NordVPN disables features when you turn off auto-renew
reddit.com
reddit.com
I'm not affiliated, just a very happy customer.
Mullvad is also who Mozilla trusts for the Mozilla VPN [2]. You can sign up with that if you'd like Mozilla to get a cut.
[1]: https://mullvad.net/ [2]: https://vpn.mozilla.org/
Don't use their service but they do really come across as one of most trustworthy out there. Have a Protonvpn account for getting around a geoblock once in a blue moon, personally don't have much use for commercial vpns.
Also it bugs me that there are 5 "Try" buttons on the Mozilla site before they even show you the price. To be fair it does show you the price on the credit card page after you log in but still feels a bit scummy to me. Mullvad puts it in your face above the fold.
If they shoehorned bitpay in, its probably not tapping into the utility of having bitcoin payment options.
I like paying invoices with Monero over Tor, while the merchant receives bitcoin that a third party pushed to them. I’ve been doing that for at least half a decade.
But if I can’t access their invoice they just lose a customer.
I don't think MorphToken would work because as far as I can tell, they have no way to set a fixed amount of the destination currency.
Other providers like ChangeNOW do offer that but they have much higher minimums, something like .003 BTC, which is obviously not useful for a $5 payment.
Really? My Ledger app says 112 sat/byte, which comes out to $8 for me, and I'm pretty sure they were higher a few weeks ago, when I checked. Am I way overpaying?
> I don't think MorphToken would work because as far as I can tell, they have no way to set a fixed amount of the destination currency.
That's too bad, XMR.to was really useful for this...
Hm, maybe? I think those clients usually just use the average fee paid in recent transactions, which will result in overpayment if everyone else is doing it too.
The real question, "how low can I set the fee and still have my tx confirmed," is given an attempt at an answer by https://fees.watch, which is what I checked -- it showed less than $2 for every speed at the time.
To be honest I don't actually use Bitcoin, but I do use Ethereum regularly and I use this fees.watch site for that. My transactions almost always get confirmed exactly when expected, and it's almost always cheaper than whatever the wallet suggests.
still waiting for something better but its good enough
1. https://www.reddit.com/r/Monero/comments/la46ds/xmrto_servic...
One day people will figure out how to connect XMR to other chains, really unlocking its value and utility for those markets
You can pay any bitcoin invoice with Monero and people have been doing that for 6 years
ChangeNOW allows that, but has a much higher minimum, .003 BTC or so. Not useful for small transactions.
And all of these services take many minutes to complete the exchange, by which time the invoice you're paying might expire. AFAIK xmr.to was the only one that did instant exchange with zero confirmations for smaller amounts.
Edit: I should say, I used their support email, they responded pretty quickly for a cheap service, offered a beta client and that fixed the issue (I'd actually tried the beta by the time I got the email back, but still).
Most VPN services get blocked eventually and then play cat-and-mouse to get themselves back up, so the service is overall unreliable.
The China firewall also does some "intelligent" blocking of common VPN protocols by fingerprinting their traffic patterns, handshakes, ports, and other things.
If you set up own server, it helps to modify the protocol or wrap it in a proxy that obfuscates the VPN traffic as something innocent-looking. Basically, if you implement something like TCP/IP-over-cat-picture-jpeg-files-on-HTTP-port-80 you'll generally have a rock solid experience. (That's not exactly what I do, but it's along the same lines of thinking, you get the idea, be creative.)
Unfortunately I'm not going to provide code to do this though because that makes it vulnerable to its traffic pattern being fingerprinted and blocked.
Also, avoid AWS. Using slightly lesser-known IaaS providers helps.
1: https://www.digitalocean.com/docs/networking/floating-ips/
That said, I never had problems using an SSH tunnel and the end result is the same.
However, I don't fully understand the privacy argument. It would seem to be that instead of handing over your entire DNS query history and unencrypted HTTP history to your own corporate IT department or the Starbucks Wi-Fi router, you're now handing over all that data to Mullvad. Are people okay with that?
I usually create my own VPNs. I realize that involves handing data over to AWS or whoever I use for my servers but I somehow feel slightly better about that than handing it over to some Mullvad dude.
Google tries to impose its VPN on Android too and my first insinct is: do I really want all my traffic going through Google?
Yes, it's crap, and any techbro worth their salary should know this.
It's also incredibly annoying when VPN this and VPN that pops up on youtube.
If you do believe that, it's more private. If you don't, they still might have access to that data. Otherwise AWS or someone else will.
However, even so it will be more difficult for third parties to track you since you will generally not be assigned a dedicated IP address. You are probably NATed with a bunch of other customers from all over the world. If you set up a VPN in a VPS you'll most likely have a permanent public IP.
Personally, I believe that Mullvad is truthful about its privacy claims, but I'm not a customer.
Well, you're of course right that the privacy argument for VPNs doesn't make a lot of sense. But there's a whole industry living from people believing it does, and ad partners of that industry willing to proclaim that VPNs are essential for your personal privacy.
It's mostly moot. In the days of HTTPS and DoH, they're essentially selling snake oil. It was a lot more useful in 2010.
Also getting around some geoblocking.
AWS I would "trust" slightly more only because I get to implement the infrastructure and among the sea of trillions of requests they serve it would be a bit more of a challenge for them to figure out which of those requests are VPN browsing data and clean that data. I can also mildly obfuscate and pollute requests using their own infrastructure and make it hard for them to extract anything meaningful about me unless they really wanted to.
Basically AWS isn't already set up as a VPN service, so they'd have to put in a nonzero amount of time to extract, parse, collate, and analyze VPN logs, let alone figure out which instances among their billions are actually VPN instances, especially if I run a non-standard, modified protocol. Unless I was some Snowden-like target it's unlikely they would waste a couple weeks of engineer hours to wireshark and clean the data from my instances.
Mullvad on the other hand handles 100% VPN browsing data so if they unscrupulously keep logs, they would have clean logs to begin with, nicely organized by username, which is scary. They wrote the client and they control the protocol. They also rent their instances from various providers (the names of which they disclose on their website) and I could presumably just bypass them and rent an instance with one of those providers directly.
Of course, either approach should work if the goal is merely to disassociate your traffic from your identity in order to keep marketing companies knowing your interests. Your approach is more provably reliable, but some VPN providers do provide 3rd party audits and such which seems a reasonable way to establish trust.
Hiding IPs while engaging in piracy.
Other than that, I think it's mainly geoblocking evasion, which might have overtaken piracy recently as the most popular reason for using a proxy service.
Any use where the slowness of tor is a dealbreaker, and where criminal liability is not so high that law enforcement will attempt to unmask proxy users in realtime.
https://www.digitalocean.com/community/tutorials/how-to-set-...
If you're talking about bulk collection, then your ISP is probably already doing that.
If you're worried about a government, your personal info from a VPS provider is just one court order away. If you use a VPN service that actually is serious about not keeping PII or logs, you might fare better there (they might be coerced to log future traffic of yours, but at least your prior activity is still secret).
If you're worried about ad tracking, a VPN just doesn't do you much good period: ad tracking is sophisticated enough to not care about your IP address.
But all of this "VPN for privacy" stuff is predicated on trusting faceless third-parties to help keep you safe, so it's generally a losing proposition. Agree that the only "safe" thing to use a commercial VPN for is to bypass geographical restrictions.
If you are trying to avoid your ISP knowing you are downloading movies a VPN is a good solution.
If you don't want others in the coffeeshop to be able to snoop on remaining unencrypted http traffic. VPN
If you don't want your employer to have a list of your web traffic from your personal device. VPN
If you don't want a service which you don't pay with a credit card to have a way to connect your pseudonym to your real name. VPN
If you want to opt out of some degree of dragnet surveillance/data collection via parties like your ISP. VPN
None of these are incredibly uncommon. VPSs work great for most scenarios. If your actions are dangerous to your continued existence or you need to keep your own government from watching you then you probably need to adopt far more stringent measures but I feel this is vastly less common than the above situations.
If I pirate using a VPN in a country hostile to mine, the local RIAA/MPAA can't do anything. They probably already can't when VPN is in same country. A VPN doesn't stop a determined adversary, but if you worry about these you should probably use Tor or something like that, possibly without going back to clearnet.
While your stance is a good wake-up call, and perhaps a decent rule of thumb the above are reasonable exempts.
If you're serious you send a machine, that you own, to a colo provider and you register for service with a corporate entity that you created for just that purpose.
Your name exists nowhere and ... regulatory inquiries are directed to your corporate contact email.
Or, if you feel like that's a heavy burden and you don't attach any value to the physical machine (some old 1U, right ?) then you can just sign up under an assumed corporate name with some colo provider that doesn't care that it is, or is not, an actual corporation and you can pay with your non-AMEX credit card[1] using whatever Mickey Mouse name you feel like.
Trust me - it won't take long to find someone who will take your money.[2]
[1] Only AMEX validates First Last ...
It looks to me that NEITHER would be prevented by you using a colocated machine. It's not like your colocation provider is incapable of compromising you and probably would if ordered to do so in a jurisdiction where this act would be legal.
A hacker presumably isn't concerned about whether they are attacking a machine on your desk or in Nebraska.
Over a 5 year time frame your colocated machine would presumably run you between $6600 and $19000 and would have bought you zero additional privacy compared to paying $360 for a vpn in the same jurisdiction.
Very likely, no one cares about me enough to put effort towards specifically monitoring or hijacking my internet traffic.
However, someone puts out a shingle as NordVPN or Mullvad or whatever else, and starts advertising VPN services to the world.
That VPN provider has a finite number of endpoints / egress nodes, and those become a very high value target. Now my threat model has to include not just targeted attacks at me, but general attacks on the VPN provider.
An analogy would be, if you have 1 million dollars worth of real-world valuables (artwork, say), it's better to store it in a nondescript warehouse than a warehouse with a neon billboard out front that says "BOB'S HIGH-SECURITY WAREHOUSE FOR EXPENSIVE VALUABLES". The latter is painting a giant target on itself for anyone interested in stealing stuff.
If the vpn provider doesn't keep any logs your total exposure is that they may start collecting logs of traffic for the duration during which they are compromised. If they are attentive and competent this either will never happen or it will be for a short duration. Again this breaks the example of valuables in storage.
In fact a VPS or indeed any host actually has the same problem you describe in that a host is a bigger target than you and therefore more valuable.
On the other hand for most people the differential between know how between you and professionals is probably sufficiently useful that you are less likely to get hacked with them than on your own. After all nobody has to actually target you in particular they can look for vulnerable hosts in an automated fashion.
I don't think you have provided any substantial argument for most commercial vpn users to switch. I feel like for most threat models its a more than acceptable tool.
Also, as others have pointed out, all you have to do is sniff the traffic going in to the machine, something both the colo and ISP and upstreams are trivially able to do to obtain your residential or GSM IP, linked to your name/identity.
This is bad advice. Mullvad is like five bucks and offers equivalent privacy.
I don't know about obscuring the fact of the connection between you and it though. Tor isn't enough by itself.
Nah. If you're worried about the kind of attacks that necessitate sending your own hardware, then, regardless of who owns title to the device, the firmware being replaced to snoop on or alter what is actually in RAM is in-bounds.
There are lots of ways of hiding persistence on a system, and decades of research along these lines. Once it leaves your possession, there's not much you can do to ensure that it still has unmodified code on it (assuming standard PC hardware).
Really though this isn't the threat model at all for someone who just wants to use a VPN, I only went there because the comment senselessly advised shipping your own hardware to the colo. That's the same privacy as using the colo-owned machine, which, for a VPN, is the same privacy as using a generic $5/mo VPN service, as in all cases the upstream can be trivially monitored (even in the case where it's your own, tamper-evident HSM-whatever remote attestation hardware).
Why don't they just desolder the cpu and wire up an emulator and laugh at all those secure enclaves and encryption?
Apple can decrypt the whole thing without any input from the user: they don't need their phone, they don't need their password, they don't need their keys.
The whole thing was a carefully orchestrated media dance designed to make it seem like the feds can't get the data off of iPhones. Not only do they have access to almost all of the data on almost every iPhone, they have access to it without a warrant or probable cause thanks to the FISA Amendments Act. Apple compromised over 30,000 accounts for the US government without a warrant in 2019, per Apple's own transparency report.
If just you want to torrent the last season of game of thrones (why would you?) then a reasonably reputable no-log vpn service will probably do a perfectly fine job.
If you want to access non-https websites from coffee shops, buy a $5/mo vps from amazon/prgmr/digitalocean/whomever and tunnel through it.
I don't see a situation in which the dedicated colocated hardware is the right choice.
Probably yes, but it does not necessarily break your anonymity for https websites.
(On the other hand, if you want to perform a public service, using tor is a good way of masking the traffic of people who actually want to use it to disseminate sensitive information.)
> non-https websites from coffee shops
If the website you are accessing is unencrypted then the exit node knows the entirety of your communication with it. (It doesn't know your IP; but small consolation. You're still vulnerable e.g. to injection.)
I'm not expecting privacy, I just want a way to occasionally geo-hop to other countries, for streaming video and to test if a problem is related to my IP/location or not. And occasionally to have some minimal level of protection in a coffee shop.
>The secret to not dealing with crapty company practices is to avoid ones that advertise literally everywhere 24/7 nonstop around every single corner you look.
This is so true it nearly qualifies as physics.
I am going to (over)use this phrase from now on. Thank you.
It's kind of like a wooden building burning down: something that was previously in stable, long-term equilibrium state (no fire, no energy release, serving a useful purpose) switches suddenly to a runaway reaction (exponentially accelerating, pulling in more and more reactants from the environment, serving no useful purpose.)
The only reason i would use one is to get cheaper steam keys from brasil and for that i can get a free one.
From a security standpoint it is awful because you increase the number of providers you have to trust.
Apart from your ISP and the server you connect to, you got a third party involved for no reason.
And VPNs can not that trustworhty as shown by the leaks of logs and what not.
Maybe someone can enlighten me why these services exist and what usecase they have?
I mean sure, if you want to sell Netflix access sure, but their security claims are way off.
Geoblocking I see, but other stuff without knowing exactly who you get VPN from and who is your ISP is extremely murky... And I think there is very few who can make educated decision on these. And they are running their own or using tor...
I frequently access my bank info etc. on such trips. With a VPN at least I have fewer random threat vectors to consider on a network.
"bank info" in this case being anything from logging in to check my balance, pay bills or even contact them via their secure messaging because I'm disputing a transaction.
It doesn't eliminate all threats, but I'm not a secret agent ninja that needs 100% hardened communications. I just need a modicum of assurance.
The hotel might be able to see that you visited a certain website but thats about it.
Which is not that trivial to begin with.
How hard would it be to take over the dns and simulate a fake VPN too?
Or just constantly disconnect the vpn and hope the user stops using it for a while.
And, I guess, just ignore anything thats not https.
Or just be okay if your hotel blocks certain ports or destinations, which I've had happen multiple times.
Don't you have to trust the CAs in any case?
Just don't do that, use a private tracker and use Tor for small stuff like ebooks.
This is not much of a problem, because you are seeding to "friends" making the whole thing non commercial and a private affair in some legislatures.
Not sure if the laws have changed but what.cd used to have a certain number of users which was capped by the number of friends some judge thought to be reasonable.
If i recall correctly that whas around 200k meaning that you could run a private tracker and in case of a bust claim to know everyone.
Back in the day i had a what.cd account and when they got busted (took them many years) nothing happened to the users. I think they shredded the servers before the cops could seize them.
so, essentially, even the most knowledgeable people on youtube tell you that nordvpn is a must have thing. and they "use it all the time". what do you want people who don't know better to do?
that's the sad online world we live in.
No, a VPN replaces an ISP in most threat models (by shifting who can see your traffic). For some people, this is a good trade (ex. me: my ISP has straight-up admitted to analyzing people's traffic for marketing info).
ISP logging traffic anyway in UK in order to comply with, say, Snoopers charter.
ISP providing out-of-date router hardware with unpatched firmware that most people connect directly to their WiFI networks instead of isolating.
Also ISPs in the US are able to sell your browsing history (https://protonmail.com/blog/private-browsing-history/) but I believe this can be mitigated by DOH.
And HTTP will always reveal the host name with or without DOH.
Midway I realized I was missing an offline map of a country I was about the be passing through the next day. I had an unlimited data plan with traffic abroad included, and despite this, it didn't allow me to download the maps for my gps (everything else worked!), even after fiddling around with third party dns.
So I downloaded a vpn app, and managed to get everything sorted out.
2) protecting your browsing traffic from being observed by your ISP (where you may not have much choice), at the risk of it being observed by the VPN company (which you trust).
3) Torrenting without having to worry about fines, nastygrams and other annoyances
4) Bypassing geoblocking
1 + 2 is what the VPNs advertise, but I think 3 + 4 are what people actually use them for.
Open wifi networks still exist. When last I was at my public library (a year ago... covid) they still had an open wifi network for public use. I think for them it's a matter of principle, since it means nobody has to ask permission to use it.
As someone else pointed out, URLs are not trackable, host names are, but the advice often comes in the form of "don't do sensitive stuff like online banking from untrusted networks". Since especially this has had HTTPS for 10+ years now, this advice is far outdated.
> 1 + 2 is what the VPNs advertise, but I think 3 + 4 are what people actually use them for.
I don't know, I've seen two different "household" gaming Youtube channels advertise VPNs with a focus on geoblocking. I was kind of shocked at how brazen it was.
Long-outdated? It's more important today than it was 10 years ago. That public wifi you're on is tracking your every move and correlating your devices back to you if you happened to purchase anything in the store with a credit card.
Security interests are niche compared to people wanting to watch 'xyz program' or 'xyz super game'.
Because there are lots of people that can't create their own VPN even though these days you can spin up a lightsail instance for $3.50 pcm and be up and running with Wireguard in minutes.
And for those people that cannot, their threat model changes to now needing to trust a single entity after they are up in minutes.
As you say, those providers have oftentimes been proven to not be so trustworthy. But how many CAs have been shown to be not trustworthy in the last couple years?
It also can be nice to get a new IP more or less whenever you want by just connecting to a different, already setup server.
I don't believe VPN providers are buying residential IPs. They use a p2p architecture and route traffic through their customers, usually without informing them. If I do use a commercial VPN service, I prefer to use the openVPN client rather than their proprietary client.
So my usecase is simply preventing my ISP from knowing what I browse and from keeping this record. I'd much rather take my chances with a VPN company than my ISP and the British government.
Thankfully a tube of toothpaste doesn't allow implementing dark patterns like this... yet.
or does it? Call from the past "3D" tooth paste marketing, whitening agents, microplastics, multi-color squirts, same FUD "brush like a pro only with XXX". Those are just few (top of my head) of the levels marketing goes to attempt and sell toothpaste.
But there's more! since posting my comment, I've noticed Amazon dark-patterning a "monthly subscription on diapers" into a product description page.
Gotta chase that sweet sweet MRR
I have noticed personally, however, that all people i know that have purchased a vpn subscription don't do this. They simply buy into the FUD. N=1 of course...
Maybe the market size has become so large that less savvy users propel the unscrupulous companies to the top?
> Maybe the market size has become so large that less savvy users propel the unscrupulous companies to the top?
I would say that is the case for many products. Personal example: our family car is nearly 10 years or so old and still going strong, its reliable and good overall. We spent time researching good vehicles on the market then and bought the care after research, it paid off.
I'm not going to stop using vpns nor flying on airplanes because of that.
That "you should not use a VPN" link someone posted elsewhere explicitly disproves that claim, saying that HideMyAss were caught breaking their privacy promises and have yet to go out of business.
The prices of VPN services also don't make sense and potentially suggest something nefarious is going on (not saying Mullvad is doing this, but any VPN advertised on YouTube is very likely to do so). It's difficult to imagine that they can afford such bandwidth/hardware and the amount of support/abuse cases (remember that VPN services will attract scum as a side-effect of their privacy/anonymity claims) for such a low price.
https://www.theverge.com/2016/11/23/13718768/uk-surveillance....
https://www.amnesty.org.uk/why-taking-government-court-mass-...
TL;DR: My bank wouldn't let me use their online banking because I had run a Tor service sometime in the past.
I use a VPN for geo blocked free-to-air sport(6 nations <3) from my home country so VPNs work well for my needs. Ironically it's not even possible to pay for access to view the sport in a legitimate way since everything is region locked.
The conclusion is that servers/websites can check so many parameters of your browser that they can produce a (unique) fingerprint based on the settings and drivers on your phone. No VPN or Tor will cover that, only burner phones or pen and paper.
When you use multiple browsers, with 1 (FF) used for general browsing setup to blocks fingerprintin, all cookies, js, etc... will the other (Brave, Opera) browsers leak info to web sites, when using FF ?
It depends if the browsers have matching characteristics. If you're not using a VPN, then they can be matched by IP. If you are, then it's down to side-channels which are a pain but usually differ by browser (and perhaps even profile) - but I do wonder if ex. font availability and possibly GPU-based fingerprints wouldn't match. Of course, if your locked-down browser blocks enough then you can solve that.
edit: this is a serious question I am not trying to troll anyone here
With some protocols you can identify that they are sending VPN traffic to and from a destination, but that should be it, otherwise something has gone horribly wrong in a dangerous way.
- Access geo-restricted content on say Netflix
- Privacy - one encrypted pipe to hide what you're doing
- Hide source IP address (perhaps for researching a competitors website etc)
- Protect insecure services (though the services would need to exist on the VPN endpoint or they would be exposed at the VPN->insecure service termination).
- Bypass ISP throttling (yup this works and is always funny as ISPs deny they do this but hey, easy to check!)
- Avoid censorship even in places like the UK (https://en.wikipedia.org/wiki/Internet_censorship_and_survei...)
And more. So there's plenty of use-cases for a VPN in 2021. But it's worth thinking about how the threat model changes as a result of using one especially if you're not hosting it yourself.