Google is working on a new VPN service for use on open WiFi networks
pocketables.com
pocketables.com
Net neutrality promises that AT&T won't be able to discriminate VOIP but Google doesn't trust them. This VPN is a hedge so they won't have their traffic interfered with when they compete directly with the traditional telecom providers.
I suppose Google's philosophy on advertising is similar to how they feel about operating systems: if they can't make money on something, they want to ensure that no one else can, either.
Technical users like you and I can already set up our own VPN-server-that-logs-nothing. This would serve the needs of others, who currently have the options of (a) be MITM'ed or (b) get scammed by some shady offshore company because it was the first search result for "vpn service".
http://lifehacker.com/126454/google-secure-access---encrypt-...
My vpn is often blocked at airports and the like. I doubt the would dare block a google server.
If you want a Google Server, use Google Compute Engine :)
I have had better luck with a SOCKS proxy hosted at my home, but it's still not as good as VPN.
It's hard not to see an offer of at least some form of security to be a net positive in that case.
If they don't provide an easy and apparent way to turn that off, this is the word that always sets off alarm bells in my head.
Honestly, how are everyone's alarms not going off right now? Google fiber, alright, at least I get fucking 1 gbps. Google VPN?? A VPN?? Keep Google/<substitute-3-letter-agency-of-the-day> in charge of what you use to hide your illegal torrents?? Genius.
Are you torrenting, or planning terrorist acts, or whatever else, on your mobile connection? You're crazy. I would never do anything I'd want to hide from the government on my phone; it's already got that mysterious baseband coprocessor running god-knows-what with direct DMA access to main memory. Adding a VPN pipe directly to the manufacturer doesn't make me any more potentially-spied-on than I already was, since the ISP already, effectively, had arbitrary code execution and their own backchannel.
Security professionals don't avoid smartphones altogether, of course; they just use them only as conveniences for "unclassified" day-to-day operations.
That's the logic that brought us ads plastered all across the web, with nothing sanctified, including the _content_ of the web page. 'I mean, we _already_ see them anyway, what's the difference if they're blinking/videos/popups? I mean, we don't have to look.'
And yes, I pretty much use my mobile as less as I can, just for these reasons. I'd never use it willingly as long as there's even a trace of google in android. However, can you elaborate more on the coprocessor? Maybe some additional reading? I'm very interested in what possible surveillance do they have in the hardware itself.
P.S - At this point, I'd rather use apple than google. At least apple can't tie my activities to my search results, which is an insanity that the world will come to terms with several years down the road, and then repent.
Likelihood Bob the Tomato's Coffee Shop is collecting your info: Low.
Android phones are sold globally, remember. There are much worse places to "moor your ship", data-wise, than the US. If this VPN circumvents Chinese Internet censorship, for example, then it's a win by sheer numbers, whatever it does to US domestic citizens.
Airport itself? Low Other people in the airport? High
It's not necessarily the place itself, but anywhere there's open (or easy to get) WiFi, the chance of nefarious users increases dramatically.
Citation needed. I get that it's trivial to actually do, but do you have any studies that show that a lot/any WiFi is being sniffed and/or MiTM'd? The most I've seen is airports and so on tracking people via MAC addresses or the WiFi AP names they request.
That is, if you believe the company that is operating behind it.
If you're worried about a Google VPN provided by the Google Operating System you run, I think you may have your knee-jerk circuits prioritizing incorrectly.
> Arguably, that operating system is open source, and at the least, decently vetted
The one provided pre-installed by Samsung and Verizon. Right.
> If you disable spyware like Google Play Services, it's likely to be reasonably safe.
Ah, so we're going with the "well it feels safer" school of computer security.
"The one provided pre-installed by Samsung and Verizon. Right."
For the average user, yes. Developers can go deeper and install a version that's not just binary blob installed on your phone.
How is google allowed to repeat this again and again is beyond me