Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

241–250 of 281 posts

Re: VPN – Very Precarious Narrative

#241

Earlier quoted context omitted.

If Google has my data, does that mean I should also give it to Comcast? This kind of argument comes up a lot, and I really don't understand it, at all. Privacy is a process, it's something you improve over time. The alternative is completely circular. I shouldn't care about switching to Firefox, because my ISP is already getting all this data anyway, and I shouldn't care about using a VPN because Google is getting al…

My point is if you are trying to prevent someone to build a profile on you entirely then VPN is useless. For majority of the public who use a VPN provider, they are essentially shifting all the risks of their personal privacy from a highly regulated industry (ISP) to one that is much less regulated (VPN providers). This is a bit similar to all the ICO scams associated with an unregulated cryptocurrency industry. ISP…

> For majority of the public who use a VPN provider, they are essentially shifting all the risks of their personal privacy from a highly regulated industry (ISP) to one that is much less regulated (VPN providers).

But I don't like the logs that my ISP is _required_ to keep, an and the organisations that have access to them as a result. A VPN removes that.

> but there's no law in preventing a VPN provider not to do so

GDPR.

(for a UK perspective)

Re: VPN – Very Precarious Narrative

#242
post #125

Earlier quoted context omitted.

>most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? What percentage of (typically rushed) people at an airport will notice that a website is loading over http instead of https? SSLsplit is pretty useful.

Does your bank, or whatever, not use hsts?

My bank doesn't _and_ there's a redirect to a different domain (rbs.co.uk homepage does to personal.rbs.co.uk, rbs.co.uk/englandandwales or the login link goes to rbsdigital.com). Serve a redirect on the non-HTTPS rbs.co.uk to some other plausible domain with a valid HTTPS certificate, and I probably wouldn't notice.

Re: VPN – Very Precarious Narrative

#243

Earlier quoted context omitted.

>Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine that he's using an email service that doesn't use HTTPS. Because the Internet is more than the stuff that lives on port 443? What does the author do about UDP packets? It’s interesting that you mention email.…

That would imply the author cares enough about privacy / security to use VPN to hide for example POP3, but not enough to immediately drop an email provider which uses unencrypted POP3 service. And that's a strange argument.

Probably because a person can more trivially be taught vpn = privacy than understanding ANY of the details and be legitimately better off especially if they are doing other stupid things like using unencrypted pop3 or use the same password at random http site as they use on their bank.

Re: VPN – Very Precarious Narrative

#244

The articles like this are disastrous. So many people are using VPN to bypass government restrictions, protect themselves from ISPs, which are no longer run by idealists dreaming about uncensored access to information, but by managers, that will share your information with any agency the minute request shows up in their inbox. And these people don't always have good knowledge of how security works, and who this artic…

a) The unproven assumption you are making is that VPN providers are run by idealists, not by managers. There is no indication for this. b) The article outlines that using a VPN to bypass national censoring measures is perfectly valid. c) Your argument about the ISP knowing everything vs. the VPN provider knowing everything is exactly what the article is about. There is no indication to trust a VPN provider more than…

> a) The unproven assumption you are making is that VPN providers are run by idealists, not by managers. There is no indication for this.

Maybe you misread? I think he was saying the reverse.

Re: VPN – Very Precarious Narrative

#245
post #69
post #5

Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.

No it cannot be better. It can be only equally good or as bad as your ISP. Just because they claim that they protect your privacy that's just a blind faith. Users trusted PureVPN claims for protecting their privacy but all it took was an FBI investigation and through court documents to find out that they actually were keeping logs, despite all their claims.

>No it cannot be better. It can be only equally good or as bad as your ISP

False

>Just because they claim that they protect your privacy that's just a blind faith.

Even if this is the case, it does not make your previous statement true

Re: VPN – Very Precarious Narrative

#246
post #9

>However, the sad reality is, there is no such thing as a “no logs” VPN. Because running it would technically be impossible. PIA has told the feds in the US to fuck off multiple times when asked for logs. You can't provide what you don't have, and lying to the feds is a fast track to PMITA prison (PIA is based in the US). I feel pretty confident they're not risking prison to cover for Joe Blow subscriber. Other "no l…

Who cares if they log now? They can be forced to log --- and are in fact running businesses the practically beg the DOJ to force them to log.

>They can be forced to log

Not if they aren't in US, hence why so many people choose non-US VPNs

Re: VPN – Very Precarious Narrative

#247

Earlier quoted context omitted.

> They can be forced to log There is no legislation in the US that can be used to do this [1]. Some very misguided companies may voluntarily log, but those that care about privacy or, at the least, realize that holding people's data is a liability, won't make poor decisions like that. [1] https://en.wikipedia.org/wiki/Data_retention#Failed_mandator...

Oh come on now. The US Government forces tech companies to share information all the time. http://www.msnbc.com/msnbc/us-government-threatened-yahoo-bi... They certainly can, and will, go after any company they want to, without referencing any specific US legislation.

US companies perhaps. That's why so many recommend non-US VPN services

Re: VPN – Very Precarious Narrative

#248
post #16

Damn. I don't even know where to begin. It's true that VPN services at best provide less anonymity than Tor does. And that some, such as HideMyAss (which pwned that LulzSec dude) provide none. But PIA clearly does, as demonstrated now in two criminal investigations.[0] Of course, in both cases, defendants pwned themselves through poor OPSEC. But at least PIA didn't give them up. And the Facebook example. Nobody payin…

> And the Facebook example. Nobody paying attention expects a VPN service (or even Tor) to hide their identity if they login using their real name. That's just stupid.

A lot of users care about privacy, but have no idea how computer networking works. It's hard for these users to understand whether they're private or not. If you don't believe me, check out the tech support and recommendations over at old.reddit.com/r/vpn -- there's clearly a lack of knowledge about VPNs and computer networking. Probably once a week, someone will ask "How did [paid video streaming service) know I was using a VPN?" Or "X country can only spy on me if I have a VPN in that country, right?"

Re: VPN – Very Precarious Narrative

#250

There's a couple of bad faith arguments in this article that I didn't care for: - Regarding user identification, rolling my IP address is trivial with a VPN. Less so on my static IP. - The Facebook example without cookie deletion is a low-effort Straw Man - I reject the leap that "we have figured out that they [VPNs] do not add much to your online privacy". In the very narrow terms defined, yes of course, but either…

>I tunnel my traffic over a VPN to avoid my ISP building a profile on me.

What do you believe this profile is made of? I don't mean this sarcastically. Facebook or Equifax's profile of you must be very complete and contextual.

But, your ISP has:

- The domains you visited, but not the specific URLs (via SSL & certificate names)

- The domains you visited, but not the specific URLs (via DNS)

- The IPs you visited.

- The ports of those IPs.

- Any unencrypted traffic, which as noted, is pretty rare these days.

Do you believe that with this information your ISP can build a very meaningful profile? It seems to me that the profile which Amazon, Facebook, and a Bank, (VPN or not) can build is far more damaging. (and, I admit that just because you can't prevent the worse profiling, it doesn't mean you shouldn't mitigate what you can.)

I promise, I don't mean any of this in a negative way. I'm somewhat in your boat -- I tried to do a lot for privacy via blocking and other mitigations, but I often wonder: do Amazon and Gmail effectively defeat my efforts?

Post reply on HN