably gonna have a bad time. What you do is absolutely a part of your advertising/tracking profile. Payment information - some p…

> If you want to pirate movies and chat on facebook at the same time, you're probably gonna have a bad time.

Not really. There's not a single documented case of a major VPN user ever receiving a copyright infringement notice. Despite the fact that millions use this exact same use case.

In security it's always important to understand the threat model. If I know I'm being personally targeted by Mossad, that's a very different story than if I'm trying to avoid getting identified in a mass copyright notice from the MPAA.

Facebook would never ever ever in a million years voluntarily give the MPAA unrestricted root access to their IP level user tracking data. If they tried to subpoena it, Facebook can afford much much better lawyers than Warner Brothers.

And I guarantee that at least in the American judicial system, any judge is going to be extremely skeptical against such a sweeping request.

Re: VPN – Very Precarious Narrative

#235
post #27
post #20

Earlier quoted context omitted.

So what protection does a foreign VPN provider have from the NSA? The answer: None.

If your threat model includes NSA you need to reconsider lot more than just a VPN

Disk encryption, firmware lockdown, home security with notifications, burner phones, Tails and Tor (via VPN), IRC, fleet of hacked Windows machines to route through, 10 online identities.

Re: VPN – Very Precarious Narrative

#236
post #16

Damn. I don't even know where to begin. It's true that VPN services at best provide less anonymity than Tor does. And that some, such as HideMyAss (which pwned that LulzSec dude) provide none. But PIA clearly does, as demonstrated now in two criminal investigations.[0] Of course, in both cases, defendants pwned themselves through poor OPSEC. But at least PIA didn't give them up. And the Facebook example. Nobody payin…

If we talking OPSEC, PIA of out, as any other with your payment info. You'll need to have few different anonymous VPNs and self hosted VPNs/proxies to make random chains. Pay by coins only, throwaway emails.

Re: VPN – Very Precarious Narrative

#237
post #36
post #9

Earlier quoted context omitted.

Who cares if they log now? They can be forced to log --- and are in fact running businesses the practically beg the DOJ to force them to log.

Which is why many people don't use US-based VPN services.

So that, instead of the US using legal formalisms to gain access to your data, they can simply (under our law) hack it directly? While at the same time, whatever host country is involved can use their legal formalisms to get access to the data? How is that helping you?

Re: VPN – Very Precarious Narrative

#238
The only way to get on a network is via an ISP or mobile provider and this step itself gives up your identity and credit card/financial details and your browsing history, location data and other metadata is available to any state entity and the private surveillance economy. If you use a VPN you paid for that is the same thing.

There is no way to get absolute privacy in this context for the average user. Journalists and activists should be aware there is no technology solution to protect them from spying by any sufficiently committed actor, with state actors all bets are off.

It's false self empowerment by some technical folks to presume there is a technical solution against state actors who are well staffed, have near endless resources and are working 24/7 to thwart any localized technical solutions.

If there is a way to get online truly anonymously ie public wifi points, mesh networks these will immediately be subverted by state actors with things like illegal porn, terrorism and made illegal or compromised and used as honey pots. There is no winning here.

Re: VPN – Very Precarious Narrative

#240
post #228

> If you are using your device on a public network, VPNs can help you protect your data. I have a ProtonVPN subscription myself, just for those instances where I am sitting in an airport waiting for my plane Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine t…

I felt exactly the same way. I've run into people who have the idea that public wifi is insecure, as in don't hit your bank's website over that insecure channel. But in reality, the services that really need security are going over TLS, where at least the connection itself is secure (presuming that you are taking the same safeguards that you'd take on a "secure" network). In reality, no internet network is naturally…

The bigger issue with public wifi is even actually finding your bank's server in the first place. HSTS largely saves the day here, but is far from universal. If any non TLS requests are in the request chain, and you don't have an eagle eye on the address bar, all bets are off.
Post reply on HN