• Security incident: ISF was recently accessed by intruders. Please change your password, and change it anywhere else you used it. Read more

Merged Should I have a VPN?

Well, it's SOMETHING you're trying to solve, no matter how you call it. You can still start from there when figuring out a solution. That's all I was saying.
No, it's not. I'm not trying to solve/battle/rage against anything. You may have forgotten what prompted this drift, but another member opined that these private browsers aren't all they were cracked up to be. I agreed, and have said more than once that I pretty much gave up on them, and have asked about particulars about some of the details (that's what a discussion thread is for).

This whole thing you keep repeating about battles and problem solving and raging is entirely between your ears.
They can still remember you by that banking info, even if it's Paypal.
How so? Broadly, PayPal works like PP using their own credit card for payments, then hits up mine for reimbursement. The vendor never sees my info, directly or otherwise.

I take PayPal payments from customers sometimes, often if they want to pay by credit card (rare, with my customer base). I never see anything about the personal payment method, except that I get hit for another couple percent if they used a CC instead of direct debit.
Compare to whom, and based on what sample? The imaginary people in your head?
Knowing prices when I shop from searching them before buying. Pretty much most people can handle this, and know how to comparison price and what going rates are. This is news to you?

For instance, the last personal online purchase I made was a pair of Vans sneakers, Seldan model in Tonal Check Drizzle color, and one of the most common sizes (US men's 11.5). Retails for $70. I paid $29.95 shipped, not open box or anything, brand new in factory packaging. Find me a substantially better deal before you freaking lecture me about how I don't know how to make a dollar tap out.
They will anyway, in case it hits any of you. Plus, they still have your MAC address anyway, which is different from your wife's or your kids', and different login cookies unless you all use the same computer. And I guess you COULD have given them all the login and 2FA for your Paypal account, but otherwise they could correlate that. If they wanted to. So, yeah, placebo effect,
...wut? PayPal is 2FA, but that is done on a different connection than the retailers checkout. You log in to PayPal seperately, then they interface with the retailer. The seller never knows through what institution i paid.
Also, do you use a different email address every time? Because that's the #1 way to correlate who someone is across multiple sites. Including some recent doxxing cases.
I use several, yes, including ones associated with other addresses in other States, and occasionally fire up a new dummy email if I have doubts about the seller.
No, you invoked things pulled out of your ass,
That is a lie.
with zero evidence
LOL, the exact same amount as you provided for many more claims you made.
zero base in actual programming experience,
...yes... yes, because we are not remotely discussing programming. Do you plan to criticize my lack of dentistry expertise, too?
zero everything else.
Meaningless.
Even zero understanding your browser.
Lol, I understand it's operation at the user level just fine. You are the one claiming to be constantly surprised by what features it has.
Zero understanding how even e-commerce works, if you think they just want to overcharge you, as opposed to advertise to you.
Then yet again, you think wrongly. I said (as most people are aware of) that algorithms are analyzed to figure out what you are willing to pay. I did not, per your delusional claim, say that was only what they did. They do a ton of stuff, that's just one thing.
Just you BELIEVE that it gets you better deals.
Again, you're off for a ride on the Imagination Train. I make a dollar bleed and never impulse buy, due to growing up with not much disposable income. You find a better price on those Van's yet? BTW, I'm sure you couldn't figure this out on your own, but look at Amazon's selling price for those shoes. It shows the $29.95 as the low selling price on the history, and there is no better price out there. $30 is stupid low for this years Vans.
As usual.
There it is. You're just doing the That Thread thing, making silly claims and repeating them till you think it sounds believable with the repetition. Lame, babes.
That's actually worse than hypotheticals.
Then you acknowledge that you were lying about hypotheticals? Great, that's forward motion. Now, can you show where I "pulled anything out of my ass"? Or should we just acknowledge in advance that you are lying about that too? It does save time.
 
Last edited:
Your ISP can see it. Any WiFi, including in some cafe can see it. Plugins can see it. It used to be all the rage to have the user download some ActiveX thingie that then sent the MAC back. Or really any site that requires you use some plugin or player or anything of any kind.

This is a red herring, and not a good one. We're talking about internet in 2026, not in 1996.

First, ISP's only have the MAC address of your gateway\router, not your individual device. Which is what Thermal was referring to, I believe.

Websites haven't used ActiveX in forever because that "rave" was a security risk that no one would put up with. Even Microsoft Defender would instantly remove\block anything that gives out system details without user approval.

That WiFi in the cafe would also only get your WiFi MAC Address, but your cellular signal uses a different identifier.

There is no standard, non-software related way for a company to get your MAC address. It would require, as someone mentioned later, specific approval and something to be installed to get it.

MAC addresses are layer 2 traffic that are stripped at the router. It doesn't get sent on.
Java can too, back when it was actually used in browsers:

InetAddress ip = InetAddress.getLocalHost();
NetworkInterface network = NetworkInterface.getByInetAddress(ip);
byte[] mac = network.getHardwareAddress();

Yeah, back when...this isn't that time anymore. It doesn't happen, and now browsers block such information from going unless, again, specifically approved by the user. Browsers don't even gather MAC address information by default.
JavaScript normally can't, unless it uses a browser exploit. It's not like those don't pop up all the time, though. Or if you run the code in node.js, but that doesn't apply to most users. (See, several libraries that do that.)

All of which would be blocked by even the most basic security that's built-in to any phone or laptop.
So can any internet programs, really. E.g., online games. So you ain't gonna fool, say, Blizzard by using a VPN to troll. Or Android apps for that matter, before Android 10. Later, not without you giving them whatever privileges they want. (Which most people just accept anyway.) if nothing else, but there's nothing to prevent someone from sending it in the payload.

There are so many things preventing it from being sent via payload. I don't know if you work in networking or network security, but this seems like the working knowledge of someone who hasn't been in the game in 15 years. It's pretty outdated.
 
Last edited:
...this seems like the working knowledge of someone who hasn't been in the game in 15 years. It's pretty outdated.
That's my impression too, but I am very admittedly out of the tech loop and more inclined to listen to you guys who have more up-to-date and practical, in-depth experience.

And yeah, router v device was the distinction I was making. I'm not sure how that pans out with a mobile operating without wifi though (internet connection via standard cel service). What address would be picked up in that case, assuming the device had as masked IP via VPN or whatever?
 
That's my impression too, but I am very admittedly out of the tech loop and more inclined to listen to you guys who have more up-to-date and practical, in-depth experience.

And yeah, router v device was the distinction I was making. I'm not sure how that pans out with a mobile operating without wifi though (internet connection via standard cel service). What address would be picked up in that case, assuming the device had as masked IP via VPN or whatever?

Well, again, not a lot of websites are looking for device hardware information because that's kind of yesterdays news. I believe the most used is what's called Browser Fingerprinting:
Browser Fingerprinting: Combining your canvas rendering hashes, WebGL configurations, installed fonts, and screen resolution to create a unique ID.

Pretty much everything else will be changed through the VPN in a standard session. Most websites you actively buy from don't really need that stuff (they absolutely still collect it, and always will) since you provide them with information willingly. Even if, as in your case, several users use the same IP address, location, etc. it doesn't really matter if their ads are specifically tailored to you (Thermal), as long as they're tailored to your household.

I've been a networking guy for a long time but I'm probably the worst when it comes to security stuff. I'm practically endorsed by Google. I have the Google Pixel 11 phone, I use 5-6 chromecasts in my house, we use Google Chrome as all of our browsers, and all of us have Gmails accounts. I just genuinely don't really care what information they're getting from me. It means very little. I don't volunteer anything, make no mistake, but I'm not as aggressive with covering my tracks as I used to be. If the dumb ◊◊◊◊◊ at Google want to know that I paid $3.46 for a gallon of milk, let them.
 
Last edited:
Well, again, not a lot of websites are looking for device hardware information because that's kind of yesterdays news. I believe the most used is what's called Browser Fingerprinting:


Pretty much everything else will be changed through the VPN in a standard session. Most websites you actively buy from don't really need that stuff (they absolutely still collect it, and always will) since you provide them with information willingly. Even if, as in your case, several users use the same IP address, location, etc. it doesn't really matter if their ads are specifically tailored to you (Thermal), as long as they're tailored to your household.
Seriously good stuff, thanks for that. Never heard of browser fingerprinting, and didn't realize is is that sophisticated. I mean, incorporating screen resolution into the ID? Wow.
I've been a networking guy for a long time but I'm probably the worst when it comes to security stuff. I'm practically endorsed by Google. I have the Google Pixel 11 phone, I use 5-6 chromecasts in my house, we use Google Chrome as all of our browsers, and all of us have Gmails accounts. I just genuinely don't really care what information they're getting from me. It means very little. I don't volunteer anything, make no mistake, but I'm not as aggressive with covering my tracks as I used to be. If the dumb ◊◊◊◊◊ at Google want to know that I paid $3.46 for a gallon of milk, let them.
LOL, I hear you. it's really a very back burner thing from me. I just wonder if there is a relatively cheap and simple way to stay +/- off being profiled unnecessarily that doesn't become a pain in the ass while browsing. Firefox and Ghostery seems pretty bang-up for me, at least to the effect of no ads and no spam in my inboxes.

I think you have my shared experience of the cop and prosecutor who did you wrong? That's my secondary concern, having a mountain of digital activity available that you could retrofit almost any "proof" of wrongdoing with. The idea that such a trove is available (or could be) is back burner unsettling too.
 
Your ISP can see it. Any WiFi, including in some cafe can see it.
Most people these days use a router of some description, usually supplied by their ISP. The ISP can see that device's MAC address, but not the addresses of the computers behind it.

Where you're correct is:
  • There are exploits there will trick the browser into revealing the MAC address, but as far as I know they're rare
  • A program other than a browser, such as a media player, a game with a local component, a PDF reader, or AI agent connecting to the internet can get the MAC address and transmit it

Your standard run of the mill web site isn't getting the MAC address, only the IP address assigned to it by the ISP. That in turn is sometimes mitigated by:
  • Carrier-grade NAT: due to a shortage of IPv4 addresses, some ISPs are exposing a single IPv4 address for a block of customers, and using Network Address Translation methods to route the packet back to the correct subscriber
  • IPv6 has ways to obscure the the full IP address

As far as collecting identifying information goes, browser fingerprinting [Wikipedia] is a thing, too. It's a bit of JavaScript that collects as many metrics as it can from the browser to build up a remarkably unique identifier for a given browser. Both Firefox and Brave Browser have code designed to frustrate this, and adding Privacy Badger to Firefox helps as well.

ETA: I'm unsure if browser fingerprints are shared among web sites, or if they're used primarily by sites to identify repeat visitors.

ETA: See coveryourtracks.eff.org at the Electronic Frontier Foundation for a demonstration on what the fingerprinting can find and how useful each item is. Major components include the User-Agent HTTP header the Accept HTTP header, time zone offset and name, screen size and colour depth, canvas and WebGL fingerprints, WebGL vendor and renderer, and audiocontext fingerprint. Note that a VPN will not alter this information.
 
Last edited:
Most people these days use a router of some description, usually supplied by their ISP. The ISP can see that device's MAC address, but not the addresses of the computers behind it.
I know, but added to the fact that DSL and (I think) fibre-optic connections are basically point to point with the ISP, and you have to be logged into that ISP account in SOME way, that's still enough to know which house it's coming from. If someone actually went to the trouble of getting a subpoena to see what's stored on your computer (since the complaint I was answering to was about browsers still saving stuff locally, which some ad provider doesn't have access to) that's more than enough to get there, don't you think? Duly noted, with the notable exception of using a wifi hotspot in some cafe, but I don't think anyone is going to browse for dark web stuff in a cafe.

For mobile devices it's even easier, since it's tied to your phone number.

And yes, the gummint can issue a subpoena to the ISP or mobile provider, and at least in the USA they can use a 1509 subpoena that doesn't even need a judge's signature. See, the one issued for the defendants in the Don Lemon case.

A VPN is actually the only way to frustrate the specific complaint I was answering to. Otherwise, nobody cares about what's in your browser history either.

Like, geesh, just use a different browser to search for medications for embarassing conditions. And delete everything afterwards. That way the ad providers are no wiser.
 
Last edited:
Like, geesh, just use a different browser to search for medications for embarassing conditions. And delete everything afterwards. That way the ad providers are no wiser.
That seems to be the remarkably simple approach, much like the decades old "use a burner" technique for anonymity.

Depending on how sophisticated the fingerprinting is, it seems like they might be able to correlate the different browsers into one identity (with enough volume of data)? I mean, they popped the Silk Road home boy who was using TOR.

But it's not the FBI or Illuminati or whatever that's a looming threat. As I see it, if I'm not being bombarded with ads or spam, I'm golden. Just gotta keep a burner around (and I have one, very intentionally a model that is rugged/waterproof and no GPS).
 
I have no idea what this conversation is even addressing anymore. How did subpoenas and warrants get brought into it? Did I totally miss a right turn somewhere? Logged in to my DSL or Fiber ISP? I am completely lost at this point.
Carrier-grade NAT: due to a shortage of IPv4 addresses, some ISPs are exposing a single IPv4 address for a block of customers, and using Network Address Translation methods to route the packet back to the correct subscriber

The fiber provider I'm with now uses CGNAT and I am not a fan at all. I had to put in a request for a static IP because I couldn't host anything. Granted, I should have asked before I changed my service over but it took me a minute to troubleshoot it and track down the issue.

Sure it's an extra $10/mth but worth it for me.
 
Last edited:
That seems to be the remarkably simple approach, much like the decades old "use a burner" technique for anonymity.
Pretty much.

Depending on how sophisticated the fingerprinting is, it seems like they might be able to correlate the different browsers into one identity (with enough volume of data)? I mean, they popped the Silk Road home boy who was using TOR.
As Blue Mountain was saying, it still depends on a bunch of stuff from your browser. They MIGHT trace your Edge account when you use it again, AND it goes to the same ad provider, but you're safe from THOSE targeted ads when using anything else. And AFAIK Google doesn't use that anyway. Yet.

As for the silk road guys, more like a couple of them, but that involved a huge Interpol effort, involving the exact timestamps to their honeypots. And AGAIN subpoenas. An ad provider ain't gonna have either the resources or the authority to request those.

Or even simpler, for crying out loud, just use some ad blocker if you don't want to see ads. Beats worrying about why they gave you those ads.
 
Last edited:
I have no idea what this conversation is even addressing anymore. How did subpoenas and warrants get brought into it?
When Thermal went paranoid about his browser still supposedly saving SOMETHING on his local device while in private mode. Well, if it's on your local device, the ad provider can't read that. It takes a subpoena and a warrant to do that, and only the police can get those. So that's my way of telling him in a technical way that his paranoia misses the mark by a couple of miles.
 
When Thermal went paranoid about...
Thermal isn't paranoid about anything. Thermal is idly considering what options are broadly more private than others.

My favorite example is how locally, scanning drivers licenses for ID in commercial transactions has become ubiquitous. A retired State Trooper buddy of mine (who worked in online scamming and still does in the private sector) opines that the database they are using was never built for public access, and is riddled with security holes that have never been successfully patched. And unless you are a teen trying to buy alcohol, the commercial usage is completely unnecessary. It is convenient for a store to scan the license, but it accesses your driving and police records, which a vendor has no reason to need.

A big home improvement store here (Home Depot) has an option on their screens to visually verify ID for, say, returns. But the manager demands (in violation of law) to collect this data against you by scanning. While I don't think it makes me 'paranoid', I don't like the idea of ANYONE harvesting unnecessary data about me for no reason. Databases get hacked. It's a real thing.
his browser still supposedly saving SOMETHING on his local device while in private mode. Well, if it's on your local device, the ad provider can't read that.
No, what i am considering is how identifiable a user is, even without a cookie left on your device. As others have said, it seems they can identify a unique user through fingerprinting, and store the browsing data on their end, without relying solely on cookies on the user device anymore. Which is interesting, anyway.
It takes a subpoena and a warrant to do that, and only the police can get those. So that's my way of telling him in a technical way that his paranoia misses the mark by a couple of miles.
Want me to go over hacking again? You ever been subject to a data breach? I have.
 
Or even simpler, for crying out loud, just use some ad blocker if you don't want to see ads. Beats worrying about why they gave you those ads
You're having a lot of trouble understanding the posts lately. I said I use an adblocker, and it works well, and I'm pretty much happy on the user end.

What we are further kicking around are exactly how much they can still collect on you, and what they could do with it, and peripherally, what could happen if the commercial end is unsecured and they get hacked, or even just sell their collected data to someone with unscrupulous ends.

I mean, just asking around to see if there is something simple out there to mitigate the threat is not that big a deal.
 
...no. No, it wasn't. A VPN is widely promoted as a privacy feature, even though it really isn't. The actial OP, if his continued use of Avast is any indicator, has no clue about internet privacy. That led to a very related drift about privacy features more generally, even still touching back to VPNs during the discussion.

Are we going to fast for you this week?
 

ISF - Join now!

Every member here is approved by hand. No bots, no spam, just people who care about evidence and honest debate.

Membership is free!

Create your free account

Back
Top Bottom