I’ve thought about it for while, but for my needs and threat models, I don’t see the benefits of using a VPN. I already block trackers to an extent and try to use privacy friendly services as much as I can.
I’ve thought about reasons on why would I want to use a VPN, hide my IP address, or the websites I visit from my ISP, but I can’t think of really good reasons that:
Can be done so using Tor (like being anonymous)
Are scenarios I don’t usually encounter (like region locked media)
Can’t be used anyway or risk being banned (such as anything involving online transactions or using websites that just strait up doesn’t allow VPNs)
So while I can’t find good reasons for me, I do wonder why you use VPNs or how it fits to your own threat model. Try even convincing me to actually use a VPN.
My region does not have particularly strong data privacy laws. I consider my ISP to a bad actor - I expect they track & sell browsing data. My VPN keeps my internet activity private from ISP
I do use Tor, but its latency is often a factor. If Im doing any denanonymizing activity (account logins, for example), anonymity is broken anyways. And I prefer chromium-based browsing for security reasons when using anything but the most trusted websites
disclaimer: I build VPN apps and sell public VPN services
The VPN providers recommended by PG at least make it explicit that doing so is violation of their ToS. They also make it explicit that they’ll abide by the rules and regulations of the countries they are based in.
Anyone who thinks merely hiding their “home IP” behind a VPN is enough are in for a surprise.
Please explain what you mean with your last sentence. Not that we think your lying about your VPN building/selling, but please include sources that we all can fact check, too.
If you trust your ISP you probably don’t need one.
If I didn’t have an ISP that sold my data for marketing purposes, I would not use one. Maybe tor or a proxy (like firefox browser’s “VPN”) for web forums, as forum admins can and do track users by IP.
I don’t want the government to have access to my online activity: this is how I exercise my right to privacy. In addition to a VPN, I actively use the Fauxx mobile app, which creates a fake profile of my interests.
Streaming content that is not available in my country
Privacy whilst torrenting (Linux iso’s only, of course)
Keeping my DNS requests out of the hands of my ISP and government
Reducing the single biggest heuristic for fingerprinting across the web
Blocking “trackers” isn’t magic. Google can, and does, very easily triangulate your web browsing across any sites with their ads, even if blocked. When IP address 123.456.78.910 requests 30 websites, then logs in to their gmail and social media, then Google knows what you’re doing online without a tracker ever doing the work.
I also don’t trust my ISP at all.
Yes, also when I collect “Linux ISOs.”
I compartmentalize VPN locations with browsers to have a few different “profiles” of what I do online. Anything to do with my name gets a specific VPN location, cookies are allowed, and everything looks very vanilla. Anything to do with forums or socials with no names involved gets another location. Then I jump around for all other browsing, always in a blind/private browser.
Then, also changing location to watch TV or use streaming services not available where I am.
My point was not that you can do what ever you want, but that its less likely to fall back on you if you download a copyright protected image from a website or share an meme.
Of course VPN are not peak privacy/anonymonity. so if stakes are high I would recommend to use Tor
It should at least protect you from minor infractions like small copyright claims.
At least if we assume that there “no log” policies are honest.
Is that your assumption or the VPN provider’s? Security and privacy don’t work on assumptions but guarantees.
If the VPN companies tell you that they’ll abide by the law of the land, especially those based in the EFTA + EU, then “no logs” is now firmly in the marketing gimmick territory, especially when it comes to law enforcement.
What does the “last sentence”[1] have anything to do with “lying about VPN building/selling”?
Sources for what? What do you want fact checked?
Which was: Anyone who thinks merely hiding their “home IP” behind a VPN is enough are in for a surprise.↩︎
There’s a difference between what’s technically possible and what happens in reality. Also nothing is really guaranteed if your adversary has enough resources. I’ve never heard of someone getting sued for a minor copyright violation when they were properly using a good VPN. Have you? If so I’m very curious to learn more
Why would you trust an ISP? Even if you’re using HTTPS, they can see every website you connect to. You have no control over how that data gets saved or used. ‘You have nothing to hide’ is an anthem of the anti-privacy crowd
We do have users who live under authoritarian governments, where ISPs function as a state-sponsored surveillance vector. But even in free countries, your internet activity is valuable data for marketing purposes - do you really trust some corporation to leave that money on the table, out of the goodness of their heart?
What’s that difference in the context of digital security?
In the long run, we are all dead. So, why are you anonymous?
Right.
This same data is available to the VPN providers, btw. From the deals I’ve seen, there’s good money to be made by them, too. Of course, some of the “better” VPNs claim not to log data to auction it away… (Encrypted DNS + TLS 1.3’s ECH at least plugs this big data hole for a good amount of traffic).
‘You have nothing to hide’ is an anthem of the anti-privacy crowd
I’m not echoing, or at least not trying to echo, this statement.
You have no control over how that data gets saved or used…do you really trust some corporation to leave that money on the table?
While I do agree that your ISP may not be trustworthy, with a VPN, they still could see what sites you visit and you still have to trust some other corporation that doesn’t sell your data behind your back.
Youre both right; VPN (or any proxy) just shifts the trust. Your activity becomes private from the ISP, but the VPN operator is now in the mix. So it becomes a threat model game.
ISPs, just by nature of having an open account, already have a ton of PII (name, phone number, probably an email, home address, probably billing info, etc). At the very least, shifting trust to a VPN operator segments your data across independent entities who would need to cooperate to assemble the same comprehensive profile as an ISP alone
But of course, for stricter threat models, (pseudo)anonymous VPN accounts can be leveraged (Mulvad’s monero payment is a strong contender).
Not to imply that this becomes a ‘truly private’ setup - data brokers with advanced surveillance techniques could theoretically buy your ‘anonymous’ browsing activity & still manage to correlate it to you through other data theyve acquired. But it’s certainly an incremental improvement imo