VPNs Are Absolutely a Solution to a Policy Problem
journal.standardnotes.org
journal.standardnotes.org
This article is saying, basically, that the tendency of ISPs to try to monetize user data is a natural consequence of capitalism, and trying to curb that tendency with legislation is ineffectual compared to the real solutions (fight monopolies, and everyone use a VPN).
I don't buy it. Roughly the same argument could be made about virtually any regulation. "Corporations are incentivized to pollute, so there's no point trying to stop them. Buy a water filter." "People will always try to get heroin, so there's no point in restricting it. Get some naloxone." Damn near every regulation is an attempt to counteract some profit-motivated tendency which is the unfortunate consequence of capitalism. And as regulations go, user data is a lot easier to regulate than drugs or pollution.
"Just get a VPN" might be good advice for individuals, but it is emphatically not the society-wide solution to data privacy. We can and should continue to fight for good legislation that protects us.
Certain industries have a tendency to be monopolistic, or else have incredibly high barriers to entry. ISPs should be regulated to protect customer privacy. This is the equivalent of USPS, the public library, and the phone company selling your data to whoever wants it, and it's wrong.
If you wanted to make it slightly less "government-y," you could just establish rules that those running the last-mile lines, and those providing the connectivity must be separate entities (and not connected to each other like some "spin it off as a separate division of Comcast but they are still parts of / owned by the same company"-type deal) so that everyone gets a fair shake.
[ That said, I'm not in favour of letting the privacy war play out in the market, because I'm not 100% sure that the market wouldn't just settle into a state where everyone was doing something I don't like to some extent. ]
Telcos loathed it and pitched many mighty fits and threw every (physical and metaphorical) wrench they could in front of their brand new competitors. But it worked, in spite of the problems[0]. The absolute best I ever had was in Southwestern Bell territory. Over a single copper circuit I could choose from TEN different ISPs. Speakeasy, Megapath, Covad Direct, August Net, and a handful more that I can't remember. In 2002, I paid Speakeasy $160/month for 10mbps symmetrical with 8 real IP addresses and no port blocking.
President Bush was elected and the telcos' complaints were given new life at the new FCC. The unbundling requirements were swiftly removed. Now, we have this.
0 - And don't get me wrong, the problems were legion. UNE-P didn't apply to cable providers nor the new-ish fiber optic last mile buildouts. Only ILECs were subject to it so competitive providers who had built physical plants got to skate by. And there were some legitimate complaints over the "profit margin" calculation (in quotes because what's a margin in the telco business, really?). But, damn, it did work for a brief time...
Oh, I know that. The US also had more "competition" in the ISP space nationally because all of the regional telephone companies and cable tv providers hadn't yet consolidated into the mega-corps we have now.
> Telcos loathed it and pitched many mighty fits and threw every (physical and metaphorical) wrench they could in front of their brand new competitors.
Separating (e.g.) AT&T from their last mile infrastructure (and placing barriers to them re-obtaining it) would go some of the way to preventing this. Someone operating the last mile infrastructure that is not also a direct competitor to their customers[1]. It's a conflict of interest that no law or regulation is going to properly resolve.
[edit: I should clarify this. No law or regulation is going to properly resolve the situation unless we remove the incentives for the last mile operator to find loopholes to screw their customers.]
[1] the ISPs connecting to people over the last mile infrastructure
This is why in the USA the cable companies are the big ISP leaders and the telecoms are second fiddle.
Verizon only built Fios when they got clearance that they wouldn't have to share it.
The unbundling is a great way to make sure that legacy systems are fairly priced. It's a bad way build new systems.
So there's no simple cause+effect here related to unbundling. And even with unbundling it's not like a company loses money; they just lose monopoly rents but are guaranteed some profit whether or not they have to share.
Really the issue is about opportunity cost and financing: Verizon would rather invest in endeavors with a higher return than what they'd get with copper or even fiber. That higher return is wireless.
But there's so much cash available, or at least there has been for the past 10 years, that theoretically somebody could have stepped in to invest in these projects. Google was tentatively one of those people--initially it was enough for them to break even--but it looks like the only entity capable of committing for the long haul will be a non-profit or government entity. More so as the era of freakishly low capital costs slowly comes to an end.
Don't forget the fact that it's 2017, and DSL sucks. 40mbit down and 10mbit up at best is what DSL providers tend to offer. DSL just isn't viable compared to cable.
> [...] stop relying on governments for self-protection that you can handle yourself. If it’s not the current administration that will repeal our protections, it will be the next one. And what then?
The whole point of a democratic government is to protect the interest of the majority of their citizens, and the selling of personal personal data is clearly against the interest of most Americans. In a democracy the tool we have to protect our interests is the law. Unfortunately this tool sometimes is also used by small but powerful actors for their own purposes, colliding with the will of the majority. That's exactly when we have to fight back to keep the government democratic.
VPNs can be used as a temporary workaround by some people, but it's definitively not a good permanent fix for this constant invasion of privacy that many corporations in the US are so willing to attain. Even if you think you have a perfect technical solution (GNUnet? Tor? I2P?) the next administration can simply say that solution is unlawful, and what then? The fact is, sometimes we have to demand our government to do the right thing, and this now is one of those times.
Once you notice that, the whole piece is basically just ancap apologetics.
Is this the goal we strive for? There are lots of things that we don't want that could be largely couched in the language of "being in the interest of a majority of citizens". For example: Aggressive policing against petty theft, stop and frisk, prohibiting sales of off label unpackaged cigarettes; antiterrorism laws with intrusive cavity searches at every airport; fugitive slave laws...
Think about the original purpose of the FCC. Some regulation is required to make the services work at all. With a completely deregulated system, your microwave would disrupt cell-phone service for blocks. Your computer power supply might do the same thing. And Verizon phones would probably intentionally interfere with AT&T phones.
Low-frequency spectrum is a public resource, full stop.
Can't agree more. Corporatist rent-seeking is the fundamental problem with our political economy and/or society. But both sides keep talking past each other (as they are incentivized to do).
Tangent, thanks. This is the phrase I was trying to conjure to mind earlier today in a discussion about the very topic of this thread. Ended up taking a long, exhaustive and context-laden road to get to my point; after which I had already lost an audience but so it goes.
For the interested: https://www.wikiwand.com/en/Rent-seeking
https://arstechnica.com/business/2014/04/one-big-reason-we-l...
https://motherboard.vice.com/en_us/article/the-fcc-cant-help...
https://consumerist.com/2015/05/26/why-your-cable-company-do...
Government regulation contributes much to the cost of investing in infrastructure and starting an ISP business in most areas. I think it would be interesting to see what would happen if that cost could be brought down.
VPNs are a strategy for mitigating an individual's exposure—leaving the monopoly of the ISP intact.
Monopolies don't last in a free market. Someone hungrier will eventually come in and undercut the incumbent.
Anti-cartel ones do the latter. Many properly made regulations are not easier to adhere to by big vs small agents.
Regulation is a tool, and it does more or less what the tool user intends it to.
It seems odd to reject regulating against certain practices and reject the breakup of monopolies as well. Without a market that works properly many more specific practices are going to have to be banned. That's not an ideal situation. Monopolies are indeed the main problem here.
Also, VPNs seem to be under attack from governments, so I wouldn't rely that option being available forever either.
I have to wonder why government regulation is to be avoided at all cost when it comes to consumer protection whilst the very existence of corporations, their property rights and hence markets themselves is owed entirely to government regulation.
I am very much in favor of using market mechanisms to solve as many problems as we can, because if and when markets work they solve a very complex coordination problem that is extremely hard to replace with planning. But to claim that markets can solve every problem including their own dysfunction is just logically nonsensical.
We've seen what the wrong people in power do. Mussolini, Stalin and his gulags, Pol Pot and his genocides, Kim Jong-il, Slobodan Milošević. This isn't a statement about the current US President, but we depend on having right (enough) people in power in a lot more ways than this one policy decision.
There's nothing that says this will be the case. It would be very simple to deprioritize VPN connections, and recommend an upgrade to their "business" ISP plan if you need your VPN connection prioritized.
They have no reason not to, and every reason to. Either way, they get more money out of your existing internet use. It would be a pyrrhic victory at best; they wouldn't be spying on you, but you're paying twice more for that "right".
Then the author should go all out and suggest that the federal government completely deregulate all the spectrum from, say, 500 MHz to 1 GHz. We'll have lots of wireless providers, and none of them will work well because they'll all interfere with each other.
There's a variant that might work, though: force the licensees to operate on a wholesale basis only. No Internet, no voice, no SMS, no phone number, no streaming NFL games, purely connectivity to a wholesale backend provider that can provide whatever services they like using whatever peering, transit, CDN, etc relationships they want.
As a practical matter, it would probably work better to let the spectrum licensees provide voice and SMS, just because the protocols are so absurdly complicated that it might be very hard to get it to work wholesale.
(As an aside, public utility regulators could do the same thing for wired services. Let one provider supply every property in an area with a 10Gbps point-to-point fiber link to a nearby datacenter. Anyone else can lease space in the data center and cross-connect to residents' fibers.)
Unfortunately, in the real world, history teaches us that free markets will absolutely go to hell in a handbasket if the wrong people are in power even for a short time.
So much for ivory tower "free market" idealism.
On the other hand, we can work for a decade to introduce regulation over the hard-to-define concept of an ISP monopoly, and then spend more decades going through the inevitable break-up and re-conglomeration of these entities under different forms, like we had with the telcos through the last half of the 20th century. In 50 years we may have a landscape that resembles that of the current cellular carriers: three or four large players in most metro areas, fewer rural options, and little real choice among them in terms of QoS or T&C. I suppose this would represent a slight improvement over the status quo?
This is the problem with so many free-market proposals, they would have you off tilting at windmills instead of directly addressing a fairly straightforward problem.
Why not? Author didnt say much at all about this. What else is regulation for if not to keep certain things in check better than the free market/people/whatever can do?
Where incentives are misaligned and/or the issue is a technical/complex and users are highly unlikely to vote with their dollars regulation is the only possible achieve success.
Ideally, you wouldn't rely on trust, i.e. Policy, you would rely on math. As far as we know, judging from the Wikileaks releases, encryption still works.
With pollution, it is a policy issue, because there's no mathematical way to prevent polluters. So we have to negotiate amongst lawmakers, regular people, and corporations.
I think what the author is saying here is that we shouldn't bet our privacy and safety on who is in charge, as we are always one flick of the pen away from losing those protections. I think this is especially the case when there is a mathematical solution to the problem, that doesn't require trust. Obviously, having math and policy would be an added bonus.
> I think what the author is saying here is that we shouldn't bet our privacy and safety on who is in charge, as we are always one flick of the pen away from losing those protections.
Yes, and what I'm saying is that the same is true of every other regulation, which is why it's not a compelling argument against this one. You may have noticed that the same Congress currently gutting privacy protections is also gutting air quality protections...
So, on this point I agree. We should live in a world where lawmakers protect privacy and the environment, and the fact that they don't is disappointing and a short term (hopefully not long term) failure of government.
So far we are in agreement. In addition to that, I think what I'm trying to add is that VPNs are absolutely a way to mitigate the need for lawmakers to do the right thing, a concept in the abstract we all agree on but in reality proves to be very difficult. I'm not sure you're disagreeing with that point or if you think they're mutually exclusive, maybe you can clarify.
To go with your analogy about water filters being a substitution for having protection for keeping water clean. No, of course I don't think it's an effective substitute, but I'm still going to filter my water in addition to demanding that adequate protection is put in place.
So hopefully we are in agreement on that point as well, as they're not mutually exclusive.
But the overall, larger point to be made is we should just always do what we can. So voting is one thing, among other avenues within the process of government, however I'm also going to use a VPN, because, damn it, it works.
One last thing I'd like to say from another comment that I wrote somewhere else in here is that hopefully this will be an impetus for full decentralization the internet further, because an ideal solution would be to make it logistically intractable to snoop. A distributed internet, similar to how it was originally envisioned.
We are all engineers and can understand the concept of a patch versus a refactor. Yes, a refactor may be harder, but there is never an excuse to rely indefinitely on a patch; that's how you get burned with technical debt.
The government needs to change to be more responsive to the people and not constantly sell them out at the flick of a pen. Yes, use a VPN! But don't buy the message that there isn't more that can be done. There is, and many people are working tirelessly to see it through. Don't ignore or devalue their efforts to make a better system for people.
Google is already toying with the idea of creating VPNs for consumers. In the case of the pixel it's legit because they allow you to opt-in to VPNing to google servers on untrusted WIFI connections. The irony is that now google has even more data on you. Once your VPN exits, you can still get MitMed/injected on non-TLS resources, so what is the VPN really doing for you? The only thing the VPN does is control which party will spy on you.
The blind lead the blind I guess.
And the FCC has never attempted to regulate that level of privacy.
https://developers.google.com/speed/public-dns/privacy
So they don't track personally-identifiable information directly; it's certainly possible you could de-anonymize someone from their dataset, but most of what they do track is on their end (what machine handled the request, how quickly, etc.)
VPNs are a tool, but it's easier for users to install a plugin that pollutes their data than to enable VPN.
I think this ignores article too much about what is actually at risk, regardless of whether a VPN is a viable solution for some.
I think privacy and pollution regulations can be good, but they need to be carefully tracked and aren't always effective.
The best solution for you is always to be a vigilant consumer. Something like this can be protected entirely by doing so. Pollution is harder to defend against. Using a VPN is a great strategy to mitigate these issues before they're allowed to happen to you.
Fighting monopolies is an argument for more aggressive application of competition law, to break up monopolies, and disallow anti-competitive conglomeration. But again the article doesn't bring up anti-trust.
The article also doesn't account for the fact that an ISP, without net neutrality regulation, can block or throttle or charge extra, for VPN usage.
Buying water filters doesn't do anything to the polluting party. They can just keep polluting.
On the other hand, using a VPN makes your data worthless. It allows you to directly hit back at the companies trying to monetize your data. It's entirely different that just avoiding the problem.
It's not a long term solution.
[1] "The eruption of Mt. St. Helens should have alerted everyone to the ever-present processes of natural pollution (...) In sum, no one has a right to clean air, but one does have a right to not have his air invaded by pollutants generated by an aggressor (...) such aggression may take the form of pollution of someone else's air, including his owned effective airspace, injury against his person, or a nuisance interfering with his possession or use of his land (...) this is the case, provided that (...) while visible pollutants or noxious odors are per se aggression, in the case of invisible and insensible pollutants the plaintiff must prove actual harm; the burden of proof of such aggression rests upon the plaintiff; the plaintiff must prove strict causality from the actions of the defendant to the victimization of the plaintiff; the plaintiff must prove such causality and aggression beyond a reasonable doubt; and there is no vicarious liability, but only liability for those who actually commit the deed." https://mises.org/library/law-property-rights-and-air-pollut...
When you find, for example, your crops damaged by acid rain, that acid rain can have been caused by pollutants releases hundreds or even thousands of miles away, from hundreds of sources.
Who do you sue? It's generally not going to be possible to prove that the pollution emitted by any particular source ended up in the rain that fell on your crops.
And while the law would probably let the ISPs sell your actual web history, in the past ISPs never went anywhere near that far. They more or less did what Facebook and Google do with their data.
Isn't "user privacy" is a collective noun that describes a shared resource? I.e., Tor's anonymity pool.
It's disgusting, and I'm disgusted (_yet again_) by the mercenary Republican Party. They are declaring war on me and my loved ones and the vast majority of our fellow Americans and anyone else unfortunate to have to use an internet connection in the US (and live under the rest of their insane policies).
For the record, I signed up for a personal VPN two weeks ago because this anti-consumer outcome was assured with the current party in power in the US.
I found this comparison matrix[1] which provided me the info I needed to identify a few services to compare. I'm really just looking to keep my ISP from snooping on my traffic, so my criteria are pretty limited and I just wanted something quick. I don't plan to watch Netflix with it for example, which might have pushed me to a service that would allow me to select specific servers for traffic egress.
I have no complaints
>I don't plan to watch Netflix with it for example, which might have pushed me to a service that would allow me to select specific servers for traffic egress.
PIA has servers in many different countries that you could switch to, does that not that fulfill this?
Its a "has power" vs "doesn't have power" split.
The Democrats are just as culpable as Republicans. Don't give either party a pass.
The vote count sure looked like it to me.
https://www.govtrack.us/congress/votes/115-2017/h202#admin_p...
Yea 215 (Republican 215, Democrat 0) Nay 205 (Republican 15, Democrat 190)
On actually contentious issues, like CISPA and the like, the votes split almost exactly down donation lines as opposed to party lines.
Regardless, even if the split is supposedly true what do you think is the real problem? The current republican gang or the influence and power the rich wield? Even if you replaced every single politician you hated with the wave of a magic wand the powers that be would still find ways to influence the new group.
We should tackle the systemic problems first as a whole nation, then hopefully the issue of removing those that wish themselves our master will be much easier.
[0] https://www.opensecrets.org/industries/totals.php?cycle=2016...
Congress is completely corrupt. They don't write legislation, k-street does. They don't read legislation they pass. When confronted, they waffle about benefits to corporations being beneficial to their constituents. Almost all are in violation of their oath.
After much deliberation I think reprent.us has it right, the only way for us to take of this issue is for a new rallying cry to elect third-parties and indepedents to take away the majorities of both parties. (which is also how we get an independent or third-party elected president by taking the 270 votes away from both parties and the vote goes to the house).
We need to stop letting people push the farcicle duverger's law as if it's irrefutable fact, because it's not.
But combined, their views represent only a narrow slice of the political spectrum.
Both parties have their own flavor of expanding the powers of the government, while no one in office is advocating reduction of government power.
Sure, the republicans occasionally give lip service to the idea, but they're all the same as the dems.
I guess I'm a bit fed up being told "pick a party that represents you" and finding absolutely zero options who don't make me feel dirty or stupid.
I maintain that both parties are the same, neither is capable of delivering real change. (A perfect example is the last US presidential election. Trump and Hillary? FFS.)
Not everyone is interested in across-the-board reduction of government power. I understand it appears to be your view, but you need to be careful to treat that as another political position, not as a global constant.
>I maintain that both parties are the same, neither is capable of delivering real change
I think it's a naive fallacy to have the base goal being some nebulous thing called "real change". When things like Obamacare and gay marriage and raising the minimum wage and protecting the environment, like Obama did and Clinton would have worked for, can't be called "real change" because they aren't the perfect solution some liberals/libertarians would want belies a privilege in not being a member of the classes that these things really affect, which coincidentally are not classes often represented well in the tech industry or on tech boards like this one.
I am too quick to elevate my political _opinion_ to that of fact, and in doing so, commit the exact same mistake that drives me bonkers when other people do it.
Also, my own use of "real change", as soon as I read your comment, made me hang my head in shame. "Real Change(TM)" is just a stand in for "something that I think should be done, and until it's done, nothing else matters!"
It's related, I suspect, to the "no true scotsman" fallacy.
So, you're right. I worded that entire comment poorly.
This is one of the reasons I enjoy dipping into the HN comments now and again - I sometimes get really high-value feedback like this.
So thank you, /u/mejari, for taking the time to comment what you did. It's a good gift. :)
It kinda depends on what you mean by "across-the-board reduction of government power." I do believe that everyone is interested in peace. And justice. And creativity. And hope. And being able to relax and do what they want.
And even if government isn't in opposition to these things in every case, empire certainly is. And people recognize that.
So yes, deprecating the American Empire is something that enjoys very broad support; certain aspects enjoy consensus.
While 'No Empire' seems to be a Good Thing, in general, if the question was instead, "Which country should lead the global Empire if not America?" I wonder what the survey results would be.
That is (by way of the Median Voter Theorem) a consequence of the two-party system, which is (by way of Duverger's law) a consequence of winner-takes-all or first-past-the-post (and not proportional) voting, I'd say.
https://en.wikipedia.org/wiki/Median_voter_theorem
https://en.wikipedia.org/wiki/Two-party_system
A Democratic president put these protections in place.
He expanded the powers of the NSA because he could, or had to, or whatever. I struggle to imagine that he then turned around and used the FCC to push meaningful reform along for his citizens.
I think the burden of proof is on you to show that his track record with government spying should be ignored when thinking about his track record with FCC/consumer protections.
It is in their interests for us to think there is meaningful difference between them, and I'm confident that many dems and republicans do earnestly believe there are differences between them and the other party.
But the differences are _so small_.
If one party wants to pass legislation that does X, and the other wants legislation that does Y, there is _no one_ advocating for all the myriad unspoken options.
My wife used to be a kindergarten teacher. One of her classroom management strategies was to try to give her students options. She'd say "would you like to do X or Y right now?"
Of course, she only gave options that she already approved.
So, for the "powers that be", the real power is deciding what bills go up for a vote. What happens in the actual vote is trivial compared to the power that comes with killing a bill before it hits the floor, or passing other legislation in omnibus spending bills.
I maintain that they work together to screw us all over for their own benefit, and to keep the corporate spigot flowing.
Stop this BS. The democratic party has done pretty much similar bad things that violate our privacy. Are you just good at selectively ignoring things? This is really the fact that every US govt is not for personal data privacy. You have to just accept it (if you are an american).
It's also a good concrete issue to use in understanding that while arguments like "Democrats Do Bad Stuff Too So IDK Apathy" may be persuasive to some people in justifying not voting, it's ultimately not true. If this issue matters to you, there was a ballot box solution to preventing it. Not enough people used it.
If this recent attack on privacy is something both sides support (as you seem to claim), why did the Obama administration set out those rules? And why did the Democrats in Congress not vote for this repeal?
Those rules were a proactive measure
Were? Obama's rules affected by this legislation wouldn't have taken effect until next December at the earliest. It was an Obama administration screwup that opened this privacy hole in 2015, and it's been there ever since. Why is the outrage only popping up now? The ISPs have almost 2 years' worth of data already.Don't bring that weak Whataboutism here.
If when given the option you don't use services that keep your data private, why is this a big deal to you when yet another service you use sells your data? If you want privacy you either need to shop for services that provider it, or like this article states, take measure to ensure some level of privacy.
Politically, it means that people who should be getting angry about reduced privacy are "comfortable" with the fact they can work around it, while a new generation grows up with fewer and fewer expectations of what privacy means. It's short term protection in return for normalization of anti-private behaviours and long term damage.
But I also have a problem with it technically:
Issue: You don't trust ISPs to not sell browsing history.
Solution? Provision a virtual server, set-up a VPN and tunnel.
But your server still has a service provider. It might not be literally tied to your billing information but that was never going to be anyway.
You've shifted which ISP gets to sell the data from "home provider" to "virtual server provider", but there is still browsing data isn't there and it's just as valuable from a private single-use VPN as it is from your home connection.
The idea is to use a VPN provider that keeps no logs and runs many concurrent connections NAT'd behind the same public IP address. That way your traffic is mixed in with everyone else's who's using the service and provides you with an additional layer of anonymity.
You might also not realize just how shady and willing to sell you out many of these VPN services are. They tend to be un-audited, un-regulated.
This is one specific way in which a VPN is a poor solution to protecting privacy. It means the user has to constantly be on guard to which traffic should go over the VPN and which should not. Even one single slip up could negate all the benefits you think you are getting.
Edit: This reply should have been a couple levels higher, addressing the general tracking discussion rather than NATs specifically.
* edited for spelling error
I would say the "better" solution would be to find a provider with a good reputation and stick with them, and leave them in a heartbeat if it appears that they've sold your data. It gives them an incentive to continue behaving well through referrals and recurring revenue.
edit: Here's the GofundMe trying to raise money to buy their Internet history. Something tells me this dude is going to run off with the money though
http://resistancereport.com/resistance/crowdfunding-lawmaker...
And even if it was remotely like that, I can guarantee you that the providers will go to lengths to make sure they didn't just lobby millions (speculating, of course) to get this through and then throw the same congress members under the bus that they lobbied to and then hand out their data to get them in trouble with the public.
However, they can do what everyone else does; buy anonymized data for the area person X lives in. They can then use countless techniques (that have been demonstrated repeatedly) to de-anonymize the data and find out about person X.
This is what UK members of parliament did with a very similar bill, where they exempted themselves from the law itself: https://www.independent.co.uk/life-style/gadgets-and-tech/ne...
All-in-all, I think if you donate any money towards these crowdfunding initiatives, you might as well burn that money because it's not going to get people the info they think they are going to get. ¯\_(ツ)_/¯
It has been a few years since my Econ 101 class, but I suggest the author Google "market for lemons". Users have no way to verify the intentions of VPN providers as there is natural information asymmetry. Trust is not an issue that market economies have come up with a good solution to fix. The solution we often use ironically enough happens to be policy and regulation. So maybe this is a policy problem.
https://en.wikipedia.org/wiki/UL_(safety_organization)
There could be an identical service for privacy/internet tech. There isn't, but I'd trust an "Internet Underwriter Laboratory" group way, WAY more than a group of politicians.
So, while I can't speak to how these things _normally_ come about, this is a compelling example of self-regulation entirely outside of the scope of the government.
[0] https://en.wikipedia.org/wiki/UL_(safety_organization)#Histo...
You can select a paid VPN service that helps protect you from specific adversaries. You can roll your own VPN on your own VPS that helps protect you in some use cases.
You can, and should, advocate for good privacy policy.
So, how is that problem solved? I can't see what VPN companies are really doing inside their stack. They might very well be logging everything and I have no way to find out other than to "trust them" - so there's no real market mechanism to choose a VPN provider which doesn't log anything.
I suppose it could be in the contract.. so does VPN contracts have a clause like that, and how is it enforced?
You can always run your own VPN. Buy a cheap VPS, and set up OpenVPN to route traffic through it.
I ask because, I use a cheap VPS for a VPN, but wonder if it actually accomplishes anything.
I imagine they wouldn't know how to monetize the data, but if the market matures, there could easily be the same people behind buying data from Comcast-sized ISPs, creating tiny VPS and VPN providers that don't get any meaningful scrutiny in practice.
A VPN that sells your information and eventually, inevitably is caught, will lose their entire business. Meanwhile they can make a perfectly good profit just... providing the desired service. There are also people who take the time to investigate these various services, and you can do some work to find one that meets standards you deem to be acceptable.
There isn't going to be a perfect solution here, but the issues with VPN's are really not the issues you raise. My concerns are: Google and other major sites endlessly pestering VPN users with CAPTCHA requests, or the government actually making them illegal. Your concerns are largely answered by researching which product you're willing to buy, not unlike all other similar decisions in life.
Yes, a VPN company caught selling info would crash and burn. The invisible hand would ensure this, etc etc. But only if they got caught, and even then it's not like there would be any actual legal punishment (outside of a lawsuit if they were contractually obligated to not sell the info, I guess). And if selling that info meant double the profits, I doubt the owners who were willing to lie to their customers would feel all that bad or embarrassed. They'd probably also be shameless enough to re-brand.
And all that is ignoring the fact that with VPNs privacy becomes a privilege only to people who can a.) afford it and b.) understand how to use it. And finding a VPN that won't sell your info on the side requires the time and know-how to research it, not to mention even considering that a VPN might sell your info requires interacting with news orgs or people who might bring this concept up.
Chalk this up as another "HN readers don't realize most people don't read HN", color me surprised.
So yes, there are better solutions involving the law, but unfortunately the innocent lambs you're defending are the ones calling us nerds and buying IoT junk!
This is just the start though, you'd also have to guard against common keys and other various gotchas.
Also, another idea is VPN providers might start seeing it as a business opportunity to provide robust, secure connections and advertise how they work. These claims could easily be verified.
Just a start, I'm not an expert in networking, but it seems fairly doable. Obviously MITM is always possible if you're not connecting via ssl.
Also, this could be the impetus for further decentralizing the internet, although who knows how far that's out. The centralization of the internet might have taken things too far and killed the golden goose by abusing their position, incentivizing an acceleration of full decentralization, like with IPFS and their ilk.
Is there any evidence for this? I'm pretty sure that in the case of Google, at least, it's a flat-out lie. In fact, they state in massive letters: "We do not sell your personal information to anyone." (https://privacy.google.com/how-ads-work.html) Who would they even sell it to? They're at an advantage having that data themselves.
Expect more of FB's "internet.org" and Google's wifi balloons.
Very sad that Google Fiber isn't viable anymore.
Google runs the ad network, so they don't have to sell or "pimp out" personal data to advertisers. They use it themselves to make sure the ads are being seen by the people the advertisers want them to be seen by.
But, yes, pimping it out was just hyperbole for renting it for particular, well-defined purposes. But even that doesn't convey the fact that advertisers never have full access to the underlying data itself. They can specify the market demographics desired and google or any other ad network delivers the matching eyeballs.
Point: Locked doors and a shotgun under the bed is not a solution to the violent crime problem. We also need laws, and police to enforce them.
Counterpoint: Locked doors and a shotgun under the bed is absolutely a solution to the violent crime problem. You can't rely on laws, because they can easily go away with a stroke of the pen.
And that's despite crime being a very hard problem to fix. The privacy problem we're talking about here is actually trivially fixable with legislation alone.
But it's a false dichotomy. We need (the rights to have) both. Defense in depth.
The counterpoint is the one that sets it up as a dichotomy of sorts - that you don't need regulations, because the things that you can do on your own are sufficient.
1. VPNs are slow: They will never get widespread adoption because people pay for internet speeds and want them. Not to mention many people use internet that is so slow that VPNs are just not viable. I try to use a VPN at least when I go on public WiFi, but I've been to hotels were the service was so slow that the internet would just not work while using a VPN.
2. The article encourages ad blocking. The problem is that a lot of the web relies on ad revenue. Content doesn't just produce itself without funding. Yes, most content creators are finding alternate means of getting money, but we still need to keep in mind that this is an issue.
Therefore, while VPNs and Adblockers can help, I just don't see them as viable enough strategy to take down the ISPs. You are both slowing the user's ability to get content and the creator's ability to make it. Yes, the privacy focused community can use these tools, but everyone knew we liked privacy already. It isn't until the mainstream users speak up or do something that we can get stuff done.
The only way to break the monopolies is with government regulation forcing them to share the lines, because running the lines is the very costly part that stops new ISPs from competing.
http://f1x-2.deviantart.com/art/Robo-President-K3n3-DY-IV-62...
If they give me the broadband access for free then I might feel some sympathy for this line of argument. At 97% profit margins, not so much.
Funny how "entitlement" can be a positive thing when it describes a rich, powerful entity but a negative thing when it describes someone or something more ordinary.
Whitelisting would be nice too. Netflix video traffic, for example, would be nice to not put through another hop.
> Other articles have argued that VPNs are not a solution to a policy problem, because you can’t necessarily trust a VPN provider, or some VPN providers don’t encrypt your data properly. That may be the case, but that’s an easily solvable problem. And there are no monopolies on VPNs. This is something that a market economy can solve in a year.
That's where the author lost me. Building a secure VPN is different than your run of the mill SAAS - it's a difficult security problem, and an incredibly complicated user problem.
On the security side, it isn't hard to make a mistake that will give motivated parties the hole they need to crack the VPN. On a business side, it's hard to know which companies have received lucrative deals (or national security letters) from three letter agencies. And from a communications side, it's damned near impossible to let the whole world know that VPN Provider A collects data for a three letter agency.
Sorry to say it folks, but this is an area where we either need wholesale political change, or technological change. I'm Canadian, so I can't help you with the first one and I'm not even remotely qualified to help with the second.
That's right folks: the overwhelming power of the state to enact actual policy that can impact millions of lives? It crumbles before the power of my 1ghz Atom router. It has AES-NI, after all. That's, like, impossible to beat.
I've heard I can just "disable IPv6" on my Mac, but I don't know the full implications of this. If anyone has any input I'd appreciate this, because then I would use a VPN all the time.
EDIT Sorry I meant to type VPN not VPS, stupid typo.
Any sites you use that are exclusively available only via IPv6 will stop working, but due to slow adoption of IPv6, that list of exceptions is quite small. IPv6 adoption is big in China, but even then the major services themselves are available over IPv4. (Weibo.com doesn't even advertise an IPv6 AAAA DNS record, so the things I read about IPv6 adoption in China may be overstated.)
There are, of course, exceptions. There are a number of intentionally ipv6-only test sites like https://ipv6.google.com that won't work. Things like Google.com which are available over both IPv4 and IPv6 will degrade gracefully if you turn off IPv6 on your mac, and just connect over IPv4.
https://www.perfect-privacy.com/vpn-with-ipv6-support/
What I'd really like is a vpn that gives me an ipv4 address and an ipv6/64 so I can have my router do the vpn and route my whole network through a vpn by only configuring one computer.
I can think of a few off the top of my head that do:
* Linode
* Vultr
* Tilaa
* DigitalOcean.
EDIT: And the full implications of disabling IPv6 are approximately nothing.
It sounds like you're in the UK - I'm a US person, if I give you my traffic, what will courts say about my expectation of privacy?
I already operate https://smsprivacy.org/ which is essentially a VPN for SMS.
I don't have any way to prove I'm not logging your traffic, but I am a big believer in privacy and promise not to. If you don't trust me, you don't have to use it.
The same way you know any VPN company isn't. You just have to take their word for it.
Why is the word of a fly-by-night VPN provider any better than a HN poster?
How do you solve the problem without policy then?
We're talking about EVERYTHING you do online on your devices. It's no longer limited to what you're doing on Google or Facebook or any other place who's primary product is your data.
I'll quote it in full:
>Hey Google, when all email providers sucked you fixed it with Gmail, you run a DNS at 8.8.8.8, and now -- now, I think you know what you need to do now :)
>(I personally recommend you also do a web-based proxy, because who is going to filter https://www.google.com now or in the future?)
>I believe in you. You can do it!
>Counter this chilling effect today - and show more adwords as a result. (There is no irony in this statement. I mean from web sites that opt into adwords, not from selling VPN traffic logs.)
----
Google, pay attention: step up to the plate. Please!
That might be true at the moment, if you're using a good computer, but many computers do not provide full access to the system, including: Android, iOS, Windows 10. (Almost all mobile devices block root access as much as they can.)
Watch out for attempts to appify the WWW and reduce the ability of consumers to block ads and tracking: AMP, FB Instant Articles, etc.
One of the most dangerous threats to privacy is the increasing restriction on access to devices' hardware and software. If it isn't stopped, there won't be any way to block tracking.
https://pbs.twimg.com/media/CeqLfB5WIAAPZZh.jpg https://www.wired.com/how-wired-is-going-to-handle-ad-blocki...
However, either they've removed it or uBlock is currently winning the blocker blocker fight since I actually can read that article (I hadn't tried.)
If you want to be in the ad business, stop being an ISP and go into the ad business, but if you're providing a service and that service is internet-for-pay, and we pay you the money you have said it costs to use your service, then it is not reasonable for you to complain that there is more money to be had, and you want all of it.
1. The government's laws/policies are a threat to users' privacy.
2. You can currently use VPN's to protect your privacy.
3. People point out that the VPN's might lie to you willingly or under compulsion by LEO's w/ existing surveillance legislation. The same LEO's that Snowden leaks say compelled secret backdoors in all kinds of products and services.
4. "That may be the case, but it's an easily solvable problem."
Lol. If it was so easy, we wouldn't have a surveillance state or it would be well-regulated based on GAO's reports. Instead, we do have one, VPN providers might be compelled by it, market choice doesn't change that, and you're still essentially hoping via a numbers game that you don't pick a bad one. This isn't even considering the fact that ISP's beholden to US TLA's might ban VPN's or require their assistance for decryption/tracking.
The VPN's could be a decent solution if a very popular one was a non-profit in a non-surveillance state with protections for consumers built into its charter, contract, whatever. People who were previously shown trustworthy [enough] would have to operate it. The endpoints and monitoring would have to be strong. It would need enough traffic from each country to obscure the users. If it wasn't getting enough, they could pull trick from high-assurance's book to do fixed-rate, fixed-sized transmission constantly from the apps. That would get expensive on bandwidth side, though.
So, it's doable to make VPN's useful until law or ISP policies start killing them. Just hard to evaluate who if any are doing all the above to be trustworthy enough. For now, you're throwing dice for a probabilistic level of protection that's hard to quantify.
VPNs may be a solution to privacy issues, but the whole Internet will be worse for it if everyone were to use one.
I wish we could quantify how much electricity is wasted just routing things around inefficiently from VPNs. How much infrastructure must be upgraded because of the growing use of them. Maybe this would incent ISPs to avoid selling analytic data on its customers?
Hell, take it a step farther - sell VPN-like anonymization. Think about it, your ISP is technically able to do it far better than any VPN: no impact on speed, no impact on latency, no software required, wouldn't miss any types of traffic, and increases anonymity just by having more customers.
If ISPs don't realize that they can make money selling privacy then they're just bad businesses.
I really believe that engineers live with the belief that "We can work around politics or route around corruption" that only makes us better off. There are many more people who don't have the knowledge to work around it. No amount of engineering is going to educate or move a change in policy. You're essentially saying "I've got mine, so fuck you."
With that being said, given that VPNs are the only practical chance until the software developers of the world start running for Congress, I have gone ahead and paid ipredator for the next two years.
A question which I find interesting is why we can't make these policy choices in the real world. For example, choose which country's social safety net you want and be taxed accordingly. It may be impractical, but are rivers and mountain slopes (aka borders) really the best way to draw a line between two different policies?
How fast would the market be able to respond, and what kind of damage would be done in the meantime?
We regulate based on the public interest. It was in the public interest to place limits on telecom. I don't see any reason to treat the Internet differently.
It is super important to keep in mind of course that there may indeed be no good solution, or it may be that the good solution is politically, economically or otherwise unfeasible. In this case a good solution is technically very feasible, but that may often not be the case.
And maybe. I don't control the carrier firmware.
If another person can't open your mail, then why is it so hard for lawmakers to understand that this adds up to the same? You route my mail/traffic, doesn't give you the right to spy into the contents of it, to know what I buy, what media I consume, what my hobbies are, how often I check my bank balances, whether or not I'm left or right leaning based on the news I consume, whether or not I'm shopping for internet at competing ISPs... List goes on. Imagine the depth of the information an ISP can build on you if they have all your browsing information.
The lack of respect shown towards the people who have made these companies possible by buying their services is appalling. And the fact that they keep competition away is even worse.
Provide your services and stop trying to suck in every penny from every potential revenue stream possible.
To make a comparison, just because my car has GPS, doesn't mean the manufacturer should track and sell my location and build a megacorp ads company to interrupt my radio and force me to listen to ads for businesses in my direct vicinity.
Just because you make shoes, and you could integrate piezoelectric energy capture devices, doesn't mean you should integrate tracking devices into people's shoes so you can sell the data to who ever wants it.
Just because you provide a service and because you've squashed competition by lobbying for everything which gives you monopoly, doesn't mean you should drop all sense of right and wrong.
There's countless business models which could abuse data collection and make a few extra bucks, but they don't. Because you don't always have to be a dick. Because at the end of the day, a businesses image should still be important because it is USUALLY what decides if consumers will keep on buying from them or not.. Unless there's no competition....
This by itself is big enough although some will argue its not a big deal. But once you remove all protections, you have no clue how far they'll go and once they go there, its harder to backtrack.
They understand, they just are rewarded by those with a financial interest for treating the cases differently.
Also, with SSH, I own both the client and server, and setting it up is extremely easy. Setting up a VPN, when you do own both client and server, takes more effort, I think.
Basically, I set up SSH on a server somewhere (I actually have many), and a local SSH key (I don't use passwords with SSH). The SSH server can be a cloud server or a physical one; it doesn't matter. Then, I create an alias in my .zshrc or .bashrc configuration file to easily create a tunnel to that server, like this:
alias <alias_name>="ssh -D 8080 -f -C -q -N <username>@<host>"
Then, I go into my network settings and create a local SOCKS 5 proxy that points to the port I'm tunneling through (8080 in this case). Once I've done this, everything between me and the remote server is encrypted, and it appears that I'm browsing from the remote location. This works well for services that are not available in my country, as long as I can set up a server in the country I want to appear to be coming from.
If you want to keep the SSH tunnel open all the time, you can use autossh, like this:
autossh -M 20000 -p <port> -D 8088 -f -C -q -N <username>@<host>
- The US government tries to restrict 'strong' crypto --> people print PGP source code on t-shirts and the government eventually has to accept SSL/TLS.
- The government starts capturing information directly off devices (using regular search warrants etc. --> people start using encryption (e.g. truecrypt, veracrypt) and large device makers respond to consumer concerns by encrypting by default.
- The government starts MiTM'ing everyone's traffic at the ISP and online service provider (e.g. google, microsoft) level, using their newly created pseudo-court, secret warrant process (FISA) --> people start using VPNs.
- The government starts talking about key escrow, banning encryption.....
You can't eradicate a disease by just treating the symptoms as they pop up (in ever increasing severity). If you do this, you'll die. You have to attack the disease directly (and, in many cases, first convince people that they really are ill). So far, we've made one attempt at the direct approach by 'engaging in public discourse'. It's clear this is not effective in this case.
I doubt protesting in the streets would make much of a difference either, if the lead up to the Iraq war is anything to go by. Consider these two quotes from the previous thread (the second is mine), as just one example of the many possible actions that could be taken:
"The Video Privacy Protection Act was passed after Supreme Court nominee Robert Bork's rental history was leaked to a newspaper."
and
"I've always liked the idea of using the copious public video of these politicians to train voice and face recognition NNs, specifically targeting anti-privacy politicians. Maybe even sell pre-made raspberry pis with all of this stuff preloaded for journalists to scatter around places that politicians congregate.
I think it's only fair that these folks get to be the first ones to live in the kind of world they are creating. And none of them should have a problem with any of this, because I'm certain none of them ever do anything wrong and therefore have nothing to hide."
Although one always tends to like one's own ideas, I think this idea has merit, because:
- It's low effort compared to organising protests and then getting everyone to take to the streets
- It directly attacks the source and (assuming you aren't sent to a Federally funded leisure resort for your efforts), creates a 'heads I win, tails you lose' situation: they either pass laws to stop this kind of privacy invasion, or we end up with a long-term selective pressure against anti-privacy politicians. Everyone has secrets...
- It directly educates the public about their "illness" (through example). It shows them exactly how their life could be in the near future if they don't start paying serious attention to privacy issues. If a bunch of angry nerds can pull it off, imagine what the NSA and CIA are capable of...
The time for 'reasoned public discourse' and 'teching around the problem' is well and truly over. It doesn't hurt to do these things, but it does no good in the long-run either. More drastic measures are required.
Crowdfunding some guy to do it is not the answer. We can not trust him.
If it isn't possible, anyone can explain why?
I don't have and iDevice so I don't know for sure, why do you think this'd be a problem? Or am I misunderstanding your question?
Source: Figured it out over the weekend and have been pleased by it for the past few days.