Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

271–280 of 281 posts

Re: VPN – Very Precarious Narrative

#271
I got a question:

So lets say you visit a website p0rn.xxx without a VPN, but this target website indeed gets HTTPS version of encryption, in such case, does your ISP know which website u visit?

Another case, when you connect to a VPN, your ISP indeed know you connected to an IP right?

Any more similar cases to let me learn more about what data gets encrypted and whats not?

Re: VPN – Very Precarious Narrative

#272
post #146

Earlier quoted context omitted.

It seems rival agencies (Chinese, Russian) should be interested in doing the same, or at least denying NSA this capability. I mean adding some exit nodes is not exactly expensive, seems like a low hanging fruit, doesn’t it?

Yeah, that's another argument. The NSA competes with its counterparts to own Tor infrastructure. And that competition prevents any one from owning enough to pwn users. And it's no accident. Tor was designed that way.

Listen-only access is non-exclusive, and works for packet correlation attacks.

Security wise, we really need to be moving away from this instantaneous-datagram model.

Re: VPN – Very Precarious Narrative

#273
post #5

Seems to ignore two things... a) Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. b) A VPN has some incentive to deliver on privacy. Your ISP does not. It's fair to call out that a VPN isn't perfect for either privacy or anonymity. But it clearly can be better than your ISP.

> Your ISP is almost always in the same legal jurisdiction as you are. A VPN need not be. Most of them are registered in five eyes countries, or twelve eyes. If they have anything in the US even if its just a single server they will claim jurisdiction over the lot. There are too many agreements and loopholes to rely on the whole jurisdiction thing. Unless you use a 100% Estonia VPN company and server with no other lo…

Yeah you are right totally agree with you. I m also using purevpn's 100% Estonia VPN company and 2000+ server spread across 180 locations including Estonia and surrounding regions.

Re: VPN – Very Precarious Narrative

#275

It seems that the author's target audience is highly non-technical readers. I'm not sure if the article does more harm than good by just citing existing technologies that aren't used by privacy-minded power users without pointing towards proven solutions as well, even if they may require effort to implement. All is not lost. The article touches on the OpenVPN protocol, "commercial" VPN providers (ExpressVPN in the sc…

I'd very much appreciate the write-up... I've not been able to find a very coherent (and current) best-practice document. Where can we find it when it's up?

Re: VPN – Very Precarious Narrative

#276
post #153

Earlier quoted context omitted.

I signed up for ExpressVPN before visiting China due to all sites recommending this (I badly wanted Google maps and Google to work). ExpressVPN does not work in China so either something changed very recently or a lot of people have been bribed to lie. I would not trust ExpressVPN anymore for anything.

ExpressVPN works well in China, although there was a week in March where it was very spotty. I'm using it right now. I agree that it's annoying how many review sites are getting paid to recommend them, but the service actually has been good for the last year. I've tested several VPNs here, including Mullvad and Nord. ExpressVPN has the fastest speeds by a quite a bit. However, self-hosted is much faster still. Unfort…

"Works in China" as an unqualified statement is useless, equally "ExpressVPN does not work in China."

Are you in Beijing or Shanghai? Are you on China Telecom or China Mobile? Are you using the Sweden 2 or the Hongkong 3 server? Every permutation of those variables can have a different answer, and that answer can change from day-to-day.

My experience is that in southern provinces and bigger cities it is _more likely_ to work at any given time. But things change.

> However, self-hosted is much faster still. Unfortunately, it's less reliable.

Using a CN2 VPS is definitely a :racecar: in my experience. I primarily use shadowsocks instead of a proper VPN because moving to a different port when the interference starts is usually sufficient.

Re: VPN – Very Precarious Narrative

#277
post #154
post #150

Earlier quoted context omitted.

> The web should be ideally end-to-end encrypted with HTTPS. No. People designing public access networks should use encryption and AP client isolation.

They should, of course. And for when they don’t, a VPN can protect you. That’s what the article is saying.

I'm responding to OP's comment, not the article.

Re: VPN – Very Precarious Narrative

#278
post #153

Earlier quoted context omitted.

ExpressVPN works well in China, although there was a week in March where it was very spotty. I'm using it right now. I agree that it's annoying how many review sites are getting paid to recommend them, but the service actually has been good for the last year. I've tested several VPNs here, including Mullvad and Nord. ExpressVPN has the fastest speeds by a quite a bit. However, self-hosted is much faster still. Unfort…

"Works in China" as an unqualified statement is useless, equally "ExpressVPN does not work in China." Are you in Beijing or Shanghai? Are you on China Telecom or China Mobile? Are you using the Sweden 2 or the Hongkong 3 server? Every permutation of those variables can have a different answer, and that answer can change from day-to-day. My experience is that in southern provinces and bigger cities it is _more likely_…

I disagree that the statement is useless, but here's some more info for you. I use China Telecom and China Mobile. Haven't tried China Unicom.

ExpressVPN has a message on most of their apps saying to use Tokyo 1, HK 4 or 5, Los Angeles 5, or UK Wembley when in China. I have used all of those servers, although HK 4 and 5 are the fastest.

I've used Shadowsocks and ShadowsocksR for my VPS. Switching ports will work for a while, but I've always found the server will get blocked eventually, possibly due to "active probing" as defined in this paper[1].

This person[2] suggests hosting a website from your Shadowsocks server as a cover, but I haven't tried it yet.

[1]https://conferences.sigcomm.org/imc/2015/papers/p445.pdf

[2]https://medium.com/@phoebecross/bypass-gfw-china-2019-dc5959...

Re: VPN – Very Precarious Narrative

#279
post #269

Earlier quoted context omitted.

Does this one end with you saying 'The Aristocrats!' because I really don't follow at all.

The Aristocrats? Lost me there, and I refuse to search. It's really very simple. The VM host that I'm using connects to a mainstream VPN service, which is quite popular for torrenting and such, using a server in the EU. Through that VPN tunnel, I connect with a different VPN service, which operates in someplace like Russia. Then, through that tunnel, I connect with a third VPN service, which operates in some ~neutral…

Why do you go through this amount of work for preserving your privacy? Honest question out of curiosity.

Re: VPN – Very Precarious Narrative

#280
post #228

> If you are using your device on a public network, VPNs can help you protect your data. I have a ProtonVPN subscription myself, just for those instances where I am sitting in an airport waiting for my plane Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine t…

I felt exactly the same way. I've run into people who have the idea that public wifi is insecure, as in don't hit your bank's website over that insecure channel. But in reality, the services that really need security are going over TLS, where at least the connection itself is secure (presuming that you are taking the same safeguards that you'd take on a "secure" network). In reality, no internet network is naturally…

Right, and he's not counting the metadata an ISP or wifi provider can be collecting about you, they might not be able to see your private traffic to your bank, but now they know who you bank with. You might be passing that information on to ProtonVPN, but I'm more afraid of what someone sniffing wifi traffic can find out about me than a service I'm paying for, its about the same risk with my ISP. AT&T even collects data from its consumers.
Post reply on HN