I remember using VPNs long before, to my knowledge, people were using them in the way you describe, and I was always under the impression that the "P" in VPN meant "connecting private networks" together over the Internet.
This document from 2001 agrees with me: https://docs.microsoft.com/en-us/previous-versions/windows/i... "From the user’s perspective, the VPN connection is a point-to-point connection between the user’s computer and a corporate server. The nature of the intermediate internetwork is irrelevant to the user because it appears as if the data is being sent over a dedicated private link."
Yeah, that was the entire argument.
This is basically the same thing people do with VPNs now, only instead of hiding their internet activity from IT, they hide it from their ISP.
VPNs were always used for things other than connecting someone to a corporate network, it's just that most of the general internet population at that time (and I'm guessing you're old enough to remember this) were not aware of the technology and not tech savvy enough to set it up. This is true even for the employees of the companies we had as customers. We had to build entire software products that did nothing but hand hold people through setting up a dial up networking connection. It's not surprising that corporations were the majority users of VPN technology until the rest of the public (who don't have IT staff) caught up, at which point it became increasingly more common for people to use it to hide their internet traffic.
> You are wrong on this, the private part indicates the privacy it provides not the destination.
In your own recollection, what do you think "Virtual Private Network" stood for? Connecting private networks together, or privacy?
I might have been influenced by the product we were selling though. These were dial up users on workstations looking to access their company's LAN so the idea of connecting two discrete private networks wouldn't have fit as well. There was also a lot of focus on the insecurity of passing traffic (even encrypted traffic) over the internet. We had companies paying us a premium to sign up for the service and host their gateway on our network so that the traffic between the users who dialed in and the company's own network never left the ISPs network (never reached the internet at large). I knew at the time it was marketing and that with a well encrypted connection it shouldn't matter if the traffic ever left our "cloud", but it could have helped to shape my view of the technology.
Clients ate that up too. The internet was scary to them. Being able to say that their employee will dial directly into our equipment, and that no packet would pass through a device we didn't operate until the moment it hits your company's gateway made a lot of companies feel better about letting workers remote in.
At this point it just seems like arguing for arguing's sake, but I was rejecting the notion that VPNs were always intended for privacy (along with saying others are wrong for suggesting otherwise). It still seems to me that VPNs did not always imply "privacy", and I think in my sibling comment to this, an RFC from 1999 seems to support that (focusing on "intranets" and "extranets" in the definition of a VPN, and only mentioning encryption once as an optional component, with possibly only authentication instead, or even none).
Let's say you have an IPSec tunnel between a branch location and HQ site. The typical solution was GRE where you encapsulate it inside another IP packet that has public IPs only for the destination to decapsulate it. When VPNs came along they added privacy hence the name.
In networking you are not connecting two networks. You are interconnecting three networks! the branch would have its own subnet so would HQ but the VPN also would have its subnet all routed as separate networks. The tunnel network getting privacy because it traverses untrusted networks (back in the day it wasn't typically the interent but ATM, frame relay,T1,etc... "directly" between sites), that's where term cloud comes from FYI the untrusted magic ISP network in the sky.
The earliest reference to VPN I can find in the RFCs, RFC2547, seems to call the "destination" (the network spanned by the tunnel) the VPN, not the tunnel itself:
"If all the sites in a VPN are owned by the same enterprise, the VPN
is a corporate "intranet". If the various sites in a VPN are owned
by different enterprises, the VPN is an "extranet". A site can be in
more than one VPN; e.g., in an intranet and several extranets. We
regard both intranets and extranets as VPNs."
That same RFC has only one mention of encryption at all, in passing, and as being optional (note the "and/or"): A security-conscious VPN user might want to ensure that some or all
of the packets which traverse the backbone are authenticated and/or
encrypted.
It does not seem to me that privacy was implied.I still think that VPNs were invented to connect smaller private networks to a larger private network together, where private != privacy. (But rather related to authorities, such as using "private IP addresses" in e.g. 10.0.0.0/8, instead of publicly routable ones.)
Privacy was a (good, likely popular) option, but just not part of the strict definition of what a VPN is (much unlike today).
And even then it isn't like individuals did not VPN in the 90s at all.
A connection that does not provide privacy like a GRE tunnel for example is called a tunnel never a VPN or more and GRE specifically connects networks which are typically private.
You can also have VPN between two ASes on on the internet which are public networks. Wrong is wrong. Give me another argument to shoot down against VPNs lol.
The correct term for both private and non-private network tunnels is an overlay network (includes stuff like 6-in-4).
The same RFC also pretty clearly calls the network spanned by the tunnel, not the tunnel itself, a VPN.
By now, the meaning has shifted.
That being said, I think this is my last message on the topic, since, well... it's quite a lot of wasted time on pedantry (which is totally my fault).
These two words have the same root and etymology. The adjective "private" is transformed into a noun using the abstract noun suffix, "cy," to become "privacy." These two words have the same word root dressed as different parts of speech.
The argument that privacy doesn't mean private, and vice versa, in regards to the meaning any of the letters in acronyms is specious, such as, the word private in VPN does not mean that you will have privacy, because, in fact, any transfer of data between the VPN nodes will be kept private from the Internet at large, thus the transfer is in privacy.
The fallacy you and OP committed (if you are not OP, didn't check) is known as the appeal to definition.
One can have a private parking spot without privacy, though. Or a private pilot license.
> any transfer of data between the VPN nodes will be kept private from the Internet at large, thus the transfer is in privacy
Not if your VPN is not encrypted, which exists, although it isn't very common anymore, for obvious reasons.
The IP address "10.1.1.1" is still part of IANA's private IP address space, no matter whether it is transported in a way (say using an unecrypted tunnel over the public Internet) that provides privacy or not.
This is equivocating between two distinct and separate definitions of "private." You are mixing these homonyms.
In the sense you're using in the quote I pulled from your comment, it means intended for or restricted to the use of a particular person, group, or class, but in the sense that it is used in Virtual Private Network, it means something else, namely not known or intended to be known publicly; secret.
> in the sense that it is used in Virtual Private Network, it means something else, namely not known or intended to be known publicly; secret.
Great. Present some evidence or stop wasting time. My evidence that it actually does not mean that is RFC2547.
RFC2547 does not support your claim... anywhere.
I'll use Webster's definitions for my evidence. Also, every explanation of what VPN is everywhere on the Internet speaks of anonymity and privacy. This means the P in VPN could only mean free from public attention, secret and NOT for the use of a particular person or group, as in private parking.
A security-conscious VPN user might want to ensure that some or all
of the packets which traverse the backbone are authenticated and/or
encrypted.
Webster's definition of a VPN is (https://www.merriam-webster.com/dictionary/VPN): a private computer network that functions over a public network
A private network at the time was defined according to RFC1918. It also provides the motivation for private networks/the private IP address space, which was growth, not privacy/secrecy.It's a happy coincidence that you can sell a "Virtual Private Network" to endusers as a privacy-enhancing machination, given that it already contains the word "Private", even if that was meant as in private parking space, not private conversation.
Sorry - that's just not the case, you're retconning VPN terminology. VPNs were originally implemented to replace dedicated WANs and dial-in access to private networks - they were not originally designed to provide privacy for individual access to the Internet. Heck, even the RFC for VPN terminology makes that clear (RFC 2764 is over 20 years old).
Oh, and this: > There have always been client-access VPNs
If your first exposure to VPNs was from shady privacy-snake-oil salesmen, I can see how you'd think this, but take it from the people who were there before client based VPN access was even a thing: Site-to-Site VPN was the original use case for VPN, and you didn't waste tunnel bandwidth (encryption chips were slow and expensive back in the day) routing general internet traffic over your tunnel...
What it actually says is:
The widespread deployment of VPNs has been hampered, however, by the lack of interoperable implementations, which, in turn, derives from the lack of general agreement on the definition and scope of VPNs and confusion over the wide variety of solutions that are all described by the term VPN.
Some people's ideas of the definition and scope of "VPN" might have involved the requirement that it terminate on a private network, but others would not.
Read the acronym carefully. It is virtual and it is a network. Not the destination but the tunnel itself is the network that is private. It was described as such from the start and in no networking context have I ever heard otherwise (correct me if wrong please). Let's say you have an IPSec tunnel between a branch location and HQ site. The typical solution was GRE where you encapsulate it inside another IP packet that has public IPs only for the destination to decapsulate it. When VPNs came along they added privacy hence the name. In networking you are not connecting two networks. You are interconnecting three networks! the branch would have its own subnet so would HQ but the VPN also would have its subnet all routed as separate networks. The tunnel network getting privacy because it traverses untrusted networks (back in the day it wasn't typically the interent but ATM, frame relay,T1,etc... "directly" between sites), that's where term cloud comes from FYI the untrusted magic ISP network in the sky.
I wouldn't entirely agree with that (although out of context I do agree).
It's a Virtual Private Network connection, you create a Virtual (not physical) Private Network (between your device and another device/server) there's no real difference between a site-to-site VPN and a client-access VPN other than if the devices at each end route more than just the partner traffic over the private network.
If I connect a "site-to-site VPN" between my computer and your computer, if I add a route to send all traffic for a particular network to your computer as the next hop, that makes it "client-access" for that particular network, if I add a default route it then sends any internet request I make to your device as the next hop.
If your device decides to forward the packets (and probably NAT them) then I now have some privacy for my internet traffic.
VPNs were originally designed to replace dial-up modem connections since the internet was becoming more ubiquitous and it would be far cheaper for someone to connect to their local ISP then use a VPN to connect to their remote network (either personally or usually between sites), than dial directly to their other site (also it was usually far cheaper for one internet connection than a bank of modems and ISDN lines (if you wanted 56.6Kbps or 64Kbps connections)
The difference is one end is not a network but an endpoint part of a network. Multiple client access VPNs can be part of the same subnet.
> If I connect a "site-to-site VPN" between my computer and your computer, if I add a route to send all traffic for a particular network to your computer as the next hop, that makes it "client-access" for that particular network, if I add a default route it then sends any internet request I make to your device as the next hop.
In site-to-site VPN, your computer would need to route a separate site network as would the remote end. With client access only the remote end routes a sparate network. Windows for example cannot be used (unless server versions) to provide site-to-site connectivity because it does not route between NICs. Your tunnel IP is used for connectivity with client access but with site-to-site the remote end expects you to adverise a route or have a separate config for a static route back to some other network on your end which is what it will route (won't work otherwise). Hope that is more clear. You can turn your nix box to a s2s vpn terminator but in every VPN type this requires different config which is why the different terms exist.
What are VPN services SOLD AS? If they promise something and do not do that thing, then this is a problem. They should be sued or regulated or similar, and they shouldn't be able to get around that, even based on techinical definitions.
I see no deception or nothing misleading about the service they provide. The fact that you need to trust them more than your ISP and country's network is not unclear to anyone, they even advertise "no log" because obviously they can log if they choose to.
It is preposterous that you call them snake oil when there are so many discoveries about ISPs doing mitm on their own behalf or governments and even in the US/west it is a default that they will sale your location and address along other things as a service. You have no choice in the matter because they are monopolies. It is a simple risk calculation that if I trusr some rando vpn provider over my last-mile or country/locality network I can pay to use them to move my trust boundary to their servers. Now marketers and other hostile parties can buy my metadata from a myriad of VPN providers who all risk to lose their whole business if that deal was ever exposed (unlike ISPs).
SOMEONE should be punished for this because it's effectively a lie. This is the only way we will actually improve the bad situation you're talking about.