Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.debian.user > #229435 > unrolled thread

VPN ideas

Started byellanios82 <ellanios82@gmail.com>
First post2020-12-07 22:30 +0100
Last post2020-12-09 17:40 +0100
Articles 20 on this page of 36 — 14 participants

Back to article view | Back to linux.debian.user


Contents

  VPN ideas ellanios82 <ellanios82@gmail.com> - 2020-12-07 22:30 +0100
    Re: VPN ideas Roberto C. Sánchez <roberto@debian.org> - 2020-12-07 22:40 +0100
      Re: VPN ideas ellanios82 <ellanios82@gmail.com> - 2020-12-07 23:40 +0100
      Re: VPN ideas Mark Fletcher <mark27q1@gmail.com> - 2020-12-08 00:50 +0100
    Re: VPN ideas Georgi Naplatanov <gosho@oles.biz> - 2020-12-07 22:50 +0100
    Re: VPN ideas Charles Curley <charlescurley@charlescurley.com> - 2020-12-08 02:00 +0100
      Re: VPN ideas john doe <johndoe65534@mail.com> - 2020-12-08 08:20 +0100
        Re: VPN ideas <tomas@tuxteam.de> - 2020-12-08 09:50 +0100
          Re: VPN ideas Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2020-12-08 10:00 +0100
          Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-08 14:00 +0100
    Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-08 10:50 +0100
      Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-08 11:20 +0100
      Re: VPN ideas Joe <joe@jretrading.com> - 2020-12-08 13:30 +0100
        Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-09 11:00 +0100
          Re: VPN ideas Joe <joe@jretrading.com> - 2020-12-09 11:30 +0100
            Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-09 12:00 +0100
              Re: VPN ideas Joe <joe@jretrading.com> - 2020-12-09 12:10 +0100
                Re: VPN ideas Stefan Monnier <monnier@iro.umontreal.ca> - 2020-12-09 15:30 +0100
                Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-09 16:10 +0100
                  Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-09 18:10 +0100
                Re: VPN ideas Henning Follmann <hfollmann@itcfollmann.com> - 2020-12-09 16:10 +0100
                  Re: VPN ideas Joe <joe@jretrading.com> - 2020-12-09 20:10 +0100
                    Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-10 09:10 +0100
      Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-08 20:50 +0100
        Re: VPN ideas Roberto C. Sánchez <roberto@debian.org> - 2020-12-08 23:10 +0100
          Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-08 23:40 +0100
            Re: VPN ideas Long Wind <longwind2@yahoo.com> - 2020-12-09 03:10 +0100
            Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-09 11:10 +0100
              Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-09 18:00 +0100
                Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-10 09:50 +0100
                  Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-10 18:50 +0100
          Re: VPN ideas <tomas@tuxteam.de> - 2020-12-09 09:50 +0100
            Re: VPN ideas Henning Follmann <hfollmann@itcfollmann.com> - 2020-12-09 15:30 +0100
            Loadbearing services Henning Follmann <hfollmann@itcfollmann.com> - 2020-12-09 16:00 +0100
              Re: Loadbearing services Stefan Monnier <monnier@iro.umontreal.ca> - 2020-12-09 16:40 +0100
                Re: Loadbearing services Henning Follmann <hfollmann@itcfollmann.com> - 2020-12-09 17:40 +0100

Page 1 of 2  [1] 2  Next page →


#229435 — VPN ideas

Fromellanios82 <ellanios82@gmail.com>
Date2020-12-07 22:30 +0100
SubjectVPN ideas
Message-ID<Bjwf0-4UQ-13@gated-at.bofh.it>
  Hi List   :)


  - any suggestions please , for a handy VPN for everyday use : no 
specific purpose, but only to add a little more privacy ??

  - and , is this a reasonable idea ?


  regards

  ellan

....

[toc] | [next] | [standalone]


#229436

FromRoberto C. Sánchez <roberto@debian.org>
Date2020-12-07 22:40 +0100
Message-ID<BjwoH-4Ym-15@gated-at.bofh.it>
In reply to#229435
On Mon, Dec 07, 2020 at 11:27:25PM +0200, ellanios82 wrote:
>  Hi List   :)
> 
> 
>  - any suggestions please , for a handy VPN for everyday use : no specific
> purpose, but only to add a little more privacy ??
> 
>  - and , is this a reasonable idea ?
> 
It is difficult to know since you don't specify any actual requirements,
but OpenVPN or WireGuard should be suitable for most uses.

Regards,

-Roberto

-- 
Roberto C. Sánchez

[toc] | [prev] | [next] | [standalone]


#229438

Fromellanios82 <ellanios82@gmail.com>
Date2020-12-07 23:40 +0100
Message-ID<BjxkK-5xJ-7@gated-at.bofh.it>
In reply to#229436
On 12/7/20 11:35 PM, Roberto C. Sánchez wrote:
> On Mon, Dec 07, 2020 at 11:27:25PM +0200, ellanios82 wrote:
>>   Hi List   :)
>>
>>
>>   - any suggestions please , for a handy VPN for everyday use : no specific
>> purpose, but only to add a little more privacy ??
>>
>>   - and , is this a reasonable idea ?
>>
> It is difficult to know since you don't specify any actual requirements,
> but OpenVPN or WireGuard should be suitable for most uses.
>
> Regards,
>
> -Roberto
>
  - Many thanks Roberto & Georgi


  : looks like OpenVPN should be 'just-the-ticket'

......
  Saludos

[toc] | [prev] | [next] | [standalone]


#229440

FromMark Fletcher <mark27q1@gmail.com>
Date2020-12-08 00:50 +0100
Message-ID<Bjyqu-6aJ-3@gated-at.bofh.it>
In reply to#229436
On Mon, Dec 07, 2020 at 04:35:09PM -0500, Roberto C. Sánchez wrote:
> On Mon, Dec 07, 2020 at 11:27:25PM +0200, ellanios82 wrote:
> >  Hi List   :)
> > 
> > 
> >  - any suggestions please , for a handy VPN for everyday use : no specific
> > purpose, but only to add a little more privacy ??
> > 
> >  - and , is this a reasonable idea ?
> > 
> It is difficult to know since you don't specify any actual requirements,
> but OpenVPN or WireGuard should be suitable for most uses.
> 
+1 for OpenVPN. I've used it for some years and love it.

Some time ago I also used HMA (stands for "Hide My A$$" I believe), as 
something I could use across Android devices and Linux. It also did the 
job and let me pretend I was in a different country.

Mark

[toc] | [prev] | [next] | [standalone]


#229437

FromGeorgi Naplatanov <gosho@oles.biz>
Date2020-12-07 22:50 +0100
Message-ID<Bjwyl-51S-1@gated-at.bofh.it>
In reply to#229435
On 12/7/20 11:27 PM, ellanios82 wrote:
>  Hi List   :)
> 
> 
>  - any suggestions please , for a handy VPN for everyday use : no
> specific purpose, but only to add a little more privacy ??
> 
>  - and , is this a reasonable idea ?
> 
> 

Hey ellanios82,

many people and companies use openvpn here in Bulgaria. I saw that
network manager has openvpn support as well so you can check if it is
suitable for your needs.

Kind regards
Georgi

[toc] | [prev] | [next] | [standalone]


#229442

FromCharles Curley <charlescurley@charlescurley.com>
Date2020-12-08 02:00 +0100
Message-ID<Bjzwd-6NY-1@gated-at.bofh.it>
In reply to#229435
On Mon, 7 Dec 2020 23:27:25 +0200
ellanios82 <ellanios82@gmail.com> wrote:

>   - any suggestions please , for a handy VPN for everyday use : no 
> specific purpose, but only to add a little more privacy ??

With no requirements, it is difficult to say.

Will a VPN be overkill? Would you be better off with openSSH to log in
remotely?

-- 
Does anybody read signatures any more?

https://charlescurley.com
https://charlescurley.com/blog/

[toc] | [prev] | [next] | [standalone]


#229446

Fromjohn doe <johndoe65534@mail.com>
Date2020-12-08 08:20 +0100
Message-ID<BjFrY-2fr-7@gated-at.bofh.it>
In reply to#229442
On 12/8/2020 1:50 AM, Charles Curley wrote:
> On Mon, 7 Dec 2020 23:27:25 +0200
> ellanios82 <ellanios82@gmail.com> wrote:
>
>>    - any suggestions please , for a handy VPN for everyday use : no
>> specific purpose, but only to add a little more privacy ??
>
> With no requirements, it is difficult to say.
>
> Will a VPN be overkill? Would you be better off with openSSH to log in
> remotely?
>

If you use SSH only the SSH connection will be encrypted, the way I read
the OP's question is that all traffic should be encrypted through the VPN.

--
John Doe

[toc] | [prev] | [next] | [standalone]


#229448

From<tomas@tuxteam.de>
Date2020-12-08 09:50 +0100
Message-ID<BjGR3-2YY-1@gated-at.bofh.it>
In reply to#229446

[Multipart message — attachments visible in raw view] — view raw

On Tue, Dec 08, 2020 at 08:12:09AM +0100, john doe wrote:
> On 12/8/2020 1:50 AM, Charles Curley wrote:
> >On Mon, 7 Dec 2020 23:27:25 +0200
> >ellanios82 <ellanios82@gmail.com> wrote:
> >
> >>   - any suggestions please , for a handy VPN for everyday use : no
> >>specific purpose, but only to add a little more privacy ??
> >
> >With no requirements, it is difficult to say.
> >
> >Will a VPN be overkill? Would you be better off with openSSH to log in
> >remotely?
> >
> 
> If you use SSH only the SSH connection will be encrypted, the way I read
> the OP's question is that all traffic should be encrypted through the VPN.

You can tunnel things through an SSH. See the -X option (to tunnel an
X connection) and all the -L and -R options to proxy a socket.

As a simple-to-set-up VPN, SSH is unbeatable. It has its downsides, mind
you; the SSH protocol isn't optimised for such things. But if you're using
SSH day-to-day, then starting with it and re-thinking once you reach some
bandwidth/latency limit is a very sensible path.

For the occasional customer with some (stupid Java) app which can't live
without a GUI (go figure!), I do regularly tunnel X11 VNC over SSH. Works
like a charm.

Cheers
 - t

[toc] | [prev] | [next] | [standalone]


#229449

FromAlex Mestiashvili <amestia@rsh2.donotuse.de>
Date2020-12-08 10:00 +0100
Message-ID<BjH0J-32f-1@gated-at.bofh.it>
In reply to#229448
On 12/8/20 9:43 AM, tomas@tuxteam.de wrote:
> On Tue, Dec 08, 2020 at 08:12:09AM +0100, john doe wrote:
>> On 12/8/2020 1:50 AM, Charles Curley wrote:
>>> On Mon, 7 Dec 2020 23:27:25 +0200
>>> ellanios82 <ellanios82@gmail.com> wrote:
>>>
>>>>    - any suggestions please , for a handy VPN for everyday use : no
>>>> specific purpose, but only to add a little more privacy ??
>>>
>>> With no requirements, it is difficult to say.
>>>
>>> Will a VPN be overkill? Would you be better off with openSSH to log in
>>> remotely?
>>>
>>
>> If you use SSH only the SSH connection will be encrypted, the way I read
>> the OP's question is that all traffic should be encrypted through the VPN.
> 
> You can tunnel things through an SSH. See the -X option (to tunnel an
> X connection) and all the -L and -R options to proxy a socket.
> 
> As a simple-to-set-up VPN, SSH is unbeatable. It has its downsides, mind
> you; the SSH protocol isn't optimised for such things. But if you're using
> SSH day-to-day, then starting with it and re-thinking once you reach some
> bandwidth/latency limit is a very sensible path.
> 
> For the occasional customer with some (stupid Java) app which can't live
> without a GUI (go figure!), I do regularly tunnel X11 VNC over SSH. Works
> like a charm.

Another interesting approach is VirtualGL over ssh: 
https://virtualgl.org/About/Introduction

In some cases works really smoothly.

Best,
Alex

[toc] | [prev] | [next] | [standalone]


#229463

FromCelejar <celejar@gmail.com>
Date2020-12-08 14:00 +0100
Message-ID<BjKKZ-5lD-3@gated-at.bofh.it>
In reply to#229448
On Tue, 8 Dec 2020 09:43:31 +0100
<tomas@tuxteam.de> wrote:

> On Tue, Dec 08, 2020 at 08:12:09AM +0100, john doe wrote:
> > On 12/8/2020 1:50 AM, Charles Curley wrote:
> > >On Mon, 7 Dec 2020 23:27:25 +0200
> > >ellanios82 <ellanios82@gmail.com> wrote:
> > >
> > >>   - any suggestions please , for a handy VPN for everyday use : no
> > >>specific purpose, but only to add a little more privacy ??
> > >
> > >With no requirements, it is difficult to say.
> > >
> > >Will a VPN be overkill? Would you be better off with openSSH to log in
> > >remotely?
> > >
> > 
> > If you use SSH only the SSH connection will be encrypted, the way I read
> > the OP's question is that all traffic should be encrypted through the VPN.
> 
> You can tunnel things through an SSH. See the -X option (to tunnel an
> X connection) and all the -L and -R options to proxy a socket.
> 
> As a simple-to-set-up VPN, SSH is unbeatable. It has its downsides, mind
> you; the SSH protocol isn't optimised for such things. But if you're using
> SSH day-to-day, then starting with it and re-thinking once you reach some
> bandwidth/latency limit is a very sensible path.

Yes - I don't do X tunneling, but I frequently do LocalForwarding
(usually via config file stanzas) to securely access insecure local
HTTP services (e.g., OpenWrt and Home Assisstant GUIs). It's a lot
simpler than configuring each one to use HTTPS, or setting up a reverse
proxy.

I do use Wireguard for general remote access, though.

Celejar

[toc] | [prev] | [next] | [standalone]


#229454

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2020-12-08 10:50 +0100
Message-ID<BjHN7-3yw-5@gated-at.bofh.it>
In reply to#229435

[Multipart message — attachments visible in raw view] — view raw

On Lu, 07 dec 20, 23:27:25, ellanios82 wrote:
>  Hi List   :)
> 
> 
>  - any suggestions please , for a handy VPN for everyday use : no specific
> purpose, but only to add a little more privacy ??
 
This is quite vage. VPNs are generally used for two purposes:

1. Connect a remote system (e.g. a laptop) to the "home" network
   (home server, company network, etc.).

   This is its originally intended use. Once the VPN tunnel is 
   configured one can work remotely as if directly connected to the 
   "home" network (barring speed penalties).
   
   This is especially useful in case some of the used services should 
   never be exposed to the internet (e.g. NFS or Samba).

2. Access the internet from a different point in the world

   This done for some increase in privacy[1] and/or to pretend you are 
   in a different location (country) and/or to hide your traffic from 
   your ISP.

   Unless you have access to a system on the internet to set up your own 
   VPN server you have to rely on (paid) VPN providers.

   Tor is also an option for this use case.

Which of the above would apply for you?

>  - and , is this a reasonable idea ?

Depends on the use case (see above) and/or your country and/or your ISP, 
internet connection speed, VPN provider etc.

[1] a VPN will just hide your public IP address and the traffic between 
you and the exit point. It doesn't do anything about your browser user 
agent, cookies and many other methods you can still be identified and 
traced on the internet, if this is what you are worried about.

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#229458

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2020-12-08 11:20 +0100
Message-ID<BjIga-3Y0-21@gated-at.bofh.it>
In reply to#229454

[Multipart message — attachments visible in raw view] — view raw

On Ma, 08 dec 20, 11:44:36, Andrei POPESCU wrote:
> On Lu, 07 dec 20, 23:27:25, ellanios82 wrote:
> >  Hi List   :)
> > 
> > 
> >  - any suggestions please , for a handy VPN for everyday use : no specific
> > purpose, but only to add a little more privacy ??
>  
> This is quite vage. VPNs are generally used for two purposes:
> 
> 1. Connect a remote system (e.g. a laptop) to the "home" network
>    (home server, company network, etc.).
 
Or connect two remote company or home networks, of course. The rest 
still stands.

>    This is its originally intended use. Once the VPN tunnel is 
>    configured one can work remotely as if directly connected to the 
>    "home" network (barring speed penalties).
>    
>    This is especially useful in case some of the used services should 
>    never be exposed to the internet (e.g. NFS or Samba).
> 
> 2. Access the internet from a different point in the world
> 
>    This done for some increase in privacy[1] and/or to pretend you are 
>    in a different location (country) and/or to hide your traffic from 
>    your ISP.
> 
>    Unless you have access to a system on the internet to set up your own 
>    VPN server you have to rely on (paid) VPN providers.
> 
>    Tor is also an option for this use case.
> 
> Which of the above would apply for you?
> 
> >  - and , is this a reasonable idea ?
> 
> Depends on the use case (see above) and/or your country and/or your ISP, 
> internet connection speed, VPN provider etc.
> 
> [1] a VPN will just hide your public IP address and the traffic between 
> you and the exit point. It doesn't do anything about your browser user 
> agent, cookies and many other methods you can still be identified and 
> traced on the internet, if this is what you are worried about.
> 
> Kind regards,
> Andrei
> -- 
> http://wiki.debian.org/FAQsFromDebianUser

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#229462

FromJoe <joe@jretrading.com>
Date2020-12-08 13:30 +0100
Message-ID<BjKhX-5b7-1@gated-at.bofh.it>
In reply to#229454
On Tue, 8 Dec 2020 11:44:36 +0200
Andrei POPESCU <andreimpopescu@gmail.com> wrote:


> 2. Access the internet from a different point in the world
> 
>    This done for some increase in privacy[1] and/or to pretend you
> are in a different location (country) and/or to hide your traffic
> from your ISP.
> 
>    Unless you have access to a system on the internet to set up your
> own VPN server you have to rely on (paid) VPN providers.
> 
>    Tor is also an option for this use case.
> 
> Which of the above would apply for you?
> 
> >  - and , is this a reasonable idea ?  
> 
> Depends on the use case (see above) and/or your country and/or your
> ISP, internet connection speed, VPN provider etc.
> 
> [1] a VPN will just hide your public IP address and the traffic
> between you and the exit point. It doesn't do anything about your
> browser user agent, cookies and many other methods you can still be
> identified and traced on the internet, if this is what you are
> worried about.
> 

This application is also useful with a home VPN server, if you're not
trying to hide anything, but just want to use the Net reasonably safely
from an unsafe location e.g. Internet cafe. You can tailor a set of
firewall rules to allow nothing in or out except DNS, DHCP and HTTP
(normally a local web login is required), not forgetting the tunnelling
protocol port out. A VPN client will normally have a switch to route
everything through the tunnel to achieve this.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#229533

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2020-12-09 11:00 +0100
Message-ID<Bk4qm-19c-11@gated-at.bofh.it>
In reply to#229462

[Multipart message — attachments visible in raw view] — view raw

On Ma, 08 dec 20, 12:27:40, Joe wrote:
> 
> This application is also useful with a home VPN server, if you're not
> trying to hide anything, but just want to use the Net reasonably safely
> from an unsafe location e.g. Internet cafe. You can tailor a set of
> firewall rules to allow nothing in or out except DNS, DHCP and HTTP
> (normally a local web login is required), not forgetting the tunnelling
> protocol port out. A VPN client will normally have a switch to route
> everything through the tunnel to achieve this.

Sorry, I must be dense. How is this improving safety compared to 
accessing the internet from my home network?

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#229537

FromJoe <joe@jretrading.com>
Date2020-12-09 11:30 +0100
Message-ID<Bk4Tn-1yG-19@gated-at.bofh.it>
In reply to#229533
On Wed, 9 Dec 2020 11:49:45 +0200
Andrei POPESCU <andreimpopescu@gmail.com> wrote:

> On Ma, 08 dec 20, 12:27:40, Joe wrote:
> > 
> > This application is also useful with a home VPN server, if you're
> > not trying to hide anything, but just want to use the Net
> > reasonably safely from an unsafe location e.g. Internet cafe. You
> > can tailor a set of firewall rules to allow nothing in or out
> > except DNS, DHCP and HTTP (normally a local web login is required),
> > not forgetting the tunnelling protocol port out. A VPN client will
> > normally have a switch to route everything through the tunnel to
> > achieve this.  
> 
> Sorry, I must be dense. How is this improving safety compared to 
> accessing the internet from my home network?
> 
>
It isn't. It's improving safety compared to surfing the web from public
wifi or other untrusted network. It then uses your home Internet
connection for surfing the web, etc., which should be safer.

Only local DHCP, DNS and HTTP must be allowed to the local network
initially, and once the VPN is up, even these are routed through the
encrypted tunnel.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#229539

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2020-12-09 12:00 +0100
Message-ID<Bk5mq-1IH-1@gated-at.bofh.it>
In reply to#229537

[Multipart message — attachments visible in raw view] — view raw

On Mi, 09 dec 20, 10:21:46, Joe wrote:
> On Wed, 9 Dec 2020 11:49:45 +0200
> Andrei POPESCU <andreimpopescu@gmail.com> wrote:
> 
> > On Ma, 08 dec 20, 12:27:40, Joe wrote:
> > > 
> > > This application is also useful with a home VPN server, if you're
> > > not trying to hide anything, but just want to use the Net
> > > reasonably safely from an unsafe location e.g. Internet cafe. You
> > > can tailor a set of firewall rules to allow nothing in or out
> > > except DNS, DHCP and HTTP (normally a local web login is required),
> > > not forgetting the tunnelling protocol port out. A VPN client will
> > > normally have a switch to route everything through the tunnel to
> > > achieve this.  
> > 
> > Sorry, I must be dense. How is this improving safety compared to 
> > accessing the internet from my home network?
> >
> It isn't. It's improving safety compared to surfing the web from public
> wifi or other untrusted network. It then uses your home Internet
> connection for surfing the web, etc., which should be safer.

Let me rephrase that: how is connecting to the internet from some public 
hot-spot decreasing my security?

I can think of possibly messing with DNS queries (use "own" DNS server 
instead, maybe with DNSSEC) and possible some attacks are easier via the 
local network (e.g. by other hot-spot users or local staff).

Other that that, as far as I'm aware, the biggest threat are the servers 
I access with my client software (typically web sites accessed with a 
browser), in which case it doesn't make any difference whether I access 
them via some VPN and/or (home) firewall.

(Assuming one doesn't run NFS, Samba, etc. *listening* software on the 
laptop in which case stopping those and/or running a firewall would be 
indicated.)

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#229540

FromJoe <joe@jretrading.com>
Date2020-12-09 12:10 +0100
Message-ID<Bk5w5-21p-1@gated-at.bofh.it>
In reply to#229539
On Wed, 9 Dec 2020 12:49:44 +0200
Andrei POPESCU <andreimpopescu@gmail.com> wrote:

> On Mi, 09 dec 20, 10:21:46, Joe wrote:
> > On Wed, 9 Dec 2020 11:49:45 +0200
> > Andrei POPESCU <andreimpopescu@gmail.com> wrote:
> >   
> > > On Ma, 08 dec 20, 12:27:40, Joe wrote:  
> > > > 
> > > > This application is also useful with a home VPN server, if
> > > > you're not trying to hide anything, but just want to use the Net
> > > > reasonably safely from an unsafe location e.g. Internet cafe.
> > > > You can tailor a set of firewall rules to allow nothing in or
> > > > out except DNS, DHCP and HTTP (normally a local web login is
> > > > required), not forgetting the tunnelling protocol port out. A
> > > > VPN client will normally have a switch to route everything
> > > > through the tunnel to achieve this.    
> > > 
> > > Sorry, I must be dense. How is this improving safety compared to 
> > > accessing the internet from my home network?
> > >  
> > It isn't. It's improving safety compared to surfing the web from
> > public wifi or other untrusted network. It then uses your home
> > Internet connection for surfing the web, etc., which should be
> > safer.  
> 
> Let me rephrase that: how is connecting to the internet from some
> public hot-spot decreasing my security?
> 
> I can think of possibly messing with DNS queries (use "own" DNS
> server instead, maybe with DNSSEC) and possible some attacks are
> easier via the local network (e.g. by other hot-spot users or local
> staff).
> 
> Other that that, as far as I'm aware, the biggest threat are the
> servers I access with my client software (typically web sites
> accessed with a browser), in which case it doesn't make any
> difference whether I access them via some VPN and/or (home) firewall.
> 
> (Assuming one doesn't run NFS, Samba, etc. *listening* software on
> the laptop in which case stopping those and/or running a firewall
> would be indicated.)
> 

I suppose it may depend on where you are. In the UK, public wifi
normally uses no encryption, because there are no local staff who can
help with problems. So any unencrypted protocol you use can be
overheard.

-- 
Joe

[toc] | [prev] | [next] | [standalone]


#229549

FromStefan Monnier <monnier@iro.umontreal.ca>
Date2020-12-09 15:30 +0100
Message-ID<Bk8DE-3Or-9@gated-at.bofh.it>
In reply to#229540
> I suppose it may depend on where you are. In the UK, public wifi
> normally uses no encryption, because there are no local staff who can
> help with problems. So any unencrypted protocol you use can be
> overheard.

Around here we have a mix:

- for small businesses (like coffeehouses or family-owned businesses),
  it's typically WPA-PSK with the password displayed somewhere like at
  the bottom of the menu, on the bathroom door, you name it (and/or
  given upon request).

- for more "corporate" environments, it's typically an open wifi with
  a "portal" where they get to show some advertisement and collect
  email addresses.

Supposedly with WPA other machines connected to the same wifi can't see
your traffic, but often enough the AP is likely easy to hack into, so
it's safer to assume that your network packets are easy for someone
to see.

Nevertheless, I largely agree with Andrei that this is but a small part
of the potential attacks.


        Stefan

[toc] | [prev] | [next] | [standalone]


#229553

FromAndrei POPESCU <andreimpopescu@gmail.com>
Date2020-12-09 16:10 +0100
Message-ID<Bk9gm-4gJ-9@gated-at.bofh.it>
In reply to#229540

[Multipart message — attachments visible in raw view] — view raw

On Mi, 09 dec 20, 11:00:41, Joe wrote:
> 
> I suppose it may depend on where you are. In the UK, public wifi
> normally uses no encryption, because there are no local staff who can
> help with problems. So any unencrypted protocol you use can be
> overheard.

It doesn't matter much whether the public WiFi is using encryption or 
not.

Any unencrypted communication over the internet is vulnerable. Period.

Even if some segments[1] are somewhat protected, the segment between the 
router/firewall/VPN exit point and the server on the internet is still 
completely vulnerable.

It's probably a good idea to always assume your system is connected 
directly to the internet. If you really need to run (vulnerable) 
listening services on it configure them to be stopped and/or firewalled 
whenever outside your home/company network.

[1] in this case the segment between the laptop and the AP via WPA, or 
the segments between the laptop and the VPN exit point.

Kind regards,
Andrei
-- 
http://wiki.debian.org/FAQsFromDebianUser

[toc] | [prev] | [next] | [standalone]


#229569

FromCelejar <celejar@gmail.com>
Date2020-12-09 18:10 +0100
Message-ID<Bkb8u-5oq-9@gated-at.bofh.it>
In reply to#229553
On Wed, 9 Dec 2020 17:04:43 +0200
Andrei POPESCU <andreimpopescu@gmail.com> wrote:

> On Mi, 09 dec 20, 11:00:41, Joe wrote:
> > 
> > I suppose it may depend on where you are. In the UK, public wifi
> > normally uses no encryption, because there are no local staff who can
> > help with problems. So any unencrypted protocol you use can be
> > overheard.
> 
> It doesn't matter much whether the public WiFi is using encryption or 
> not.
> 
> Any unencrypted communication over the internet is vulnerable. Period.
> 
> Even if some segments[1] are somewhat protected, the segment between the 
> router/firewall/VPN exit point and the server on the internet is still 
> completely vulnerable.
> 
> It's probably a good idea to always assume your system is connected 
> directly to the internet. If you really need to run (vulnerable) 
> listening services on it configure them to be stopped and/or firewalled 
> whenever outside your home/company network.
> 
> [1] in this case the segment between the laptop and the AP via WPA, or 
> the segments between the laptop and the VPN exit point.

It's certainly true that "any unencrypted communication over the
internet is vulnerable," but security is not black and white. Say we're
talking about some sort of 0-day MITM vulnerability. Yes, you'll never
be entirely safe insofar as you don't control the entire network path,
but I might be (marginally?) more worried about random people having
access to my network traffic via an unencrypted wireless connection
than about the proprietor of that wireless network or the staff at my
ISP. 

Unless my threat model includes state actors, in which case
compromising my ISP might actually be easier and more straightforward
for them ;) But of course, they could also just use the $5 wrench ...

Celejar

[toc] | [prev] | [next] | [standalone]


Page 1 of 2  [1] 2  Next page →

Back to top | Article view | linux.debian.user


csiph-web