Personal VPN services are snake oil
httpscolonforwardslashforwardslashwwwdotzoltanbalazsdotcom.com
httpscolonforwardslashforwardslashwwwdotzoltanbalazsdotcom.com
It’s kind of like when shops selling bongs would market them as “tobacco accessories”, but there was a wink-and-nudge understanding about how they would really be used.
Did you know the original vibrator was a medical device by doctors to automate treatment of Hysteria?
1) https://jhupbooks.press.jhu.edu/content/technology-orgasm
2) https://www.psychologytoday.com/us/blog/all-about-sex/201303...
3) https://www.bbc.com/future/article/20181107-the-history-of-t...
We might have a long way yet to go as a species, but we’ve sure come a long way.
Nonsense like "rhino horns look like an erect penis, so surely they will give you erections" should be dismissed without further discussion, but unfortunately a multi-billion dollar industry continues to wipe out rare and endangered species for magic cures that can't possibly work.
[1] A large subset of such medications are basically stimulants that make patients feel better but do more harm than good. My father in law was scammed this way by a herbal doctor that gave him such huge doses as to cause heart damage.
Plenty of herbal medicines are effective. Which is why we need research to understand which ones are, and which ones are bullshit.
Aspirin used to be extracted from tree bark.
Opium and morphine is the juice of the opium poppy.
Penicillin is from a mould.
Botox is from a bacteria.
Heck, there's an entire subset of the pharma industry running around testing every damned plant, weed, and flower to see if it has some sort of useful effect! There's even been movies made about this! https://www.imdb.com/title/tt0104839/
We've tested herbal medicines, and use the pure extracts from those that do actually work every day in every country.
That doesn't mean the guy selling dried tiger penis should be allowed to open shop next to a pharmacy and claim mysterious properties "unknown to science".
https://www.theatlantic.com/health/archive/2018/09/victorian...
Whenever a state in the US passes a new "we need your ID to watch porn" law, sales of personal VPNs must predictably skyrocket in that state.
Yes, in practically every jurisdiction. It’s wilful breach of contract, tortious interference with the content distributor’s licensing schemes and copyright infringement.
I also don’t think there is prosecutorial precedent for murdering someone with a sea cucumber; that doesn’t make it licit (or legal).
Laws only mean what courts say they mean. Besides that, I have simply never heard any argument of region bypass being illegal or otherwise illicit, and you haven't provided any evidence to the contrary.
INAL, but while this use case might violate ToS, the case law suggests that courts deem this to be fair use provided you don't breech other laws in the process (e.g, copyrights).
No it's not.
Tortious interference with a business relationship is no doubt what you're referring to here, but it's a long bow with multiple layers of indirection. It is "intentionally acting to prevent someone from successfully establishing or maintaining business relationships with others".
Miramax, as a content distributor, might license their content to Netflix.
You are a customer of Netflix.
Now say you are a customer of NordVPN.
For one, NordVPN isn't trying to prevent you maintaining a business relationship with Netflix. Nor is it trying to prevent Netflix having a business relationship with Miramax.
NordVPN may provide you means by which you can choose to be in violation of your TOS with Netflix. It's not acting to ensure you are.
Netflix doesn't have to -allow- this, hence VPN/proxy detection. But they have recourse, drop you as a customer, for you, the customer's, actions, not for NordVPN's actions. Miramax can't argue that NordVPN acted to interfere with their licensing scheme with Netflix.
No, but they could argue that the VPN user interfered with their licensing scheme. (If everyone in a region circumvented geoblocks, why would someone in that region pay for regional rights to that content?) They wouldn’t, because it’s not worth it.
I highly doubt you know the laws in every region globally. This may be true in yours, but it's not a good idea to make such blanket, objective statements online.
Hi! /waves I use a VPN to stop my ISP from monitoring my traffic and selling my personal information. My VPN (usually) exits in the same "region" as my real location; I guess if I hit a geoblock I could look at that, but it hasn't come up.
Wouldn’t that address your concern?
Skipping the broader discussion of AI, the ridiculous amount of automatic and human impossible pattern, matching and correlation with seemingly harmless data is something that I don’t think we are equipped to fully comprehend.
The time at which I hit some meta CDN, seems harmless. Until combined with some cookie and some access time to some asset it uniquely identifies me to previously anonymized data.
So no, I do not think HTTP and a good DNS are enough.
But then how do you stop your VPN company from doing the same? You essentially have two ISPs now.
(Longer answer: This boils down to the weighted probabilities; if the ISP was meaningfully regulated such that it was legally restricted from doing certain things with my data, that might matter, and one should also play in the exact likelihood that either party is selling my data. In my case the weighted probability is wildly in favor of a VPN, but I suppose I can imagine situations where that wouldn't hold.)
They probably could sell my traffic, but I estimate it (based on vibes) as being less likely than for most other intermediaries
Yes.
> who has all the same incentives.
And no. The ISP has little to no competition or incentive to not sell my information, while the VPN provider has loads of competition and often has user privacy as a core part of their value proposition.
Besides - even if both of the did have the same incentives, one openly says they're selling my data and one says they're not. At worst it's a gamble between the VPN lying and the ISP telling the truth.
"Are you downloading films from anywhere?"
"Huh what from Disney Plus?"
He can barely work the Sky box never mind stream stuff from the internet, he got duped into thinking it would make him "safer" when in reality it just makes using the internet a lot harder as everyone flags your traffic as malicious based on the datacentre IP.
I occasionally fire up Mullvad when I’m on the go. I get blocked way more often when I use it
So has anyone behind random CGNAT.
VPN companies are more trustworthy than my ISP. Many get third party audits and publish results. And if the VPN company and server are in a privacy friendly country, they are hard to subpoena. Individual privacy being the default is itself valuable.
This is leaving aside numerous other reasons like avoiding censorship or persecution or whatever.
But that said, on this point I do agree with the author: privacy improvements from using a VPN are marginal for the average user due to the now widespread use of HTTPS. Yes, your ISP can see which domains you visit, but that's about it. I'm curious if there have been any successful lawsuits or prosecutions based solely on domain access logs.
Side question: Anyone know of a gateway or self-host service which supports DNS over HTTPS relay?
i.e. it will accept vanilla DNS requests, but if it needs to forward requests, it will only do so to DoH / DoT servers?
The main reason they exist is to do grey market bypass of controls becoming media access. If you trust them to not do some grey/shady exploitation of your metadata, more power to you. Sounds foolish to me.
Ie, it's the use case where you Pirate all the media, and use a VPN as a security bandaid against anti-post-scarcity busybodies.
> Is there anyone whose primary use case for a personal VPN is not "Geofence bypass for region-locked content"??
There's no ethical difference between faking your location to bypass licensing and copyright and downloading a file via torrent to bypass licensing and copyright. Both are piracy.
does that count?
Beer, wine, booze, tobacco, and vapes are obvious, but things like cough medicine (dextromethorphan), diarrhea pills (loperamide), little roses in neat glass tubes, and air dusters (let's kill some brain cells!) are perhaps less-obvious.
The bodega wants to be associated with being the place where a person can stop in and buy anything, from a can of soup to a pair of pants.
I once asked why levothyrox, a drug to compensate a dying thyroid, is so regulated (at least in France). It's not like it's psychotic or something, it is just a hormone. Turns out people were buying it expecting weight loss...
It's because of such idiots that people whose life is already complicated gets it even more.
News to me as well
And that's not a result of regulation (anyone can buy as much as they want), but is rather a result of stock shrink. It tends to disappear in some less-than-savory neighborhoods.
(I use loperamide occasionally for its main intended purpose of settling my gut down enough that I can do something other than hang out near a bathroom while I quickly dehydrate, and more than once it has been legitimately hard to find in some areas when I've needed to buy more.)
Sure you and everyone else on HN know what a VPN for, but that’s not the case for 97% of the people on a subway car who see their latest campaign.
"Our hotel uses unencrypted wifi, so if you want any kind of privacy on hotel network, please use a VPN, kthxbye."
> - Geofence bypass
> - Piracy
> - Soft network block/censorship
Among all the people I know who use the kind of VPN services talked about here, these are exactly their reasons for using them. Obviously advertisements are going to shy away from these angles.
The problem is people who aren’t aware of this see these ads and think that they actually do prevent hackers from stealing their information.
Considering that confidentiality is a vital component of overall security, it's not necessarily unreasonable to describe a VPN as a security product. Of course, it's not the panacea some companies claim; nobody's "surfing the web in full security and privacy" with just a VPN service.
Renting a car in Belgium from the Canadian website is cheaper than renting the same car on the Belgian website.
I use Visible (pre-paid Verizon), and they very clearly deprioritize, say, youtube when things get crowded. I turn on my VPN and all of a sudden I can play 1080p no problem.
4. Making all your traffic look "neutral" to your ISP, in places (think corporate / college campuses, cellular data, hotels and boarding schools, not countries) where net neutrality isn't enforced and certain traffic (most often torrenting, video streaming and/or gaming is deprioritized. I guess this could be classified as blocking or censorship, but deserves a separate category IMO.
5. Places where the networking hardware messes about with your data. I've seen places that would add their own iframes to unencrypted HTML content, which broke some software because their algorithms to detect what was HTML weren't very good.
A fifth use case is related: evading bad peering. Deutsche Telekom was infamous for years to "double dip", i.e. requiring that other (backbone/regional) ISPs pay them for peering, and so DTAG customers that tried to access Hetzner servers were throttled as the Hetzner-Telekom link got saturated in the peak traffic times.
[1] https://www.golem.de/news/hetzner-und-netzneutralitaet-extra...
Some end-users need straight forward advice like "Use a password manager" or "Use a non-free VPN on open WiFi connections". The rest is going to get thrown out with the bathwater.
https downgrade attacks and the like (html injection on http pages) can also be thwarted (unless they are done on the vpn->service path ofc),
Only if the ISP doesn't do DPI to transparently route any outgoing DNS traffic to their (censoring) servers. There have been enough cases of that.
And it's hell for the security minded people. Before I could do DNAT on my router to redirect everything to my Pi-Hole, even the Google Mini that staunchly ignored the handed out DNS, but used 8.8.8.8.
But soon they'll start using DoH and I can't do anything anymore at all.
I believe IMDb on iOS already uses DoH.
But why would I trust a random company with this information over an ISP, who yes aren't always angels, but at least are somewhat accountable.
Guess.
ISPs often have captive markets and have enough political sway to grant them said captive markets. VPN companies have none of that, and live or die based on their reputation, so they arguably have more of an incentive to behave well. Meanwhile some ISPs have even admitted to selling your traffic for marketing purposes or are forced by the government to keep records. There's plenty of shady VPN companies out there, and not all ISPs are scummy and sell your info, but there's quite a bit of range between the scummiest ISP and the best VPN, and for a subset of people using VPNs definitely makes sense.
Guess.
>even better, a browser built with privacy in mind
which is full of VPN ads https://www.privacytools.io/privacy-vpn. Browse https://www.privacyguides.org/en/vpn/ better.
And it's unregistered!
https://www.namecheap.com/domains/registration/results/?doma...
Edit: Per below, missed the last dot. zoltanbalazs is registered. https://www.namecheap.com/domains/registration/results/?doma...
Also, what would be more interesting: a financial breakdown of how an average free VPN provider makes money.
I assume ad injection + selling traffic data, but does that make enough to offset the cost?
I know I read a article about one where they at least routed some other traffic through the vpn app, but I can't find the article anymore.
facebook used their vpn onavo to mitm users of snapchat, amazon, youtube: https://techcrunch.com/2024/03/26/facebook-secret-project-sn... – somehow I had missed this, I was only aware of the much older scoop about facebook using it to track underaged users: https://techcrunch.com/2019/01/29/facebook-project-atlas/
It's worth pointing out that while it operated as a VPN (so it could capture traffic), it was ostensibly marketed as a "security" app (ie. scanning your web traffic for threats). It's not really a good example of shady VPNs.
zoltanbalazs.com was registered in 2021.
Sadly, doesn't look like there's anything hosted on zoltanbalazs.com
But, it can be helpful to trade one network's routes for another, in cases where direct routing between you and your desired peers is poor for whatever reason. And it's clearly useful for circumventing geographic restrictions (as long as those imposing the restrictions dont' care to identify and restrict access through VPNs)
Got a cheap VPN to get around the issue and it works perfectly.
* In the Bible Belt (a.k.a. Chistianstan) and some Muslim countries it is to access porn.
* In Canada and Mexico is about accessing what Netflix doesn't provide to their countries.
* In hybrid offices it is about the second job that they do remote and hidden.
They want something simple for a couple of months and then just discard it. VPNs are good for that.
The age verification laws are written pretty broadly and could be used to target a wide variety of content. Not just porn. Anything the state deems 18+ would require age verification.
These laws are facing some court challenges. If we're lucky, the laws will not survive.
I don't ever do anything illegal, I just don't like being tracked.
I run a low-volume scraper which benefits a ton from keeping the IP address fresh.
So I guess, in a sense, I’m grateful that enough people are paying for ~nothing to make the service pretty great.
However, bandwidth and latency on TOR suck, and in many cases the endpoint IPs are blacklisted to hell due to abuse. A VPN is a nice middle ground where your can put another entity between yourself and your traffic, which is valuable against most opportunist adversaries. If a TLA wants me and can get a warrant, not even TOR will save me, but a VPN keeps the ISP from selling my traffic and the media trolls from sending me grumpy letters because the neighbors keep using my wifi to watch free content.
There is no such guarantee AFAIK, as long as a bad actor controls all the nodes in YOUR route, they can deanonymize you.
[1] https://en.wikipedia.org/wiki/Online_Certificate_Status_Prot...
Getting around blocks or monitoring on networks like work WiFi. No need to tell my work I'm on Indeed, and for a little while they seemed to block my email provider (Proton) and reading my email is handy to be able to do.
For use as a network tool. For example, I was recently helping my brother set up a website, and with port forwarding he was able to really easily VNC into my VM I was working on it with.
VPNs can also be handy for the 'slightly suspicious stuff' that's not illegal. You know, things like an internet search about something you saw on TV or were just curious about that's not illegal to research, but you're worried it could be a suspicious search. Or maybe I want to use wget to grab an offline archive of a website, but don't want to raise alarms and get my IP banned.
Privacy from your ISP and government. Even the UK now mandates ISPs collect data on user behaviour "just in-case" (snoopers charter), and it has been confirmed one of the big three mobile networks has implemented this, but not which. It's bad enough trying to put up with big tech.
At its core, a basic VPN is a trust shift service, nothing more. Do you trust your ISP less than an some anonymous shell company owned by Siberian forest dwellers? In many cases, the answer is no.
That being said, depending on where you are and if you choose the "right" VPN, the answer could be yes. Here are some reasons why you may want to use a good commercial VPN, which goes beyond just the ability to tunnel your traffic through a remote endpoint:
- You are in Russia, China, Iran or other countries with heavily censored Internet. Over 3 billion people live in such places, or nearly 50% of the world's population.
- If you don't live in such places, laws in certain US states criminalize certain behaviors. This will only get worse, even in "western democracies". Using a quality VPN service is much better than barebacking the Internet.
- You want your traffic to be "lost in the crowd", something you cannot achieve with your Digital Ocean droplet, no matter how well you configure it. Changing your IP does absolutely nothing, safe a few exceptions (piracy, or keeping an alter ego if your opsec is good)
- Additional features: server side DNS filtering / blocking. Yes you can use uBlock origin, but not on mobile, and not outside the browser. Yes you can run Pi-Hole, and setup WG tunnels to your homelab. 99% of people won't.
- Advanced features: Companion browser extensions that block ads, trackers, malicious domains, mess with your browser settings to reduce chances of fingerprinting. Yes you can install 5+ different extensions to do that. Most people won't.
TLDR; If you're an elite haxor, you can do everything yourself. You will spend time, and money doing so. Most people will not bother or not be able to do these things, and a quality commercial VPN service can check a lot of the boxes I mentioned above. Just avoid the ones that advertise heavily, those are marketing / snakeoil sales companies, as the author suggested.
VPNs also usually do ad blocking, and some limited malware scanning.
On privacy, there are many situations where a private IP address may be desirable, some of which mentioned in this post. VPN hides the traffic from the ISP, but also the user from the destination. On the latter, for instance, the websites could log IPs and that information could be sold or leak in the future.
Exponentially? Can we see the data on that. Perhaps this word as used here is just a figure of speech.
"Tor Browser uses uncountable techniques that prevent tracking your browser."
Tor Browser has a number of popular browser "features" removed/disabled by default. As such the browser user does not need to do anything, no fiddling with poorly-documented options via about:config, user.js or whatever. IMHO, modifications like these would be useful even when not submitting requests through the Tor network. The question I have is why is there not a Firefox version that is like Tor Browser but without the Tor integration.
Perhaps the answer is because Mozilla is trying to perpetuate online ads, i.e., surveillance, data collection and tracking, as a "business model", such as the model adopted by Google. Mozilla is wholly dependant on financial support from Google. If Google's online ads business fails, Mozilla is out of options.
NB. I would never use Tor Browser. I am a text-only browser user and I prefer netcat and other TCP clients through one or more localhost-bound proxies for making HTTP requests. When I experiment with Tor, I use tor binary I compiled myself without relay module. In front of the tor SOCKS proxy, I use socat for requests to .onion sites that use HTTPS and tinyproxy for requests to .onion sites that use HTTP.^1
1. If anyone can explain why some .onion sites use HTTPS instead of HTTP, I would be interested to know the anwser. AFAICT, most .onion sites use HTTP.
Tor reminds me of the early public internet. Submitting a request like an Archie search and having to wait seconds for a response. Also the number of .onion sites is relatively small. I like the uniformity of .onion addresses and the general absence of "vanity" names. And the search engine for it reminds me of the web pre-Google: like AltaVista, thousands of results are accessible. That's the way I like it. None of this collecting data from searches and trying to "guess" what someone is searching for (as Google does).
- In Hotel, Airport. VPN can be used to bypass DNS based captive portal. - Yes true hopefully all website are encrypted with ssl, but still an attacker can easily fingerprint me through my internet usage, even though everything is ssl, there are still a lot of plain-text data flying around. So yeah, ProtonVPN, ftw.
So an "attacker" can figure out that you browse hacker news. Who cares?
But as for an attacker - maybe they discover something about you from one compromised service and correlate it to something else. Or maybe they extort you in some way. Who knows - there are many possibilities and it’s safer to reduce exposure.
Can use Torrent on VPN.
But yes, VPN advertising preys on people's unfounded fears.
same goes for watching Netflix from other countries, VPN are badically useless
But this is a BBC specific problem, most of the other European geofencing is quite weak and getting access to most other public broadcasters works just fine with a proper VPN.
:pondering emoji face
The US doesn't have reasonable privacy laws and I don't trust my VPN to not sell my browsing history to anybody with two pennies to rub together.
Yeah, I can (and do) use DNS over HTTP, but the ISP still knows what IPs I am connecting too. It's trivial to find out what domains are hosted there.
I play Final Fantasy XIV, an MMORPG - apparently, supposedly, the peering connection between AT&T and FFXIV's US ISP (NTT) was particularly bad. [1]
This manifested as pretty severe connection issues for AT&T customers playing FFXIV. Except, it was a chronic issue that would only flare up when that particular connection point was stressed.
One of the easiest workarounds? Hop on a VPN.
That's one example. Anecdotally, I have a few friends that toggle VPNs on and off when they encounter "network weather" in games. Personally, I'm a bit skeptical they're truly so often mitigating problems by toggling a VPN (instead of, say, just waiting a couple minutes), but hey, they swear by it.
[1]: https://forum.square-enix.com/ffxiv/threads/482155-Bad-lag-a...
> OK, but what about my DNS and TLS records being exposed to everyone so they can follow what I am doing? In a public place, anyone can look at your display already. Or, if you are worried about your ISP selling your traffic data, there are better options for you. Use DNS over HTTPS, for example. You have to use a VPN provider you trust better than your ISP/Wi-Fi provider. Also, as Encrypted Client Hello is about to start soon, it will be exponentially harder for eavesdroppers to figure out which sites you are trying to visit.
Encrypting DNS is a nice start, but the ISP can still see the IPs you're connecting to, which is enough for a lot of sites, and Encrypted Client Hello is about to start soon is a lot of words to say "today, your ISP can see the domain on every HTTPS connection you make". So no, distrusting my ISP is absolutely a compelling reason to use a VPN. (And lest you say "but do they actually spy on you?", I literally got a letter from AT&T informing me that they were going to start monetizing information mined from my connections.)
> But if you care about privacy, the answer is always ToR, ToR browser or Tails, and never VPN. Except in cases where you first have to hide your ToR usage using a VPN, which is a rare exception among users. If you don’t understand why you would need that, you probably don’t need that complexity. Tor Browser uses uncountable techniques that prevent tracking your browser. And if your privacy is essential against local Wi-Fi attackers, your ISP, why is the ad industry not in scope? Adblockers are only half the solution against tracking.
I mean, yeah I also use uBlock, but TOR makes harsher tradeoffs than are necessarily needed (multiple hops is really safe but also really slow). I'm just hiding from my ISP's prying eyes; I explicitly don't include the NSA in my threat models and lesser methods are Good Enough™ for websites tracking me.
There are some experimental servers for it, but basically not supported anywhere.
Instead of police kicking down ISP doors they kick down VPN runners doors.
Sorta ambivalent towards them overall. Just don’t have a big use for them
1. it's more expensive than commercial VPNs, which you can often get for <$3/month, or even less with promos/cashback sites
2. you're limited to one region, which means you can't use it as effectively for geoblock evasion purposes.
3. you get less anonymity because you get a static ip that's assigned to you only, as opposed to a commercial VPN provider where you can connect to hundreds/thousands of servers each of which are used by probably hundreds of users.
There's a very, very easy way to solve this problem:
vpn_command ; ip link set ens160 down
... or whatever ... this way, if the VPN exits you are immediately bringing your network down. Very simple and robust.A 'network slug'[1] is an even more robust - and network-wide - mechanism for enforcing your VPN. If you are serious about avoiding misconfiguration or opsec failures you should have a network slug as a physical choke in your PHY.
[1] A "slug" is a layer-2 bridge, with no IP address configured, that still enforces a TCP/IP whitelist. So it does not "use" a hop on the network route, and you can't see the device, but as it bridges traffic it enforces a (very simple) ruleset:
Anyway is this comment a reference to the domain? I don't understand what you mean
There's no guarantee that VPN traffic isn't being decrypted and inspected
"just trust us, bro. look at our popsec influencer approvals, bro."
In an attempt to be edgy, their website was at:
triplew.dot.net.au
"triple w dot dot dot net dot au"
My take? Do a threat assessment, build a threat model, know your adversary be it your own ISP selling your data or protection against hostile state entities when traveling overseas. There are many valid uses for the various types of commercial VPN and instead of an objective look at these services the author walks in with an assumption that they are all the same and never provide value to their customers, then bends over backwards to attempt to make weak arguments against a vast category of service.