Google kills "One" VPN service
arstechnica.com
arstechnica.com
For me, being able to switch my country is the primary use case of a VPN, so I had no reason to continue using the product.
It's a huge shame, because the Google VPN has the best technical design of any VPN I've seen. It's designed in a way that Google cannot associate your Google account with your VPN traffic. I view this as extremely poor marketing.
My assumption about a Google VPN is that it would not protect my identity or internet usage from Google, who are one of the main entities I want to hide from with a VPN.
"By employing a cryptographic blind signing step between user authentication and connecting to the VPN, we give users a stronger guarantee that their network activity can't be tied back to their identity."
If I activate a VPN on my device, it’s trivial to reconstruct who I am via a preponderance of authorized services or the sending of identifiers across the line.
I can’t help but feel that VPNs are, in most cases, merely privacy and security theater.
A proper VPN involves server(s) that either you or your company owns, hence the trust starts and ends with you/your company (and your ISPs, I suppose).
Just like cloud computing and storage, you can't, don't, and shouldn't trust Someone Else's Computer(tm) with your sensitive data.
More discussion: