Half truths are spouted about "securing your connection" and "preventing tracking" are provided, without the supplementary information that device and browser fingerprinting do more to identify you as a user than geolocation does. With HTTPS, traffic is already encrypted, and any DNS-over-HTTPS or TLS provider will also mask where you were headed to, leaving much of the supposed benefits to be mostly snake oil.
If, however, you want to use it to access geofenced content, or you employ an obscurity-in-depth strategy to anonymize your identity, then sure, go ham. But as to why usage has exploded by the masses, a healthy dose of paranoia and influencer marketing.
If you downloaded a file over HTTPS, all they can see is the IP, domain name, and the amount of data transferred on a given connection.
People/organizations run bots that pretend to be interested in popular downloads so that they can collect these IPs.
99.999% of airport wifi users don't know that their traffic is bridged. So unless WIFI-6 introduced some network segmentation features that I'm not aware of, it's still a good idea for Grandma and Grandpa Jo.
The reason it's ubiquitous on YouTube is because they are gouging the hell out of consumers. Honestly it should be provided by your ISP as a bundled service. Although then it's just Comcast gouging you instead...
Here's how I think about customer segments:
* Those interested in online privacy
* Those interested in circumventing censorship
* Those interested in a secure network channel from their machine to "The Internet", by which I mean secure from their local ISP eavesdropping on them.
* Those interested in circumventing geographical restrictions.
Due to the nature of the Internet and how its most important protocol (IP) works, changing your IP address is a necessary, but not necessarily sufficient, step in protecting your privacy online. This fact says something about the long term relevance of VPNs, Tor, and similar technologies.
Source: I'm one of the co-founders of Mullvad VPN.
> ISPs learned how to be bad from security experts explaining how much mischief a person could get up to and deciding that sounded like a swell idea
Telecommunications companies have played a central role in government surveillance schemes for at least 50 years, well before the advent of WiFi. ECHELON was fairly extensively reported on in the late 90's.
> it might have seemed like you heard about ISPs and hackers around the same time
I connected to the Internet around 1993, but my interest in computer security didn't start until around 1996. I'm not sure if that qualifies.
From the surveillance standpoint, we now have devices we take with us and leave unattended. We are all waiting for a proverbial woodpecker to destroy civilization.
VPNs of the Tailscale type: Mostly people who self host apps and want them to be available across their devices without opening them up to the internet, or be able to access their NAS from Starbucks.
[1] https://tailscale.com/tailscale-ssh/ [2] https://tailscale.com/kb/1081/magicdns/
Use a VPN for the same reason you close the stall door in a public restroom.
(I'm not necessarily agreeing with your premise that VPN usage has recently grown; I don't know that to be the case.)
Even if they'd log your IP and traffic (which they say they don't) they'd know way less about who you are then your ISP.
VPN to company is much more popular with businesses because of WFH and Covid.
consumer VPNs to random providers that advertise on podcasts are way up because of different countries having different video streaming service catalogs and because in the US consumer ISPs are increasingly privacy- and reliability-hostile. there's also a big marketing buzz because scaring people over these things was good for signups, so consumer VPN providers chose to advertise a lot.
Tailscale on the other hand is a way to re-create an actually flatly routable Internet, for myself, but with 2023 security levels.
"Security" is not a legitimate application of geofencing, in my view.
Any attacker can trivially use a VPN to defeat it, yet legitimate users are massively inconvenienced by it. I've had too many accounts (bank and otherwise) locked for the crime of trying to access them while traveling internationally.
1. Ease of use for non technical folks (my dad in the post)
2. The dangers of having an exposed ssh port (even on non standard ports)
I just don't have the time or compute to constantly tweak my security settings for a publicly exposed port, so the easiest way to solve the problem is to not have the port publicly exposed
---
It is not fully disabled, my dads account has a password for sftp.
Its covered more in part 1 (linked at the start of the blog post) but the repeated attempts at ssh'ing into my server actually killed sshd (which is how I found out about it).
The other problem is that this "server" is hosted on a residential connection in my computer room. This is just something I don't want to deal with and using a VPN fixes that since I do not need to deal with it, and its easy enough for my dad to use
I don't want to "opt-out" and hope companies actually follow their policies, or assume their policies are sufficient when I "opt-out". So I ensure all of my network traffic is routed through my home no matter where I'm at or which device I'm using, and then from my home I ensure all my network traffic is routed through a business-grade connection that is offered under standard contract terms that preclude the type of fuckery that every ISP in America seems to think is acceptable to do to consumers.
That's why I use a VPN, and I'm pretty sure a lot of people who use a commercial VPN service do it for very similar reasons and don't have the technical know-how or wherewithal to set something like I have up for themselves.
They help to mitigate IP based tracking.
Also, geographical blocks on content such as Netflix and BBC etc
Here's a visual: https://mermaid.live/edit#pako:eNptUstugzAQ_BXL5_ADHHqBSjlUJ...
* circumvention of geoblocking