VPN – Very Precarious Narrative
91–100 of 281 posts
Re: VPN – Very Precarious Narrative
#92Earlier quoted context omitted.
Russian intelligence service: https://en.wikipedia.org/wiki/Federal_Security_Service
Huh? I didn't ask about the FSB (the first initialism). I asked about FSM (the last).
For FSM the best I can do is the Flying Spaghetti Monster, nothing else here makes sense: https://en.wikipedia.org/wiki/FSM
Re: VPN – Very Precarious Narrative
#93Earlier quoted context omitted.
Of course one has to wonder how much of that "poor OPSEC" is actually just parallel construction. The linked article doesn't sound like it. But on the other hand with the way mass market VPN software generally works, how many people are going to be absolutely sure that all of their traffic definitely went out the tunnel? The FBI having access to an NSA-provided tool that takes some IP addresses and returns other "ass…
Sure, a lot of it may be parallel construction. We do know that the NSA shares with the FBI and other TLAs. If your threat model includes the NSA or the like, VPN services are at best a minor hindrance. Possible options include Tor and "anonymously" using WiFi hotspots. I only know of one fundamental fail for Tor: the relay-early bug that CMU exploited. The others have involved Firefox and Windows bugs. People using…
I thought most folks believe that the NSA/CIA/some other TLA has control of more than 50% of the exit nodes, which should be enough to reconstruct the sources of most traffic.
Re: VPN – Very Precarious Narrative
#94I use VPNs for one main reason: so that my ISP does not build a complete profile of me based on the sites I'm visiting. This can be mitigated to a certain extent by using a VPN. I do not expect to become anonymous or invisible on the internet all of a sudden, I just do not want the guy listening next to my front door to know everything about me. In the US, where personal data is a free-for-all and everybody and their…
The ISP can easily build a reasonably reliable profile based just on packet size and timing. TLS and most VPNs do nothing to these. If they actually wanted to. You could sure them under wiretapping laws if they did. If you cannot trust your ISP, you cannot really have any privacy without truly extensive measures. Not even Tor is enough, it does not pad and change timing enough. The real problem is cookies, requiremen…
Re: VPN – Very Precarious Narrative
#95I have kind of a lot of issues. First, the downplaying of IP location lookups. If you do a lookup on my home IP address, it'll get you within 5 miles of my house. From there, the only other information you need is my name and potentially one or two more details like a birthday (easy, I use my real name online) and you can get access to my voting data -- and that'll give you an actual address, not just a zip code. OP…
Why would everyone have to move to Tor? It already works, and the are good solutions for securely running it, like whonix. (Much better than just Tor browser alone, which is still necessary.) Compare that to random commercial VPN app...
I don't mean that Tor will work better if everyone uses it. Quite the opposite, it will slow down considerably.
I mean that anyone who isn't using Tor needs a different solution. We have two solutions being proposed to the problem of leaking IP addresses: VPNs and Tor. Unless our plan is to move literally everyone onto Tor, we need a non-Tor solution for the people we don't move over.
Re: VPN – Very Precarious Narrative
#96Earlier quoted context omitted.
Logs are worth a lot of money to advertisers if your customers can't effectively avoid the process.
And a lot of money to a lawyer who will sue the ISP under privacy laws if it comes to light. It has to be clearly stated in the signed contract that your data will be shared with third parties, in what way and how they will be processed. The company involved would definitely lose any Privacy Shield provisions for the EU and potentially peering rights. Losing enough peering is identical to being disconnected. Class su…
The most valuable companies in the world trade in identity. They spend billions trying to figure out who you are. ISPs have it served on a silver platter, and there is generally little ISP choice. If ISPs haven't written it in contracts already, there must be a political reason for it, otherwise they doubtlessly would. Anyone know what the societal contract with ISPs is?
Re: VPN – Very Precarious Narrative
#97Re: VPN – Very Precarious Narrative
#98Earlier quoted context omitted.
> I can walk into a store right now and get a prepaid visa using cash WalMart, Target, and many other large retailers retain photographic records of all purchasers. Many cases have been broken by police claiming to have found a match at a WalMart for the purchase of items committed in some crime. So cash purchases of cards is not always a completely anonymous choice.
Sure, if you are doing illegal stuff very little of what you can find online will protect you. But if you are hiding from non-law enforcement it is easy to get pretty anonymous.
Those engaging in crimes though, such as watching region locked content outside the region in violation of copyright law, rightly should fear. But that is OK since they are criminals subverting the establishment of course. Along with those such as gays in regions where being gay is illegal. Or apostates where apostasy and heresy are death penalty crimes. And numerous other examples of despicable criminal behavior in violation of local laws.
Re: VPN – Very Precarious Narrative
#99Earlier quoted context omitted.
Which case are you talking about? You have no links in the "no-log" section. Other fatal flaws in that section, fwiw >Starting with the obvious, if you pay for a VPN service, they have to keep your user account and associated payment information and your payment history. So, unless you are using a fake identity and an anonymous credit card (is that even possible these days?), your VPN account will be linked to your a…
Bitcoin has very little anonymity as well BTW. Probably less than credit cards.
> In December 2013 the site was used to launder a part of the 96,000 BTC from the robbery of Sheep Marketplace.
> In February 2015, a total of 7,170 bitcoin was stolen from the Chinese exchange Bter.com and traced back to cryptocurrency-tumblers like Bitcoin Fog.
Re: VPN – Very Precarious Narrative
#100Or is the solution multifaceted and you should use a combo of VPN, don't logon to services connected to first party data etc.?