How to find a trustworthy VPN service
protonmail.com
protonmail.com
The only trustworthy solution is your own OpenVPN server on some cloud provider (not difficult to setup). Even then it is debatable whether it would remain private long. Probably draw attention if anything but you won't get your logs sold to Target.
It's hilarious how many 'VPN providers' don't even encrypt the traffic.
Below snip from blog:
"In the months since the law was first introduced, we have had repeated contact with the Swiss government and held a meeting at our office together with legal counsel and members of the PTSS. In our meetings, we discussed the practical challenges of implementing such a law, and helped to advise policy makers on the most sensible implementation. We appreciate that the Swiss government has recognized the leading role that Proton Technologies AG plays in developing the cybersecurity tools of the future, along with the role that we play in the economic re-orientation of Geneva, and Switzerland as a whole towards the high tech sector, and sought a meeting with us to discuss how to ensure both security and privacy in the digital age. As a participant in these discussions, we can confirm unequivocally that upon implementation, the provisions regarding data retention introduced by the BÜPF will exempt companies like ProtonMail and ProtonVPN which are not major telecommunications operators. This is in addition to the points in the article below, which still hold."
Source? Their website [claims][1] they don't store logs.
> ProtonVPN is a no logs VPN service. We do not track or record your internet activity, and therefore, we are unable to disclose this information to third parties.
- IPSec will be blocked on many places where port 443/TCP isn't and OpenVPN or similar could work. So it's not ideal for free wifi, enterprise or school networks.
- You will still get DMCA takedowns from your datacenter or cloud provider if you don't choose one carefully
- You're limited to a single IP so if you're using it for a scraper and get blocked, you have no option of just clicking next IP.
Commercial VPN providers are often able to hit all these points.
https://github.com/apenwarr/sshuttle
Virtually no configuration. Saved the day when my ISPs DS-Lite (IPv4 over IPv6) was broken. Just sshuttled to a IPv6-capable server and I was up and running again.
The only trustworthy VPN service is one that you operate yourself. There are plenty of Github projects that will deploy a personal VPN for you:
Further more, what makes you think they aren't?
[0] https://privacytoolsio.github.io/privacytools.io/#vpn
Also what's to stop someone stacking anonymously-bought VPNs on top of each other (proxy chaining) similar to how onion routing works, and creating their own homebrew Tor? If the VPN provider is peeking at the logs (which it shouldn't be doing), then all they see is another VPN IP. VPNception!
(Something like the SHALON[1] technique is useful for this, for example):
------------
> Abstract—In this paper, we introduce a novel lightweight anonymization technique called Shalon. It is based on onion routing, aims to reduce complexity, and delivers high bandwidth. We have, compared to the widely known approach Tor, slightly reduced the level of security in favor for greatly increased performance.
> The most significant advantage compared to other approaches is that Shalon is fully based on standardized protocols, which makes our approach highly efficient and easy to deploy. It also makes Shalon easier to understand for normal users, eases protocol reviews, and increases the chance of having several implementations of Shalon available. In this work, we provide a description of the design and implementation of Shalon, a performance and anonymity analysis, and a discussion on the scalability properties.
[1] https://pdfs.semanticscholar.org/6f30/f14ff4972ddd787bf7e859...
If I discover that they're singling out my $5/mo VPN server for monitoring, the rest of my $1500/mo is moving to another company.
I have always assumed that VPN services like PIA, AirVPN, etc. are useful for, among other things:
1. To make the content you are viewing private from your ISP, employer, public WiFi, etc.
2. To make it more difficult for some remote host/website/actor to link your activity on their site with you.
Isn't point (2) negated if you host your own VPN on AWS? In the sense that if you're in a country with a nefarious government, wouldn't it be easier for them to subpoena AWS than to get info from some VPN service over in ________ country that doesn't store logs, and has a million other users using the same IP?
An example situation might be the RIAA notices that an IP is downloading Janet Jackson MP3s, and all they need to do is subpoena AWS if you're hosting your own VPN which has a unique IP, versus tracking down some Caribbean company who has given you an IP that's shared among thousands of users and has a public reputation for trustworthiness to hold?
The following command is for cygwin on Windows.Can be customised for Mac OS or Linux
ssh -o StrictHostKeyChecking=no -C -f -q -D 7070 username@servername sleep 10 ; "/cygdrive/c/PortableApps/GoogleChromePortable/GoogleChromePortable.exe" --proxy-server="socks5://localhost:7070" &
This article is no different
(I’m aware this isn’t really the same as a VPN, but for my current purposes it’s Good Enough.)
Whereas OVH/DigitalOcean/Linode/Scaleway/Amazon/Google/whomever all have much stronger incentives to put their customers first and foremost. In terms of business model (due to how utterly trivially I could rip down a VPS and set of containers/services at any one of them and set up something identical at any other at any time) they're much more closely aligned with customer interests.
It has nothing to do with any illegal behavior per se (at least in the USA, in many countries "illegal behavior" may encompass things we consider basic rights), it has to do with economic alignment and additional privacy/security at a cheap price.
If you are okay with that, godspeed, but I think you would have to be deranged or clueless (or both) to be okay with the idea that mega-conglomerates can sell your personal browsing history to the highest bidder.
There are myriad other legitimate concerns, but this alone makes the whole debate something of a non-starter in my opinion.
I'm reading a foreign sports site, and their videos will only show to people from that country.
Same with various national TV station sites.
Interesting that you say "external auditors" though - have any commercial VPN providers offered anything like that? Of course, it'd only be worth something if they'd put their money where their mouths are in a form of insurance payout if they were wrong.
It does seem to vary quite a bit, I've always found that Shenzhen is a bit more lax with the firewall than even neighbouring Dongguan.
I'd be more concerned about using a VPN when browsing other, less secure sites that don't support HTTPS.