Don't Get Pwned on Public WiFi: Use Your Own VPN
tinfoilsecurity.com
tinfoilsecurity.com
- I don't recommend rolling your own on EC2: pick a VPN with a good reputation and a policy of not retaining logs. See: http://torrentfreak.com/vpn-services-that-take-your-anonymit... (you don't have to use torrents to need a VPN, btw!!)
- I recommend using a Debian VM w/ OpenVPN for your private traffic. That way, 'am I using my VM?' is a quick test for whether your traffic is private or public.
- I can't stress this enough: _be sure to firewall your VM from any traffic not to your VPN provider_. If OpenVPN drops its connection, it will fallback to sending packets normally! At least if you firewall, your connection will just die, instead of potentially sending private traffic in the clear. The article doesn't mention this, and it should.
- Be sure not to log in to your usual services on your VPN, or there is a possibility that someone can connect your real traffic and your VPN traffic. I use LastPass with random passwords to manage all of my accounts, so I solve this problem by simply not installing LastPass on my VM, which makes logging in a very deliberate action on my VM.
But I have a question about this: "be sure to firewall your VM from any traffic not to your VPN provider."
Is there a good generic way to do this on Windows? I've looked around and it's never very clear. I think the PIA client has a "VPN kill switch" that should effectively do the same thing, but not all VPN providers have a client.
Unfortunately I don't use Windows, so I don't know how to firewall from it.
https://www.privateinternetaccess.com/forum/index.php?p=/dis...
https://www.privateinternetaccess.com/pages/client-support/#...
"2. Our company currently operates out of the United States with gigabit gateways in the US, Canada, Germany, France, UK, Switzerland, Sweden, the Netherlands and Romania. We chose the US, since it is one of the few countries without a mandatory data retention law. We will not share any information with third parties without a valid court order. With that said, it is impossible to match a user to any activity on our system since we utilize shared IPs and maintain absolutely no logs."
If you have a threat matrix that includes governments or maybe even large corporations, it's definitely not for you. But c'mon, for $4 a month or whatever, what do you expect?
https://www.privateinternetaccess.com/forum/index.php?p=/dis...
servers=( ip1 ip2 ip3 ... )
# Can fwd over internal network
iptables -A OUTPUT -s 192.168.0.0/16 -d 192.168.0.0/16 -j ACCEPT
# Can fwd over loopback
iptables -A OUTPUT -o lo -j ACCEPT
# Can fwd over the tunnel
iptables -A OUTPUT -o tun0 -j ACCEPT
# Can send packets to VPN
for server in "${servers[@]}"; do
echo "Installing rules for $server"
iptables -A OUTPUT -d $server -j ACCEPT
done
# Otherwise drop
iptables -A OUTPUT -j DROP
Use it with a package like iptables-persistent so you don't have to run this every time at boot.Works like a charm, and hard as hell to detect using standard windows tools.
I have been meaning for a while now to make a mini distribution of Linux that works well for VPN usage out of the box. If people are interested in this sort of thing, maybe I could try to make time for it.
I would love to see a VM that I can just spin up that allows for an IPSec tunnel to terminate to it in a road-warrior config.
FWIW, here is what I have so far. http://superuser.com/questions/553193/how-do-i-configure-dd-...
Anonymity is what something like Tor is made for, and depending on your level of paranoia even that may not be enough on its own.
This seems to be a bug in network setups - surely it's highly desirable to be able to control which route traffic takes and whether fallback to a different connection occurs or not.
If you Google around, a lot of other people seem to have trouble with this as well--there are a lot of tutorials for how to setup iptables to block OpenVPN fallback on dd-wrt and Tomato, for example.
I'd love to be proved wrong though!
My experience is that when it merely loses the connection, Openvpn will try to reconnect, and in the meantime you have no internet. It won't fallback. But sometimes, when the problem is more serious, the openvpn daemon can quit and then it becomes dangerous.
If you're going to use a VM for your Tor browsing, consider Whonix [1] instead, which was developed specifically for that usecase. (Note that this is not developed by the Tor project people!)
But indeed, to get the full benefits from Tails, always use the live boot option whenever you can.
Cloak is a super simple VPN where both the back-end service and front-end apps are tightly integrated. (We think of it as the "Dropbox of VPNs" in the sense that, like Dropbox, it's so easy to use.)
Basically, it's the VPN service+applications I wanted for myself when I started looking around and couldn't find anything (1) easy enough and (2) non-sketchy. Right now Cloak supports OS X (10.7+) and iOS (6+). We've been around for a while and I know there are a number of happy customers here on HN.
In any case, please let me know if you have any questions, and please do give it a spin. Cheers!
(EDIT for clarity, and because X of Y descriptions are not always loved.)
Do you mind sharing an appropriately scrubbed config so that I can compare to see what I'm doing wrong in my setup? There seems to be a dearth of viable configs out there and this would be immensely helpful. Thanks in advance.
FWIW, this is what I have so far. http://superuser.com/questions/553193/how-do-i-configure-dd-...
I can't recommend it enough, the damn thing is super stable and secure, works via NAT via NAT via NAT etc and super flexible (push routes, push dns, proxy and other settings), works in routed mode, bridged mode and so on.
I recommend you get a server or a VPS somewhere "nearby" and install openvpn software on that.
I can't trust VPN providers that they do not monitor or log my traffic and neither should you.
No root/admin privileges required on your "VPN server" - just the ability to ssh. It solves the tcp-over-tcp issue. It just works.
It only does TCP (with a specific hack for DNS, but no general UDP or IP). But it works exceptionally well, and just needs an sshable account on the server.
I use sheepsafe to pull these up automatically when I'm away from a trusted network https://github.com/nicksieger/sheepsafe
The next level of 'detail'/risk to consider here is the fact that so many apps, and even browsers, will bind to the "on connection" event of connecting to a wifi hotspot - before you can initiate your VPN your twitter client* has already sent your authenticated token over the wire, etc.
I've tried to hack something together with iptables but that doesn't work either in airports/etc where there are splash screens to negotiate, etc.
( = yes, you could use a better client, but then the reason we need VPNs in the first place is that so many apps and sites don't use https)
Shouldn't be too big of a deal now that tabs/sessions are mostly saved in chrome/firefox no? And well not like losing your twitter credentials is a big deal anyway. (i'm not a huge twitter fan btw :D)
Evidon provides reports to different types of companies that give them information about what trackers appear where, how prevalent they are and/or whether they're in compliance with privacy laws. High-level reports, not "your data."
pokoleo forgot to mention that 1. GhostRank, the feedback feature of Ghostery, is very explicitly opt-in: no data is collected unless you enable it, and 2. We anonymize all of the data that's collected. We have no interest in tracking individual GhostRank users. What's interesting to us is being able to say "This tracker appears on the most websites, or causes the biggest slow-down of a page load on average."
More details here:
> Evidon sells two main services based on the data it collects. One allows website operators to see which tracking code, from which companies, is active on their site and how it affects the speed with which its pages load. The other provides ad companies with figures on how common the tracking code from different companies is around the Web.
[1] https://en.wikipedia.org/wiki/Ghostery#History_and_use
[2] http://m.technologyreview.com/news/516156/a-popular-ad-block...
GhostRank is explicitly for collecting tracker information, and in no way does it allow an advertiser (tho most of the customers are publishers) to somehow improve their targeting.
This explains article what GhostRank does and what its for: http://purplebox.ghostery.com/?p=1016023438
I assume most of the others are trying to block scrapers that copy all their content and republish it.
As someone who has used these lovely devices to prank others it's a good idea to do so.
Well if you set the "Pineapple detected" SSID in your computer as the top priority, you'll connect to that when the pineapple is around. You're just putting in a dummy network on your computer to warn you that you've just joined the network f*&%ville, and you're not the mayor.
So anyone running a pineapple should alter the code not to respond to any SSID client probe containing the string "pineapple" and just wait for the next probe, and latch on to that as that will result in the MITM'ing of a high-value target.
Easy solution and system-wide, if your OS supports it and you can ssh to a trusted server. My personal plan-B tool when a simple ssh -D and firefox's socks-proxy isn't enough.
(BTW, why doesn't Chrome have socks-proxy like Firefox yet?)
https://library.linode.com/networking/openvpn/ubuntu-10.04-l...
See http://www.tinc-vpn.org/documentation-1.1/tinc_4.html#How-co... to get an idea of the mesh feature.
For example, when I was at Birmingham airport, I couldn't connect to my VPN because they blocked domains of well-known VPN providers and even hijacked all my DNS requests so I couldn't circumvent so easily it.
I guess running your own local DNS server which has your typical requests cached would solve this problem though.
Amazingly, there is very little information about this despite what would seem to be a pretty common desired config. Or maybe my google-fu just sucks.
At this point, I can get a tunnel established but it fails to correctly route after the tunnel is set up. Frustrating.
I would love to see the ability to specify 'safe' or 'trusted' WiFi networks and if you connect to a network other than these, the VPN gets initialized and used.
Setup on the phone is once and usage of the VPN happens automatically after that.
I'm guessing that it would cost less than $5/month on energy and I have one sitting on a drawer.
Also, I don't live in the US and proxying all my data through the US and back would introduce unwanted lag.
I've made a beefy VM or even used a spare server at the office on a 100/10mb pipe and a $5 VPS is much more responsive. Especially noticeable with things like an IRC shell.
So using Raspberry Pi is definitely an option.
http://netforbeginners.about.com/od/readerpicks/tp/The-Best-...
A lot of these torrent-anonymously consumer VPN services look pretty dodgy.