How often do y'all use a VPN?
from monovergent@lemmy.ml to privacy@lemmy.ml on 23 Aug 00:16
https://lemmy.ml/post/51738483

Bit of an uphill with captchas everywhere. Do people here conduct all online activity over VPN whenever possible? Only for the sensitive stuff? Or perhaps the inverse because the bank already knows you? Maybe when travelling or getting around region blocking? Something else?

The one provided by my work aside, I realized that I don’t have any consistent rules around using VPN. Except sometimes, you know, when downloading ISO’s for my favorite distos.

#privacy

threaded - newest

Zedd_Prophecy@lemmy.world on 23 Aug 00:24 next collapse

I have a VPN configured at the router. I use a PI-hole with a lot of restrictions and lists to run my own DNS and downstream DNS is Adgaurd. Several machines I let bypass the VPN umbrella and they have local clients they can switch on at will. I’d like to make a Linux firewall too but not with prices where they are now. These days you have to distrust everything.

oeuf@slrpnk.net on 23 Aug 00:59 next collapse

Mine is on pretty much all the time. Capchas are indeed annoying, but I’m choosing to see that as something which helps me to be more intentional about my use of the internet.

My bank and government portal don’t seem to care about it, even if my traffic is coming from a random country on the other side of the world because I’ve forgotten to route through one of my VPN’s domestic servers. Online freelancing platforms, on the other hand, have instantly banned my accounts, and I’ve had problems with corporate social media (which I try and use for my business).

webghost0101@sopuli.xyz on 23 Aug 13:28 collapse

Whats this with vpns using capatchas?

My client device having the right encryption key is the authenticator for me.

some_kind_of_guy@lemmy.world on 24 Aug 03:25 collapse

Most sites can tell if you’re using a VPN. It depends on the site, but this can cause sites to treat your visit as suspicious and throw up their defenses. This includes use of CAPTCHA. Some sites (e.g. Reddit) don’t work at all if your traffic exits from a known VPN.

artyom@piefed.social on 23 Aug 00:59 next collapse

Pretty much always. If someone blocks my VPN, I just don’t go there or don’t use that. Sucks but it is what it is. I’m just not willing to enter your site bareback.

IEatDaFeesh@lemmy.world on 30 Aug 00:51 collapse

I literally can’t comment on Lemmy if I’m using a VPN so what are you taking about? XD

artyom@piefed.social on 30 Aug 00:52 collapse

I’m not using Lemmy.

RodgeGrabTheCat@sh.itjust.works on 23 Aug 01:39 next collapse

100% of the time I’m behind a vpn.

Luminous5481@anarchist.nexus on 23 Aug 01:54 next collapse

absolutely at all time. I can’t say that I see many captchas. I think the last one was for some site I used a couple weeks back that used google recaptcha. it’s pretty rare for me to see one.

wuphysics87@lemmy.ml on 23 Aug 02:01 next collapse

Most of the time, but I would emphasize always in airports or public wifi

manuallybreathing@lemmy.ml on 23 Aug 02:39 next collapse

I use a VPN 99% of the time, i turn it off when i need to access archive.org, or watch something on the public braordcasters streaming platform

yeah sure the captchas are annoying but it’s not like websites load within 10 seconds anymore

I only wish protonVPN was a good as the one i used previously, but i cancelled it cause it had ties to israel

utopiah@lemmy.ml on 23 Aug 15:38 collapse

You might want to check into split tunneling.

Commiejones@lemmygrad.ml on 23 Aug 02:50 next collapse

I leave mine on almost all the time. If a website takes a little longer to load “Oh no” its a half second instead of milliseconds. it really doesn’t change my life much.

realbadat@programming.dev on 23 Aug 03:18 next collapse

General activity goes out the VPN always. My self hosted setup, lab stuff, and work stuff gets different connections out (logically, not physically).

NauticalNoodle@lemmy.ml on 23 Aug 04:23 next collapse

98% of the time. I hate having to turn it off to look at my local grocery store’s website but I have done it before.

Fizz@lemmy.nz on 23 Aug 04:49 next collapse

24/7 on any device except my home PC.

chicken@lemmy.dbzer0.com on 23 Aug 07:00 next collapse

Mostly just for torrents, one machine on my local network is always using a VPN to connect to the external internet. I would use it for more things like private web browsing, but without substantial additional setup I think my web browsing is guaranteed to be fingerprinted regardless of whether I conceal my IP so until I bother to set that up it doesn’t seem like there is much point.

hirihit640@sh.itjust.works on 23 Aug 09:31 collapse

Do not try to do anti-fingerprinting yourself. Cobbling together your own configuration will only make you stand out more. Use a pre-configured browser from a reputable company. This way you blend in with everybody else using the same browser. And don’t install extensions either unless you really know what you’re doing. Extensions usually change your fingerprint.

Use Tor Browser for browsing over Tor, Mullvad Browser for everything else. Librewolf is fine for when you don’t care about hiding your fingerprint, like when you are logging into email and bank accounts.

willington@lemmy.dbzer0.com on 24 Aug 12:09 collapse

fonts, screen resolution, many things can affect fingerprint.

The solution is not “a browser from a reputable company.”

It will be a browser designed by security professionals to spoof fingerprints, along with a “crawler” that analyzes the current blend of fingerprints already out there, crawling not web pages but the request headers instead, and canvas outputs, etc.

I don’t think such a browser plus infrastructure exist yet, but they will. It is inevitable.

Such a browser will output garbage yet plausible and believable fingerprints that maximize ambiguity.

hirihit640@sh.itjust.works on 24 Aug 13:01 collapse

What makes you think the Tor Browser and Mullvad Browser are not made by “security professionals”? Have you used either of them? They already have defenses against font, screen resolution, and many other fingerprinting vectors.

Also, “plausible and believable” fingerprints were already considered by Tor Browser and Mullvad Browser, and I believe are actively in use by Brave Browser. I forget why Tor Browser and Mullvad Browser opted to instead give everybody the same fingerprint, but there was a reason for it.

willington@lemmy.dbzer0.com on 24 Aug 23:33 collapse

Of these Tor is the best for protecting identity, however Tor produces a recognizeably Tor-like fingerprint, which for my preference is not ideal.

So for example Tor browsers can all be denied access, because Tor, not the individual user, but the kind of browser used, can still be identified.

My ultimate latent goal isn’t to only protect the anonymity of a security-conscious user, but to poison all fingerprinting data so that the entire technique is abandoned as useless.

hirihit640@sh.itjust.works on 25 Aug 00:04 collapse

Adversarial methods like that won’t work. Google will know when their data starts getting poisoned. Their ad targeting will lose effectiveness, their profit margin impacted. And they will tweak and tighten their trackers until they can squeeze out a good fingerprint again. In the end Google simply rolls out Web Environment Integrity, and consumers won’t be able to use the web unless they prove their identity. If you want to fight big tech, this is the endgame they will push toward. If you want to play a cat and mouse game with big tech, big tech wins in the end since they have all the money.

Tor Browser recognizes this. So Tor Browser just erases any existing identifiers, while accepting that websites can identify Tor users and block them if they want. It’s a very explicit signal that “this is a user that cares about privacy”, and it’s up to the website to accept that user or not. If a website doesn’t care, then usually it will work fine in Tor Browser. If a website does care and tries to block Tor users, then Tor Browser doesn’t bother fighting it. There are better places for them to focus their energy.

Ultimately if you want the web to be private, the only solution is to convince everybody else to want the same. Websites won’t block privacy-seeking users, if everybody is a privacy-seeking user. Then, even big tech will have to concede.

willington@lemmy.dbzer0.com on 25 Aug 00:25 collapse

Just fundamentally, to fight, you have want to win.

You are arguing to stop fighting on the basis of a supposedly improper desire. Wanting small bite sized things is proper. Wanting something audacious is not. Your kind of argument could work in theory if my desire is unserious. That’s just psychology, not technology.

The scariness and the capabilities of an adversary is never, on their own, a proper reason to not fight.

The valid reasons can be: a deeply reasoned and deeply felt long term change in priorities, or a tactical hiatus to rest, regroup, reload. These are completely internal affairs, meaning, a serious person cannot be casually argued either into or out of these. I would check in with my soul to know whether or not to fight. Not with strangers on the net.

People fight to satisfy a certain hunger, and not because it looks easy or is a popular thing.

hirihit640@sh.itjust.works on 25 Aug 01:00 collapse

But there’s strategy to this. What I’m saying is that it’s more productive for privacy advocates to spend their efforts convincing others that privacy is important, or pushing for privacy-friendly regulation, rather than trying to fight a war of attrition with big tech.

willington@lemmy.dbzer0.com on 25 Aug 01:10 collapse

I don’t think what you’re saying here in this last reply competes with what I am saying.

It is both/and. Not either/or.

My strat combines naturally with using advocacy, electoralism, lying flat, malicious compliance methods, militancy, legal/beurocratic methods, economic methods, etc.

I am for all of these. Whatever works.

But ignoring the human relationship dimension and exclusively focusing on prosecuting tech, imo, is not a serious strategy.

Besides, someone who needs to hide their ID now should use Tor now. Someone who has a lower risk profile can afford a solution that aims to poison the well for the long term in preference to a better ID protection.

I am not doing anything illegal, I want to poison the well if I can. I still use Tor sometimes anyway. I want the whole fingerprinting industry to just go away.

hirihit640@sh.itjust.works on 25 Aug 01:48 collapse

I want the whole fingerprinting industry to just go away.

Be careful what you wish for. As hardware attestation continues to spread, companies won’t need fingerprints to identify you. Though if you want, hardware attestation can be thought of as an unique and unforgeable fingerprint. Poisoning the well won’t work for it.

Just to clarify, hardware attestation is not bad in itself. It can be used by the user to secure their device (aka secure boot). It’s when third-parties try to use it, where it becomes a threat to privacy. Like a website asking for your hardware-attested device id.

Of course we don’t want to give our id to these third parties. But we need to convince everybody else to do the same. Because if everybody else gives up their id, then websites won’t care about the few “privacy extremists”. And those people will simply be locked out of the web.

But anyways, back to fingerprinting. I feel like the best way to get a sense of the scale of the issue, is to simply dive into the developer discussions around it. Look into mailing lists and feature discussions for Tor browser, Mullvad browser, and Brave. I guarantee you there are discussions around trying to make the browser look identical to the average user, and the challenges of doing so.

willington@lemmy.dbzer0.com on 25 Aug 02:04 collapse

Again we’re back to bad fear-based logic.

You’re saying hardware attestation is a looming punishment for poisonin fingerprinting.

Wrong.

The enemy wants hardware attestation now, and they want it bad. Nothing you do or avoid doing can influence this because they, the enemy, are responding to their own hungers.

I repeat, there are only two valid reasons to stop prosecuting a fight, and this isn’t one of them.

You are offering an incorrect model of the enemy as a nanny who will try to shape my behavior in responce to my behavior. I “need” to please the nanny and I “need” to avoid pissing off the nanny. Your argument is designed for that sentiment: nanny-pleasing.

The correct model is one based on INTERESTS. The enemy has an interest in hardware attestation regardless of what we do or don’t do. They will prosecute their interests KNOWING those are deeply unpopular. Look at the Guardians Of Pedophiles party, the GOP in USA. They are unpopular. They are hated. They KNOW this. They keep trucking. Why? The INTEREST didn’t go away. The interest is not socially shaped, unfortunately (or fortunately?).

hirihit640@sh.itjust.works on 25 Aug 02:15 collapse

If you believe hardware attestation is inevitable, then why bother poisoning the well for fingerprinting? None of that will matter once hardware attestation takes hold

willington@lemmy.dbzer0.com on 25 Aug 02:17 next collapse

Nothing is inevitable. Everything is negotiable.

willington@lemmy.dbzer0.com on 25 Aug 02:33 collapse

I apologise for a 2nd reply, I just wanted to clarify.

What I cannot readily control (or don’t know how) is the internal hunger stemming from the soul (mine or enemy’s).

But which hungers get to dominate in a public arena, I do have a say in that. So having some hunger may be inevitable, but making that personal hunger into an impositional system for everyone, that’s not inevitable.

So yea, they want hardware attestation now. They’re not relaxing until they find out what we do with the fingerprinting ecosystem first. That’s laughable.

Since they’re going to do what they’re going to do, and since the outcome is never set in stone ahead of time but instead has to be discovered by living life, we have no reason not to chase our dreams and ambitions as much as they chase theirs. I have no reason to preemptively block or throttle my energy. I am not here to please any would be nannies. I have fears, but do not allow my fears to impact my logic. And besides I fear surveillance capitalism more than whatever else the “punishment” is promised to be.

hirihit640@sh.itjust.works on 25 Aug 03:33 collapse

I admire the drive. And I am not here to discourage you. The privacy world could always use more driven people. There are tons of projects that can use more supporr, like I2P, Tor, Monero, Internet Archive, Whonix, Qubes, etc. Keep at it and I’m sure we can win.

Pika@sh.itjust.works on 23 Aug 07:43 next collapse

if you include my intranet vpn daily, if you include external vpns generally only if I’m going to a hotel or a location I expect would be insecure.

thanksforallthefish@literature.cafe on 23 Aug 07:45 next collapse

Permanently on. Anything I can’t access without it I generally find an alternate with very few exceptions. I have a quarantine virtual machine I use for the couple of websites that are worth making an exception for.

SolarPunker@slrpnk.net on 23 Aug 10:20 next collapse

Never, I’m in EU and I don’t travel that much, pirating since 2000s

random_character_a@lemmy.world on 23 Aug 12:49 next collapse

In a way always.

Whole family is connected to home network and home network has filters and blockers in the outgoing router.

Additionally home security system doesn’t have to keep connections open outside or have ports forwarded.

Outgoing router however does not have VPN set, so home network IP is visible. This is to keep everything operational and CAPTHCA from annoying users.

curious_dolphin@slrpnk.net on 23 Aug 13:49 collapse

Whole family is connected to home network and home network has filters and blockers in the outgoing router.

Aside from the obvious benefit of blocking advertising traffic for all devices on your home network, does this strategy also improve your ability to blend in by eliminating the need for an ad blocking browser extension such as ubo?

random_character_a@lemmy.world on 23 Aug 18:37 collapse

If I login to youtube and click a video, advertisments are mostly female hygiene products, braziers or frozen food products, because wife sometimes forgets to sign out from Facebook or Instagram. There also used to be gaming related stuff, but after my son became “privacy oriented”, those.disappeared.

I’m guessing that for data brokers we are one singular blob.

Not sure about how it all effects on blending in.

webghost0101@sopuli.xyz on 23 Aug 13:26 next collapse

<img alt="" src="https://sopuli.xyz/pictrs/image/c409f90b-6982-4505-a697-3f56fadc4116.webp">

somegeek@programming.dev on 23 Aug 15:22 next collapse

going around government censorship, being safer from being tracked

webghost0101@sopuli.xyz on 23 Aug 18:42 collapse

I get the idea but all of it depends on placing your trust in some company who’s entire business model is to sell you privacy.

If you live in an area with such heavy censorship then can you trust the business that is legally allowed to advertise and sell to you?

I personally think such company is way more likely to sell my data on the dark web then the government has resources to investigate what web domains i have visited.

somegeek@programming.dev on 23 Aug 21:35 collapse

They aren’t legally allowed to advertised and sell. Having them installed and selling them is a crime. (China, Iran, many other countries)

webghost0101@sopuli.xyz on 23 Aug 22:14 collapse

It is a valid use case. But thats not my usecase by far, which is what was asked.

My comment is slightly directed at people i know irl that are not very technological and believe that surfing the web is inherently not safe, but completely safe one you pay to connect to name_tm.

My apologies if it felt condescending for people who have good reason to tunnel outside there local jurisdiction.

remotedev@lemmy.ca on 24 Aug 00:12 collapse

Do you know of a guide for a setup like this?

webghost0101@sopuli.xyz on 24 Aug 01:02 collapse

I have a router with opnsense which has q plugin for wireguard making things quite easy for me.

A router is usually also always online and sits at the center of a network so it is the best place for it but there is nothing stopping someone from setting it up with commandline on a home device.

www.wireguard.com/quickstart/

There are many online video guides that cover different ways to do it (like docker)

In all casss you first setup a main server on the device that stays home and from it you generate a peer per device you want to connect. (A bunch of settings/codes) Sometimes a peer is a qr code that your device can scan (wireguard app for some devices) otherwise you have to manualy type.

Once set you can just leave it on. The only exception i found is some apps for local payments, presumably because they require both devices to report the same location to perform a transaction.

Zerush@lemmy.ml on 23 Aug 14:30 next collapse

At home never, only sometimes a proxy (CyberGhost extension, Chrome, Firefox) in case of country restrictions. In my phone no need, I don’t use public WiFi, it’s enough with InVizible Pro. Apart the Portmaster app on desktop (Windows, Linux)

bleustenns@lemmy.ml on 28 Aug 21:34 collapse

Someone else already put this in much wordier ways, but anything CyberGhost I would stay away from if you truly care about privacy on a significant level. You may want to consider using a full-on VPN like IVPN or Mullvad as much as you can if you’d like to stay away from targeted advertisements and profiles being built about the people that connect to things using your IP address.

DarrinBrunner@lemmy.world on 23 Aug 15:10 next collapse

I never have. Don’t know how to do it (I know it’s not hard). The only use I occasionally have is blocked media, but I just don’t watch whatever it is. It’s not that important to me.

What’s important to me is blocking ads, which I do as much as possible. The way I see it, the main point of them tracking me is to serve me ads, so I break the chain at the ads.

If I want privacy, I use Tor. Everything else seems like spitting into the wind.

Zerush@lemmy.ml on 23 Aug 16:41 collapse

I also think, ad/trackerblocker, Portmaster and common sense in what you public on the web is mostly enough (How much claims of the lack of privacy I saw in Facebook through the years…)

somegeek@programming.dev on 23 Aug 15:21 next collapse

Constantly.

utopiah@lemmy.ml on 23 Aug 15:36 next collapse

mostly against geoblocking when I want to watch public TV channels from while I’m not in the “right” country, e.g. when I want to watch PBS outside of the US, Arte outside of Europe (even though I dont think they block anymore), FranceTV outside of France, Ray out of Italy, etc.

Sometimes also for blocked content, e.g. PirateBay in France or AnnaArchive in Belgium but typically for these public proxies are enough.

Ah I also use self-hosted VPN for my own self-hosted services when I’m on the move but it is typically very small traffic.

FWIW I’m not using a large commercial ISP, so trusting my ISP is a big part of my behavior.

Nighed@feddit.uk on 23 Aug 15:57 next collapse

My phone almost always has a Vpn on to my home network (gets me pi-hole goodness)

Other than that, very occasionally use the Firefox built in one + the one for my “Linux iso” torrenting container, that’s not on most of the time though.

technocrit@lemmy.dbzer0.com on 23 Aug 16:36 next collapse

Almost always. I turn off for certain websites that are blocked otherwise, but I hate to leave it off.

pineapplelover@lemmy.dbzer0.com on 23 Aug 16:55 next collapse

All the time basically

dragospirvu75@lemmy.ml on 23 Aug 18:02 next collapse

I would use VPN, but it makes my Bitcoin Node stop receiving incoming connections.

swelter_spark@reddthat.com on 23 Aug 20:03 next collapse

I use tor for everything.

AfricanExpansionist@lemmy.ml on 23 Aug 23:40 collapse

Everything??? Sounds slow

gwl@lemmy.blahaj.zone on 24 Aug 11:32 next collapse

Sounds like you’ve got a shit VPN if it’s slow for you

hirihit640@sh.itjust.works on 25 Aug 01:52 next collapse

If you use Tor Browser in the “safest” security setting, websites will actually load pretty fast since javascript will be disabled. Well, at least for the websites that load at all

swelter_spark@reddthat.com on 25 Aug 20:36 collapse

I don’t use the browser, but I also don’t use javascript, and you’re right about that. 😂

swelter_spark@reddthat.com on 25 Aug 20:34 collapse

The internet is fast where I live, so there’s no noticeable speed difference.

AfricanExpansionist@lemmy.ml on 30 Aug 00:16 collapse

Illive in a country with the world’s fastest internet speeds and I notice performance differences

Maybe you’re not using a bridge?

swelter_spark@reddthat.com on 11 Sep 21:40 collapse

No, no need to use a bridge where I am.

Interesting. I didn’t know a bridge made so much difference in performance. If only this could be improved.

AfricanExpansionist@lemmy.ml on 12 Sep 15:58 collapse

I find TOR annoyingly slow most of the time, but I try to appreciate its vintage internet qualities

geneva_convenience@lemmy.ml on 23 Aug 23:49 next collapse

<img alt="" src="https://lemmy.ml/pictrs/image/b732bf4b-e0f8-4b34-a0cf-4f1b35d860c1.jpeg">

NutWrench@lemmy.ml on 24 Aug 01:28 next collapse

My VPN is on about 95% of the time, except when I need to pay a local utility bill (or check my bank account) where they need to know my location.

MasterBlaster@lemmy.world on 24 Aug 14:04 collapse

If you’re paying them, why do they need to know your location to accept it? We’re in a capitalist system. Money is money.

Brutticus@midwest.social on 24 Aug 03:12 next collapse

maybe like 75 percent of the time. the Invidious APIs for Freetube.

My job requires secure outlook and access to our database. I do occasionally have to interface with banking sites.

communism@lemmy.ml on 24 Aug 11:14 next collapse

On at all times at the router level. Because it’d be annoying to selectively disable it. My VPN isn’t really an anonymity feature anyway; I have a dedicated browser profile for things like banking where I intend the fingerprint to be associated with my government identity.

gwl@lemmy.blahaj.zone on 24 Aug 11:32 next collapse

UK porn ban, always-on VPN

willington@lemmy.dbzer0.com on 24 Aug 11:58 next collapse

Always, unless by mistake it is off.

MasterBlaster@lemmy.world on 24 Aug 14:02 next collapse

Always on although my Phone VPN recently has failed to start up automatically or has shut down randomly lately and I got to get that fixed.

My reasons are just privacy. I’m not using it to get around regional restrictions. Additionally, it helps when I want to use a public Wi-Fi, especially if it doesn’t have any passports on it.

I will not connect to public wifi without VPN.

non_burglar@lemmy.world on 24 Aug 20:29 next collapse

100% of the time.

My VPN turns on automatically when I leave my home lan. I don’t use split-tunneling, so all my traffic goes back to home before going to internet.

alexquiniou@lemmy.zip on 24 Aug 21:01 next collapse

Always. Wireguard is easy to setup and work like a charm.

Truenas + wireguard for pc, server and phone. Always everywhere.

Crackhappy@lemmy.world on 24 Aug 23:40 next collapse

Always.

Zoma@sh.itjust.works on 25 Aug 23:57 collapse

Allways use your vpn and just spit tunnel things that don’t work with them eg freetube. If you’re getting captchas lots you could look into getting a residential socks5 proxy, I use mullvad’s socks5 they wont be as good as a residential one though.