Live data from Hacker News

VPNs are not the solution to a policy problem

asininetech.com

71–80 of 228 posts

Re: VPNs are not the solution to a policy problem

#71
post #2

Ok, so which vpn providers are good?

I went looking for a spreadsheet I once saw, apparently it's become a website. https://thatoneprivacysite.net/vpn-section/

France runs a warrantless mass surveillance program [1]. It is one of the countries our OpSec consultant specifically recommends taking clean computers to. It is labelled, by "That One Privacy Site" as NOT being an "enemy of the Internet" (whatever that means). Difficult to take the rest of its recommendations seriously.

[1] http://www.cnn.com/2013/07/05/world/europe/france-surveillan...

Re: VPNs are not the solution to a policy problem

#72
post #36

Another thing often overlooked with VPNs is that they're just not that fast. I have a 600/40 connection, and I've tried at least six for-pay VPN providers. The fastest one I found (won't mention as my goal isn't to advertise for them) hits, at best, 100/30. And even then, only over L2TP. For whatever reason, OpenVPN is always slower on every PC I've tried this with. And obviously, you gain a good deal of latency, esp…

Plus you will be banned participating from so many places because the vpn and vps ip blocks are over abused and blocked.

Re: VPNs are not the solution to a policy problem

#73
At the end of the day, it is obvious that policy is the right direction to stop this bleed of infringement. However; be it noted: those who have the capability to circumvent, or ethically "get around" such enchroachment; have a responsibilty to free those who may be entagled by that which is "freedom limiting". The argugment could be had, however; is it really freedom limiting for others to know your web history? Obviously, there are second, and third abilities to be held when a dominant party knows of the lesser's behavior. Still a great bit to parse. As for me and my house, we will tunnel safely through VPN.

Re: VPNs are not the solution to a policy problem

#75
post #61

Lots of people seem to think the right answer is selling improved security. I disagree. It would be much more exiting to get the data coming from politicians homes, and the homes of their staff. It would be a fantastic way to generate news. Why is senator X's household researching cancer treatment? Will they step down this year? I can't help but think military bases would google their next deployment, that's another…

I think somebody's doing a kickstarter exactly for what you're talking about.

Got a link?

Re: VPNs are not the solution to a policy problem

#76
Why aren't VPNs, and more broadly encryption, a solution to this problem? "Waving the wand of a technical solution," as the post pejoratively calls it, isn't such an unreasonable thing to do with an inherently technical problem. This problem only exists because of other technical wands we waved. Why solve this problem with policy? Policy is hard to get passed, hard to keep passed and even when it is passed often times it means nothing. Remember this is the same government that contains multiple organizations surveilling your every move, not because they legally can, because they illegally can. The point is, it's foolish to count on USG to give you a right to privacy, just look at the history on this, it's not going to happen. But it's especially foolish when this is a right that you can enforce for yourself. If you actually care about your privacy use a VPN, or Tor, don't sit around waiting for the government to do it for you.

Re: VPNs are not the solution to a policy problem

#77
post #19

I think the bigger hole is DNS. Full-tunnel VPNs to primarily TLS-encrypted sites seems like overkill. Encrypted DNS plus an "HTTPS Everywhere" plugin should obfuscate enough info for most people without significantly affecting latency.

Wouldn't it be fairly trivial to guess most of the domains you're visiting by looking at what IP addresses you connect to?

You can guess some of it trivially, cloud services such as AWS are popular and mask the ORG using the IP addresses.

Example: any traffic to 17.0.0.0/8 = user probably has an Apple device

Re: VPNs are not the solution to a policy problem

#79
post #2

Ok, so which vpn providers are good?

I just did a bunch of research at https://www.reddit.com/r/VPN -- looks like Mullvad is the most recommended / highest rated.

Sweden is a member of the EU [1]. It has a 6-month data retention law [2]. Much safer to route through Norway, Switzerland or even the United States. (I use PIA [3].)

[1] https://europa.eu/european-union/about-eu/countries_en

[2] https://www.purevpn.com/blog/data-retention-laws-by-countrie...

[3] https://www.privateinternetaccess.com

Re: VPNs are not the solution to a policy problem

#80
post #37

Earlier quoted context omitted.

Why does he refer to OpenVPN as a "risky server"? Does it have a history of embarrassing security vulns?

I think a recurrent concern is OpenVPN's reliance on TLS, and its codebase complexity as a result of being built on OpenSSL--but with far less attention and resources and vuln hunting compared to say, actual browsers. Complexity + lack of auditing person-hours is never a good combo. (See https://twitter.com/tqbf/status/806646188158152705 ) Matt Green's audit of OpenVPN, when completed, may lead to more light on the m…

Except all the shenanigans with IPSEC.

https://en.m.wikipedia.org/wiki/IPsec#Alleged_NSA_interferen...

As a "security people" I think me and tptacek could split a great number of hairs and get not too far on this one, but I am open to new info. I know a lot can hide in the complexity of OpenSSL. Maybe the whole thing with IPSEC was to sway us toward OpenVPN likes. Regardless, I still lean slightly towards OpenVPN

But honestly I am out to defeat ad networks. I only aspire to give nation states indigestion (at a mass scale). Individually if a well funded adversary wants any one of us I think they have us.

Post reply on HN