Why You Should Start Using a VPN
lifehacker.com
lifehacker.com
I feel pretty double about VPN as a solution for masking my online activities. My reasons for using a VPN break down into these (related) categories:
1. Security. I don't trust this network at all, such as unsecured wifi in coffeeshop.
2. Access. This network has draconian restrictions I need to get around, such as corporate proxy servers or country firewalls.
3. Privacy. It's none of this network's business what I'm doing.
4. Legal. I don't want to get in trouble here. Especially when traveling where I don't know the laws, but increasingly in my own country. Hell, the courts in NL haven't figured out if TPB is legal, how should I know?
VPN can solve many of these problems most of the time... but always using a VPN means that I have a single point of failure for all four of these.
If my VPN provider is compromised, shady, or coerced to turn over my data, I'm sunk. In that way using various internet connections at home/work/coffeeshop/mobile may be better.
For the single point of failure issue (which is also valid)... just setup two or more VPNs :) And, in an emergency, you can always fall back to the underlying connection.
If you use Linode to set up a VPN, Linode knows your personal and Linode IP, knows when you access their network, and knows your name and billing info. If compelling by warrant they will turn that over to law enforcement.
Way better than a SSH tunnel (check the readme) and you don't need to have a VPN server on the remote server, just ssh access. Supports both Linux/OSX, been using it for nearly one year without issues.
Just a correction: you need ssh and python, since it launches a daemon on the server (it uses a clever way of doing that, by packing and pushing all the necessary code over the SSH connection to the Python interpreter).
It's like a VPN, since it can forward every port on an entire network, not just ports you specify. Conveniently, it lets you use the "real" IP addresses of each host rather than faking port numbers on localhost.
On the other hand, the way it works is more like ssh port forwarding than a VPN. Normally, a VPN forwards your data one packet at a time, and doesn't care about individual connections; ie. it's "stateless" with respect to the traffic. sshuttle is the opposite of stateless; it tracks every single connection.
You could compare sshuttle to something like the old Slirp program, which was a userspace TCP/IP implementation that did something similar. But it operated on a packet-by-packet basis on the client side, reassembling the packets on the server side. That worked okay back in the "real live serial port" days, because serial ports had predictable latency and buffering.
But you can't safely just forward TCP packets over a TCP session (like ssh), because TCP's performance depends fundamentally on packet loss; it must experience packet loss in order to know when to slow down! At the same time, the outer TCP session (ssh, in this case) is a reliable transport, which means that what you forward through the tunnel never experiences packet loss. The ssh session itself experiences packet loss, of course, but TCP fixes it up and ssh (and thus you) never know the difference. But neither does your inner TCP session, and extremely screwy performance ensues.
sshuttle assembles the TCP stream locally, multiplexes it statefully over an ssh session, and disassembles it back into packets at the other end. So it never ends up doing TCP-over-TCP. It's just data-over-TCP, which is safe."
"ssh -D" is closer to a proxy server:
-D [bind_address:]port
Specifies a local "dynamic" application-level port forwarding.
This works by allocating a socket to listen to port on the local
side, optionally bound to the specified bind_address. Whenever a
connection is made to this port, the connection is forwarded over
the secure channel, and the application protocol is then used to
determine where to connect to from the remote machine. Currently
the SOCKS4 and SOCKS5 protocols are supported, and ssh will act
as a SOCKS server. Only root can forward privileged ports.
Dynamic port forwardings can also be specified in the configura-
tion file.
On the other hand, sshuttle is closer to a VPN connection. If you're confused about the difference between a proxy and a VPN, then I suggest you hit up Wikipedia and do some reading.Of course, OpenSSH itself provides VPN capability too without the need for sshuttle but it's harder to set up.
I suppose the most practical purpose for sshuttle is for shell accounts on a box you don't own, if you need to do random transport-level stuff to remote hosts through an intermediary and you want to use a client on your local host. So basically NMap if your shell doesn't support it and you can't copy-and-run 3rd-party binaries. I'd be interested to see how well sshuttle performs under an intense NMap scan.
It also has a -x option that let you exclude local subnets from the forwarding, e.g. -x 192.168.0.0/24,
very wrong. It's not really much. It's probably just limiting your possible bandwidth.
If somebody wants to catch you, it's just one additional step to get to you (via the VPN provider).
I had some dodgy stuff going on over at an amazon free tier, including; socks proxy, ping tunnel, Metasploit, semi hidden tor end-node, ctorrent, and a few other things. I also linked a 25$ visa card from a convenience store, so very limited traceability.
All they did was bill me for the bandwidth.
If they don't log that then it makes finding downloaders much harder.
Nevertheless, I can't think of a way to get internet access where you don't have to trust someone at some point (except perhaps for Tor).
These consumer-oriented VPN services marketing to bittorrent users seem kind of sketchy to me.
You probably shouldn't. There are most likely laws against your ISP from listening in on your traffic, not for your VPN. If the government wants to listen in it doesn't matter, your VPN service is forced to cooperate anyway so you haven't gained anything.
If I'd use a VPN I'd make sure to use one that is in another country, probably making it a bit harder to connect the VPN and ISP to you that way - but hardly bulletproof.
Of course, the providers there could be lying about not keeping logs, but it's interesting none the less.
How many VPN's companies has deals with content networks? How many ISP has a content network deal?
How many VPN's has has a past of cooperative with government surveillance? How many ISP has cooperated with police and government secret police?
How many VPN's has lobbyist in government. How many ISP's has lobbyists in government?
An ISP has all the reasons to snoop at the traffic of their users, and they commonly do. Their core product is advertised as an service that provides Internet connectivity. Their core product is thus not effected by much if they get caught snooping on their users. A VPN has few reasons to snoop (QoS is the major exception), and their core product is to provide privacy. If they are caught snooping, their core service of providing privacy suffers.
Thus, yes. I trust more a VPN provider than an ISP.
ISPs, on the other hand, provide a different service and privacy is merely an additional consideration. It's not their main reason to exist.
Not even that. Look into CALEA - a law which, summarized briefly, requires that ISP gear have backdoors for law enforcement packet capture.
There's a reason you don't see anonymous ISP's around in the USA; the laws as written explicitly prevent them from existing in any meaningful capacity.
Yeah, but given the lack of history, openness, and reputation a lot of the VPN providers have, it seems to me that a provider could just "pick up and move": start a new company with a new name and new IPs and what not, and just do it all over again.
The VPN account is directly tied to you by your payment details. Also most VPN services that claim to "not keep any logs whatsoever" are just a 3 page website with not much information. Maybe that's safer since they are low profile, or maybe it isn't? I honestly have no idea and I wish I did.
It feels like your just trusting some random person to not mess with you.
I guess my problem is more that you are trusting an overall unknown entity with your real ip, which is only one step away from your real info for someone who is able to compel that information from the VPN provider in the first place.
Buying bitcoins anonymously is very difficult due to money laundering laws. Spending them anonymously is not "simple" either.
Your best bet would be to mine them yourself and then pay over a public wifi with a throw-away laptop.
But really, cash in an envelope is less error-prone. Just don't leave your DNA-sample on it.
- I mine
- you can buy them to your name, and then after a few transfers/transactions it would take the collaboration of an army of disparate users worldwide to determine where did the coins come from
- #bitcoin-otc in freenode
Although I do agree that's not easy to grasp for outsiders. It takes some time to get familiar with the best options. There's no way in hell they can connect your id with your coins (or a subset of it you keep for stuff like this) if you are moderately careful. Even satoshi-dice does the trick.
Sounds exactly like money laundering to me, even if there isn't malicious intent. I'm genuinely surprised the government hasn't done much to try killing off bitcoin, even with it being (relatively speaking) a tiny fringe movement.
What muyuu is talking about is akin to wiping your dollar notes, to remove any dna evidence that you ever touched them
Conventional banking assigns each new identity that enters through the door an account, to access that account you prove your identity. All transactions are kept confidential and in-house.
Bitcoin works by giving everyone an account and forgoing any identification. If you own the private key to the account you are the account holder. Next, all transactions are publicized. Since no one has ID information tied to their Bitcoin wallet, it doesn't matter if transactions are publicized.
Now here is how you get found out. If you use a service such as Mt. Gox which requires you to tie your identification to your Mt. Gox account, any bitcoins you send from Mt. Gox can be traced. So, when you corrupt bitcoins by using a site that has id on you, you lose your anonymity.
OpenVPN is all you need and then you're good to go.
The main selling point of a VPN is to avoid suffering your ISPs craptastic network. It isn't anonymity.
If you want true anonymity, use tor.
Of course, your VPN can still _choose_ to log your IP address (e.g. if they're acting as a honeypot), so at some point you have to trust someone (perhaps by looking at whether there have been news reports of that VPN handing over data to other entities, ie. don't use HideMyAss).
[..] all of your internet communication is encrypted and secured from eavesdropping.
The most important thing you need to know about a VPN: It secures your computer's internet connection to guarantee that all of the data you're sending and receiving is encrypted and secured from prying eyes.
Eh.. No? It secures the data from you to the VPN provider. After that, it's just as open and unencrypted as it would otherwise be.
Sure, it probably helps protect your data from the local network & your ISP, and gives you extra anonymity. But after leaving the provider, the traffic would be in the clear, and if you use the same connection to log-in to your facebook, the anonymity will go out the window.
[Edit] not protected/still at risk.
It really needs to be VPN, plus separate browser, plus separate browser fingerprint, plus proper failover.
But that is much harder to sell/explain to users than something you just pay $6 a month for and forget about
If you play games online, you want a VPN that is either close to you, or close to the game servers, or which traffic is highly prioritized. If you are lucky, you might increase your latency going through a vpn than if you went without. It sound illogical, but routing is not equal for all, and traffic might be boosted if your VPN's network has higher priority than your ISP.
Going from europe to US, I found that different AS had latency up to 200-300 MS in difference, and this does not take into account the stability of it. One net had a average of 80ms which only differentiated with 50m over time (the Swedish national university ISP). The Swedish ISP's that offer services to the public almost all uses a other backbone network than the university ISP, and that has an average of 250 ms to US, and which latency goes up and down between 150-800ms.
Many ISP's serve requested pages from massive caches. Although provider caching can improve performance in some cases as well as reduce bandwidth costs for the ISP, it can often result in stale information being passed to the client (you!).
Another common speed/cost improvement for ISP's is serving degraded images from their cache -- by recompressing images (jpg) at a higher compression ratio, the file size is reduced at the expense of degrading the image quality. This is extremely common on mobile networks, but it is becoming more common with land-based providers. In most cases, you'll never notice, since you'll just assume it's a crappy image from the original server. On the other hand, if you do any work with images, then you could be stuffed by the modified images being delivered to you.
Having a consistent endpoint provided by a VPN provider can also be a real advantage. For example, if you're doing checking, testing or trouble shooting, against a system on the `net, then knowing what traffic is yours in the logs can be real helpful. With dynamic IP addressing, your endpoint (public IP) always changes. When you're using a VPN and helping out a friend with something as trivial as reporting bugs, you can tell them that the funky traffic from xxx.example.com is just you running some tests. Even if the site owner isn't your best friend or anyone you really know, it's great when reporting bugs to say, "Hey pg, my traffic is always coming from la.tunnelr.com" so it's easier for them to find it in their logs.
If you need to do your own pen testing across the `net and your ISP does deep packet inspection (DPI) and egress filtering, then once again, you're stuffed without a VPN or unfiltered remote host. Of course, you need to be on good terms with your VPN provider and let them know in advance that you'll be sending some dodgy traffic over their network, but that's not a big deal most of the time.
If you participated in the recent Stripe.com Capture The Flag contest without using a VPN or staged connection (ssh), then you really didn't put very much thought into what could happen if some malicious person rooted the game server and attacked the game participants. Sure, the Stripe folks are fantastic, and they keep an eye on things, but no person has sub-microsecond response times. ;)
Also, some ISP's have bandwidth caps and automated thresholds for reducing connection performance, but they usually have a stipulation in their contract excluding VPN bandwidth from the cap/limit accounting. The reason is simple; business customers would use another ISP if the caps/limits interfered with doing work, and most (sane) businesses provide a company VPN to their employees for remote work.
I use http://www.tunnelr.com almost all of the time simply because it makes my mobile (EVDO VerizonWireless) connection a lot more consistent and reliable on UNIX (OpenBSD). A lot of mobile ISP's don't support UNIX at all, and they expect you to run inane and unaudited software ("VZAccess" which is actually just rebranded stuff from SmithMicro). Having a SSH connection present prevents some of the (intentional) oddities of mobile connections (e.g. "pausing" the link/connection).
There are plenty of good reasons to use a VPN that don't involve bittorrent or similar. The best reason of all is if your ISP does not provide all of the exact details of their filtering and caching methods --of course, none do.
T-Mobile in the UK does this. They also re-write the HTML. This line is added after the first <html> - <script src="http://1.2.3.8/bmi-int-js/bmi.js language="javascript">
Images come from <img src="http://1.2.3.11/bmi/ycombinator.com/images/s.gif
And they add an alt message to tell you how to update the images to the original images. Which is annoying if the alt originally contained useful information. (The original alt comes back if you update the images.)
I'm in the UK. Having images served from 1.2.3.x is suboptimal.
I ask since 1.0.0.0/8 is APNIC and 1.2.3.0/24 is the APNIC "Debogon" project. For notes, a "bogon" is an supposedly unroutable address, or more accurately, an address that you shouldn't see in use.
1.2.3.8, 1.2.3.13, etc. I'm in a coffee shop at the moment, but when I get back I'll try and get a list of the IPs that are used. (The last digit is always quite small though.)
Address space that hasn't been allocated by any of the RIR's (Regional Internet Registries like APNIC, RIPE, ...) are sometimes used without permission, and usually for nefarious purposes. These are also considered bogons since you should never see those addresses in use.
When you see a bogon, something is definitely wrong. It could be your service provider is misusing address space that hasn't been allocated to it, or it could be something far worse (malware, compromised network routers, ...).
The "Debogon Projects" and "Bogon Monitoring" are run by the various RIR's to find those who are squatting on misued address space, and also to get firewall sysadmins to no longer block the unused ranges. Usually, following the allocation lists of the RIR's is sufficient, but some folks don't update their firewall rules as often as they should.
The urls have the same 'bmi' stuff mentioned above, apparently they are using a similar implementation.
I was mostly trying to confirm that it was the carriers and not malware or whatever.
When a network/ISP misuses unallocated address space by routing the traffic to something internal, this prevents the inside of the network/ISP from reaching those addresses normally. Unallocated address space can be allocated by the RIR's at any time, so misuse of unallocated address space results in parts of the Internet unreachable.
If some huge networks/ISP's (Comcast, Verizon, Sprint, ...) decided to misuse the address block allocated to you for some internal purpose, you'd be rightfully upset since it would prevent all users of those ISP's from reaching your service/servers. Now let's assume you're a new company and just got a new allocation of addresses from the RIR only to find out the users of major ISP's can't reach your service because the ISP's have already misused your address block for something internal on their networks. Yep, you'd be livid, and livid with good reason.
If you put a lot of work into your misuse of unallocated address space, all that effort could turn out to be wasted a few hours later when the block you misused gets allocated. To reach the newly allocated block, you'd need to redo all that work over again, correctly.
This is T-Mobile mangling stuff. They do some other things which are annoying, but not Internet breaking. It's a sub-optimal Internet experience, but pretty handy for what I want to do.
What damage could an attacker cause? (And how would a VPN help?)
I remember using hotspotshield and torproject.org in the past but they always made things so slow it wasn't worth using. Maybe those were just the free/cheap services.
I installed TunnelBlick on my mac to be the VPN client; it was a nice interface to setup for the client side, and handles things like DNS flushing automatically.
I'm also going to setup ssh servers on 80 and 443 for times when access to ports is restricted by the wifi provider.
The local community college blocks all sorts of websites with nannyware on the gateway. I tried changing DNS to googles: no change. I tried a few other things as well, no change. Looked for open proxies: "PROXY search prohibited".
What they didnt stop was looking for VPSes. I found one for 20$ a year as well. Loaded up immediately upon payment into a ubuntu 12.04 (rh, slackware, ubuntu, or debian: i dont care). I got a socks proxy running on its localhost, and then ssh tunnelled to the proxy. And there I went.
Their current site: http://flashping.com/en/
Website archive: http://web.archive.org/web/20100108103341/http://www.flashpi...
Personally, I find "Cloak" (https://www.getcloak.com/) to be a fantastic app that works on my Mac and iOS devices. It's super-simple to get setup and running, and very cheap, too.
If you want to give it a try by yourself, I recommend the following articles (doesn't seem that complicated but trust me, you can be stuck on a bug for hours!): http://library.linode.com/networking/openvpn/ubuntu-10.10-ma... http://blog.riobard.com/2011/11/12/pptp-vpn-on-ubuntu. I can help with minor problems on Skype as well (o-lalonde).
I have tried PPTP Server (simpler than Open VPN) but i avoid it because vulnerabilities.
Plus, windows and OSX have native L2TP/IPsec support.
https://play.google.com/store/apps/details?id=de.blinkt.open...
This presents a nice frontend to OpenVPN and doesn't need root.
Key points from the description are "Uses the new VPNService API that requires neither Jailbreak nor root on your Telephone." & "Only tun mode support (Sorry no tap, with Android 4.0 only tun can be supported)."
1. Don't do anything the state considers naughty. I suggest you kill yourslf now if you consider this viable.
2. Steal someone else's WiFi and deal with the moral consequences. You can do this by finding a "VendorA7E4B4" lookalike SSID (default configuration) and using the password calculator here: http://www.nickkusters.com/Services/SpeedTouch/Lookup - I only know of this as I had to lock my router down due to unauthorised access.
3. Use a VPN and risk being logged or falling foul of RIPA.
4. Use a dead drop http://deaddrops.com/ and risk being bagged at site.
5. Use SSH tunnels + proxy and risk misconfiguration + logging and RIPA.
6. Use paper or sneaker net and risk stop+search and RIPA.
Welcome to the machine.
To make something like that more user friendly though you could just install VPN software like OpenVPN on your VPS. This also ensures things like DNS queries are sent over the VPN so they can't be intercepted on their way to the server.
Of course this assumes you trust your VPS provider, at least more than your ISP.
[1] Although I can't think of any suitable alternative countries – I mean, most countries are either fairly friendly with the US, or fairly corrupt, or both (or even fairly corrupt and fairly unfriendly with the US and currently surrounded by big US military bases on all sides). Perhaps the Principality of Sealand?
http://www.slashgeek.net/2012/06/15/how-to-be-completely-ano...
For using bit torrent or other file sharing in a private, anonymous session, I would use I2P. In fact, they welcome it.
I'm not sure why a lot people put VPN's up on a pedestal. VPN's are useful for other things but I wouldn't rely on them for 100% or even 90% privacy against a foe that _really_ wants to know who you are.
I2P, my friends.
You could maybe run a server behind the VPN, but many don't give you a dedicated IP but use NAT. It could be that you're allowed to open ports and redirect them to you, but whether this is possible differs per provider. It's not usually part of the normal package.
With a VPN, you simply connect, and you can access any services on any ports. Additionally, I think UDP is supported, which is a bit tricky with ssh tunneling.
Sigh.