VPN Extensions are not for privacy
blog.innerht.ml
blog.innerht.ml
A surprising number of these are implemented as open HTTPS proxies. You don't even need the extension installed to use the proxy, nor any kind of authentication. The extension just fetches a list of proxies that the company has configured and picks one.
The free ones are rather questionable. For example, Hola makes your computer part of an expensive VPN service (sold under a different name) aimed at bypassing IP bans[0]. On some the free tier is made so inconvenient that you will almost have to subscribe to the paid tier if you're using it legitimately (but it's usually usable if you just want to get around some ban).
There used to be some ad-supported VPN providers, which would ironically trade away all of the privacy you'd normally otherwise get by using a VPN, making them only useful for ban/block evasion. These have mostly died out now that ads == tracking is common knowledge[1], but I'm still very suspicious of "free" providers that offer generous access without payment. It's difficult to prove that logs aren't collected, and they could just as easily be collecting and selling user logs.
If you're in the market for a VPN, pick a reputable provider that has no free tier (you should make sure that you are the customer and not the product), and ideally one that also provides actual VPN servers and not just a browser extension that connects to proxies. Another good option is to set one up yourself using a cheap VPS.
[1]: https://blog.cyberghostvpn.com/en/ending-free-version-cyberg...
I don't think it would be possible if you're depending on a single entity? I don't see a way a provider would be able to prove they are not logging connections, for example.
That's why I pay for a VPN service, to watch geo restricted YouTube videos.
So to me it's as secure as a WiFi hotspot and that's alright.
1) Slightly better security/privacy using airport, cafe, etc. wifi
2) So I can watch iPlayer, YouTube etc. in different countries.
Do Nord keep logs? Are they based in a five eyes country? I don't care to be honest. I don't use it to protect myself from that. I use it to get around stupid geo-retrictions and to make it hard for an attacker to intercept my data when I have to send an email at the airport.
While on the subject I haven't had any issues with Nord, they are not the cheapest but no way near the most expensive either. Their iOS, Android, macOS and Windows apps are all very nice to use as well or you can do it manually with OpenVPN or whatever but that is more hassle that it is worth for me personally.
If hiding from your ISP is your threat model then a VPN is fine. It'd be better to use individual per-application tunnels though so you can still host servers with your ports locally and participate in the internet as an equal. Using a full VPN you rent prevents that.
Wait what? This is the first I'm hearing about this!
Comcast's behavior isn't exactly malicious right now, but it could be pretty easily.
They may have desired to notify me of things but it's obvious what would happen. Those who implemented this system were not ignorant. They were malicious. Those above them telling them to do so may have been just ignorant or stupid.
These days I tunnel everything through one of my remote VPS.
I found a github repo with the code once but I don't seem to have saved it. I'm sure it's on here somewhere though.
On the client side, configuring an IKEv1 VPN (IKEv2 doesn't support Split DNS yet) in MacOS, iOS, and Android is a piece of cake. You specify the server, username, password, and pre-shared key. Done. If you want to use a certificate instead of a pre-shared key it's a bit more work, but still do-able.
With iOS devices you can provide a profile file that has all of the settings already baked in so it's even easier. OpenVPN is similar, though you need to install an OpenVPN client first.
With a use-case of "I'm paying a 3rd-party to secure my traffic", which matches what these "VPN" extensions claim to provide, then the answer is simply "Wherever the 3rd-party runs it".
I don't necessarily assume my VPN is 100% secure; I do trust a company that I pay money to more than I trust that nobody's sniffing my traffic at a rando coffee shop.
That said, the few times in the far past I've tried to use Tor as a VPN, it's been slower and less reliable than the VPN I pay for (especially on my phone). Using a regular VPN also makes it easier for me to do things like spoof my country for region-locked services.
(If I was going to bother making a change, it'd probably be to hosting my own VPN server on a VPS provider instead of specifically paying a VPN provider)
For what it's worth, Tor does support choosing the country of your exit node, and is not as slow or unreliable as it has been in the past (although still not as fast as just using a VPS), but I watch YouTube over Tor without noticing anything unusual.
That is the benefit of Tor.
There's also the fact that the VPN provider is in a position to know where your traffic is both coming from and going to, and there is nobody who can do that in Tor.
Why not both? Why does my ISP need to know when I use Tor?
Some rando at a coffee shop sniffing my traffic will get a tiny portion of my online life, but my ISP or a few other large firms can build a much bigger privacy-destroying picture of my behavior.
My concern with a large VPN company is that there is now a single place where all my traffic can be gathered, trivially.
As an aside, I use Striesand - https://github.com/StreisandEffect/streisand - to create my own VPN. I generally create a new one every week or so with a simple script and I tend to rotate hosting providers fairly regularly. It's definitely not completely secure, but it's very fast, very cheap and works well for all my devices.
Interesting. I'd be interested in hearing more about how you did that. Algo seems to require a human in the loop to generate and insert an API token.
Cloudflare DNS resolves archive.is to no-ecs.archive.is.
If you have non-ECS ciphers disabled, you won't be able to access it while using CF DNS. Google DNS works correctly though.
Anyway, this is Google's webcache of the original server https://webcache.googleusercontent.com/search?q=cache:CfxN6O...
Odd sites you might not think of immediately, mouser.com for electronic components for example.