I was wondering if a VPN would add any kind of security or privacy if one is connecting to a host with a client/browser that supports DNS over HTTPS and that host supports encrypted client hello. Is there a way for the ISP or anything in between to shape traffic or even know what is being accessed? The only thing that should be visible is traffic between two IP addresses right?

4 points
Deleted by creator
permalink
report
reply
6 points
*

[This comment has been deleted by an automated system]

permalink
report
parent
reply
11 points

The DNS traffic might be encrypted but that doesn’t mean that other protocols are. A VPN tunnel encrypts all traffic passing through regardless of protocol.

permalink
report
reply
4 points
*

This is the correct answer. A VPN encrypts and obfuscates all your connections, not just the web browser.

If all you care about is hiding the websites you visit from your ISP, DNS over TLS is fine. But just remember that you’re bleeding data by using your real IP (ISP, geolocation, etc.). And any other connection, is just unabashedly, you.

permalink
report
parent
reply
1 point

Well I was mostly thinking about Usenet but I guess everything else applies. Websites really can leak everything.

permalink
report
parent
reply
1 point

But so does TLS right?

permalink
report
parent
reply
1 point

Yes, HTTPS traffic is encrypted also, but I wouldn’t trust that all of your activity online is hidden just because DNS and HTTPS are encrypted.

Up to you, but I use a VPN when online.

permalink
report
parent
reply
3 points

To add to what the others have said, a VPN requires one end to authenticate to the other. Regular HTTP and DNS connections don’t.

If you need to access a service remotely, doing it over VPN requires the user to authenticate (to use the VPN).

If you simply expose the service publicly, even if the connection to it is encrypted, it doesn’t prevent random strangers from accessing it or trying to break in.

permalink
report
reply
5 points

HTTPS does enforce at least one sided authentication though. In the scenario the service they access is most likely being hosted by a server that does authenticate via X.509 cert.

Unless it’s p2p of course.

permalink
report
parent
reply
-2 points

In this case, a VPN only offers obscuring that you are connecting to the dns over http end point.

permalink
report
reply
5 points

That "traffic between two IP addresse"s is enough reason to use a VPN you trust.

Put it this way, bit torrent traffic can be encrypted and routed over standard ports to make it look like regular web traffic, so still “just traffic between two IP addresses” but you wouldn’t run that without a VPN, would you?

permalink
report
reply

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

!piracy@lemmy.dbzer0.com

Create post
⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don’t request invites, trade, sell, or self-promote

3. Don’t request or link to specific pirated titles, including DMs

4. Don’t submit low-quality posts, be entitled, or harass others


Loot, Pillage, & Plunder


💰 Please help cover server costs.


Community stats

  • 5.6K

    Monthly active users

  • 3.2K

    Posts

  • 84K

    Comments