Earlier quoted context omitted.
I find tor is usually just fine for coffee shop browsing. I went to a couple that blocked it someway or other though. Most are no issue.
Yes but tor is slow, making it slightly less practical than the tunnel through the VPS. It also doesn't hide your traffic from the exit nodes, who may be less trustworthy than a VPS provider if you are doing strictly legal things. (On the other hand, if you want to perform a public service, using tor is a good way of masking the traffic of people who actually want to use it to disseminate sensitive information.)
NordVPN disables features when you turn off auto-renew
231–238 of 238 posts
Re: NordVPN disables features when you turn off auto-renew
#232Earlier quoted context omitted.
Yes but tor is slow, making it slightly less practical than the tunnel through the VPS. It also doesn't hide your traffic from the exit nodes, who may be less trustworthy than a VPS provider if you are doing strictly legal things. (On the other hand, if you want to perform a public service, using tor is a good way of masking the traffic of people who actually want to use it to disseminate sensitive information.)
The premise of Tor is exactly that you need not trust any of the nodes. The only exception being, all of the nodes in your path being controlled by the same entity. But an exit node knowing that an anonymous user has an encrypted connection to a specific site is usually not a privacy concern.
> non-https websites from coffee shops
If the website you are accessing is unencrypted then the exit node knows the entirety of your communication with it. (It doesn't know your IP; but small consolation. You're still vulnerable e.g. to injection.)
Re: NordVPN disables features when you turn off auto-renew
#233Earlier quoted context omitted.
I think it's at least conceptually possible to pre-load a machine with software that doesn't pass any plaintext between you and it, and which the software image can't be modified without you knowing it. I don't know about obscuring the fact of the connection between you and it though. Tor isn't enough by itself.
> which the software image can't be modified without you knowing it. Nah. If you're worried about the kind of attacks that necessitate sending your own hardware, then, regardless of who owns title to the device, the firmware being replaced to snoop on or alter what is actually in RAM is in-bounds. There are lots of ways of hiding persistence on a system, and decades of research along these lines. Once it leaves your…
Why don't they just desolder the cpu and wire up an emulator and laugh at all those secure enclaves and encryption?
Re: NordVPN disables features when you turn off auto-renew
#234Earlier quoted context omitted.
> which the software image can't be modified without you knowing it. Nah. If you're worried about the kind of attacks that necessitate sending your own hardware, then, regardless of who owns title to the device, the firmware being replaced to snoop on or alter what is actually in RAM is in-bounds. There are lots of ways of hiding persistence on a system, and decades of research along these lines. Once it leaves your…
Then why can't the entire FBI break in to an ordinary iphone, except by virtue of finding errors in implementation rather than the fundamental invalidity of the concept of secure hardware? Why don't they just desolder the cpu and wire up an emulator and laugh at all those secure enclaves and encryption?
Apple can decrypt the whole thing without any input from the user: they don't need their phone, they don't need their password, they don't need their keys.
The whole thing was a carefully orchestrated media dance designed to make it seem like the feds can't get the data off of iPhones. Not only do they have access to almost all of the data on almost every iPhone, they have access to it without a warrant or probable cause thanks to the FISA Amendments Act. Apple compromised over 30,000 accounts for the US government without a warrant in 2019, per Apple's own transparency report.
Re: NordVPN disables features when you turn off auto-renew
#235Earlier quoted context omitted.
If you're serious , you use tor. If just you want to torrent the last season of game of thrones (why would you?) then a reasonably reputable no-log vpn service will probably do a perfectly fine job. If you want to access non-https websites from coffee shops, buy a $5/mo vps from amazon/prgmr/digitalocean/whomever and tunnel through it. I don't see a situation in which the dedicated colocated hardware is the right cho…
If you're super super serious, can you even trust Tor? I personally give it better than 50% chance that some consortium of goverments control the majority of tor exit points but won't reveal it for small cases so as not to reveal this trick.
Probably yes, but it does not necessarily break your anonymity for https websites.
Re: NordVPN disables features when you turn off auto-renew
#236From the thread: >The secret to not dealing with crapty company practices is to avoid ones that advertise literally everywhere 24/7 nonstop around every single corner you look. This is so true it nearly qualifies as physics.
my goto explanation for this is the crappiest companies out there have highest profit margin simply because they have a whole host of bad practices available to pick from. that basically means they have most resources to burn on marketing & promotion.. egro most highly advertised stuff is what one should avoid the most.
It's kind of like a wooden building burning down: something that was previously in stable, long-term equilibrium state (no fire, no energy release, serving a useful purpose) switches suddenly to a runaway reaction (exponentially accelerating, pulling in more and more reactants from the environment, serving no useful purpose.)
Re: NordVPN disables features when you turn off auto-renew
#237Earlier quoted context omitted.
> You have now shifted your trust from your VPN provider to certificate authorities. Don't you have to trust the CAs in any case?
There are 168 root certificates in macOS and 255 in Windows.
Re: NordVPN disables features when you turn off auto-renew
#238Why are these VPNs even a thing? The only reason i would use one is to get cheaper steam keys from brasil and for that i can get a free one. From a security standpoint it is awful because you increase the number of providers you have to trust. Apart from your ISP and the server you connect to, you got a third party involved for no reason. And VPNs can not that trustworhty as shown by the leaks of logs and what not. M…
One reason is to help reduce some identifying information Ad networks and the like might collect since a common IP is shared among many users. There are disadvantages too but this is something you won’t get with self hosting. Also ISPs in the US are able to sell your browsing history ( https://protonmail.com/blog/private-browsing-history/ ) but I believe this can be mitigated by DOH.
And HTTP will always reveal the host name with or without DOH.