Gaming The VPN Fallacy

Do you use a VPN?

  • Yes

    Votes: 14 23.7%
  • No

    Votes: 17 28.8%
  • For some purposes

    Votes: 28 47.5%

  • Total voters
    59

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,329
Trophies
2
XP
18,209
Country
Sweden
Tor =/= Full anonymity. It's been proven a couple of times that people been caught using TOR. Use a VPN + TOR if you wish to be safer. I use PIA that have been proven in court not to log anything at all!
I would rank your post more as scare mongering than anything else. A VPN is better than not if you use a public wifi or want to hide your IP.
 
  • Like
Reactions: 6adget

Alexander1970

XP not matters.
Member
Joined
Nov 8, 2018
Messages
14,973
Trophies
3
Location
Austria
XP
2,498
Country
Austria
For some purposes.

Mainly for watching Videos or Live Streams from TV Mediathekes,because they are not allowed in Austria (due Country restrictions mainly from Germany.....:rolleyes: ).
 
Last edited by Alexander1970,

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,316
Trophies
4
Location
Space
XP
13,893
Country
Norway
In order to access Tor in China you'll need to use a bridge. Use the built in meek-azure pluggable transport. China can't block it because that would mean blocking Microsoft Azure.
I would not put it past the Chinese government to do such a thing. They are blocking a rather large part of the Internet already after all, I would not be surprised at all if they were to block a little more.
 
  • Like
Reactions: Deleted-236924

dAVID_

Well-Known Member
OP
Member
Joined
Oct 23, 2016
Messages
1,405
Trophies
1
Location
The Game
XP
2,276
Country
Mexico
Tor =/= Full anonymity. It's been proven a couple of times that people been caught using TOR. Use a VPN + TOR if you wish to be safer. I use PIA that have been proven in court not to log anything at all!
I would rank your post more as scare mongering than anything else. A VPN is better than not if you use a public wifi or want to hide your IP.
VPN over Tor can only be helpful if you have complete trust in your VPN provider, which is absolutely impossible. They don't need to keep logs in order to do a timing correlation attack on Tor. All they need is the exact time you made a request on their servers, and the exact time an exit node that you are using sends a request to a site.
On the other hand, at the very least you can be sure that the people developing Tor aren't trying to monitor your traffic. This is because Tor is free and open source software. Attempting to implement a backdoor into source code that anyone can see is useless. VPN providers cannot prove that they are not monitoring your traffic.
"But you can't trust Tor nodes to not monitor your traffic either".
No, you can't have complete trust in Tor nodes either. Who's to say they're not monitoring my traffic?". That's right, but at the very least you can be 100% sure that the developers of Tor are not attempting to snoop on your data.

Also, even if an attacker attempts an ARP spoofing attack in order to downgrade your connecting to HTTP, your browser will probably alert.
And even if an attacker was successful, all it takes to avoid having your data exposed is common sense. In other words, not entering sensitive data on HTTP sites.

Also, I'd say this post is the opposite of scare mongering. All I am doing is talking about the common misconceptions about VPN services, and what they do and don't provide.

I think these links pretty much sum up my thread:
https://matt.traudt.xyz/posts/you-want-tor-24tFBCJV.html
https://matt.traudt.xyz/p/mRikAa4h.html

--------------------- MERGED ---------------------------

The lock icon is often confusing for non-tech savvy. On sites like this one you will (sometimes) get warnings of mixed content (secure site but insecure content pulled in from other sources).

As said, if you just want a secure tunnel and not a different IP you can setup a VPN server at home for free.
Tor already does this. Your connection to the Tor network is always encrypted.
 
  • Like
Reactions: ThoD

UltraDolphinRevolution

Well-Known Member
Member
Joined
Jul 30, 2016
Messages
1,806
Trophies
0
XP
2,436
Country
China
Just make sure you're using the meek-azure pluggable transport, or chinese authorities might realize.
They might have already. The first day was slow but I could watch youtube videos in 144p pretty easily. Now it's basically impossible.
Then again, I have no idea what I'm doing. Before starting it I choose meek-azure, but I didn't change anything so I don't why it is working so poorly now. Maybe their system already figured it out.
 

bodefuceta

Well-Known Member
Member
Joined
Apr 3, 2018
Messages
436
Trophies
0
XP
1,267
Country
Brazil
I agree with most of what you said. Though you seem to believe Tor is some sort of silver bullet, it most definitely is not. Remember you only need to control 2 nodes of someone's circuit, or 1 node and one clearnet pathway, to completely deanonymize someone, and it's widely believed NSA has access to over 50% of all nodes and most of the clearnet paths.

TOR is basically a military project designed to honeypot foreign governments into believing it is secure. They will NOT use access to your data to give you piracy warnings nor expose you downloaded illegal content, to keep TOR's security believable. But will ABSOLUTELY sniff on secret information. Mostly relevant if you have ties to government.

Even the hacker group lizard squad (or something) managed to sniff on most of TOR traffic by renting servers and operating TOR nodes on them. I think all of wikileaks first release batch was sniffed from TOR too. It's also believed some popular darkweb markets were taken down through these vulnerabilities. Using TOR helps other people blending in, but nothing can be done if the nodes are compromised.
 
Last edited by bodefuceta,

ThoD

GBATemp Addict (apparently), but more like "bored"
Member
Joined
Sep 8, 2017
Messages
3,631
Trophies
1
Age
27
XP
3,049
Country
Greece
I agree that Tor is the best choice, VPNs are overrated in security. Also, while it hasn't been mentioned in this thread, I should point something out for anyone who thinks using Opera is good because of the built-in VPN... it's NOT, Opera clearly states that they ARE logging your data when you use the built-in VPN if you go over their agreement. One more thing, on the topic of VPNs, 99% of them only use either 1-2 nodes, claimining it's safe, when it's very easy to get past just that much security with advanced tools and a tiny little bit of patience, ESPECIALLY if the one trying to steal your data is in the same network (eg: public networks), hell, most VPNs do nothing against attacks from the same network so it's all on your OS's settings and firewall alone, since while they can't steal your data packets, they can ridiculously easily install a remote access tool in seconds without you even realizing it even with VPN active (and before some idiot says "they can't do that if you use VPN", they can, even the standard RATs you find on the clearweb can do that much).
 

ghjfdtg

Well-Known Member
Member
Joined
Jul 13, 2014
Messages
1,362
Trophies
1
XP
3,291
Country
Tor already does this. Your connection to the Tor network is always encrypted.
If you can live with the slowness. Not as bad as it used to be but still slow. It's also overkill for this scenario in my opinion because all you really need is a secure tunnel and not a network designed against censorship.
 

Ericthegreat

Not New Member
Member
Joined
Nov 8, 2008
Messages
3,455
Trophies
2
Location
Vana'diel
XP
4,287
Country
United States
Pretty sure all the people who recommend vpn's are either corporate paid trolls, or brainwashed people. A few years ago a guy would post on Reddit that he got an isp warning letter, people would say "throw it in the trash", now they get 20 people telling them how stupid they are and how they might get sued because they didn't get a VPN, many of these also talk about the price like "it's $26 for a year idiot", seems to be the only real reason to use a VPN is if you pirate porn.
 
Last edited by Ericthegreat,
  • Like
Reactions: ThoD

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,329
Trophies
2
XP
18,209
Country
Sweden
Pretty sure all the people who recommend vpn's are either corporate paid trolls, or brainwashed people. A few years ago a guy would post on Reddit that he got an isp warning letter, people would say "throw it in the trash", now they get 20 people telling them how stupid they are and how they might get sued because they didn't get a VPN, many of these also talk about the price like "it's $26 for a year idiot", seems toe the only real reason to use a VPN is if you pirate porn.
hmm? I use my VPN service for various reasons. I sure as heck won't want to be connected without a VPN on an airport network. There is a whole bunch of reason to get an VPN. It's not just for piracy. And that example you gave was probably because of a faulty torrent client leaking info via the DHT network.
 

dAVID_

Well-Known Member
OP
Member
Joined
Oct 23, 2016
Messages
1,405
Trophies
1
Location
The Game
XP
2,276
Country
Mexico
I'd rather my ISP see my activity than risk scrutiny from authorities for even touching tor.
Don't you think they're already on to you for using a VPN? Also, just using Linux puts you on a watchlist, so I wouldn't worry too much.

I agree with most of what you said. Though you seem to believe Tor is some sort of silver bullet, it most definitely is not. Remember you only need to control 2 nodes of someone's circuit, or 1 node and one clearnet pathway, to completely deanonymize someone, and it's widely believed NSA has access to over 50% of all nodes and most of the clearnet paths.

TOR is basically a military project designed to honeypot foreign governments into believing it is secure. They will NOT use access to your data to give you piracy warnings nor expose you downloaded illegal content, to keep TOR's security believable. But will ABSOLUTELY sniff on secret information. Mostly relevant if you have ties to government.

Even the hacker group lizard squad (or something) managed to sniff on most of TOR traffic by renting servers and operating TOR nodes on them. I think all of wikileaks first release batch was sniffed from TOR too. It's also believed some popular darkweb markets were taken down through these vulnerabilities. Using TOR helps other people blending in, but nothing can be done if the nodes are compromised.

Yeah, that's what I said. You only need to control two Tor nodes. However, where did you get the "NSA controls 50% of Tor nodes part"? I'd like to know.

Also, believing Tor or any tool provides perfect anonymity is foolish. If your adversary has enough power, they will find you.

If you can live with the slowness. Not as bad as it used to be but still slow. It's also overkill for this scenario in my opinion because all you really need is a secure tunnel and not a network designed against censorship.

Like I said earlier, your connection to the Tor network is encrypted. In fact, the only Tor node that can see unencrypted data (not counting HTTPS) is the exit node.
 
  • Like
Reactions: yuyuyup

dAVID_

Well-Known Member
OP
Member
Joined
Oct 23, 2016
Messages
1,405
Trophies
1
Location
The Game
XP
2,276
Country
Mexico
They might have already. The first day was slow but I could watch youtube videos in 144p pretty easily. Now it's basically impossible.
Then again, I have no idea what I'm doing. Before starting it I choose meek-azure, but I didn't change anything so I don't why it is working so poorly now. Maybe their system already figured it out.

That's weird. Alternatively, you could go to bridges.torproject.org and request an obfs4 bridge (the default one won't work because the chinese authorities blocked it). I don't know if they can detect obfs4 traffic, but if you can't connect to meek-azure at all you should try this.
And if that doesn't work either, consider using Snowflake, an experimental pluggable transport.
 

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,329
Trophies
2
XP
18,209
Country
Sweden
Well TOR was created by DARPA. So to hide their agents they made it public, turning in to a hidden in plain sight situation. But yeah, NSA have spyed on TOR users before, especially by exit nodes.
"
So no, Tor won't make you anonymous, just a bit harder to find.

"An adversary may try to de-anonymize the user by some means. One way this may be achieved is by exploiting vulnerable software on the user's computer.[16] The NSA had a technique that targets a vulnerability – which they codenamed "EgotisticalGiraffe" – in an outdated Firefox browser version at one time bundled with the Tor package[17] and, in general, targets Tor users for close monitoring under its XKeyscore program.[18] Attacks against Tor are an active area of academic research[19][20] which is welcomed by the Tor Project itself.[21] The bulk of the funding for Tor's development has come from the federal government of the United States,[22] initially through the Office of Naval Research and DARPA.[23]"

How else do you think they manage to take down pedonetworks etc on Tor if it was 100% secure? It isn't, and never will be.
 

dAVID_

Well-Known Member
OP
Member
Joined
Oct 23, 2016
Messages
1,405
Trophies
1
Location
The Game
XP
2,276
Country
Mexico
Well TOR was created by DARPA. So to hide their agents they made it public, turning in to a hidden in plain sight situation. But yeah, NSA have spyed on TOR users before, especially by exit nodes.
"
So no, Tor won't make you anonymous, just a bit harder to find.

"An adversary may try to de-anonymize the user by some means. One way this may be achieved is by exploiting vulnerable software on the user's computer.[16] The NSA had a technique that targets a vulnerability – which they codenamed "EgotisticalGiraffe" – in an outdated Firefox browser version at one time bundled with the Tor package[17] and, in general, targets Tor users for close monitoring under its XKeyscore program.[18] Attacks against Tor are an active area of academic research[19][20] which is welcomed by the Tor Project itself.[21] The bulk of the funding for Tor's development has come from the federal government of the United States,[22] initially through the Office of Naval Research and DARPA.[23]"

How else do you think they manage to take down pedonetworks etc on Tor if it was 100% secure? It isn't, and never will be.

That vulnerability only affected people who used outdated version of Tor Browser, since NoScript wasn't enabled by default.
Also, I don't recall describing Tor Browser as a tool that gives you complete anonymity. The truth is that no software is bulletproof, and if that you can always be deanonymized if your adversary is powerful enough.

However, I think believing that the NSA can't gain access into VPN servers is a bit naive.
 
  • Like
Reactions: ThoD

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,329
Trophies
2
XP
18,209
Country
Sweden
That vulnerability only affected people who used outdated version of Tor Browser, since NoScript wasn't enabled by default.
Also, I don't recall describing Tor Browser as a tool that gives you complete anonymity. The truth is that no software is bulletproof, and if that you can always be deanonymized if your adversary is powerful enough.

However, I think believing that the NSA can't gain access into VPN servers is a bit naive.
Oh the NSA probably have more 0days than Snowden knew about.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BakerMan @ BakerMan:
    i said i was sleeping...
  • BakerMan @ BakerMan:
    sleeping with uremum
  • K3Nv2 @ K3Nv2:
    Even my mum slept on that uremum
  • TwoSpikedHands @ TwoSpikedHands:
    yall im torn... ive been hacking away at tales of phantasia GBA (the USA version) and have so many documents of reverse engineering i've done
  • TwoSpikedHands @ TwoSpikedHands:
    I just found out that the EU version is better in literally every way, better sound quality, better lighting, and there's even a patch someone made to make the text look nicer
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    DinohScene @ DinohScene: when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying