The Best VPN Is The One You Use
blog.justinsb.com
blog.justinsb.com
That being said I did not use it more than a few days and maybe people have better anecdotes than me. I personally would stick with a properly configuring OpenVPN, or FreeSWAN if the whole HTTP/SSL tunneling VPN systems aren't your bag.
As to more demanding uses, I haven't tried e.g. accessing a video site like the BBC iPlayer, though maybe I should do so "in the name of science".
You may theoretically have worse performance with a TUN/TAP tunnel compared to an IPSEC tunnel because the packets have to travel into and out of userspace whereas IPSEC stays in the kernel, but I've never noticed this in practice. In contrast, the TCP performance degradation is very noticeable in practice.
Cheap VPS with a prepaid (gift) card = poor's man VPN.
It does seem that SSH has a lot of ways to do a "VPN", some of which are better for different things. I think it is very underutilized!
How is running a custom script every time you need connect 'almost no configuration'? It's all relative, I suppose, but having to procure/run a Python script just to make a VPN connection is too much hassle for me.
What Justin ought to do is wrap his script into a menubar item, and submit it to the App Store. That would truly require "almost no configuration" because:
a) downloading/installing the script would be easier, even when using a strange Mac in a cafe or lab environment
b) making a VPN connection would be no less convenient than Apple's VPN menubar item.
I do like the fact that a script exposes its inner workings and is easy to modify. It also sounds like TCP over TCP might be sufficiently problematic (in the general use case) that this option may be unsuitable for others.
But it's definitely an interesting idea... :-)
As frustrating and expensive as Microsoft tech may be, it sure works wonders sometimes!
sshuttle crashes OSX (grey screen of death) about once a day, does your script avoid that?
However, I would guess that a grey screen of death bug is due to a kernel-space issue, i.e. the Tun/Tap drivers. They are not built into OS X, which seems a real shame (as they're used with every user-space VPN: OpenVPN, sshuttle etc).
It is possible that sshuttle is doing something wrong causing the tun/tap drive to crash. I would guess that my script would crash as often as OpenVPN does, as I bet/hope ssh is as solid as OpenVPN. If OpenVPN crashes as often as sshuttle, then the problem is likely the tun/tap driver.
I hope to be trying this on a Mac in the next few days... just need to buy one first!
They behave the same as the Free/OpenBSD tunnels, in that they prepend the IP version as a 32-bit word.
See:
http://www.opensource.apple.com/source/xnu/xnu-2050.18.24/bs...
Now I really need to get a Mac and get this working there!
We're currently using it in Cloak for Mac. (https://getcloak.com/ -- bbits is our github organization and Cloak's parent company.)
Previously we maintained (and used) the tuntaposx kext, but keeping it up to date was becoming a burden. At WWDC, some of Apple's fine kernel networking engineers shared the proper incantations with us; this patch is the result.
If you want the best possible reliability, run the server on port 443 with TCP (even though UDP is almost always better for performance since TCP over TCP is icky). You have a much better chance at not being blocked by firewalls, and it actually works on a lot of the less-sophisticated captive portals without first logging in.
(Granted, the article is talking about using OpenSSH and not OpenVPN—but I suspect that should work fine behind NAT as well).
I'll test the 3G connection within the next few hours, however I suspect the providers have moved to block some kinds of tethering.
Have you found a real IP I've missed?
You're right that PPTP is fine for your purpose.
I traveled through Hong Kong, Shanghai and Shenzhen for weeks in November 2011 and was able to ssh anywhere I needed to ...
I was staying in nice, expensive, western chain hotels ... perhaps that made a difference ?
It's definitely not appropriate for doing something illegal or where you want plausible deniability for other reasons. I point that out fairly clearly in the README, though I should have made it clearer in the blog.
I would wager though that many VPNs don't actually offer much more security than this. The good ones (LavaBit, CryptoSeal) did. How do you verify that your VPN provider isn't handing over this information just as readily as this approach does?
Generating false traffic is a good idea, but I don't think you should rely on that if you want to use this for illegal purposes.
The point I was trying to make with the title is that OpenSSH does a lot of what a full "VPN" does, yet is a _lot_ easier to configure than anything else I've encountered. Apart from PPTP, which is apparently the "rlogin" of VPNs ;-)
free652 posted an even easier approach here, which sets up a SOCKS proxy with no extra configuration. If SOCKS is good enough, you should use that! If you want full tunneling, hopefully we can make my script easier / unnecessary.
The author gain to reader gain is really, really low in this case, so I don't think it's content-free linkbait.
It was a (poorly implemented) "secure email" service.
Err.. no it's not.
The point of using a VPN is protection against eavesdropping.
Some may use it for plausible deniability, but that isn't even the most frequent use case (I'd imagine the most frequent use is access to corporate networks).
"Privacy" yes - as in avoiding eavesdropping. NOT for plausibly deniability.
To quote the post:
I use VPNs not for illegal purposes, but (1) to get IPv6 wherever I am, (2) to prevent casual snooping on my web traffic (the Firesheep scenario) and (3) to get onto a ‘private’ network.
None of those purposes require plausibly deniability.
Imagine some ISPs start rolling out such routers per default.
People usually reach for a VPN when they do not trust the link they are using. e.g. it's coffee shop wireless. A VPN obscures the traffic travelling over the dangerous link and delivers it to the endpoint where it is usually on-routed.
On the whole, VPN's do NOT provide anonymity, they provide privacy. VPN connections always need a fixed endpoint which likely has some sort of billing relationship with you.
Services such as i2p and Tor provide anonymity.
The fact that the first (only) use for VPN you can think of is to hide criminal activity says a lot about you, really.
Because it can protect the sensitive (internal corporate network) information while its travelling over untrusted networks, with the destination being none the wiser.
Bridging two networks (or a host and a network) together securely over the internet has far more applications than merely telecommuting and is so effective and easy to apply, why not use it to protect your Facebook session while you're at the coffee shop?