I’ve never completely understood this, but I think the answer would probably be “no,” although I’m not sure. Usually when I leave the house I turn off wifi and just use mobile data (this is a habit from my pre-VPN days), although I guess I should probably just keep it on since using strange Wi-Fi with a VPN is ok (unless someone at Starbucks is using the evil twin router trick . . . ?). I was generally under the impression that mobile data is harder to interfere with than Wi-Fi, but I could well be wrong and my notions out of date. So, if need be, please set me straight. 🙂

28 points
*

Commercial VPNs as a security measure are pretty much a scam, at least in the way they are marketed.

These days, basically any web traffic is encrypted through HTTPS. Even on an untrusted network, nobody will be able to see the actual content (passwords, personal data) of what you’re doing. DNS spoofing isn’t viable either as any fake site they would send you to would lack the right certificates to establish a convincing HTTPS connection. So all someone can see is what servers you’re connecting to, either by logging your DNS requests (can be prevented by using some form of encrypted DNS like DNS over HTTPS) or the IP addresses you connect to. And honestly, how much value does one get out of knowing that there’s someone on their network who browses beehaw.org, supergreatbank.com and bigtiddygothgfs.to with no information to connect that to an actual person?

Unless you routinely use shady open Wi-Fi networks - and I’m talking about something that may have been setup on purpose by a malicious actor, not your local supermarket - to do security-critical stuff, you don’t need a VPN. Also, if you trust your mobile data provider less than a company that tricks people into thinking you absolutely need their product to secure your data, you should get a different mobile data provider.

Now, there are use cases for VPNs but those are more along the lines of accessing stuff that’s not available in whatever region you’re currently in.

See also Tom Scott’s video on the topic. It’s a few years old but still relevant.

Edit: there is of course also the use case of hiding illegal stuff. In that case, I will not give any advice. Put some onions on top of your router or something, that’s probably cheaper and more reliable.

Edit 2: just to make this entirely clear, I’m talking about commercial VPNs like NordVPN, Surfshark and whoever else pays YouTubers to advertise for them. If you host your own VPN, some of the downsides may not be as relevant. Though I would assume that anyone who even considers hosting their own VPN has enough technical knowledge about how networking works to know about the pros and cons.

permalink
report
reply
15 points

Do you want a random third party looking at all of your mail before you pick it up? Even if they can’t open the envelope, having somebody else write down every message that comes in who it’s from and who it’s too and how frequent it is, that creep me out.

If you’re uncomfortable with a third party looking at your mail, it’s very reasonable to not one third party’s looking at your internet traffic. It’s the same thing.

permalink
report
parent
reply
22 points

A commercial VPN provider is just another random third party.

permalink
report
parent
reply
18 points
*

You get to choose them. You can research them. They don’t have a geographic monopoly on your internet connection. That gives you more control, and then more incentives to do the right thing

If you pay for your VPN using crypto, then they can’t tie it to your name, when they’re reselling the traffic it’s harder to tie it to an identity

https://www.privacyguides.org/en/basics/vpn-overview/

A VPN has many advantages, including:

  1. Hiding your traffic from only your Internet Service Provider.
  2. Hiding your downloads (such as torrents) from your ISP and anti-piracy organizations.
  3. Hiding your IP from third-party websites and services, helping you blend in and preventing IP based tracking.
  4. Allowing you to bypass geo-restrictions on certain content.

VPNs can provide some of the same benefits Tor provides, such as hiding your IP from the websites you visit and geographically shifting your network traffic, and good VPN providers will not cooperate with e.g. legal authorities from oppressive regimes, especially if you choose a VPN provider outside your own jurisdiction.

permalink
report
parent
reply
6 points

That, unlike your ISP, isn’t obligated by law to log the connections you make (‘data retention’). Depending on the jurisdictions.

permalink
report
parent
reply
6 points

HTTPS, sure. But your ISP can and will create a pretty comprehensive social graph about you using only metadata (server IPs or hostnames). Where I live, all home networks basically have a static IP. Also, besides a commercial incentive, ISPs are also mandated to log your connections. VPNs are not.

permalink
report
parent
reply
1 point

As a gay pirate assassin I encourage everyone to watch that Tom Scott video

permalink
report
parent
reply
24 points

Usually when I leave the house I turn off wifi and just use mobile data

I would stronly recommend that you set your wifi to only join trusted networks. That way you can also just leave the wifi on and not have it connect to every random network it encounters.

permalink
report
reply
6 points
*

I would still recommend turning wifi off when leaving home for privacy reasons (which can easily be automated). The process to identify if a network is trusted or not requires a handshake. So leaving wifi on makes you trackable by the wifi network operators and the apps on your phone with access to your wifi, wether you connect a network or not.

permalink
report
parent
reply
22 points

You’re hiding your traffic route from your mobile operator and giving it instead to your vpn company who swear they are honest

permalink
report
reply
20 points
*

I run my own wireguard VPN at home and connect to it from my phone when I’m traveling.

Grants me privacy (but not anonymity) from my mobile carrier. Sure, my home ISP still sees my VPN’s traffic, but that’s still one less company able to monitor my web traffic when I’m mobile.

permalink
report
parent
reply
5 points

Running your own VPN in that situation is a good use-case agreed - assuming you trust yourself :)

permalink
report
parent
reply
8 points

I’m experienced enough to know that out of my mobile carrier and ISP, I am the least trustworthy operator.

permalink
report
parent
reply
3 points

Same. Also feels a bit safer connecting to public wifi.

permalink
report
parent
reply
1 point
*

Well facebook VPN waa sniffing data to see what other Social media the person was using. But something like Proton that prides itself on privacy and encryption should be fine

permalink
report
parent
reply
2 points

Absolutely. Unless they’re actually evil. Which I’m sure they aren’t. But they could be.

permalink
report
parent
reply
14 points

Your provider will just see encrypted traffic (mostly), so yes it will provide protection.

permalink
report
reply
8 points

Only if you trust your VPN service more than your mobile Internet provider.

permalink
report
parent
reply
6 points

You forget that nation-states control your ISP. And of course you can choose your VPN provider or run your own.

permalink
report
parent
reply
7 points

Your provider will just see encrypted traffic (mostly) anyway, so no it will not provide protection. The only thing that you’re now hiding from your provider is which servers you’re connecting to. Instead you’re showing that info to a VPN company whose main business practice is scaring people into buying a product they probably don’t need. Think about who you would trust more.

permalink
report
parent
reply
6 points

Your replies all make a very big assumption that the only connections being made, by people who are advocating VPNs, are over https (or possibly ssh) and thus VPN isn’t necessary. There exists more services than that some of which aren’t end-to-end encrypted (many messaging apps, for example).

Also, I agree that at the end of the day, a user is trusting someone not to snoop. But given that ISPs have been proven to snoop (for various reasons), I personally will put my trust in a VPN provider that I have researched and one that has shown a considerable resilience against outside forces. Mullvad comes to mind here.

Yes, a VPN is probably overkill if all the user is doing is using a web browser, nowadays. But it is useful beyond just setting up a tunnel for access.

permalink
report
parent
reply
5 points

Although it is possible that some messaging apps send completely unencrypted messages, most (reputable) non-E2E apps are probably still using HTTPS. It just means that when the message arrives at the messaging app’s servers, they can decrypt the message and store it in plaintext.

permalink
report
parent
reply
3 points

A VPN doesn’t do much to protect HTTP connections.

permalink
report
parent
reply
6 points

The provider and national TLAs will see all traffic that is in cleartext and meta traffic which is even more valuable. It can also actively tamper with that traffic. So you’re technically incorrect and you assume your threat model is universal. It’s not. And, of course, there are use cases for Tor, whether with or without VPN.

permalink
report
parent
reply
3 points
*

While my threat model is not universal, it comes close, at least for the average user which OP seems to be from their question. In practice, there is very little unencrypted traffic these days and in the case of that traffic you will have to ask yourself if your (commercial) VPN provider is more trustworthy than your ISP.

If you need to ask if you need a VPN there’s a 99% chance that you don’t. There are certainly a few use cases for both commercial VPNs and TOR (see my other comment) but to even be aware that those apply to you, you probably already have enough technical knowledge to approach the question from the direction “I want to do XYZ, how can I be more secure?” and not “I’ve heard of VPNs, do I need one?”

permalink
report
parent
reply
13 points
*

Using a VPN for your mobile traffic protects your mobile traffic from Flow analysis from your mobile operator. So that is a strict net benefit.

permalink
report
reply

Technology

!technology@beehaw.org

Create post

A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.

Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.

Subcommunities on Beehaw:


This community’s icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.

Community stats

  • 3K

    Monthly active users

  • 3.3K

    Posts

  • 81K

    Comments