Consolidation of the VPN industry spells trouble for the consumer
blog.windscribe.com
blog.windscribe.com
Looking at why someone would want to use a VPN:
- Protection from governments or big businesses: you probably do actual research, not listen to some ad by your favorite gamer
- Protection from scummy ad tracking: Most people still do some research here albeit less carefully. But again, if you’re worried about ad tracking, wouldn’t you worry about a VPN aggressively advertising themselves?
- Access region-locked content: Any VPN works here. This could explain some of the advertising. But still, most VPNs talk a lot about security, and only a small section on region switching. I would imagine if this was the main target audience VPN advertisements would be different.
Are people so gullible that they see an ad for NordVPN, think “oh shit I need to protect my security”, and then buy NordVPN, without questioning at all if it’s worth the money, if there’s an alternative, or why NordVPN advertises on XxGamerClipz? So much that NordVPN makes money off of its ads? And if so, why don’t other companies do this that could better target dumb people?
Importantly, most advertising and tracking does not care what your IP address is, and so a VPN does nothing here unless you can separate your cookies / hardware profile / etc.
This use case is definitely very underrated, people usually associate VPNs with higher latency but if your ISP has bad peering to certain locations, which many of them do, a good VPN can do wonders.
Yes? I think theyre usually riding off the trust of the content creators they advertise with.
>And if so, why don’t other companies do this that could better target dumb people?
NordVPN arent the only ones.
Actually, most of the time your VPN is just going to be blocked entirely by the service: they have a limited pool of IP addresses being shared by users, so the patterns of access of users randomly popping up on their addresses makes even automated bans pretty easy.
https://news.ycombinator.com/item?id=28143238
To really get this right requires crazy tricks like taking all of the traffic destined for a service and routing it to per-user stable addresses that you cycle much more slowly. NordVPN seems to do this with Disney+, for example. There was a great analysis of this done (but to get it you will need to use an archive site as the author mysteriously deleted it).
https://news.ycombinator.com/item?id=21664692
The result is that users trying to do this tend to have to keep using different VPN services until they find a server on one that actually works today, and probably in the process keep accumulating subscriptions to "too many" VPN services for "too long". A lot of random review sites are then just claiming to tell you which service is best able to access such content at any time (but honestly, it is a losing battle: there is no obvious way to win this in the long term).
Doesn't seem to be the case 'most of the time' for non-free VPNs or at least mine. You can definitely access YouTube videos available abroad or BBC iPlayer or whatever. I'm on VPN a 3rd of the time and it's only very occasionally I have issues. Sure, maybe it's worse with some services but not 'most of the time'.
(FWIW, I could accept an argument that I am not "weighting" my certainly-informal statement well on actual usage figures: if NordVPN and ExpressVPN are even the only two VPNs that work well against the BBC, maybe they are alone a considerable percentage of the market. I am pushing back on the idea that "any" VPN would work, and so I am looking more at the idea of choosing a random brand, equally weighted.)
> In iOS 15 and macOS 12, Private Relay will apply to all web browsing in Safari, all DNS name resolution queries, and a small subset of traffic from apps.
> Specifically, this will include all insecure HTTP traffic, such as TCP port 80.
So I can see most services not needing to block iCloud Private Relay.
Actually, my experience is Netflix blocks some of the time; Wikipedia blocks (edits) all of the time (which really pisses me off - I'm logged in!); and nothing else that I use blocks me.
The only differences are:
* Undetectable things (they say they don't keep logs, but do they really not keep logs?)
* Price - which they don't want to compete on if they can avoid it
* Reputation - which advertising can buy you a simulacrum of
Some VPN companies have decided the way they're going to stand out in the sea of very similar looking options is by being the company whose name you recognise.
The next big question is jurisdiction. I would never trust a VPN that is based in the US, UK or a similar country where government access is virtually a given.
Insofar as there are shitty ISPs that sell your data, yes. Most ISPs don't though. Also: I trust a VPN based in Gibraltar more than an ISP which is known to sell your data.
You sure? ISPs can, and do, this fairly readily. They wiggle on what “your data is” (“CPNI”) but browsing history via DNS queries is not uncommon (and cheap, to boot).
Go read Spectrum’s policy and how they wiggle around it as just one example: https://www.spectrum.com/policies/your-privacy-rights-opt-ou...
Sue to shitty peering, and some bad connection between me and a service, I was seeing horrific latency and packet loss.
A VPN let me route my packets through Chicago, which had a better connection to the service in question.
Because there is enormous incentive to deanonymize Tor. In 2020, nearly 25% of the network was controlled by a malicious attacker. [1] You had, then, a 1.5% chance of complete and total deanonymization by a single party - a near-certain chance of deanonymization if you heavily used Tor. And this is without any traffic correlation antics.
Turning off the devil's advocate, most "trustworthy" VPNs are almost certainly intelligence gathering operations, claiming "no logs" in court but in reality being a tool for parallel construction. It's too valuable a position for the 3LAs of the world to not have some ownership and stake in major VPNs. Crypto AG-style.
IMHO there is no hope for modern anonymity. Interesting connections will be logged for future deanonymization with quantum computers. In the meantime, mixnets like Nym [2] might emerge to be our saving grace.
[1]: https://www.intego.com/mac-security-blog/why-tor-is-bad-for-...
[2]: https://nymtech.net/
I see ExpressVPN ads all the time and they're almost always advertised as "protecting yourself from hackers or your ISP".
Well not the people serious about VPNs. The ones I consistently see popup in online discussions about what VPNs to use are Mullvad, ProtonVPN (Because of their Switzerland location), & iVPN (because they're based in a non fourteen-eyes jurisdiction, namely Gibraltar).
Of course jurisdiction doesn't matter since the point-of-presence of the particular VPN country is usually housed in some cheap colocation datacenter that could have questionable ethics and could be feeding logs to adversaries, without the VPN provider even knowing.
Then there's the whole 'we never keep logs' claim which can't be proven. So, caveat emptor folks!
Then there's the whole 'we never keep logs' claim which can't be proven. So, caveat emptor folks!
It can be trusted with a fair degree of certainty depending on the company. For instance, we know that PIA at the very least was willing to testify under oath that they had no records to provide the US government. Could they be keeping secret logs or have changed practices since? Sure, but at some point the claim seems credible.Now those flavor-of-the-month budget VPNs that cannot possibly be profitable unless you're the product? Different story.
https://restoreprivacy.com/private-internet-access-kape-cros...
https://blog.getfoxyproxy.org/2017/11/04/secret-service-subp...
The company has been owned by the same individuals since 2006.
It doesn't hurt that the "no logs under oath" assertion will no doubt engender trust with the very people you want to log.
That doesn’t make sense. If the provider has the logs, they’ll be presented in court if the company is given a subpoena and the owners are American. No one is going to risk contempt and jail time for their customers.
Gibraltar is an British territory under the jurisdiction and sovereignty of the United Kingdom, it's part of the fourteen-eyes.
So I use a VPN to pretend I'm in the UK, and get English language.
I actually have to turn this off to watch streaming services, because they detect it too easily. The streaming services then cheerfully serve me English UI (because my account preference is for English) but German language content. I understand why, but this is such bullshit.
If you want people to stop using VPN's, then stop assuming that their IP address has anything to do with their physical location, culture, language, bank account region, home address, telephone prefix or anything else.
Also, a Swedish distant relative of mine told me (decades ago) "We Swedes prefer to talk to foreigners in their own language, and keep Swedish as a private language for ourselves". I've never heard that said by anyone else, but it has always stuck with me as a cool idea, and the antithesis of the English ;)
The unfortunate truth is that analytics have show that more users have their browsers configured than an IP that doesn't "match" a language that they understand. Very unfortunately but is basically the common case for browser defaults on the internet.
I have started a one-man campaign of creating support tickets for all sites that ignore my browser setting. Join me!
Being that it is 2021, it seems absurd to actually believe that some cheap service provider is providing any kind of meaningful privacy. I get the notion of being able to watch BBC or avoid baseball blackouts, but competent content providers block VPNs all of the time… consolidating will only help that effort.
It's basically the 2010s version of web hosting in that regard, an industry that absolutely proliferated with tiny companies that were ultimately just reselling larger providers or running their own infrastructure very shoddily. It was seen as easy money, and that was true to an extent until they proliferated so much that it was hard to grab many customers... which lead to some very heavy-handed advertising pushes.
Consider, for example, the large number of Usenet providers that have affiliated VPN services now... they're priced so cheap it's hard to imagine them making much money off of them, but consider that they're just reselling from a larger Usenet provider that already has a lot of owned capacity and bandwidth. Since Usenet is so storage heavy they may just run the VPN endpoints right on their NNTP servers. It's basically free for them to offer!
It would seem that people do [think “oh shit I need to protect my security”, and then buy NordVPN, without questioning ...] or else they would have stopped all that advertising.
There's some truth to the fear they are promoting in some situations. I doubt most consumers are in those situations (ignoring people living under oppressive regimes, as presumably they aren't watching the typical consumer tech videos on Youtube). But like a lot of types of insurance, the consumers are convinced that they need the solution to the problem which they don't really have.
This is the interesting question. I think mostly it's the (correct) fear most businesspeople have of being caught taking advantage of rubes. They fear the social stigma, the impact to their business reputation, and potential litigation. It's the ones willing to take on all this additional risk that go on to rake in cash selling snake oil and magnetic holistic government-grade encryption bracelets.
I mean they're not wrong, but it's hard to take seriously when they've got a horse in the race.
I subscribe to not one, but two VPN providers, but it's less about anonymity and more about region blocking and the fact that certain sites behave differently if you're out of the country (which, I am on a permanent basis).
This is mostly, I presume, anti-fraud measures that seem to pop up when visiting niche Australian web apps from overseas.
Services that expect to be contacted by robots (which is mostly what runs on AWS) won't blacklist it, but sites that expect to talk to humans very much do so.
“Anyway, here is an advertisement for our VPN company”
I think those vpns are monetizing your traffic everyway they can and are often circumspect about it.
Do you have evidence some don’t?
I often wonder how good AdGuard really is, anyone know about this? I’m aware they use some kind of proprietary connection scream, but the actual VPN tunnel appears over IPSec, I think it’s the negotiation that is for some reason non standard.
Anyone know anything about this? I am only testing it out cause I get it in this package deal
I have friends who are non technical who often ask me "what VPN provider should I use?", and my response is usually "Why are you using one?". They often say it's to protect their privacy from... someone, they don't know who. However they never know the privacy policies of their VPN company or how to protect against things like DNS leak.
It seems most people actually use them to watch a streaming service in a different country. This is just piracy with a hat on. I don't understand why they don't just pirate the media without paying anyone a monthly fee and be done with it.
So a better question is, "Is consolidation of products you shouldn't buy trouble for you?" Probably not.
While not a VPN, it's the sales of Lastpass and Keybase that really bothered me. Those were losses for the consumer.
Small aside: a VPN which sponsors a few dozen youtube tech videos is probably not one you want.
But the points it makes are all very true. You shouldn’t trust VPN companies. They all seem super sketchy.
If I download 1TB through my VPN, dont they have bandwidth costs for 1 TB as well?
Wireguard protocol is the new and faster trend.