What ISPs can see
teamupturn.com
teamupturn.com
Another risk, which the article may vaguely allude to, is using ISP-associated DNS servers. Even if all traffic uses the VPN tunnel, DNS requests reveal sites being visited, and it's trivial for ISPs to correlate them with traffic.
IPv6 is a huge looming risk. Many VPN services don't route or block IPv6 traffic. As full IPv6 service becomes widespread, there will be major pwnage. However, this is easy to firewall, and good custom VPN clients do so.
Edit: For suggestions about leak-testing, see https://www.ivpn.net/privacy-guides/how-to-perform-a-vpn-lea...
Edit: Changed "URLs" to "sites".
Nevertheless, setting your Firewall to only allow VPN traffic is pretty easy. I've done that on Linux and Mac OS X. I don't think it is complicated on Windows either.
In Windows Firewall, you label the physical and tap adapters as different domains. Then you allow only connections with the VPN server via the physical adapter. It's not all that different from iptables. I'm not very familiar with pf, but I'm guessing that the approach is similar.
WebRTC is indeed invasive. But WebGL is arguably worse. HTML5 overall is hard on privacy.
Never let yourself get lulled in to a false sense of security just because the information you wish to keep private has been encrypted.
From https://en.wikipedia.org/wiki/Forward_secrecy:
>As of March 2016, 49.4% of TLS-enabled websites are configured to use cipher suites that provide forward secrecy to modern web browsers.
Whereas if you have a record of encrypted traffic, you have to find a flaw in the encryption algorithm itself, or wait until someone else does.
When are we going to get an article on "what google can see" from this team?
ISP snooping on network traffic really only happened after Google started getting into the ISP business.
Monetizing your traffic (beyond transport) only became a thing after Google Fiber fired a cannon ball across the broadside of carriers. Carriers responded by offering ad networks around anonymized, aggregated data about customer behavior. It drives the value of Google Adwards down. It doesn't make carriers rich.
Maybe someday we'll need to worry about big-I innovation from carriers in this domain, but I don't see it happening soon.
I'm all in on tearing it all down. But focusing only on the companies that offer services that huge populations are willing to actually pay for is extremely dishonest.
ISPs have always snooped. Maybe just in limited circumstances, true. But the key point is that they can, not how prevalent it is.
Online Privacy and ISPs: ISP Access to Consumer Data is Limited and Often Less than Access by Others http://www.iisp.gatech.edu/sites/default/files/images/online...
To combat this, you can use compartmented, disposable and anonymous 3G sim cards for specific purposes. (One for dating sites, one for health records, etc). Slap them in the microwave after a browsing session. (You can get these for basically free in places like Thailand or India). Block all HTTP. Use something like
sudo ufw deny out to any port 80
Always assume your connection is tapped. Always assume there's somebody MITM'ing your traffic. (To prove this, download executables several times over time and diff the hashes. It's clear that MITM happens all the time).Always use a hardware version of TOR. That way if a box is compromised, the naked IP can't be disclosed. The same goes for VPNs, See WebRTC vulns.
Use public Wifi as much as possible (behind a VPN of course). Use your friends phone for casual surfing. Minimize the reliance on one monolithic connection. Use 4G, or even WiMax if they have it in your area.
Share your connection with your neighbor and split the bill if you are so inclined...
Also I don't follow how does one "prove" a MITM attack by downloading the same executable serveral times and getting different hashes?
Well, unless this is baked in, which it is not. It's the old privacy rich vs privacy poor debate. If I buy black curtains, I cast less of a (nude) silhouette than my neighbor for all to see, but the tradeoff is, I have to research black curtains on the internet, where there is no privacy, and so I have no choice but to build my own private Internet.
If the internet was private, no such measures need to be taken and I have perfect autonomy. Autonomy being a luxury since the digital space has effectively perfect memory.
This is why I'm against logs and data retention. It's very un-natural and it's why the human brain habitually flushes memories. Nature needs to renew itself and re-invent itself, and in some sense, forget itself (if you believe in a Gaia mind).
Yes, but would it be win-win for us?
Google's already demonstrated that "don't be evil" is now just a sad memory. I'm not ready to believe them to "do the right thing". Their entire existence is predicated on increasing and refining their data collection and analysis, and acting on such.
Google's seedy behavior already directly impacts me every day. I, for one, don't welcome this new corporate overlord.
Also, good VPN services run their own DNS servers, which are reachable only through the VPN tunnel.
See https://dnsleaktest.com/ to determine which DNS server(s) you're using.
Very few people, as a proportion of the population, are paying attention.
Privacy: your ISP has a log of the DNS queries you've made. (of course, they have a log of the IP addresses you've made HTTP/HTTPS requests to, so that may be less relevant).
I'd say most ISPs do it nowadays including some datacentre providers. I only noticed it when my ISP screwed up their DNS proxy making all Cloudflare domains inaccessible no matter which DNS server I point queries to, the packets simply disappear down a black hole.
Good reason to use a VPN, I guess.
After all, it is really a lazy way to save transit costs by making sure that domain names resolve to a CDN they have peered with, or in the worst case, to a transparent HTTP caching proxy they have set up.
Otherwise, it's mostly about how mistyped URLs get handled. Some DNS servers point mistyped URLs to neutral "did you mean?" pages. But others redirect to sites that pay for the service. Even worse, there's the possibility of outright MitM attacks.
And then there's censorship. Hit https://thepiratebay.se/ and see what you get. And that's just a torrent search site. To reach some sites, it takes some work to find a DNS server that will give you the IP address.
I get a database error visiting thepiratebay.se. I can't tell if that means my ISP is doing something naughty, or if it means they're not!
Some DNS servers will show you a page about copyright infringement instead of TPB. Years ago, some German DNS servers were null-routing Nazi stuff. The FBI sometimes takes down sites through DNS spoofing aka cache poisoning. But normally, they go after root nameservers. In 2014, the Turkish government banned Twitter and YouTube through DNS cache poisoning: http://googleonlinesecurity.blogspot.com/2014/03/googles-pub...
And Chrome cannot be use dnscrypt by default. It uses UDP ports which are sometimes closed on other networks. So there are technical limitations. Even using another DNS than the network one is often not allowed (you will experience that if you travel often).
Also some people will not like using a Google DNS by default ;)
A zone file of public DNS information can be served by a daemon bound to the loopback on the user's device, obviating the need for many (but not all) lookups sent over the network.
These local lookups are also more private than ones sent out over the private LAN or public internet.
Same goes for any type of data. It's not limited to DNS information.
If a user downloads publicly available data dumps from Wikipedia, and then serves them from a local database and httpd, the response time will be faster and the requested URL's more private than accessing the same content over the public internet. Not to mention the small benefits of reliability and reduced dependence on the network.
I know a user who does this and has automated the process of setting it up.
To use the examples in the article, the idea is that a user can periodically download bulk data, e.g., information on medical conditions, in an open format, load it into her database of choice and query to her heart's content, without any ISP or website knowing what she has queried.
Same with daily newpaper content, and even a catalog of toys. "Browsing" through the data remains private.
The alternative is to have this data served from third party computers and have the user send each and every request for each small item of information over an untrustworthy, public network (the Internet).
Despite ample, inexpensive local storage space for users to store data of any kind themselves, let us break up the data into little bits and make users request each and every bit individually. (Not only that, let's make them register for the the ability to make numerous queries.) Then we can record all user requests for every item of data.
Metadata. Sell. Profit.
The only advantage is that your VPN provider (or their ISP) might have little reason to spy on your traffic instead of your regular VPN.
Yes, that's the point. You want to pick VPN providers that can't readily be forced to spy. See https://docs.google.com/spreadsheets/d/1FJTvWT5RHFSYuEoFVpAe...
Tor?
Centralization is bad precisely because it concentrates the information, adds context to it (what you're doing relative to others), and amortizes the cost of building surveillance infrastructure and developing the business relationships for exploiting it.
Although last mile wireline providers have surveillance in their genes, having descended from state surveillance organs (eg Ma Bell). They already make good money servicing warrant requests for IP address records, and preemptively keeping a record of customers' communications partners would be extremely cheap. And such "network intelligence" ties right in to fighting against the commodification otherwise driving profit margins on transporting bits to zero.
I'd bet on the infrastructure-less provider that starts off only knowing my rough geographical location and what type of gift card I paid with, and that I can drop any time.
VPN chaining does start to look somewhat like Tor. But the bandwidth can be a lot greater. However, it's far less anonymous, because there's just a static circuit. Tor switches circuits frequently, at ten minute intervals by default.
Also, one can combine VPN services and Tor. By hitting Tor through VPNs, you hide Tor use from your ISP and its friends. And you hide your ISP-assigned IP from potentially evil entry guards. By routing VPNs through Tor, you hide Tor use from sites that you visit, and also hide your traffic from potentially evil exit nodes. One can even run VPN servers as Tor onion services.
1. No other public DNS is faster. 75.75.75.75 is 6 "hops" away at 15ms rtt. Google's 8.8.8.8 is 10 hops away at 25ms rtt. DNS adds about 3 ms of latency for both services.
2. It's my understanding that many services can use DNS to do geographical load balancing when Anycast isn't an option. When using Google DNS I would routinely get pointed to Akamai nodes in Chicago. I live in Nashville. After switching back to Comcast I know reach Akamai in Atlanta, which provides much lower latency and higher throughput.
Just my two cents.
[0]https://en.wikipedia.org/wiki/Dnsmasq
N.B. I say or less because you can run it on your machine as well.
If a site is not already cached at the OS level than a typical DNS lookup from the central / east coast US to EU takes ~120-130ms. 8x slower may at first sound really bad until you pause to consider that the unit in question is milliseconds.
Your web browser and the webpage itself are generally doing far more damage to your page load times than the DNS lookup.
The same goes for maps. For example, Open Street Map data can be used offline.
I'll create a Ask HN post if there is interest...
Steer clear of PIA. https://news.ycombinator.com/item?id=8982095
https://torrentfreak.com/vpn-anonymous-review-160220/
I personally use Mullvad. They let you pay in cash by post which is always nice.
Speed is decent enough to stream/download but it won't get near maxxing out my 200Mbps connection. I've yet to find a VPN provider that offers amazing bandwidth along with anonymous payment.