Live data from Hacker News

VPN – Very Precarious Narrative

schub.io

51–60 of 281 posts

Re: VPN – Very Precarious Narrative

#51

Earlier quoted context omitted.

The ISP can easily build a reasonably reliable profile based just on packet size and timing. TLS and most VPNs do nothing to these. If they actually wanted to. You could sure them under wiretapping laws if they did. If you cannot trust your ISP, you cannot really have any privacy without truly extensive measures. Not even Tor is enough, it does not pad and change timing enough. The real problem is cookies, requiremen…

> You could sure them under wiretapping laws of they did. I assume you meant "sue", but, no, that's not actually a guarantee, because companies can require that you "voluntarily" agree to mandatory arbitration in order to get any service at all.

Those clauses are illegal, much like indemnification by you of a big ISP. Even clauses of choice of law are very suspect.

Relying on such a clause to attempt to prevent a civil suit is stupidity, if only because people are not properly informed of what the clause meant, making it void. (I could quote a few cases. But I am not a lawyer. Microsoft and EULA comes to mind.)

And by EU law, they are completely null and void by just being illegal.

That said, most of those suits do not reach court by means of settlement, not arbitration.

Re: VPN – Very Precarious Narrative

#52
post #9

Earlier quoted context omitted.

Who cares if they log now? They can be forced to log --- and are in fact running businesses the practically beg the DOJ to force them to log.

> They can be forced to log There is no legislation in the US that can be used to do this [1]. Some very misguided companies may voluntarily log, but those that care about privacy or, at the least, realize that holding people's data is a liability, won't make poor decisions like that. [1] https://en.wikipedia.org/wiki/Data_retention#Failed_mandator...

Oh come on now. The US Government forces tech companies to share information all the time.

http://www.msnbc.com/msnbc/us-government-threatened-yahoo-bi...

They certainly can, and will, go after any company they want to, without referencing any specific US legislation.

Re: VPN – Very Precarious Narrative

#53
post #43

The slimy marketing around centralized VPN services is why I consider it a point of pride to include the following as a "feature" in the AlgoVPN readme ( > Anti-features > * Does not support legacy cipher suites or protocols like L2TP, IKEv1, or RSA > * Does not install Tor, OpenVPN, or other risky servers > * Does not depend on the security of TLS > * Does not require client software on most platforms > * Does not c…

FSM == Flying Spaghetti Monster?

Re: VPN – Very Precarious Narrative

#54
>In most circumstances, VPNs do absolutely nothing to enhance your data security or privacy.

>Acting as they do, and promoting commercial VPN providers as a solution to potential issues does more harm than good.

I think this ignores the fact that some users have different threatmodels, sometimes the privacy threat model of a user does include their ISP for various reasons (think China).

>

Starting with the obvious, if you pay for a VPN service, they have to keep your user account and associated payment information and your payment history. So, unless you are using a fake identity and an anonymous credit card (is that even possible these days?), your VPN account will be linked to your actual identity.

Depends on the VPN, some VPN providers actually don't keep that kind of history or provide options to operate and pay an account anonymously.

Re: VPN – Very Precarious Narrative

#55
post #21

Earlier quoted context omitted.

> b) A VPN has some incentive to deliver on privacy. Your ISP does not. Regarding this point, I think a good strategy here is to acknowledge that ISPs, like most organizations, don’t want to add to their workloads. Of course they aren’t privacy centric, but appeals to them oriented around _not_ having to store a bunch of logs or set up a bunch of processes can help to unite more people around initiatives to make thin…

Logs are worth a lot of money to advertisers if your customers can't effectively avoid the process.

And a lot of money to a lawyer who will sue the ISP under privacy laws if it comes to light.

It has to be clearly stated in the signed contract that your data will be shared with third parties, in what way and how they will be processed. The company involved would definitely lose any Privacy Shield provisions for the EU and potentially peering rights.

Losing enough peering is identical to being disconnected.

Class suit of this kind is easy.

Re: VPN – Very Precarious Narrative

#56
post #30

I use VPNs for one main reason: so that my ISP does not build a complete profile of me based on the sites I'm visiting. This can be mitigated to a certain extent by using a VPN. I do not expect to become anonymous or invisible on the internet all of a sudden, I just do not want the guy listening next to my front door to know everything about me. In the US, where personal data is a free-for-all and everybody and their…

If you use Chrome browser or Android phone then Google is already able to build a profile on you. They have multiple ways to ID every session and individual browsing tab to link them back to your profile. VPN is completely irrelevant in their game.

If Google has my data, does that mean I should also give it to Comcast?

This kind of argument comes up a lot, and I really don't understand it, at all. Privacy is a process, it's something you improve over time. The alternative is completely circular.

I shouldn't care about switching to Firefox, because my ISP is already getting all this data anyway, and I shouldn't care about using a VPN because Google is getting all of this data anyway...

If you want to go from no privacy to decent privacy, it is inevitable that there is going to be a period where you are only plugging some of the holes.

Re: VPN – Very Precarious Narrative

#57
> If you are using your device on a public network, VPNs can help you protect your data. I have a ProtonVPN subscription myself, just for those instances where I am sitting in an airport waiting for my plane

Seems like a contradictory message. He just got through telling us how most of the web is now end-to-end encrypted with HTTPS. So why does he need a VPN at the airport? Is he checking his email? I can't imagine that he's using an email service that doesn't use HTTPS. Is he logging into his bank account? I doubt any bank nowadays still uses plain old unencrypted HTTP. Is he watching cat videos on YouTube? Well, even that's encrypted.

Remember, his argument is that VPNs don't provide privacy--so that's not the reason. And this is the section where he's talking about public networks, not about other rationales for VPNs like geolocking or ISP blocking. It weakens the argument of his essay to say that he needs a VPN at the airport or cafe.

Re: VPN – Very Precarious Narrative

#58

Earlier quoted context omitted.

The ISP can easily build a reasonably reliable profile based just on packet size and timing. TLS and most VPNs do nothing to these. If they actually wanted to. You could sure them under wiretapping laws if they did. If you cannot trust your ISP, you cannot really have any privacy without truly extensive measures. Not even Tor is enough, it does not pad and change timing enough. The real problem is cookies, requiremen…

> You could sure them under wiretapping laws of they did. Has this ever worked though? Cursory searching, I don't see or know of any examples of lawsuits that have actually succeeded on this front. And it's not like ISPs have never given consumers an opportunity before.[0] [0]: https://www.cnet.com/news/verizon-draws-fire-for-monitoring-...

The cases are almost always settled for reasons I outlined in response to another thread. (mostly related to peering and PR damage, that can kill an ISP)

The app is a tiny blip on the radar waiting for careless. (Read the darn contact, especially if you get a discount.)

Re: VPN – Very Precarious Narrative

#59
post #9

Earlier quoted context omitted.

Who cares if they log now? They can be forced to log --- and are in fact running businesses the practically beg the DOJ to force them to log.

> They can be forced to log There is no legislation in the US that can be used to do this [1]. Some very misguided companies may voluntarily log, but those that care about privacy or, at the least, realize that holding people's data is a liability, won't make poor decisions like that. [1] https://en.wikipedia.org/wiki/Data_retention#Failed_mandator...

Perhaps not (I’m not certain about the issue), but they can be forced to hand over their private keys to let the NSA [ed: or other agency] do the logging for them – as happened with Lavabit.

Re: VPN – Very Precarious Narrative

#60
There's a couple of bad faith arguments in this article that I didn't care for:

- Regarding user identification, rolling my IP address is trivial with a VPN. Less so on my static IP.

- The Facebook example without cookie deletion is a low-effort Straw Man

- I reject the leap that "we have figured out that they [VPNs] do not add much to your online privacy". In the very narrow terms defined, yes of course, but either the author has willfully missed out why people use them, or doesn't understand why.

I did enjoy this note though: "Somehow, VPNs have turned them not failing to do their job into something they can market as a special feature."; I think there's some truth to that.

I tunnel my traffic over a VPN to avoid my ISP building a profile on me. I change my IP every-so-often to mess with trackers at large. I accept that browser fingerprinting is probably thwarting my overall effort somewhat, but I'm reducing the vectors that I can. I firmly believe that VPN companies are capitalising on fear but I respect the hustle. I don't think any of those points are particularly niche (niche subject notwithstanding!) so I find it interesting to see this take on it. Perhaps this isn't an article representative of the position of the wider HN crowd?

Post reply on HN