When I did it, I could see they recorded IP addresses, time stamps and data transfer volume of every web site that I visited over their network, along with cell tower connections. It was fascinating.
When I did it, I could see they recorded IP addresses, time stamps and data transfer volume of every web site that I visited over their network, along with cell tower connections. It was fascinating.
I suspect a VPN user would show up in the Verizon data file with many large TCP sessions to a very small number of IPs.
Just curious, how many captchas do you solve with this setup daily? Or even IP bans?
I did exactly the same thing once and it was so annoying.
I set up a VPN on a Digital Ocean instance and got captchas all the time on various websites, especially ones using CloudFlare etc (I’m aware of Privacy Pass but didn’t bother setting it up as it was a temporary thing)
That said, if you're using your own EC2/lightsail instance you won't see as many CAPTCHAs as, say, using a commodity VPN service.
Given you can't detect a VPN per-se (if configured properly) usually the way it works is that the destination node knows you're coming from a source IP from a known VPN-supplier's well-known IP-block.
If you go for this kind of setup (running your own VPN on AWS) you're simply changing your ISP to Amazon. They still might (and probably will) be monitoring egress traffic at the very least to perform any kind of incident analysis.
Lightsail costs $3.50/mo with 1tb transfer bundled or $5/mo with 2tb.
If your setup is scripted then it probably makes sense to switch over to save a bit of cash. Others following the same path could save some money by using Lightsail as opposed to EC2.
I personally use lightsail for most always on things and then just use ec2 for on demand workloads, because it works out far cheaper (these are just random personal projects so I'm heavily optimising for low cost)
You can't configure the lightsail instances as much as an EC2 instance, but otherwise it's essentially the same product (both operated by AWS).
Generally speaking, this makes me feel a better when using mobile data or any foreign network (public, friends, work, etc) since I know all of my outbound requests are coming from "one location".
I can reroute outbound access to an external VPN if/when needed, but it's really a crapshoot for who you trust to keep track of your outbound requests. I don't trust any VPN out there to be strong enough to say "NO" to an intrusive 3rd-party like the US gov. No more than my own ISP at least.
For someone overly paranoid about tracking, I would probably suggest just using Tor, but for basic consolidation of internet access, routing through a self-hosted VPN at home works great.
I'm curious if other have done the same.
4.4 trillion database entries in a year
Meaning, the cost to record everything a person does all day, every day of the year for literally forever is not very much at all.
Please see my answer here https://news.ycombinator.com/item?id=29003198
Very helpful when filling out the time report if you are reporting time on many different customers.
If a company force installed it on your PC it is probably not a good place to work at.
It is not uncommon for me to have 15-30 different time tracker entries for things I worked on in a single day. This is not an exaggeration. Then other days I will work on a single task for entire day.
So all of this unscheduled stuff gets lost pretty easily. Calls scheduled for an hour run only 30 minutes. Client A needed 10 minutes of support here, 20 minutes there, 5 minutes there. I want to be as fair as possible to our clients.
And related to client support, there is often the question of "who owns this bug" and who pays for the call. So I can use screenshots of the client environment to relate to the team and get more information about whether we should really be billing for the call or if that's something that needs to be improved in our software.
Also I support other developers. Skype calls with developers tend to be short. But boy can they add up. If I'm spending 3 hours a day on support overall, I really need to track that. That time needs to go into the right project at the very least.
So that's where the screenshots come in. This is not something the company asked for or have ever requested access to. They know I do this. So when I say I spent two hours supporting a client, they feel confident sending out that bill.
It actually started as one of those experiments into time lapse video. But I multitask way too much for these to be usable videos. Though I have hand picked select days and turned them into something very cool.
This stuff is barely scratching the surface of the data those companies collect and maintain, likely for long periods of time, just to analyze and improve customer experience.
> data transfer volume of every web site that I visited over their network
Aggregate data usage is one thing, but retaining any kind of detailed logs on where one goes or how much data was used on a specific site is unnecessary for the base provisioning of network connectivity.
Heh, just to analyze and improve customer experience? Nothing else a bit more unsavory?
> Heh, just to analyze and improve customer experience? Nothing else a bit more unsavory?
The point is this data would get captured regardless, surveillance or no. Mass surveillance (at least in this matter) often isn't so much about what gets captured, but how long it gets retained and who gets access to it.
I found this article [0] describing the situation in various countries, with the following info for the United States:
> Data Retention Period = 1 Year for Internet metadata, email, phone records
> Authorization required to access the data = Various United States agencies leverage the (voluntary) data retention practiced by many U.S. commercial organizations like Amazon through programs such as Prism and Muscular.
> Status Of Data Retention Regime = No mandatory data retention regime
I'm guessing the above means that metdata (user ip and also user web and email destinations) are held for a year, but retaining actual user data (email contents, etc) is not mandated.