Poor man's VPN (pay for only what you need)
github.com
github.com
Ofcourse this is only useful for a single user, and for devices that can use ssh and proxies.
I have accidentally opened an internal network to the public this way. (Nothing bad happened.)
Only benefit I'd see is wireguard would be easier to use on a mobile device, but the setup requires the ability to run ansible and do ssh already so... that's not really practical.
Last I checked, wireguard had much better performance than sshuttle. May or may not matter for your use case, but it's a reason.
Apps that manipulate TCP packets locally to break fingerprinting [0] like GoodbyeDPI (Windows) [1], GreenTunnel (cross platform CLI) [2], Intra (Android) [3] have been adequate.
[0] https://nitter.net/vinifortuna/status/1304189371688660992 (https://twitter.com/vinifortuna/status/1304189371688660992)
[1] https://github.com/ValdikSS/GoodbyeDPI
I thought captive portals force you to use their DNS servers by grabbing all UDP packets with the DNS port (regardless of destination IP) and those servers respond with the webserver’s IP regardless of what you query.
Is that out of favor nowadays, given new technologies like Wireguard have become mainstream? Would I be better off using this, or the Algo scripts that another commenter mentioned? (https://github.com/trailofbits/algo)
For instance, I can't connect to a work VPN (vpnc) properly while tailscaled is running because Tailscale hijacked my resolver entirely. It does that even on resolved.
I'm on 128 Mbs RAM/1vCPU and OpenVPN hogs 100% of ram on one connection (and sometimes even when idle).
I'm searching for some resource conscious VPN server.
Pennies a day - $0.38 in January so far. This would definitely be free-tier level stuff, but for some reason they are charging me for it and it’s not worth my time to figure out why given the low cost.
I’m not using it as an exit node (haven’t gone down the hole of traffic scanning or anything like that), but that would make it more expensive.
It is nice - I can set up all my devices for pihole and block distractions, and have Tailscale on my wife’s computer to switch on when I’m using it. She doesn’t get frustrated I’ve broken the internet when she uses it and I flip Tailscale off.
I’ve also got a desktop that I can Connect into from my iPad on the road. Setting up a dev environment in a cloud platform and adding it with Tailscale would be trivial.
It is an interesting project and it looks good on your resume if you're just starting out in IT.
Managing your own server at 5$/month does not make sense from any perspective other than “privacy” if you believe that.
I use a router behind my router at home that runs 100% of my traffic over a VPN before it leaves the building. Any services that don't work, I simply don't use them. Someone else will take my money.
I'm on a $10/year VPS with 100 Gb/month traffic. Not great, but not terrible.
Not in my experience. Using it now on a super budget VPS ($4/year), very little CPU/memory usage even when streaming video.
If you're just doing it for fun (kinda like "hosting your own mail") I recommend setting up an IKEv2 IPSec VPN. It might be the hardest VPN to set up? But you learn a good deal about VPNs and networking. Most OSes ship with a native IPSec VPN implementation, and most "enterprise" VPNs are some variation of IPSec. Mobile devices, internal firewalls, internet gateways, enterprise AWS tunnels, etc. You can keep getting fancier by adding VLANs, GRE, BGP, certificates, RADIUS.
I recall using OpenVPN a few years ago for a similar use case in my university dorm, it was comparatively way worse - the configuration parameters were unclear, some of the documentation was out of date and even when using the faster (but less secure) methods of encryption, i found myself having a VPS that was overwhelmed and had almost 100% CPU usage (on its single core, since VPSes are generally expensive) whereas the client couldn't get much past 10 - 20 Mbps when the connection speed itself was closer to 100 Mbps.
Nowadays, for a VPN, i just use Time4VPS https://www.time4vps.com/virtual-private-network/?affid=5294 (affiliate link so i get discounts for signups, i also use them for most of my VPS hosting) because they're affordable and have more locations than i can get VPSes in those locations for comparable amounts of money. It seems like their offering is OpenVPN based which is surprising, since it works pretty well - makes me think that either i royally screwed up my own config back in the day (though default config should never hit 100% CPU usage like that, which happened to me), something was wrong with the system packages, or they just have beefier servers behind it, despite many users.
South America 600mbps > Atlanta VPS
A great experience, and I'd say it just works.
I tried it out before just to test it out, it's pretty cool.
This is the tricky part. SSH gets blocked in some LANs, so then you would have no way to spontaneously deploy your VPN server. So better deploy it ahead of time.
Blaming GDPR for this is a bit like blaming a lead mine for getting shot. Yes, it's involved but it's not the reason. It only seems to be certain large US websites that carte-blanch refuse to serve EU visitors over GDPR, mostly those with large, tendril-filled advertising networks that have no "easy opt-out". Some sites (healthcare ones that tended to be SEO'd to the max when I searched for drug names as well as more mainstream ones like, iirc, the Washington Post) carte-blanch refuse to let you browse them without accepting unnecessary cookies; this is a direct breach of the legislation and yet they still want your traffic.
If someone won't sell you something because of GDPR -- legislation that protects your privacy, and in particular considers medical information as especially sensitive -- then you perhaps have to think rather carefully about if you wish to do business with them.
(For what it's worth, from a Danish IP, the site listed in the github repo works perfectly on my home network which admittedly contains a pihole-provided dns-level adblocking. It blocks tor and I don't have an easy way of testing it otherwise).
This is fine if not abused. But if a mountain of redactions came in, I could see a company just deciding it wasn't worth it to serve the EU. Not to mention the fact that there are a non-zero amount of people that will make GDPR redaction requests and hound the company down in hopes of suing them if they don't follow the law to the letter and/or can't process the redaction in time. If a company doesn't already have that process in place, it could be a momentous task to initially process.
I'm 100% for user privacy. But it can be tricky with the way the GDPR law works, so I understand why companies outside of the EU don't bother with it.
1. Don't create surveillance files on people in the first place. It's not like the lack of privacy legislation means there are legitimate reasons to be performing surveillance. It's just that the illegitimate ones have not yet been made illegal.
2. US states should start adopting the GDPR verbatim (with no corpocratic handouts), so there is only one law to follow.
This seems to be precisely what happened--and the thinking involved invention--a way of circumventing what prevented acquiring the needed medication. (I assume that alternatives were considered, and found wanting for one reason or another).
I guess the only way to protect my privacy in this case is to risk going to the physical store with other sick people atm.
The only technical way around that I can think of is to implement Signal's and other's API proxies and let it return back fake info to the site. But I'm not that obsessed about this issue :-)
Another over-the-top way is to place the order directly against CVS APIs, using their cookies etc. Again, not worth spending time on..
Never give them your phone number. They suckered me, and it took multiple calls to a very slow call center to get the text messages to stop. And I couldn't get them to just delete it - it had to be done as a number change. So my number is now 415.555.1212.
I even called them and they stopped for a while, and are now back in full force, right after my recent order.
Incidentally, I've even discovered what seems to be one of (probably many) security issues on it (one where you could see other person's order details without authentication, in this case for myself), but I'm not gonna report it because they likely don't even have a bounty program and it was likely a "feature" implemented intentionally.
Give them Jenny's number:
(your local area code) 867-5309
It works way more often than you'd think, and if no one has yet made a store loyalty account with the number, you can be the first and add to the movement :). Use this trick whenever you need a loyalty card to get a store discount.
If only a small part of my traffic / business comes from the EU yet I am going to incur huge costs, and have to fundamentally change the way my business runs to comply with GDPR guess what, the EU is getting blocked, as make not sense to do it.
My current company does not really collect user info, does no business at all in the EU or is even consumer facing in the US but looking at our internal processes it would be almost impossible to comply with GDPR with out changing MASSIVE amounts of internal processes and procedures.
No, this is malicious compliance.
If they are indifferent to EU visitors but happen to get enough of them that 27(2) won't excuse them from 27(1), then it may be worth blocking EU visitors to try to reduce the chances that 3(2) applies. Article 3(2) is somewhat objecting, relying on whether you intended or not to offer goods or services to people in the Union so blocking is a way to make your intent clear.
IP addresses are considered to be personal data under GDPR, so a site that is doing nothing other than serving content with no advertising or targeting but that has the default Apache logging enabled could end up with an Article 27 obligation.
The silver lining of my aversion to collecting user data is that it aligns nicely with my beliefs about privacy and minimalism (ie. coming up with ideas for web applications that don't even need a backend).
> 2. This Regulation applies to the processing of personal data of data subjects who are in the Union by a controller or processor not established in the Union, where the processing activities are related to:
> (a) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in the Union; or
> (b) the monitoring of their behaviour as far as their behaviour takes place within the Union.
Recital 23 includes an elaboration on (a):
> In order to determine whether such a controller or processor is offering goods or services to data subjects who are in the Union, it should be ascertained whether it is apparent that the controller or processor envisages offering services to data subjects in one or more Member States in the Union. Whereas the mere accessibility of the controller’s, processor’s or an intermediary’s website in the Union, of an email address or of other contact details, or the use of a language generally used in the third country where the controller is established, is insufficient to ascertain such intention, factors such as the use of a language or a currency generally used in one or more Member States with the possibility of ordering goods and services in that other language, or the mentioning of customers or users who are in the Union, may make it apparent that the controller envisages offering goods or services to data subjects in the Union.
Probably nothing to worry about for a hobby site.
GDPR has been out for some years now and we can see the enforcement personnel do not go after companies worth under $100 million, let alone hobby sites. After all, enforcement personnel only have so much capacity.l just like the FDA, USDA, BLM, and countless other agencies burdened with enforcement.
I’m sure there are sites in the US, however, that block access from GDPR countries.
And it’s not only the US websites, the website OP mentioned is one of the three largest medicine websites in India. There is no reason for them to comply. And EU laws are incredibly confusing. Follow GDPR and respect privacy, while saving customer IP address for years when EU needs VAT.