The impossible task of creating a “best VPNs” list
arstechnica.com
arstechnica.com
I was in the market recently and ended up going with iVPN for $100/year. Their "18 questions to ask your vpn provider" [1] page is basically a more practical version of this article. Not that I am going to use it, but they also have guides showing you how to created nested and branched chains of tor/pfsense vm clients across countries, if you really did want to hide traffic from a nation state. If putting your trust into a VPN is the issue it's much easier to trust someone that links directly to security forums and openvpn documentation.
[1] https://www.ivpn.net/privacy-guides/18-questions-to-ask-your...
Why not?
>DO and AWS are not cool with operating as high-transfer seedboxes and will be fairly expensive
DO and AWS are certainly the last providers you'd want to use for anything high-transfer. Why would you even consider them over, say, OVH?
I've done this very thing. I wasn't trying to avoid DMCA notices; I was working around the great firewall of China, which blocks torrents normally.
Best stick to bills tendered as change only. Although who knows what red flags someone trying to hide their spending habits might be able to trip, alerting the feds that someone frequenting your favorite restaurant is trying to hide their trail...
This is why privacy, while it is a legitimate need to shield things like personal info, bank accounts, bills, your own home or communication with coworkers, friends, family, etc, when it is used to shield illegal activities, almost always, if not always, it is to the detriment of the person.
Now, some will cry foul to what I said... "If you're careful enough, you will never get caught".. or the best one, "If you've a group of people to support you (i.e. mafia style :), organized efforts are harder to break"... or "if smart people who are wicked join you..." etc.
Go ahead, try it, I double dog dare you. Come post on HN how it went. Or maybe we'll read about you on Ars or HN, but not from your direct reporting.
And for your point - I am sure we hear only about the "stupid" ones that made a silly mistake; we would never hear about the clever ones that can restrict themselves when they don't have 100% control of the situation. They do exist. And most men can't even spot clear signals when their wife is cheating on them, not mentioning the ones that can blend in perfectly... Often the balance of power is achieved by secrets the ones in power know on each other via MAD, so when there is no deviating data, there is no secret to crucify you for.
So, between all that, I think you're dramatically overestimating how effective both police and surveillance dragnets are. ;)
https://en.wikipedia.org/wiki/Clearance_rate
I want to expand on your point about privacy by pointing out that arrests are often entirely up to police discretion. A suspended license could result in a warning, a ticket, or an arrest; ultimately, it comes down to whether an officer is in a good mood when he stops me or whether he likes my face. Allowing surveillance dragnets just makes it easier for law enforcement to have something to charge you with if they don't like you.
More in my area or classified as missing persons to make murder rate look lower. Common trick in a lot of places, esp small towns. Yeah, clearance rate is a great measurement showing how often crooks get away with stuff. I didn't think of that now obvious piece of data. :)
" it comes down to whether an officer is in a good mood when he stops me or whether he likes my face. Allowing surveillance dragnets just makes it easier for law enforcement to have something to charge you with if they don't like you."
This is true. We already see that in some U.S. states and European countries. There are all kinds of BS laws on the books. The cops or courts want money. So, some percentage of people are pulled over with an assortment of "violations" to use against them. Troublemakers might be hit with a more serious version of it. Especially can be used to squelch dissent or activism.
Aaron Schwartz is a perfect example of the power prosecutors hold in a given situation. Because of who he was and his crime, they decided to go all out to set an example of him rather than keep charges lower or ignore it given students were supposed to have access. Discretion can make or break a person's life.
This is an extremely fallacious argument. How are you supposed to know who they are before they've been caught?
"In the OSF-specified algorithm for generating new (V1) GUIDs, the user's network card MAC address is used as a base for the last group of GUID digits, which means, for example, that a document can be tracked back to the computer that created it. This privacy hole was used when locating the creator of the Melissa virus." from https://en.m.wikipedia.org/wiki/Globally_unique_identifier
Apple device uDIDs are generated by concatenating the serial number, the MAC address, and some other things, then running the result through a hash function. (I don't have a source at the moment, sorry).
https://network23.org/inputisevil/2015/09/06/how-html5-apis-...
Hope that was clear.
Obviously every service has different trade-offs to consider, which is why "Tor traffic is always worth it" is HN comment idealism.
How do you differentiate between legitimate new users with a bunch of existing users vouching for them, and a returning shitposter's 10000th spam account with a bunch of existing stealth-mode accounts vouching for them?
I think you're using an extremely weak definition of "solve".
I don't know what the justification for Hacker News not allowing Tor is since there's no economic incentive to track users.
Hopefully more people will be made aware of this and start asking the question: Why do you need to know who I am?
Using your own VPS means you are easier targeted, tracked (on layer 3) and located -- since your VPS likely has a dedicated IP and you probably have a non-anonymized account with the provider. You're still relying on your VPS provider to not monitor outbound connections as you are on the VPN provider.
I've been using a VPS as a gateway to the internet for the last 2-3 years (switching providers a few times during this period).
What I gain:
1) I pay bitcoin, and don't use my real name. So the IP (albeit static) isn't liked to me _directly_.
2) This both protects me from low tier adversaries * , and "annoying" stuff that's considered normal-practice (like geolocation).
3) My connection upstream is always encrypted. I don't care what network I use, what country I'm in, etc.
4) I use torrents a lot, and overall this setup is _much_ faster than doing it from your home connection (or shared VPN). I download an HD movie in under 2 minutes, and then stream it directly from the VPS.
* - The low tear adversaries I consider defeated by this approach:
1) Bots (sometimes people) who file "semi-automatic" DMCA complaints against me (usually for the torrents). I get these every once in a while through the VPS provider - and ignore them. If I get banned, I either create a new fake account or move to a new provider.
2) "Non-privileged people" who know my external IP and want to tie it to a real world identity. For example, a "malicious" site admin that is interested in me for some reason.
3) Any (realistic) _dragnet_ surveillance implemented by any local authorities. These can't affect me. Of course I'm obviously getting flagged for doing this. However, this brings me to my main point:
What this can't stand against:
1) Any "real" investigation into my identity. By a powerful corporation / low tier intelligence outfit / law enforcement. And that's fine! Since I'm not really doing anything illegal (or illegal enough for actual people to care about).
2) And in general, this doesn't stand a chance against any active adversary that targets me directly. But neither can you, or anyone else.
And this is a good thing! By doing what I'm doing, I now have a "reasonable expectation of privacy". If anyone wants to investigate me, it is perfectly fine. They'll have to spend some man-hours on it though. Just like old times!
So far (about nine months in) I haven’t gotten any DMCA complaint, and can seed torrents without having to care for upstream bandwidth at home.
I currently use DigitalOcean, and pay via PayPal. So would be nice to get away from that. The only other cloud provider I have experience with is AWS.
I thought the same thing, until I found openvpn-installer [1]. You just need to run 1 command - the entire OpenVPN setup process takes 5 minutes. I used it on both Debian and CentOS and it works flawlessly.
At the end, you just grab the config file using rsync or SFTP, and load it into your OpenVPN client. Now I have a dedicated droplet for VPN use. Once a month I destroy it and create a new one, because I'm slightly paranoid :P
I have read that DigitalOcean have a strong stance against torrenting though, so have only downloaded a few times through my VPS.
Was considering moving to AWS, but I'm not sure Amazon would be any happier, and I'd probably end up with a big bill at the end due to bandwidth usage!
Another option is to just get a seedbox. You basically get a server running a torrent client that you can access through a web UI. Once you download a torrent, you FTP it over to your machine. Many of these providers can give you amazing bandwidth .
Yet another option is to save yourself the effort and simply get a Usenet account ;)
Thanks for the mention!
Keep up the good work.
when using a VPS you'd also have to trust the VPS-provider. There's no difference between trusting a VPN or VPS provider - both can see/log/monitor your traffic.
Tor uses a current version of Firefox and automatically updates it.
He also has a subreddit:
>Distinct services and multiple daemons provide an enormous amount of flexibility. If one connection method gets blocked there are numerous options available, most of which are resistant to Deep Packet Inspection.
I don't know too much about networking, but didn't realise it was possible? How can they do that? What protocol/service can bypass this? The network security team at work challenged me to see if I could bypass their WSA, so would like to give it a try.
They're doing more aggressive surveillance than the NSA.
Edit: words.
Getting around such blocks (such as with a SSL tunnel) is possible, but requires more than just a default install.
Also, setting up anything other than OpenVPN is a real pain in the arse. Even OpenVPN required a fair bit of Googling to make it fully functional.
I've always been a bit suspicious of OVH, not sure why...
OVH also has two cheaper brands for dedicated servers to checkout - SoYouStart and Kimsufi. The two cheaper brands have much more limited support.
1. "You must trust the VPN." This is true, but you must trust something (your cafe, your ISP, your computer). In fact the entire article really hinges on this point -- the VPN provider could, if it were malicious (or compelled to by a government) log every aspect of your traffic, or even insert malware. However, so could your home ISP or your coffee shop.
In particular I found this statement very bizarre: "VPN services require that you trust them, which is a property that anonymity systems do not have." This is true in a vacuum. In the real world, unless you're running your own hardware with software you have written yourself from scratch (on a system which you monitor continuously), you are trusting a huge amount of stuff even with the best anonymity system. The point is knowing what you are trusting, rather than trusting it implicitly.
Essentially the point of the article seems to be to point out that VPN providers may be (there are a lot of hedge words) untrustworthy. The only actual example given of an untrustworthy VPN provider is a free one which re-sold its users' bandwidth (point 8).
Real-world examples are important, because reputation is important -- at some point it is very likely that you will end up trusting someone, even if you are being very careful.
2. "Some VPNs don't permit peer-to-peer sharing and/or log such sharing". You must rely on reputation, which is not a great option. However, no alternatives are presented for someone who wants to torrent copyrighted or illegal works (TOR is heavily FUDded in the article). You certainly wouldn't roll your own VPN for this -- see below.
3. "VPNs don't protect very much against ad tracking". This is true, but I mean VPNs don't make your teeth much whiter either.
4. "A dodgy VPN could log all your data". This is the same as point 1.
5. Preshared keys. OpenVPN with server certificate checking would seem to address this.
6. "Your VPN provider might log your data". This is the same as point 1.
7. "Leakage". It's useful to inform people about this. However, once informed, it is quite simple to use one of many online services to verify that no information is leaked.
8. "Snake oil" and in particular a free VPN which sold its users' bandwidth. Fairly obviously, be aware that if you are using a free product the company will attempt to monetise you in some way.
The suggestion to set up your own VPN seems to be presented as a way to improve privacy. This is very strange particularly since no threat model is presented, and the common one (mass surveillance) gets much worse with a personal VPN.
Firstly, shared hosting providers such as DigitalOcean, AWS, OVH and so on are presented. There is no particular reason to suspect that these are more or less trustworthy than any given VPN provider. In particular, shared hosting in the US will certainly be subject to the monitoring whims of the US government.
Secondly, using such a DIY solution will associate all your traffic, and only your traffic, with a single outgoing IP address, easily traceable to you (since you're paying for it). Compare this with any shared-endpoint VPN, where your traffic is combined with that coming from many other users, and the owner of the IP address is a VPN company. In the former situation nobody would even need to inform the hosting company -- they could just monitor its traffic (though as discussed in point 1 they certainly could contact the hosting company if necessary). In the latter situation, the VPN company would need to be involved. At this point a certain amount of process is required. If your threat model is mass surveillance rather than targeted monitoring, then the shared VPN provider certainly seems like an improvement over a roll-your-own solution. "The best place to hide an incriminating letter is in a letter rack!" -- Edgar Allen Poe.
Thirdly, with a DIY solution you are implicitly claiming that you are better at hardening a system and staying on top of security patches than is the VPN provider you were considering going with. This isn't necessarily true.
If you are just concerned about opportunistic data collection from your coffee shop, then a personal VPN would help. But it's quite limited, and significantly simpler solutions like HTTPS Everywhere would get you 90-100% of the way there.
If you are specifically concerned about an entity with the resources of a government monitoring specifically you, none of the options presented will be any use.
not private but free and always available
The head engineer of Opera for computers Krystian Kolondra: “Currently WebRTC and plugins are still not routed that way”[0]
The technical difference between a VPN and a proxy is typically that the proxy works at the application layer (layer 7) of the network stack, whereas a VPN creates a new network interface and operates at the network layer (layer 3).
The practical implications (which you asked about) are:
i) With a proxy, there's no new system network interface, so no way for other apps to use it
ii) A proxy is application-specific (in this case HTTP and HTTPS) so other protocols (even those that opera supports, like WebRTC) can't go through it.
[0]https://www.helpnetsecurity.com/2016/04/22/opera-browser-vpn...
Is it for web traffic only? So no torrents? Any logging? Speed?