Who Owns, Operates, and Develops Your VPN Matters
61–70 of 203 posts
Re: Who Owns, Operates, and Develops Your VPN Matters
#62Commercial VPNs will go down as one of the greatest money-making schemes of the last decade. Outside of a few specific use cases their sales often rely on leveraging non-technical users' fear of what they don't fully understand. I have non-technical friends and relatives that have fully bought into this and when I asked why they use a VPN I got non-specific answers like "you need it for security", "to prevent identit…
Long ago, in the era of Firesheep and exploding prevalence of coffee-shop Wi-Fi, consumer VPN services were definitely valuable. But that was long ago. Now, HTTPS is the norm. The only use cases for consumer VPNs today seem to be (1) "pretend I'm in a different geography so I can stream that show I wanted to see" and (2) "torrent with slightly greater impunity". I live in Seattle and Mullvad VPN seems to have bought…
Re: Who Owns, Operates, and Develops Your VPN Matters
#63Commercial VPNs will go down as one of the greatest money-making schemes of the last decade. Outside of a few specific use cases their sales often rely on leveraging non-technical users' fear of what they don't fully understand. I have non-technical friends and relatives that have fully bought into this and when I asked why they use a VPN I got non-specific answers like "you need it for security", "to prevent identit…
Re: Who Owns, Operates, and Develops Your VPN Matters
#64Earlier quoted context omitted.
Mine is simple: avoid my ISP complaining about torrents.
Mine are: 1) I like Canadian shows in Netflix more than American 2) People in Silicon Valley get charged more on certain travel sites than people in Detroit.
I wonder how this compares to Florida vs Detroit... Hmmm...
Re: Who Owns, Operates, and Develops Your VPN Matters
#65Earlier quoted context omitted.
Long ago, in the era of Firesheep and exploding prevalence of coffee-shop Wi-Fi, consumer VPN services were definitely valuable. But that was long ago. Now, HTTPS is the norm. The only use cases for consumer VPNs today seem to be (1) "pretend I'm in a different geography so I can stream that show I wanted to see" and (2) "torrent with slightly greater impunity". I live in Seattle and Mullvad VPN seems to have bought…
What about (3) "bypass government censorship"? UK and China are examples of where this is desirable. This is different from (1) because it's broader than just streaming shows and is about authoritarian rather than capitalist restrictions.
The UK law is stipulating adult content can only be viewed if you are provably over 18. They are putting all of that responsibility onto the websites/platforms to enforce that.
If a child goes to a shop and tries to buy a pornographic magazine and they are denied, is that censorship?
If a child tries to see an 18 film at the Cinema and is denied, is that censorship?
The fact is both of these were freely and easily done on the Internet as most websites do not verify a users age.
I do not like the online safety act as it is, but it is not "censorship".
Re: Who Owns, Operates, and Develops Your VPN Matters
#66I'd like to point out that a regime may find it worthwhile to compromise more kinds/sizes of VPNs than we might expect. The evil regime doesn't need to have a popular evil VPN that everybody uses... it may be enough to operate (or hack) a smaller VPN which can unmask enough dissidents that their friend-groups can be found by other means.
If I was the US government, I'd push Google Play to offer compromised updates of Signal silently to a few people I was interested in. Even among the highly-technical, who is going to be inspecting binaries installed on a phone regularly?
Does Signal even have reproducible builds? How do I know the code matches the binary?
I'd make my own messenger.... but I don't have the money for that at all.
I wish these risks could be split up and handled separately - Suppose I run a private dark network for me and my friends, and then the GUI for chatting over it runs in a sandbox where it can only message servers that I control, using public/private keys that I control.
Conflating a million lines of Java GUI code with "Noise is a simple and secure protocol" seems like a big attack surface.
Re: Who Owns, Operates, and Develops Your VPN Matters
#67Earlier quoted context omitted.
Here in the United States, I don't know that I could trust the vpn to protect me from that. I remember an incident from a few years ago, some idiot at Harvard emailed in a bomb threat to get out of finals. They arrested him only a few hours later. It's possible he misused the vpn, but I suspect that they merely contacted the vpn provider, got a shortlist of people going through that endpoint, and eliminated all of th…
I remember that, Schneier talked about it on his blog. It was actually tor (the threat came from tor), and harvard 'found' him by constantly logging what connections were going to known tor entries from on campus. As it turns out he was one or possibly the only one using tor that morning from harvard. Bruce outlines it that he certainly could have stayed tight-lipped (all evidence was circumstantial) but, nevertheles…
I'm looking forward to when VPNs always throw up chaff traffic.
Re: Who Owns, Operates, and Develops Your VPN Matters
#68Earlier quoted context omitted.
Long ago, in the era of Firesheep and exploding prevalence of coffee-shop Wi-Fi, consumer VPN services were definitely valuable. But that was long ago. Now, HTTPS is the norm. The only use cases for consumer VPNs today seem to be (1) "pretend I'm in a different geography so I can stream that show I wanted to see" and (2) "torrent with slightly greater impunity". I live in Seattle and Mullvad VPN seems to have bought…
What about (3) "bypass government censorship"? UK and China are examples of where this is desirable. This is different from (1) because it's broader than just streaming shows and is about authoritarian rather than capitalist restrictions.
Re: Who Owns, Operates, and Develops Your VPN Matters
#69That's why we sell only the service [1] and point our users to the default app install (Wireguard in our case). Ever since Holla VPN and the entire Brightdata/Luminati clusterf~ VPNs are a risky business for users. Most of them are proxy nodes underneath, they rent you datacenter IPs while they sell your residential internet to third parties. [1] https://www.anonymous-proxies.net/products/
> We offer highly secure, /.../Residential /.../ Proxies. Where do you get residential proxies? I ask because I'm always reminded of https://sponsor.ajay.app/emails/ .
Re: Who Owns, Operates, and Develops Your VPN Matters
#70Earlier quoted context omitted.
Mine is simple: avoid my ISP complaining about torrents.
Avoid my ISPs piss poor routing and peering - especially during peak times.