Page 1 of 1 [ 4 posts ] 

smudge
Veteran
Veteran

User avatar

Joined: 6 Sep 2006
Age: 38
Gender: Female
Posts: 7,716
Location: Moved on

21 Apr 2020, 12:06 pm

Does a VPN even prevent your ISP from finding out which websites you have visited or will visit? Can ANYONE override them?


_________________
I've left WP.


Oculus
Blue Jay
Blue Jay

User avatar

Joined: 15 Jan 2010
Age: 55
Gender: Male
Posts: 81
Location: california

21 Apr 2020, 3:24 pm

A VPN can help with privacy a lot, but there are ways to circumvent them.

For example, your VPN provider (whoever runs the remote system running the VPN which is laundering your traffic) can trivially see where your connections are coming from, and where the laundered connections are going to. If they keep this information private, then all is well, but they might be selling that information to various buyers. Alternatively, they might be served a subpoena or national security letter by the government, obliging them to provide that information.

Also, cross-site web trackers (like Google Analytics) can correlate your location and/or identity with VPN-laundered network connections. When a website puts a third party web tracker on their website, your browser loads the tracker token (frequently a script or 1x1-pixel image) from the third party's website. Since cookies are tied to the remote end of the connection, the tracker site can see that the connection's cookie has been seen before, and from which source IP addresses. So if you visited a tracked site without using the VPN, and then visited other sites which use the same tracker through the VPN, the tracking service will know the VPN-laundered connections are really from you.

Also, the Snowden Revelations taught us that American intelligence communities are snooping our communication networks very broadly, and can use traffic correlation techniques to defeat protective measures like Tor and VPNs. If they see a pattern of data packet sizes and timings from A -> B, and the same pattern of lengths and timings from B -> C, then they can guess with a pretty high confidence that C is getting data from A by way of proxy B, even if the content itself is unbreakably encrypted.

So, VPNs help a lot, but not against all threats. It gets complicated, and you need to decide what level of threat you need to defend yourself against. Defending your privacy against national intelligence agencies is much harder than defending it against an employer or state police.



Oculus
Blue Jay
Blue Jay

User avatar

Joined: 15 Jan 2010
Age: 55
Gender: Male
Posts: 81
Location: california

21 Apr 2020, 3:25 pm

To more narrowly answer your specific question, if your VPN provider is outside of your ISP's network, and if the VPN provider is not selling its customers' connection data to your ISP, then it should prevent your ISP from knowing what data connections you are making.



pyrrhicwren
Veteran
Veteran

User avatar

Joined: 2 Jan 2020
Gender: Male
Posts: 1,586

01 May 2020, 9:06 am

Oculus wrote:
Also, cross-site web trackers (like Google Analytics) can correlate your location and/or identity with VPN-laundered network connections. When a website puts a third party web tracker on their website, your browser loads the tracker token (frequently a script or 1x1-pixel image) from the third party's website. Since cookies are tied to the remote end of the connection, the tracker site can see that the connection's cookie has been seen before, and from which source IP addresses. So if you visited a tracked site without using the VPN, and then visited other sites which use the same tracker through the VPN, the tracking service will know the VPN-laundered connections are really from you.

uBlock? tightened down


_________________
HFA/ASP, Synesthaesia, Tic Disorder