How Long Before VPNs Become Illegal?
torrentfreak.com
torrentfreak.com
That being said, I expect various people to continue to obfuscate and make it confusing. At some point I expect a 'VaaS' type service to be announced with pretty compelling economics, and it will be impossible to tell that the service provides access to certain third parties.
Phil Zimmerman is doing his part with Silent Circle. That too is looking to force the question.
Several of them are even from the last ten years, since the Internet has indeed raised many questions.
edit: I forgot about this[1], so apparently it already exists!
[1]: http://news.cnet.com/8301-31921_3-57412225-281/this-internet...
Perhaps there's an opportunity for a company based in Switzerland to run a private TOR network for obfuscation with guaranteed bandwidth. Private TOR network has its own problems though. You need a large number of users to anonymize each other's data, and the block of assigned IPs can be treated as a single entity and blocked / rerouted as a result.
Admittedly, it is still complicated to set-up your existing web-browser to use it, and latency is still a huge issue - not helped by the limited number of exit nodes.
At Blekko we've been very aggressive at building privacy in from the start, and we talk about that with folks all the time.
When I was at Sun I was deeply involved in doing security work both in the kernel and on the network. There were lots of places to improve.
In both the Blekko and Sun cases the 'better' version doesn't seem to carry a lot of retail influence. Which is to say if you offer a consumer a choice, the 'secure' one which costs a bit more (either in cash or in complexity) or the 'insecure' one which is cheaper, not enough people pick 'secure' to make the investment pay off. You have to pay for your investment somehow, and the fewer people who are willing to pay for a feature, and the more it costs to implement, means a higher per-consumer price for that feature. Security often pushed that cost threshold over the limit into 'non-business'.
When we were discussing implementing the best privacy policy and technology in any search engine I was pretty clear that having the 'best privacy policy of any search engine' was a nice add-on feature but you couldn't base your business on it. We had to have a search engine that was just as good or better than the competition, and the fact that 'oh by the way its got the best privacy policy' could be icing on the cake, but for the majority of people it would not be their reason for using it.
You can see this sort of effect in lots of different communities.
and of course Phil Zimmerman is giving it a go:
[ though all of that ex-SEAL presence among the founders sets off some of my paranoid alarms about US government backdoors ]
I certainly hope there's enough demand to sustain privacy protection services…but I'm not optimistic. I've never had much luck convincing "regular" people that privacy concerns are worth abandoning the convenience/entertainment of things like Google and Facebook.
(I'm one of the three guys behind GetCloak.com. We're always looking for feedback, positive or negative -- and we're easy to find. Cheers! ;-)
Eternal vigilance, etc., etc.
But I can also see America forcing their will on other countries and forcing them to keep detailed logs too (let's face it, the UK is right there with America)
Countries like the one that hosts TPB may hold out as long as possible, but eventually the rest of the "internet world" could just ban those IPs or whatever. (just like they are banning the TPB IP now).
What I'm saying is, I can see the day where it's illegal or extremely difficult to use a VPN anonymously, from any country.
And as for corporate/government VPN users, maybe this will be an excuse to introduce a VPN "license" for those who will be allowed to use them.
But now that you mention it, I could see a situation where domestic VPN providers are forced to log user data (or be on the hook for copyright violations when the VPN is used by employees) and ISPs are strong-armed into blacklisting overseas VPN providers. That's actually kind of scary.
Betteridge's Law of Headlines: "Any headline which ends in a question mark can be answered by the word 'no'".
Q: How Long Before VPNs Become Illegal?
A: No.
Doesn't flow too well here ;)Q: How long until they ban VPNs?
A: No. Just no.
A: No.
Doesn't really fit.
For those that don't know, SSL/TLS based VPN's do exist, and the most common implementation is OpenVPN. It's based on the same OpenSSL (library) code that your web browser is (most likely) using.
The SSL/TLS based VPN's use "only" 128 to 160 bit encryption, and if your tin foil hat is on tight enough to cut off your circulation, then this fact makes you nervous. You can run OpenVPN via UDP over a "tun" interface (OSI Layer 3) or even a "tap" interface (OSI Layer 2), and compared to many VPN-ish alternatives, it's pretty fast in my tests.
The other common light-weight approach to VPN's is using PPTP (Point to Point Tunneling Protocol). I have NOT (recently) studied the crypto employed in PPTP implementations, but I'd guess it's nearly on par with SSL/TLS. It's been eons since I've messed with PPTP, so I'm going to keep my (outdated) opinions mostly to myself. The most fair thing to say is there is (can be) some crypto involved, and it can be pretty fast.
Though I'm currently working on some OpenVPN stuff for firends, I personally prefer the more (ahem) sophisticated (read: difficult and complicated) VPN solutions based on SSH, or better, IPSec. They are a lot more work, but they tend to be more robust and more resistant (when done properly --and any VPN done wrong is just a false sense of security). The down-side with SSH based tunnels is there is a greater performance overhead with TCP based connections, and hence, you get reduced throughput. IPSec is better, but it's even more difficult to get right.
For a lot of testing I use Tunnelr.com. They offer both OpenVPN and SSH (SOCKS) based VPN's for a cheap price.
It's kind of sad that privacy is being equated with piracy, but the "lump it altogether" folks are idiots. There are actually lots of extremely good (and legal) reasons to use both VPN's and other types of secure connections... --Every time you buy something from Amazon or similar, you're most likely using a secure connection.
The original article has a link to:
https://torrentfreak.com/which-vpn-providers-really-take-ano...
Sadly, the above listing of data retention policies of various VPN providers is already out of date. For example, iPredator (from the folks at ThePirateBay) are now logging IP address in accordance with the EU data retention laws going into effect in Sweden.
https://blog.ipredator.se/2012/03/the-question-of-data-reten...
The iPredator/TPB blog post is intentionally distracting and painfully vague on details about the logging they've implemented to comply with the law. (NOTE: I stumbled on the poorly named iPredator service of TPB because they offer PPTP based VPN's.)
The same may or may not be true of other EU based services listed in the TorrentFreak link above. See the following for reasonably updated info:
https://wiki.vorratsdatenspeicherung.de/Transposition
If you do any work on Computer Vision (CV) or other types of image/video analysis (Machine Learning) based on data downloaded from the Internet, you need to be extremely careful. When you have scripts/programs/spiders downloading (image/video) data for you, your never know what "kind" of data is on the other end of any link, and that data may very well be illegal! --It sucks, but this is the reality everyone lives with. If you take a step back, you'll realize how normal browsing of the Internet is really no different than running your own spider to collect data. Every link you click is a potential violation of some law.
Even if a link is on/to a reputable site and ends with ".html", it could still be a link to JPG image of kiddie porn. You've just broken the law, even though you had no intention of breaking the law, and had no intention of being in possession of kiddie porn.
(NOTE: Sending an image file when a HTML file is expected is possible by manipulating the MIME type sent by the web server for the ".html" extension to tell the browser it is a JPEG image. Of course, another way to do it is redirection, since by default, most browsers follow most forms of redirection.)
Even if you had an automated agent (web spider) program following links, it is YOUR connection that is logged as accessing the image.
If the kiddie porn image was part of some sting operation being run by law enforcement, then you're stuffed.
This issue of "not knowing what you're accessing" is one of the long standing and underlying flaws in the design of the Internet, so you can be certain it won't be fixed any time soon.
So, for example if you buy a trunk at an estate sale that contains cocaine, open it realize it's cocaine, then call the cops. You did not break the law even though you where in possession of cocaine which is illegal. Work though some variations of this and you could literally be walking down the street with a suitcase full of cocaine and not actually be breaking the law while doing so.
PS: There are a relatively small number of strict liability crimes where intent is considered irrelevant. But, extenuating circumstances still come into play.
PPTP* is broken, and should only be used for anonymisation, never to ensure confidentiality or integrity of the data in the tunnel. PPTPs encryption scheme is MPPE which is based on RC4, and tunnel traffic can be decrypted in a matter of minutes unless the key is sufficiently strong. This is almost never the case since the password is the only thing used for key material. IMHO this is pretty much irrelevant anyway since you can do a MITM attack to hijack the connection or downgrade the session to not use encryption. So basically the encryption doesn´t matter.
* I´m told the exception would be to use PPTP with EAP-TLS which is certificate-based. However I don´t have any experience setting that up, so I´m staying quiet on that one.
As for data retention, I don´t see how VPN providers have any obligation to log. And even if they did perhaps a little bit of collective civil disobedience might be in order?
Full disclosure: I run a VPN service.
As for firewalls, as long as they´re not doing DPI (Deep Packet Inspection) you can just run the VPN on the right ports. In addition to the standard ports, we run our VPNs on tcp/80, tcp/443, udp/53 among others. That takes care of most firewalls.
In order to use VPNs on my Mac and on my mobile devices, I have to pay for two separate VPN services, which is a deal breaker.
I would much rather use a service that supports both OpenVPN and PPTP, with a bunch of disclaimers. I understand the tradeoff and I am willing to make it.
You were a bit vague when simply stating "mobile device" but if memory serves me, Both OpenVPN and OpenSSH will work on some "mobile" platforms (Android, iOS, etc.). I've never tried it personally, and I don't know what kind of "mobile device" you use, so for your specific case, I could very well be wrong.
Using OpenSSH via SOCKS support in applications or by using a SOCKS-Wrapper like "DSOCKS" by Dug Song or similar ("Sockify for windiws, etc), take more effort than running OpenVPN. It might take more effort, but if you don't mind the hassle, it's most likely more secure than the common alternatives (OpenVPN, PPTP, etc.). The only thing better than OpenSSH (in my opinion) would be using a correctly configured IPSec implementation. But getting IPSec right makes OpenSSH look very easy.
You might want to note how in this discussion both Fredrik Strömberg (kfreds -runs the Mullvad VPN service) and myself have intentionally tried to avoid disparaging PPTP. Whether good or bad, a lot of people like PPTP for various reasons, and a lot of VPN services offer it as an option. Other than for the sake of curiosity, learning, and experimentation, I would never use PPTP. When it comes to both security and privacy, PPTP has many known problems and some VPN service providers refuse to support it due to these issues.
Trying to be fair to those who like PPTP is being a bit too generous since the security and privacy of people is at stake. None the less, development work is still being done on PPTP, and it has supposedly made some improvements over the years.
EDIT: I misspelt Fredrik Strömberg's name. Sorry. (sigh).
So, I can either pay for tunnelr.com and have zero VPN support on my iOS devices, pay for two separate services, or switch to a provider that supports both. I suggested that while it's fine to tell people not to use PPTP, some of us will still want to use it, because it is better than nothing at all (please don't make me argue that it really is better than no VPN at all).
Here's a statement of fact: at present, the only reason tunnelr.com does not get my money is because it does not support PPTP alongside OpenVPN.
No argument at all from me. ;)
What you've said seems blatantly pragmatic to me. --It's sad how so much of HN these days is pointless arguments. Sure, it's good that we're accurate in what we say, and fair about it, but every word we utter should not lead to an argument. Oh well...
Anyhow, I did find one SSH app for iOS (iPad) when I last looked, but I still agree; Whether or not it's possible to get other apps to play well with SOCKS would be a real headache.
I'm not a real iOS user, but I have helped my parents with their iPad a bit. I'm curious how much of a pain it is on iOS to get IPSec set up properly?
IPSec can be really tricky to set up properly, but once you've got it right, it's the very best VPN solution. A lot of companies have tried to make IPSec more "usable" and "user-friendly" on desktops, but it's still an unwanted pain for users. For admins, testing it for leaks is often a convoluted nightmare. The thought of attempting both the setup and testing on a mobile device (iOS/Android) makes me shudder.
Err, yeah. That's not a very convincing argument.
In summary, it's my recollection that this is already being pushed for, in and by the U.S. government and/or its lobbyist "masters". And they don't have to outlaw all VPN connections -- just establish either legal justification or extra-judicial powers to harass and/or arrest you if you can't qualify and justify your use of a VPN to their satisfaction.
Keep in mind: They don't have to apply such powers universally. Just enough to provide the desired effect.
Edit: Only reason why I don't use tor yet is that everytime I tried, speed was slow. Thanks for the opinions on the question.
Its also an issue that most exit nodes restrict their outbound speed and ports they route outward. Without restricting the speed in my tor configuration my exit node holds a constant 10/MBs all day even with only common ports open. Once you stop restricting ports you'll be getting multiple cease-and-desist notices within a matter of days since all your traffic will be absorbed by torrents.
Someone will likely come up with an equally/more secure option before Tor gets all that close to your average user's connection speed.