Live data from Hacker News

VPNs are not the solution to a policy problem

asininetech.com

61–70 of 228 posts

Re: VPNs are not the solution to a policy problem

#61
Lots of people seem to think the right answer is selling improved security. I disagree. It would be much more exiting to get the data coming from politicians homes, and the homes of their staff. It would be a fantastic way to generate news. Why is senator X's household researching cancer treatment? Will they step down this year? I can't help but think military bases would google their next deployment, that's another set of huge news articles.

If you're more into the finance side of things, CXO's home clickstreams would probably be enlightening. Or hedge fund managers. Some will be fully encrypted and secure, but just the dns would be a strong signal about what companies they're researching.

That is the kind of business that will drive privacy legislation.

Re: VPNs are not the solution to a policy problem

#62
post #50
post #36

Another thing often overlooked with VPNs is that they're just not that fast. I have a 600/40 connection, and I've tried at least six for-pay VPN providers. The fastest one I found (won't mention as my goal isn't to advertise for them) hits, at best, 100/30. And even then, only over L2TP. For whatever reason, OpenVPN is always slower on every PC I've tried this with. And obviously, you gain a good deal of latency, esp…

I've been using PIA for a few years and have been disappointed to see an increasing number of websites blocking VPN access.

[deleted]

Re: VPNs are not the solution to a policy problem

#63
post #37

Earlier quoted context omitted.

I've used streisand on DO (while traveling in China) and it worked well. There's also a similar project called algo[1] which provides a single protocol with maximum security, in contrast to streisand's multi-protocol flexibility (and increased surface area). https://github.com/trailofbits/algo

Why does he refer to OpenVPN as a "risky server"? Does it have a history of embarrassing security vulns?

[deleted]

Re: VPNs are not the solution to a policy problem

#64
post #56

One nice although limited alternative to openvpn is sshuttle: https://github.com/sshuttle/sshuttle The limitations are: no ipv6 support :(, sometimes leaks dns, and always crashes shortly after it is first started (then works fine when you start it again). There seems to be little active development. To work around the limitations, I mostly use SOCKS (curl also supports SOCKS), plus run sshuttle to try to catch any a…

To be clear: sshuttle is more comparable to redirecting system traffic through a proxy than a VPN.

UDP is not tunneled at all.

Re: VPNs are not the solution to a policy problem

#65
post #55

Earlier quoted context omitted.

Because you have much more choice for VPN providers than for ISPs. And you can change VPN periodically, far more easily than changing ISP. Also, you can use nested chains of VPNs, much like Tor, to distribute trust. So adversaries must compromise multiple providers, quickly enough that logs will be available. Edit: Also, you can pick VPN providers outside your adversary's sphere of influence. That's standard advice f…

Also, you can pay for a VPN without revealing your identity. Not so with ISPs. I use a VPN, for instance, to mask my Tor usage from my ISP. (I'm an American using the Internet in the United States.)

True. But the VPN provider effectively knows who you are, because they see your IP address. Or rather, a resourceful adversary can get your IP address from the VPN provider, and then get your identity from your ISP.

If you chain VPNs, however, it certainly makes sense to lease the second/indirect VPN anonymously.

Re: VPNs are not the solution to a policy problem

#66

Earlier quoted context omitted.

If I was a betting man - backbone providers don't do this (sell to advertisers). It would be costly to maintain the interception/analysis infrastructure required for such data collection. I daresay it would cost more than what they would make off the data.

Thats an interesting bet. If they isolated to the subnets they sell off to ISPs (i.e exclude datacenters and such) what do you think would contribute to the cost/benefit difference of the two?

That is still a significant amount of traffic to analyze and store data for.

I don't want to speculate further as I don't know what margins for transit providers in NA look like.

Re: VPNs are not the solution to a policy problem

#67
post #37

Earlier quoted context omitted.

I've used streisand on DO (while traveling in China) and it worked well. There's also a similar project called algo[1] which provides a single protocol with maximum security, in contrast to streisand's multi-protocol flexibility (and increased surface area). https://github.com/trailofbits/algo

Why does he refer to OpenVPN as a "risky server"? Does it have a history of embarrassing security vulns?

I think a recurrent concern is OpenVPN's reliance on TLS, and its codebase complexity as a result of being built on OpenSSL--but with far less attention and resources and vuln hunting compared to say, actual browsers. Complexity + lack of auditing person-hours is never a good combo. (See https://twitter.com/tqbf/status/806646188158152705)

Matt Green's audit of OpenVPN, when completed, may lead to more light on the matter. Otherwise, we're just relying on informed intuitions.

Re: VPNs are not the solution to a policy problem

#68
post #55
post #47

Earlier quoted context omitted.

But now the VPN provider can just track you and sell all your browsing history instead of the ISP, so how is this better?

Because you have much more choice for VPN providers than for ISPs. And you can change VPN periodically, far more easily than changing ISP. Also, you can use nested chains of VPNs, much like Tor, to distribute trust. So adversaries must compromise multiple providers, quickly enough that logs will be available. Edit: Also, you can pick VPN providers outside your adversary's sphere of influence. That's standard advice f…

And now both of your vpn owners have your data connected to your ips. You do have more choice but if both of them sell the data, it doesn't make any difference.

Re: VPNs are not the solution to a policy problem

#69
post #61

Lots of people seem to think the right answer is selling improved security. I disagree. It would be much more exiting to get the data coming from politicians homes, and the homes of their staff. It would be a fantastic way to generate news. Why is senator X's household researching cancer treatment? Will they step down this year? I can't help but think military bases would google their next deployment, that's another…

I think somebody's doing a kickstarter exactly for what you're talking about.

Re: VPNs are not the solution to a policy problem

#70

Perhaps one solution might be to poison the data and have your router/device make spurious random DNS lookups and HTTPS connections. Ensure the list of random websites includes the top few hundred companies likely to be in the market for usage data. If enough people did this it would make the data useless.

Data poisoning is a fantastic approach: flood the captures with so much, and with so much trash that it becomes an increasingly large amount of work to just sort out the 'real' traffic (even before any advertiser analysis of what that real traffic contains).

There's a couple of things that do this actually: the AdNauseum plugin will hide ads for you, but will also click through on them often as well which helps pollute advertiser data capture. It won't of course be able to replicate you browsing on the page, but it'll go a long way to frustrating the efforts of 3rd parties who won't have access to the landing page metrics anyways.

There was also a post on /r/InternetIsBeautiful that was supposed to do something similar: essentially destroy your browsing habits by performing additional searches and following links in the background, but I think that relied upon a hardcoded list of searches, so it's ongoing functionality was somewhat limited.

A big challenge to making something that continually obfuscates your browsing habits is making sure it doesn't accidentally end up going throw actually sketchy or illegal stuff (i.e. sites/etc that could get you on lists/attention) and making it work in a way that isn't easily detectable/filterable as 'machine traffic'. I guess that means you'd have to build in functionality to replicate following pages several links deep, not making successive requests immediately (sleeping execution/simulating scrolling), simulating some kind of 'natural' interaction: mouse movement + hovering over things + other things that users might do?

I'm sure most of that stuff is totally possible, probably even easy, might make for a fun personal project...

Post reply on HN