You are viewing a single thread.
View all comments View context
0 points

Unless there’s something beyond switching DNS, using a VPN and your own router/modem. It’s maybe 100$ up front and ~3-5 per month to be able to circumvent any telecom.

permalink
report
parent
reply
0 points
*

You mean the VPN advertising everywhere, who gives out the user data whenever a goverment agency knocks on the door? Or the other big name VPN, where the company owner has another business that makes money by selling users internet data?

Yeah, i’m sure they will bend over backwards and file lawsuits to “protect your privacy” for $5/month…

permalink
report
parent
reply
0 points

Switching DNS does jack squat for your privacy. Any telecom worth their salt can read all DNS requests no matter which DNS you talk to. They only don’t filter content on alternative DNSes because they don’t care about filtering/blocking in general unless forced to by law.

Using a VPN doesn’t add privacy, it just swapps out who is monitoring your traffic. Many VPN services are actually owned/run by secret services or cooperate with them (like NordVPN). Others are directly run by criminals who use them to steal data or inject malware. Also, VPN providers also have ISPs that reside in countries. In the very best case it’s not your ISP spying on you, but the VPN’s ISP. In the worst case, you now have an ISP and a VPN provider spying on you.

Your own router/modem again does nothing at all for your privacy.

That’s what I mean: people think they are doing privacy enhancing things, but actually what they are doing isn’t helping at all.

permalink
report
parent
reply
0 points
*

As someone who knows a bit more about privacy in networking than watching the sponsored bits in YouTube videos, I agree with the examples you posed, but there are other technologies to fix your DNS leaking to your ISP. One of them being DNS over HTTPS. It’s default in Firefox, and pretty hard to crack just like any other HTTPS query. All your ISP can know is that you’re potentially making a DNS query. Another option is a local DNS server cache. Choose some domains you wanna be able to access, and diligently update your local cache using HTTPS from existing DNS servers every fortnight. Your DNS queries will never escape your LAN.

permalink
report
parent
reply
0 points

DoH is an actual improvement, that’s true. But at the same time it’s a meaningless one, since the ISP can just do a reverse DNS lookup of the IPs you are contacting, and there isn’t really an option to hide the IP, unless you are using TOR or a VPN, but TOR sucks in real-world usage (and can also not really be trusted) and VPNs have been discussed before.

I worked on the “evil” side for ~7 years, in a company that made internet monitoring devices. Originally I was told it’s only for debugging ISP network problems, but after a few years, when I was trusted enough in the company, they told me that a significant portion of our customers are actually secret services all around the world.

The foreign ones usually wouldn’t just say that they are secret service, but they’d buy through other companies, which lead to some weird requests. For example, one time a small little British bakery asked for network monitoring equipment for their business. But they wanted the solution to be able to handle ~100 TBit/s, which was at that time roughly the total bandwidth of the whole UK plus some margin.

Some secret services, though, talked to us completely openly.

I’ve been at one ISP quite a few times at the department that handled secret service requests. I asked that guy what they do with our products, and he showed me the full suite that they are using. He entered a random phone number into the system, and an overview over the last year’s activities of that guy showed up. It had a list with timestamps of every site he accessed. It had all emails (of his ISP account and also emails that were sent unencryped) and SMS that that guy sent and received. It had a full movement profile of that guy for the whole last year, including his visits to other countries. The system allowed the operator to easily find contacts of that guy, even through the movement profile. So you could e.g. list all users that were close to that user at a given time, or all users that are frequently close to that guy.

Tbh, it was a little shocking and eyeopening.

permalink
report
parent
reply

Europe

!europe@feddit.de

Create post

News/Interesting Stories/Beautiful Pictures from Europe 🇪🇺

(Current banner: Thunder mountain, Germany, 🇩🇪 ) Feel free to post submissions for banner pictures

Rules

(This list is obviously incomplete, but it will get expanded when necessary)

  1. Be nice to each other (e.g. No direct insults against each other);
  2. No racism, antisemitism, dehumanisation of minorities or glorification of National Socialism allowed;
  3. No posts linking to mis-information funded by foreign states or billionaires.

Also check out !yurop@lemm.ee

Community stats

  • 1

    Monthly active users

  • 2K

    Posts

  • 10K

    Comments

Community moderators