• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

Merged Should I have a VPN?

Neither is a VPN, since it propagates your cookies and everything else, even if you go through (just) a VPN. For example, I'm still logged into Crunchyroll or for that matter this site, even if I go through a VPN that says I'm in the USA.
Which is what we are talking about. We hear a lot of yap yap.about anonymity, and it's 99% theatre. You are ultimately only anonymous from like your wife casually looking at your devices history.
 
You're not following the linear time thing. I know, it's tricky.

*First*, it was set to delete browsing data. *Much later*, the feature was enabled, and the 'we totally don't store this' data miraculously reappeared. It was absolutely being stored, despite the assurances that it wasn't.
OK, I'm willing to try it. Where is that setting?
 
Which is what we are talking about. We hear a lot of yap yap.about anonymity, and it's 99% theatre. You are ultimately only anonymous from like your wife casually looking at your devices history.
As I was saying, if you actually want anonymity, use TOR. (Though even that led to some people being identified in a sting operation once.) VPNs are mostly just for accessing geo-restricted content.
 
Last edited:
OK, I'm willing to try it. Where is that setting?
Been a while so this is from memory: open a new private tab. Upper left right corner (on mobile anyway) is a settings menu.

In fairness (as I've already said) it's been a while since I bothered with it and it may have changed. Certainly there is a new disclaimer kind of window when a private tab is opened that didn't used to show (just found that out earlier today).

Eta: I checked and had wrong location of settings icon, corrected now
 
Last edited:
As I was saying, if you actually want anonymity, use TOR. (Though even that led to some people being identified in a sting operation once.) VPNs are mostly just for accessing geo-restricted content.
As I was saying, I already did many years ago. Onion routers make any kind of browsing laborious, IMO.

But what we are talking about is what these things do, and are they worth it? I think the answer is "they do almost nothing, so probably not".
 
Been a while so this is from memory: open a new private tab. Upper left (on mobile anyway) is a settings menu.

In fairness (as I've already said) it's been a while since I bothered with it and it may have changed. Certainly there is a new disclaimer kind of window when a private tab is opened that didn't used to show (just found that out earlier today).
Well, I'm on the PC, and I can't find it at a quick look.
 
As I was saying, I already did many years ago. Onion routers make any kind of browsing laborious, IMO.

But what we are talking about is what these things do, and are they worth it? I think the answer is "they do almost nothing, so probably not".
Unless you're trying to see content that's blocked in your country, then no, they're not.
 
Unless you're trying to see content that's blocked in your country, then no, they're not.
A VPN also hides your real IP address, which is actually helpful from the anonymity standpoint, and encrypts your browsing, which again, seems to be another legit safeguard.

Eta: that's what im.really driving at, I suppose. These various free and paid anonymizers don't really seem to deliver what they claim. I used to be more on top.of this, but kinda gave up when none seemed to deliver the goods. Oddly, just straight Firefox with Ghostery enabled keeps me comfortably anonymous, at least insomuch as no one is hitting me with ads.
 
Last edited:
Hmm...

The main thing a VPN provides is an encrypted tunnel that prevents any of the intermediate servers on the internet from sniffing your traffic on the way past.

It also prevents your ISP, or any of the servers on your side of the VPN provider, from logging the IP addresses of the sites you visit. All your ISP sees is the IP address of your VPN provider.

Note that from the point of view of the content provider you're visiting, you are typically always connecting from a different IP address (that is the default mode of most VPNs, each 'person' connecting to the VPN is given an IP address from a 'pool' of available addresses.) If law enforcement asks for the name of the person who connected to site A from IP B, the VPN provider can say: "Sorry we don't know that, IP addresses are randomly assigned and not logged."

The only organisation that knows what IP addresses you visit, is the organisation that provides your VPN, and only while that connection is in process. (Unless they are really stupid and log all connections.)

Note that https provides a similar level of security, in terms of encrypting the information that flows between your computer and the website that you're visiting, but, it can be defeated by a 'man-in-the-middle' attack.

That's difficult to set up because it requires your browser to accept a new certificate for a known site.
(i.e. would require reasonably low level access to your computer when you're not there, or not watching.)

It's interesting that the primary reason Joe Public now uses a VPN is that it provides 'location spoofing' meaning that they can access content that is not available in their geographic location. I suspect that many VPN users have no idea that the rest of the functionality of VPNs exist.
 
A VPN also hides your real IP address, which is actually helpful from the anonymity standpoint, and encrypts your browsing, which again, seems to be another legit safeguard.
Maybe (and I have my misgivings there), but again the question is: what are you using it FOR? What exactly is the threat you're willing to combat? So far you've been going off about how it saves stuff on your computer, but unless the DOJ gets a warrant to confiscate your device, that's irrelevant. Nobody else is going to decrypt your disc (and you can stack that twice as high) to see what sites you've been looking at. I mean, I'm not going to speculate, but again, if you're THAT paranoid, just use TOR. Yeah, it's slow and inconvenient, but it was designed to hide your tracks. That's the price you pay for THAT. For more mundane needs, like watching anime from another country or not wanting to see Google ads for your previous searches, a half-assed solution like just using a VPN or private mode works just fine. Google or Crunchyroll ain't gonna haul your device to a forensics lab. Hell, just use adblock to block the ads, and you're golden.

Hell, for Android there are alternate operating systems that can securely wipe your disc if you input a kill code as a PIN. Among other options. If you're THAT paranoid about what's saved on it, that's an option to remove everything.

Going into all edge cases where some protection fails in some forensics search on your device is good and fine for theoretical purposes, but in real life you just have to think about what's your actual need, and what solves it well enough. There's no need to want an 8" gun if you just want to kill a fly, is all I'm saying.

Like, Jaysus, dude, did you run out of other hypothetical scenarios to rage about?
 
Last edited:
It doesn't claim to be. It claims to be private.
It doesn't even claim that, making it crystal.clear that the only thing that anyone would call remotely private is that you're only being private from your own device because your 'private' activity doesn't show on your regular history.
 
It doesn't even claim that, making it crystal.clear that the only thing that anyone would call remotely private is that you're only being private from your own device because your 'private' activity doesn't show on your regular history.
Or from a site identifying you by cookies. But otherwise, yeah, that's about the extent of it.
 
Maybe (and I have my misgivings there), but again the question is: what are you using it FOR? What exactly is the threat you're willing to combat?
I dont recall saying there was a threat. I recall saying that it is a joke, and yet another example of dumb ◊◊◊◊ people believe.

What interests i have are more aligned with not having profiles built on me, as retailers actually study what the highest amount you will pay for something will be, and cater your views to that. No profile, no catering. I am also back burner concerned about unecesary data collected about me. One dumb cop and i could find myself facing a mountain of electronic evidence, and as you should know, with a mountain of data, you can concoct almost any story you want, and have the receipts. I got on the wrong end of what a dumb cop/prosecutor can bring to your door when I was a teen- it's much worse now.

The rest you just pulled straight out of your ass, so I'm not much interested in crossing swords with your imagination.
 
Last edited:
I dont recall saying there was a threat. I recall saying that it is a joke, and yet another example of dumb ◊◊◊◊ people believe.

What interests i have are more aligned with not having profiles built on me, as retailers actually study what the highest amount you will pay for something will be, and cater your views to that. No profile, no catering.
Then that is the threat. Or call it a problem to solve if you're more comfortable with that.

But then how do you deal with retailers connecting by card number and shipping address? Your IP is the least of your problems there. Your IP can change every day. Your credit card and shipping address don't. Any half-competent data miner would identify you as the same person in a second. (Which, granted, from my experience, is a stretch. Most programmers are not even a quarter competent:P)

The rest you just pulled straight out of your ass, so I'm not much interested in crossing swords with your imagination.
Well, I'm bored and drunk, so I engaged with the delusional imaginary scenarios you pulled out of yours to have another fake outrage :P
 
Last edited:
Then that is the threat. Or call it a problem to solve if you're more comfortable with that.
I.make a pretty big distinction between threats that I am.raging and battling against, and mild nuisances. YMMV.
But then how do you deal with retailers connecting by card number and shipping address?
They generally dont see my CC#s. I use old school PayPal, or one-time CC#s my bank offers as a free online shopping convenience.

If retailers are using my info to be able to charge me more, they are failing miserably. Nobody scores better deals than yours truly.
Your IP is the least of your problems there. Your IP can change every day. Your credit card and shipping address don't. Any half-competent data miner would identify you as the same person in a second. (Which, granted, from my experience, is a stretch. Most programmers are not even a quarter competent:P)
If they were relying on my shipping address, God help them to make sense of any of it. I use it for personal and work deliveries, as does my wife and our adult kids who use it as a permanent address. I dare them to pick up usable buying patterns, LOL.
Well, I'm bored and drunk, so I engaged with the delusional imaginary scenarios you pulled out of yours to have another fake outrage :P
See, that's what I'm talking about. I have invoked... let's see, 6 and carry the 3... exactly zero hypotheticals, and expressed zero outrage over anything. Maybe I could get a hit of what you're drinking? Sounds like some good ◊◊◊◊!
 
Last edited:
I.make a pretty big distinction between threats that I am.raging and battling against, and mild nuisances. YMMV.
Well, it's SOMETHING you're trying to solve, no matter how you call it. You can still start from there when figuring out a solution. That's all I was saying.

They generally dont see my CC#s. I use old school PayPal, or one-time CC#s my bank offers as a free online shopping convenience.
They can still remember you by that banking info, even if it's Paypal.

If retailers are using my info to be able to charge me more, they are failing miserably. Nobody scores better deals than yours truly.
Compare to whom, and based on what sample? The imaginary people in your head?

If they were relying on my shipping address, God help them to make sense of any of it. I use it for personal and work deliveries, as does my wife and our adult kids who use it as a permanent address. I dare them to pick up usable buying patterns, LOL.
They will anyway, in case it hits any of you. Plus, they still have your MAC address anyway, which is different from your wife's or your kids', and different login cookies unless you all use the same computer. And I guess you COULD have given them all the login and 2FA for your Paypal account, but otherwise they could correlate that. If they wanted to. So, yeah, placebo effect,

Also, do you use a different email address every time? Because that's the #1 way to correlate who someone is across multiple sites. Including some recent doxxing cases.

See, that's what I'm talking about. I have invoked... let's see, 6 and carry the 3... exactly zero hypotheticals, and expressed zero outrage over anything. Maybe I could get a hit of what you're drinking? Sounds like some good ◊◊◊◊!
No, you invoked things pulled out of your ass, with zero evidence, zero base in actual programming experience, zero everything else. Even zero understanding your browser. Zero understanding how even e-commerce works, if you think they just want to overcharge you, as opposed to advertise to you. Just you BELIEVE that it gets you better deals. As usual. That's actually worse than hypotheticals.
 
Last edited:
Uh, what? MAC addresses aren't transmitted over TCP/IP; only IP addresses are.
Your ISP can see it. Any WiFi, including in some cafe can see it. Plugins can see it. It used to be all the rage to have the user download some ActiveX thingie that then sent the MAC back. Or really any site that requires you use some plugin or player or anything of any kind.

Java can too, back when it was actually used in browsers:

InetAddress ip = InetAddress.getLocalHost();
NetworkInterface network = NetworkInterface.getByInetAddress(ip);
byte[] mac = network.getHardwareAddress();

JavaScript normally can't, unless it uses a browser exploit. It's not like those don't pop up all the time, though. Or if you run the code in node.js, but that doesn't apply to most users. (See, several libraries that do that.)

So can any internet programs, really. E.g., online games. So you ain't gonna fool, say, Blizzard by using a VPN to troll. Or Android apps for that matter, before Android 10. Later, not without you giving them whatever privileges they want. (Which most people just accept anyway.)

if nothing else, but there's nothing to prevent someone from sending it in the payload.
 
Last edited:

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom