this post was submitted on 01 Jan 2024
72 points (100.0% liked)

Technology

39575 readers
301 users here now

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

founded 3 years ago
MODERATORS
top 50 comments
sorted by: hot top controversial new old
[–] mateomaui@reddthat.com 68 points 2 years ago (2 children)

Spends most of article telling you why they probably aren’t necessary.

Ends with 4 examples why they’re useful, which are the main reasons they’re used to begin with.

[–] GammaGames@beehaw.org 40 points 2 years ago* (last edited 2 years ago) (4 children)

I feel like the opening sentences explained the reasoning behind the article sufficiently, even when there are plenty of valid use cases for them. This was mostly a response to manipulative marketing tactics:

Virtual Private Networks, or VPNs, are popular services for (supposedly) increasing your security and privacy on the internet. They are often marketed as all-encompassing security tools, and something that you absolutely need to keep hackers at bay. However, many of the selling points for VPNs are exaggerated or just outright false.

They’re not the only ones pointing this out, either. Tom Scott released a video on the topic a few years ago to explain his thoughts VPN sponsorships

[–] mateomaui@reddthat.com 14 points 2 years ago* (last edited 2 years ago) (1 children)

Your comment in no way negates my observation. If the clickbait title of the article was “You probably don’t need a VPN to avoid market tracking” or something similar, you’d have a point.

[–] GammaGames@beehaw.org 18 points 2 years ago (1 children)

I was simply adding information your comment had left out, it wasn’t negating information at all. So congrats on getting the point, not everyone is trying to argue 🎉

[–] mateomaui@reddthat.com 3 points 2 years ago (1 children)

You may want to reconsider your phrasing then if you don’t want it to appear to be argumentative.

[–] ConstableJelly@beehaw.org 21 points 2 years ago (1 children)

Neutral party here, I read it naturally as a supplement to your comment, not an opposition. I don't detect an argumentative tone personally.

[–] mateomaui@reddthat.com 2 points 2 years ago (1 children)

You’re welcome to your opinion but these phrases

I feel like the opening sentences explained the reasoning behind the article sufficiently,

They’re not the only ones pointing this out, either.

are oppositional in tone.

[–] AstralPath@lemmy.ca 17 points 2 years ago (1 children)

If you ask me, you seem to be looking for a fight here.

[–] mateomaui@reddthat.com 1 points 2 years ago* (last edited 2 years ago) (1 children)

I didn’t ask you. I didn’t ask the other neutral guy either. Not my issue that you have a problem with me suggesting the original respondent check his phrasing to make his intention clear, or pointing out the specific phrases that make it unclear.

[–] cygnus@lemmy.ca 5 points 2 years ago (1 children)

"Everybody on this highway is driving in the wrong lane! What a bunch of idiots!"

load more comments (1 replies)
[–] adespoton@lemmy.ca 7 points 2 years ago (1 children)

…and since then, Tom Scott took a NordVPN sponsorship. And possibly SurfShark too?

He found that it was actually useful while in countries with questionable Internet access.

Personally, I just host my own VPN, so no matter where I am, all my traffic exits from my home ISP. I figure they’re at least accountable to the same laws I am.

[–] _MusicJunkie@beehaw.org 10 points 2 years ago* (last edited 2 years ago)

But that's the thing. When that Video was made, almost all of the advertising was focused on the same BS the article is disagreeing with.

I remember lots of NordVPN ads by uninformed nontechnical creators just reading the provided script. Saying that Balaklava wearing hackers will steal your credit card data just by being in the same cafe as you, and only an expensive VPN subscription can protect you from that. Or that only using a VPN will protect you from malware.

This sort of advertising is what Tom Scott critizied back then. IIRC he even said that there are real use cases, but that you shouldn't believe the fearmongering. Same as the article.

The fearmongering advertising was the problem, not advertising the service itself.

[–] otter@lemmy.ca 5 points 2 years ago

Yep, articles have different audiences.

Sure one group might understand why a tool exists and use it effectively, but there are also companies over-selling their capabilities and people are using it for things it doesn't help with.

This article is for them, simple as that

[–] corbin@infosec.pub 6 points 2 years ago (1 children)

I don't know if those useful features are the main reasons VPNs are used, though. There's evidence they are used often for bypassing blocked sites (like VPN downloads jumping in Russia recently), most of the other advertised privacy and security benefits are questionable. Most of them don't advertise torrenting/piracy because that's a legal gray area.

[–] mateomaui@reddthat.com 7 points 2 years ago* (last edited 2 years ago) (1 children)

My VPN advertises protected torrenting as a feature. Many do.

And it’s pretty nondebatable that VPNs are advertised for getting around regional blocking for Netflix etc, or generally getting around censorship like in China.

[–] adespoton@lemmy.ca 4 points 2 years ago (1 children)

Ironically, almost all the exit VPNs are owned by either China or Israel. With a few exceptions.

[–] mateomaui@reddthat.com 4 points 2 years ago

citation needed

My VPN is headquartered in California, and actively removed their presence from Hong Kong once their security policy matched China’s, and removed themselves from Russia since that country was opposed to the zero logs policy.

[–] floofloof@lemmy.ca 50 points 2 years ago

The title should be "You should understand what a VPN is for, before using one."

[–] Midnight@slrpnk.net 39 points 2 years ago (7 children)

Another reason to use a VPN is that ISPs have every motive to sell your browsing data and they do. Unlike many other groups tracking you, your ISP inherently has your meatspace name, address, and payment information making their data easily collatable and very valuable.

If you use the default DNS on their provided router they can even tell if someone purchased an XBox, Playstation, or any other smart device just from update and telemetry lookups.

As the article says, by using a VPN youre using someone else's ISP making that info worthless.

If your threat model includes preventing ad networks from gathering data, a VPN absolutely is a tool to prevent that. Do you have to pay for a service? Probably not if you're technical enough; a VM in a data center is probably sufficient.

[–] derbis@beehaw.org 31 points 2 years ago* (last edited 2 years ago) (1 children)

Yep. BIG deficiency in this article. I don't use a VPN because of shadowy "hackers" who sit in front of their keyboards with a pistol and a balaclava. I use it because ISPs and governments have demonstrated they can't be trusted.

How about this?

I live in the United States, where I already have no digital privacy, and tunneling my internet traffic through a VPN owned and operated in another country won't meaningfully improve my privacy or safety

Uh, what? If someone wants my traffic logs in the US, now they have to go through Mullvad, which has a track record of not providing or collecting it.

They don't even know who I am, much less have all the data that my ISP has about me. So selling it would be pretty useless

Oh last edit: turns out this is the guy who was trying to well ackshually us into thinking Chrome nerfing ad blockers is not a big deal.

[–] mateomaui@reddthat.com 7 points 2 years ago* (last edited 2 years ago)

Yeah, part of it reads like he was paid to do it, just without including obvious marketing links so he can claim in the article that he wasn’t. Ending the article with valid use cases seems like preventing anyone saying he left out valid reasons, but after a wall of text that could make less savvy users do a “TL;DR: VPN not needed” before they got to that part. I’d respect it more if he led off with the same short description of valid uses, especially considering the article title, then pivoted to where it could be irrelevant.

[–] smeg@feddit.uk 10 points 2 years ago (1 children)

ISPs have every motive to sell your browsing data and they do

That sounds very illegal under the GDPR

[–] scrubbles@poptalk.scrubbles.tech 8 points 2 years ago (1 children)

Oh, if us in America were as privacy minded as the EU. People here gladly hand over every bit of data about themselves either to feel safer or just to save 10 cents on groceries.

load more comments (1 replies)
[–] sonori@beehaw.org 7 points 2 years ago (1 children)

You could also just set your DNS to one of the many free DNSSEC providers. That’s even more secure because there are fewer middle men who can track you. After all, while your ISP may not be able to see that DNS traffic, if you arn’t using DNSSEC anyway then your VPN and their upstream provider can.

Besides, nearly all tracking nowadays uses third party browser fingerprinting, which a VPN does nothing about. Practically, a VPN is far more security theater than actual security.

Also, isn’t it funny that sending all your data though a second nation where it no longer legally counts as Amarican internet traffic became really well advertised right after a major scandal came out where the NSA was illegally monitoring American traffic, and more protections were put in place to keep them from doing it again?

You don’t even need the VPN company to be in on it, a group like the NSA can pretty easily compromise a “no logs” VPN’s technical infrastructure or that of their upstream provider, and they’re even got people who feel like they have something to hide to self select for it to cut down on the amount of boring traffic in the first place.

[–] starkzarn@infosec.pub 7 points 2 years ago (3 children)

This is absolutely not what DNSSEC is. DNSSEC provides authenticity of the response, not privacy. You're describing a means of encrypted name resolution, like dns-over-tls, dns-over-https, etc.

load more comments (3 replies)
[–] corsicanguppy@lemmy.ca 7 points 2 years ago (1 children)

VM in a data center is probably sufficient.

Um, those aren't cost-free.

[–] IcyPenguin@beehaw.org 1 points 2 years ago

Oracle Cloud has a free tier and this video shows you how to set up your own VPN there. I wouldn't really recommend this as a free VPN solution though. If you need something that's free, go with Proton VPN's free tier, Proton is pretty trustworthy and they are very upfront about their business model...

[–] HeartyBeast@kbin.social 2 points 2 years ago

Thank goodness we absolutely know for certain that no VPN would ever sell your browsing data.

load more comments (1 replies)
[–] 0xtero@beehaw.org 24 points 2 years ago (1 children)

Well, that article was a hot mess.

I appreciate the authors effort and they are correct about lack of "what is VPN" articles that are not written by VPN-vendors in marketing purpose. But I'm not sure if this was it.

Writing an article meant to "debunk" misconceptions and getting two core concepts, Security and Privacy mixed up right from the start wasn't very good.

A lot of time was spent on explaining HTTPS and how it somehow magically makes you and your data secure on the Internet and it completely missed to mention who the potential threat actors thwarted by HTTPS are?

Could have probably used a chapter on how actual threats (both security and privacy) work and how don't have much to do with the level of encryption your TCP/IP connection happens to encapsulate.

The last chapter with the first 3 bullets was pretty good though. That could have just been the whole article and it would have been alright.

Oh well. Attempt was made.

load more comments (1 replies)
[–] t3rmit3@beehaw.org 20 points 2 years ago

I know exactly how litigious Funimation is. I absolutely need a VPN. :D

[–] NecroMemories@beehaw.org 17 points 2 years ago (1 children)

I like VPNs because you get a colorful selection of who to potentially get man in the middle attacked by.

[–] t3rmit3@beehaw.org 2 points 2 years ago

That's not a VPN issue, that's a provider issue.

[–] StantonVitales@beehaw.org 14 points 2 years ago (1 children)

Clearly whoever wrote this has not tried torrenting popular content 🤨

[–] naevaTheRat@lemmy.dbzer0.com 2 points 2 years ago (1 children)

Just use any old proxy either paid for in cash in the mail, or in a country that absolutely won't cooperate with yours legally when you need it.

Your VPN will absolutely fold under the slightest legal pressure.

[–] derbis@beehaw.org 2 points 2 years ago (2 children)

Some of them don't even log the data required to cooperate with requests. Mullvad is one.

[–] kbal@fedia.io 10 points 2 years ago

I'm not quite paranoid enough to believe that all of these anti-VPN articles are propaganda sponsored by people who want to make mass surveillance easier, but when it's from someone whose other recent posts include one titled "Youtube ads aren't actually that bad" and two explaining why Google's Manifest V3 is great, I'm at least going to suspect it as a possibility.

[–] Greenpepper@beehaw.org 8 points 2 years ago (1 children)

Another good use for VPN is to counter dynamic pricing. My wife visited a website some time ago to request the price for a ticket. When she visited the website a second time the price had increased considerably. However when visiting the price with VPN it was the original price again. It saved her a lot of money.

load more comments (1 replies)
[–] IcyPenguin@beehaw.org 2 points 2 years ago

IVPN created an awesome website called doineedavpn.com where they honestly and objectively answer that question. It's one of the reasons why I like IVPN as a VPN provider, they are honest and don't hide anything from their customers. Also their apps are open source and they support anonymous signup.

load more comments
view more: next ›