How to Setup a Secure VPN Server on Raspberry Pi or DigitalOcean
blog.hsp.dk
blog.hsp.dk
The performance argument is only relevant for the establishment of the VPN connection and any periodic rekeying — it shouldn't have any impact on the tunnel's perf.
It's a shame openvpn's easy-rsa doesn't provide a straightforward mechanism to generate ECDSA certificates, which would've removed any performance concerns.
--
edit: easy-rsa does support ECDSA[1]:
Support for generating an ECDSA certificate chain is available in EasyRSA (in spite of it's name) since EasyRSA 3.0. The parameters you're looking for are '--use-algo=ec' and '--curve=<curve_name>'. See the EasyRSA documentation for more details on generating ECDSA certificates.
But crucially you'd want to make your browser use the tunnel for DNS as well: http://superuser.com/questions/103593/how-to-do-dns-through-...
Careful if you're using this for something dangerous. I'm not a computer security expert by any stretch and I don't know whether the people who have written these articles are. Chances are that this is completely broken and will reveal your IP address and identity.
It is not a Tor replacement or anything. I think it should be effective at simple things like: masking personal browsing at work[0], masking browsing habits from your ISP.
[0] Obviously if you use a company computer, you could be keylogged/monitored in other ways. Use your judgement.
What I don't get is why people think that random VPS and VPN providers would somehow be better for your privacy than to let your ISP see the content of your traffic.
A random VPS service (preferably in another country) only cares about you insofar as you pay them and don't cause any trouble to them. They don't have as much of an incentive to invade your privacy as your home ISP does, and I trust incentive structures a lot more than I trust boilerplate words on a privacy policy.
It can also be a matter of opportunistic encryption. Most public wi-fi is vulnerable to anyone in the vicinity, in addition to the usual ISP and the NSA. Use a VPN and now you're only vulnerable to the VPS service and the NSA. That's quite a bit of improvement.
You also have the freedom to choose a VPS service with good connectivity in a relatively less snoopy country, a luxury you often don't have in choosing your home ISP.
The have a much better opportunity of correlating traffic than anyone else. It's not separated by an IP anymore. They've got a specific account they can connect to a specific person. (via billing) I believe if they wanted to sell the traffic logs, they'd easily find customers.
Also there have been companies like Hola (https://torrentfreak.com/hola-vpn-sells-users-bandwidth-1505...) that do outright evil things just because you run their software. Facebook bought Onavo VPN which gave them more traffic visibility.
There's also a few VPN services which will replace / inject ads into pages you visit without https.
So yeah - a lot of reasons to invade both your security and your privacy here.
Meanwhile, I doubt that Linode has any interest in injecting ads or selling traffic logs.
You can always try 'chaining' VPNs together, or stacking them on top of each other so that if one of the VPS servers is compromised, a TLA gets nothing but encrypted traffic and can't see what you're doing. The only caveat here is the 'exit' VPS is always going to have to be unencrypted. This is why it's worth looking into offshore VPS providers in non-five-eyes countries. I'm not sure what countries these are. I haven't done the research.
Typically I achieve chaining by doing the following:
- Hardware VPN that I connect to as normal. Personally I use http://www.pivpn.io/
- Then I connect to another VPN on my host/hypervisor machine
- Then I fire up Virtualbox and run another VPN inside the VM
- The chain now has three hops, and the exit VPN is on a box that I control. I avoid Digital Ocean like the plague as it's a US company.
There's also a law specifically making it a crime to post any information about government actions deemed a "special intelligence operation" [1], which makes me think that they're recording this data in bad faith.
So fuck 'em. Fuck the government that seeks to monitor everyone in order to entrench their power structure. Fuck them for lying to us, by claiming it's about terrorism. Fuck them for indicating a willingness to prosecute anyone who shines a light on their shady actions.
That's why I use a VPN, running on a VPS I have provisioned myself. No, I don't trust the VPS provider, but they have no power to imprison people, nor have they demonstrated a desire to expand their power over others.
[0] http://www.abc.net.au/news/2016-01-18/government-releases-li...
[1] https://www.theguardian.com/commentisfree/2014/sep/26/journa...
Going with a smaller company for a VPS intended for use as a VPN is a good idea.
Cloud Hosting Offers | Web Hosting Talk http://www.webhostingtalk.com/forumdisplay.php?f=159
VPS Hosting Offers | Web Hosting Talk http://www.webhostingtalk.com/forumdisplay.php?f=104
https://www.ssdnodes.com/startup-specials/
/utterly shameless plug
In OpenWRT, it's basically:
-setup OpenVPN with a TAP device
-create a VLAN, assign some ports on the switch (optionally, a wifi SSID for VPNed wifi)
-bridge VLAN with TAP device
also, 1024 dh prime is unsafe depending on your threat model[1]. use 2048 if nation states bother you, or 4096 if truly paranoid or at high risk / performance isn't an issue. no reason not to bump up the RSA keys too.
https://blog.elasticbyte.net/setting-up-a-native-cisco-ipsec...
If your aim is to hide your traffic from third-party networks you might be on (free wifi, school, hotels, etc) then a yearly VPN subscription is almost certainly cheaper than the cheapest DigitalOcean droplet. If you get a good provider (I use PIA but am not affiliated with them) then you get unlimited traffic, multiple clients, endpoints all over the world, tech support, all without having to setup and administer the server yourself.
If your aim is to disassociate traffic with yourself, your DigitalOcean IP will be tied back to you anyway.
If your aim is to stop government snooping, DigitalOcean is hosted in the USA so you may as well just send the NSA your browsing history.
Where I am for example almost all VPN vendors are blocked, so there's not much choice other than to roll your own. And once you've figured out how to do it on one provider you can pretty much do the same anywhere.
I spent some time submitting support tickets to all the hosting providers I had tried (many). Every one of them told me that they had no way to disable TSO and the other common TCP offload features on their hosts.
So now I use Packet.net which gives me a honest to goodness actual bare metal machine (over which I have complete control), for much the same price.
Also shoutout to Dr Duh who gave a nice run down of setting up vpn on a VPS
https://github.com/drduh/Debian-Privacy-Server-Guide/blob/ma...
Edit: Just realized that others have already noted and commented about SoftEther. Sorry guys!
http://www.selectedintelligence.com/post/128701492804/softet...
Surely for it to be a 'secure VPN server' there has got to be some stuff set up first, like setting up key only login, disabling root ssh login, disabling everything ssh, setting up firewall, disabling ipv6 entirely in the case of openvpn?
I run a vpn on digital ocean and its amazing looking at the logs and seeing how quickly, and how many attempts there are to break into the server straight after setting it up. As a person who isnt completely sure of what i am doing when it comes to firewalls and setting up 'jails' or whatever, this kinda makes me uneasy. I wouldnt even be sure how to tell if anyone had broken in to my server...
https://www.linode.com/docs/networking/vpn/set-up-a-hardened...
This has been the most useful guide that I have found on setting up an openvpn server. It has a bunch of steps to go through before you get to actually installing openvpn. But as I said, I am not that knowledgeable myself when it comes to running a server, so this may all just be unnecessary.