Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

31–40 of 281 posts

Re: VPN – Very Precarious Narrative

#31
post #26

Earlier quoted context omitted.

It's called Tor. And you don't even need a subscription for that.

I thought with tor you still connect to a single gateway and all traffic is sent to that remote endpoint? Or is it done locally?

Tor, originally from "The Onion Router", works by routing your traffic through multiple Tor nodes. Like an onion, each node only peels off one layer and passes the packet on to whoever is addressed on that layer. Each node only knows the details about the next node. Eventually, the packet will hit an "Exit-Node", at which point it will be routed via the internet through the endpoint, but it's not a single route.

And while that does not change for every request (that would be highly unpractical), all Tor clients offer you a very quick "get a new route" with just one click.

Re: VPN – Very Precarious Narrative

#32
post #29

Earlier quoted context omitted.

> Indeed here in Canada ISPs have frequently given subscriber contact information to copyright holders to issue warnings based on bittorrent usage without being legally required to. Citation needed? The “Notice and Notice” regime legally requires the ISP to pass along a notice from a copyright holder that believes your IP infringed their copyright by uploading their material. It does not permit the ISP to give subscr…

> It does not permit the ISP to give subscriber information to the copyright holder directly unless ordered to do so by a court. With honest VPNs, court orders won't yield anything.

Sure. OP is still pulling that claim out of his nether regions, though

Re: VPN – Very Precarious Narrative

#33
Author has a computer science understanding of VPNs but is breathtakingly ignorant as to the actual use cases of commercial VPNs. They're used for getting around geoocming and media throttling sure, but the biggest use is piracy.

Also, his disbelief of anonymous payment methods is incredibly stupid. I can walk into a store right now and get a prepaid visa using cash, no crypto currency shenanigans required.

Re: VPN – Very Precarious Narrative

#34
I have kind of a lot of issues.

First, the downplaying of IP location lookups. If you do a lookup on my home IP address, it'll get you within 5 miles of my house. From there, the only other information you need is my name and potentially one or two more details like a birthday (easy, I use my real name online) and you can get access to my voting data -- and that'll give you an actual address, not just a zip code.

OP is correct that your IP address doesn't directly leak your home address, but in many cases it can be a pretty helpful clue. In a small town, a zip code and a name can be good enough on its own for a stalker to find someone even without voting data or public records to pull from.

OP is also correct in that there are plenty of other ways to get this data, but I fail to see how opening yet another trivial hole in my identity helps with that.

Second, the downplaying of encryption concerns. We've come a long way on SSL, but it's frankly irresponsible to say that users should just assume all of their browsing will automatically be covered, regardless of what the top sites are doing. I am primarily visiting tech sites nowadays and I still occasionally run into sites that aren't encrypted. And that's nothing to say to the fact that there are multiple ways of configuring SSL and not all of them are equally secure.

This is just in my browser, which punishes sites with insecure warnings if they're not encrypted. How many native apps are sending unencrypted data given that there's no punishment and that the user gets zero indication of the SSL status? We know from the IOT industry that a lot of these products and apps are regularly getting rushed out the door.

Of course, VPNs only encrypts the data between you and the provider. But we don't live in a world where people are primarily using desktop computers. Most users are going to be on tablets, phones, and laptops, and they travel. And no, public networks are not the only risks -- even if a network forces you to put in a password you still don't know how that network is configured, you still don't know what vulnerabilities exist on it.

If you don't know who set up the network, you should treat it as if any unencrypted data could be intercepted before it reaches the router. And you should be suspicious of the router/provider itself, particularly if it's wifi being offered by a store/hotel/airport, or other commercial entity.

And that leads to the final, big objection -- the idea that VPNs are harmful because all they do is shift the trust model. If you're in the US, unless you are very, very lucky, you can not trust your ISP. Shifting the trust model is not a fatal flaw, it is literally the entire point.

Yes, needing to trust someone is not ideal. But my VPN provider has more of an incentive to take care of my data than my ISP does. If you're using something like Proton or PIA, then I feel very confident saying that I trust both of them more than Verizon or Comcast.

So I agree that bulletproof claims that come from VPNs are often inaccurate. I agree that there are problems. I don't see this article as any less sensationalist and inaccurate than the provider claims though. VPNs are just a kind crappy solution we're stuck with, and absent everyone moving to Tor, I have yet to see anyone propose a better solution.

Re: VPN – Very Precarious Narrative

#35
post #9

>However, the sad reality is, there is no such thing as a “no logs” VPN. Because running it would technically be impossible. PIA has told the feds in the US to fuck off multiple times when asked for logs. You can't provide what you don't have, and lying to the feds is a fast track to PMITA prison (PIA is based in the US). I feel pretty confident they're not risking prison to cover for Joe Blow subscriber. Other "no l…

Who cares if they log now? They can be forced to log --- and are in fact running businesses the practically beg the DOJ to force them to log.

> They can be forced to log

There is no legislation in the US that can be used to do this [1]. Some very misguided companies may voluntarily log, but those that care about privacy or, at the least, realize that holding people's data is a liability, won't make poor decisions like that.

[1] https://en.wikipedia.org/wiki/Data_retention#Failed_mandator...

Re: VPN – Very Precarious Narrative

#36
post #9

>However, the sad reality is, there is no such thing as a “no logs” VPN. Because running it would technically be impossible. PIA has told the feds in the US to fuck off multiple times when asked for logs. You can't provide what you don't have, and lying to the feds is a fast track to PMITA prison (PIA is based in the US). I feel pretty confident they're not risking prison to cover for Joe Blow subscriber. Other "no l…

Who cares if they log now? They can be forced to log --- and are in fact running businesses the practically beg the DOJ to force them to log.

Which is why many people don't use US-based VPN services.

Re: VPN – Very Precarious Narrative

#37

Author has a computer science understanding of VPNs but is breathtakingly ignorant as to the actual use cases of commercial VPNs. They're used for getting around geoocming and media throttling sure, but the biggest use is piracy. Also, his disbelief of anonymous payment methods is incredibly stupid. I can walk into a store right now and get a prepaid visa using cash, no crypto currency shenanigans required.

That's amazing that you can do that.

Anonymous credit cards are ruled out by law basically everywhere in the European Union. Assuming that I live in the US, and that everyone on this planets is doing so, is - as you call it - incredibly stupid.

Re: VPN – Very Precarious Narrative

#38
post #30

I use VPNs for one main reason: so that my ISP does not build a complete profile of me based on the sites I'm visiting. This can be mitigated to a certain extent by using a VPN. I do not expect to become anonymous or invisible on the internet all of a sudden, I just do not want the guy listening next to my front door to know everything about me. In the US, where personal data is a free-for-all and everybody and their…

The ISP can easily build a reasonably reliable profile based just on packet size and timing. TLS and most VPNs do nothing to these.

If they actually wanted to. You could sure them under wiretapping laws if they did.

If you cannot trust your ISP, you cannot really have any privacy without truly extensive measures. Not even Tor is enough, it does not pad and change timing enough.

The real problem is cookies, requirement for email backed login and phone home downloads. (E.g. images such as social buttons, JavaScript. They can also leak cookies or make them live longer.)

The last one is combatted to an extent by mix networks like Tor, or better yet, by aggressively caching and/or predownloading.

Re: VPN – Very Precarious Narrative

#39
post #26

Earlier quoted context omitted.

I thought with tor you still connect to a single gateway and all traffic is sent to that remote endpoint? Or is it done locally?

Tor, originally from "The Onion Router", works by routing your traffic through multiple Tor nodes. Like an onion, each node only peels off one layer and passes the packet on to whoever is addressed on that layer. Each node only knows the details about the next node. Eventually, the packet will hit an "Exit-Node", at which point it will be routed via the internet through the endpoint, but it's not a single route. And…

Thanks for clarifying.

Re: VPN – Very Precarious Narrative

#40
post #26

Earlier quoted context omitted.

I thought with tor you still connect to a single gateway and all traffic is sent to that remote endpoint? Or is it done locally?

Tor, originally from "The Onion Router", works by routing your traffic through multiple Tor nodes. Like an onion, each node only peels off one layer and passes the packet on to whoever is addressed on that layer. Each node only knows the details about the next node. Eventually, the packet will hit an "Exit-Node", at which point it will be routed via the internet through the endpoint, but it's not a single route. And…

If you hit an onion link, then that doesn’t even require an exit node.
Post reply on HN