Connections to Facebook, Google, Amazon, etc. should go un-tunneled. It's good to feed the beast with data it already owns anyway.
Connection to porn websites (say by your 16-year-old cousin who came to stay at your place for the weekend) and other ethically debatable content should be routed via Tor. Connections to torrents should be routed via VPN[1].
I understand that some people here prefer their personal VPN against a VPN provider like TorGuard, etc. There's no good and poor solution here, everything depends on the use case. A VPN provider will be handling thousands of encrypted connections and gives you a dozen exit nodes. From each exit node thousands of different connections are routed. It's way harder to target and isolate a user, even for a medium state-level actor.
Conversely, if you route all your connections from, say a DO droplet, you're controlling the droplet, but you have one exit point for all your connections... It's extremely easy to target your connections for a state level actor.
Of course there are thousands of schemes one can choose. Everything depends on the use case.
The bill was actually enacted to prevent privacy rules which hadn't even gone into effect yet, which means that technically, ISPs would have already been able to sell such data. However, the consensus seems to be that ISPs were only selling "anonymized" data, and this move will embolden them to push further into invasive practices.
Will they actually do it? Well, can they make money from it? Do you trust Comcast to be a good steward of your privacy in the absence of a legal requirement to do so? Comcast did a hard pull on my credit when switching my account to a new address because they were too incompetent to update it and ended up creating a second account as a new customer for me. Comcast is my only option of ISP, as it is for many many other apartment dwellers and many single-family homes as well.
Also important to note -- existing regulations still in effect prevent selling un-anonymized data. Selling someone the browsing habits of a particular identifiable customer is not allowed, never has been.
The 'Obama era regulation' was an attempt to maintain privacy regulations after internet businesses were found to be exempt from ftc oversight in late 2016. So now there is no privacy regulation from the ftc or fcc. Things are not the same as they always were.
I trust ISP companies more than I trust VPN companies because ISP companies are in the USA and are much larger (so engage in less risky behavior), so they at least have to sell data in aggregate and scrub PII
That fact only supports their practice of selling user data. If we did not have such a barrier of entry for new ISPs, the market would be able to react to this abuse. But instead, large ISPs like AT&T, Verison, Comcast, Time Warner, etc. hold the market so tightly that they can get away with abusing their customers without a serious reaction.
Because ISPs have so much control over the market, the only viable response without regulation are VPNs. A VPN can sell privacy to a customer who feels abused by their ISP. Since privacy is essentially the foundation of the VPN provider's business, VPN providers compete to prove to customers they can protect their users' privacy.
You should remove all CA certificates installed by software that show like it were "installed by you".
Some AV software does MITM sending you a "trusted" certificate signed by their own CA whilst acting as a proxy between the actual site and the AV.
Theoretically anybody could do the same on the network side transparently.
Also if you don't trust your ISP, you shouldn't use their DNS servers. I don't know about commercial integration between DHCP and DNS requests to track people but it is feasible with some work.
For DNS just grab a raspberry pi and setup a dns resolver. You only need the right root zone seed file. Just don't make it available to the whole internet.
In my opinion, VPNs help more than hurt privacy, assuming you choose a reputable one to use.
If a person wants anonymity, then go for Tor or Freenet.
Adopting HTTPS across the board is so much more important.
[0] Which too only gives you indirection, remember that!
I'm a developer and I run linux as my primary OS, so there weren't any new concepts, exactly. I had to do a lot of google searching of error messages.
In the end, it kept failing after droplet creation, I think when whitelisting my IP or something similar.
This happened 2 days ago.
Anyway, I couldn't even get it running on the droplet, let alone get all connected and ready to go. Might try again with AWS.
My email is in my profile if interested.
a) Look up Digital Ocean's own instructions for setting up OpenVPN. Follow exactly.
or
b) look at HN threads from today, some people wrote Ansible playbooks and scripts to set it up.
Legally maybe, probably, who knows. Personally I don't feel protected legally anymore with regards to privacy. It's a good thing I don't really do anything illegal, even if it both saddens and angers me that the world is letting this happen.
Technically I'm assuming without some serious cooperation with Digital Ocean it's going to be hard. Sure, if someone gives the authorities (or the hackers get) root, then my OpenVPN software will be more Open than "VPN."
I set it up using MacOS. It's all about the playbooks. Get that right and you're good.
The VPN comparison chart [1] is the best reference I've seen on the dozens of factors one might care about.