Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.user > #229435 > unrolled thread
| Started by | ellanios82 <ellanios82@gmail.com> |
|---|---|
| First post | 2020-12-07 22:30 +0100 |
| Last post | 2020-12-09 17:40 +0100 |
| Articles | 20 on this page of 36 — 14 participants |
Back to article view | Back to linux.debian.user
VPN ideas ellanios82 <ellanios82@gmail.com> - 2020-12-07 22:30 +0100
Re: VPN ideas Roberto C. Sánchez <roberto@debian.org> - 2020-12-07 22:40 +0100
Re: VPN ideas ellanios82 <ellanios82@gmail.com> - 2020-12-07 23:40 +0100
Re: VPN ideas Mark Fletcher <mark27q1@gmail.com> - 2020-12-08 00:50 +0100
Re: VPN ideas Georgi Naplatanov <gosho@oles.biz> - 2020-12-07 22:50 +0100
Re: VPN ideas Charles Curley <charlescurley@charlescurley.com> - 2020-12-08 02:00 +0100
Re: VPN ideas john doe <johndoe65534@mail.com> - 2020-12-08 08:20 +0100
Re: VPN ideas <tomas@tuxteam.de> - 2020-12-08 09:50 +0100
Re: VPN ideas Alex Mestiashvili <amestia@rsh2.donotuse.de> - 2020-12-08 10:00 +0100
Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-08 14:00 +0100
Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-08 10:50 +0100
Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-08 11:20 +0100
Re: VPN ideas Joe <joe@jretrading.com> - 2020-12-08 13:30 +0100
Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-09 11:00 +0100
Re: VPN ideas Joe <joe@jretrading.com> - 2020-12-09 11:30 +0100
Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-09 12:00 +0100
Re: VPN ideas Joe <joe@jretrading.com> - 2020-12-09 12:10 +0100
Re: VPN ideas Stefan Monnier <monnier@iro.umontreal.ca> - 2020-12-09 15:30 +0100
Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-09 16:10 +0100
Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-09 18:10 +0100
Re: VPN ideas Henning Follmann <hfollmann@itcfollmann.com> - 2020-12-09 16:10 +0100
Re: VPN ideas Joe <joe@jretrading.com> - 2020-12-09 20:10 +0100
Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-10 09:10 +0100
Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-08 20:50 +0100
Re: VPN ideas Roberto C. Sánchez <roberto@debian.org> - 2020-12-08 23:10 +0100
Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-08 23:40 +0100
Re: VPN ideas Long Wind <longwind2@yahoo.com> - 2020-12-09 03:10 +0100
Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-09 11:10 +0100
Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-09 18:00 +0100
Re: VPN ideas Andrei POPESCU <andreimpopescu@gmail.com> - 2020-12-10 09:50 +0100
Re: VPN ideas Celejar <celejar@gmail.com> - 2020-12-10 18:50 +0100
Re: VPN ideas <tomas@tuxteam.de> - 2020-12-09 09:50 +0100
Re: VPN ideas Henning Follmann <hfollmann@itcfollmann.com> - 2020-12-09 15:30 +0100
Loadbearing services Henning Follmann <hfollmann@itcfollmann.com> - 2020-12-09 16:00 +0100
Re: Loadbearing services Stefan Monnier <monnier@iro.umontreal.ca> - 2020-12-09 16:40 +0100
Re: Loadbearing services Henning Follmann <hfollmann@itcfollmann.com> - 2020-12-09 17:40 +0100
Page 1 of 2 [1] 2 Next page →
| From | ellanios82 <ellanios82@gmail.com> |
|---|---|
| Date | 2020-12-07 22:30 +0100 |
| Subject | VPN ideas |
| Message-ID | <Bjwf0-4UQ-13@gated-at.bofh.it> |
Hi List :) - any suggestions please , for a handy VPN for everyday use : no specific purpose, but only to add a little more privacy ?? - and , is this a reasonable idea ? regards ellan ....
[toc] | [next] | [standalone]
| From | Roberto C. Sánchez <roberto@debian.org> |
|---|---|
| Date | 2020-12-07 22:40 +0100 |
| Message-ID | <BjwoH-4Ym-15@gated-at.bofh.it> |
| In reply to | #229435 |
On Mon, Dec 07, 2020 at 11:27:25PM +0200, ellanios82 wrote: > Hi List :) > > > - any suggestions please , for a handy VPN for everyday use : no specific > purpose, but only to add a little more privacy ?? > > - and , is this a reasonable idea ? > It is difficult to know since you don't specify any actual requirements, but OpenVPN or WireGuard should be suitable for most uses. Regards, -Roberto -- Roberto C. Sánchez
[toc] | [prev] | [next] | [standalone]
| From | ellanios82 <ellanios82@gmail.com> |
|---|---|
| Date | 2020-12-07 23:40 +0100 |
| Message-ID | <BjxkK-5xJ-7@gated-at.bofh.it> |
| In reply to | #229436 |
On 12/7/20 11:35 PM, Roberto C. Sánchez wrote: > On Mon, Dec 07, 2020 at 11:27:25PM +0200, ellanios82 wrote: >> Hi List :) >> >> >> - any suggestions please , for a handy VPN for everyday use : no specific >> purpose, but only to add a little more privacy ?? >> >> - and , is this a reasonable idea ? >> > It is difficult to know since you don't specify any actual requirements, > but OpenVPN or WireGuard should be suitable for most uses. > > Regards, > > -Roberto > - Many thanks Roberto & Georgi : looks like OpenVPN should be 'just-the-ticket' ...... Saludos
[toc] | [prev] | [next] | [standalone]
| From | Mark Fletcher <mark27q1@gmail.com> |
|---|---|
| Date | 2020-12-08 00:50 +0100 |
| Message-ID | <Bjyqu-6aJ-3@gated-at.bofh.it> |
| In reply to | #229436 |
On Mon, Dec 07, 2020 at 04:35:09PM -0500, Roberto C. Sánchez wrote: > On Mon, Dec 07, 2020 at 11:27:25PM +0200, ellanios82 wrote: > > Hi List :) > > > > > > - any suggestions please , for a handy VPN for everyday use : no specific > > purpose, but only to add a little more privacy ?? > > > > - and , is this a reasonable idea ? > > > It is difficult to know since you don't specify any actual requirements, > but OpenVPN or WireGuard should be suitable for most uses. > +1 for OpenVPN. I've used it for some years and love it. Some time ago I also used HMA (stands for "Hide My A$$" I believe), as something I could use across Android devices and Linux. It also did the job and let me pretend I was in a different country. Mark
[toc] | [prev] | [next] | [standalone]
| From | Georgi Naplatanov <gosho@oles.biz> |
|---|---|
| Date | 2020-12-07 22:50 +0100 |
| Message-ID | <Bjwyl-51S-1@gated-at.bofh.it> |
| In reply to | #229435 |
On 12/7/20 11:27 PM, ellanios82 wrote: > Hi List :) > > > - any suggestions please , for a handy VPN for everyday use : no > specific purpose, but only to add a little more privacy ?? > > - and , is this a reasonable idea ? > > Hey ellanios82, many people and companies use openvpn here in Bulgaria. I saw that network manager has openvpn support as well so you can check if it is suitable for your needs. Kind regards Georgi
[toc] | [prev] | [next] | [standalone]
| From | Charles Curley <charlescurley@charlescurley.com> |
|---|---|
| Date | 2020-12-08 02:00 +0100 |
| Message-ID | <Bjzwd-6NY-1@gated-at.bofh.it> |
| In reply to | #229435 |
On Mon, 7 Dec 2020 23:27:25 +0200 ellanios82 <ellanios82@gmail.com> wrote: > - any suggestions please , for a handy VPN for everyday use : no > specific purpose, but only to add a little more privacy ?? With no requirements, it is difficult to say. Will a VPN be overkill? Would you be better off with openSSH to log in remotely? -- Does anybody read signatures any more? https://charlescurley.com https://charlescurley.com/blog/
[toc] | [prev] | [next] | [standalone]
| From | john doe <johndoe65534@mail.com> |
|---|---|
| Date | 2020-12-08 08:20 +0100 |
| Message-ID | <BjFrY-2fr-7@gated-at.bofh.it> |
| In reply to | #229442 |
On 12/8/2020 1:50 AM, Charles Curley wrote: > On Mon, 7 Dec 2020 23:27:25 +0200 > ellanios82 <ellanios82@gmail.com> wrote: > >> - any suggestions please , for a handy VPN for everyday use : no >> specific purpose, but only to add a little more privacy ?? > > With no requirements, it is difficult to say. > > Will a VPN be overkill? Would you be better off with openSSH to log in > remotely? > If you use SSH only the SSH connection will be encrypted, the way I read the OP's question is that all traffic should be encrypted through the VPN. -- John Doe
[toc] | [prev] | [next] | [standalone]
| From | <tomas@tuxteam.de> |
|---|---|
| Date | 2020-12-08 09:50 +0100 |
| Message-ID | <BjGR3-2YY-1@gated-at.bofh.it> |
| In reply to | #229446 |
[Multipart message — attachments visible in raw view] — view raw
On Tue, Dec 08, 2020 at 08:12:09AM +0100, john doe wrote: > On 12/8/2020 1:50 AM, Charles Curley wrote: > >On Mon, 7 Dec 2020 23:27:25 +0200 > >ellanios82 <ellanios82@gmail.com> wrote: > > > >> - any suggestions please , for a handy VPN for everyday use : no > >>specific purpose, but only to add a little more privacy ?? > > > >With no requirements, it is difficult to say. > > > >Will a VPN be overkill? Would you be better off with openSSH to log in > >remotely? > > > > If you use SSH only the SSH connection will be encrypted, the way I read > the OP's question is that all traffic should be encrypted through the VPN. You can tunnel things through an SSH. See the -X option (to tunnel an X connection) and all the -L and -R options to proxy a socket. As a simple-to-set-up VPN, SSH is unbeatable. It has its downsides, mind you; the SSH protocol isn't optimised for such things. But if you're using SSH day-to-day, then starting with it and re-thinking once you reach some bandwidth/latency limit is a very sensible path. For the occasional customer with some (stupid Java) app which can't live without a GUI (go figure!), I do regularly tunnel X11 VNC over SSH. Works like a charm. Cheers - t
[toc] | [prev] | [next] | [standalone]
| From | Alex Mestiashvili <amestia@rsh2.donotuse.de> |
|---|---|
| Date | 2020-12-08 10:00 +0100 |
| Message-ID | <BjH0J-32f-1@gated-at.bofh.it> |
| In reply to | #229448 |
On 12/8/20 9:43 AM, tomas@tuxteam.de wrote: > On Tue, Dec 08, 2020 at 08:12:09AM +0100, john doe wrote: >> On 12/8/2020 1:50 AM, Charles Curley wrote: >>> On Mon, 7 Dec 2020 23:27:25 +0200 >>> ellanios82 <ellanios82@gmail.com> wrote: >>> >>>> - any suggestions please , for a handy VPN for everyday use : no >>>> specific purpose, but only to add a little more privacy ?? >>> >>> With no requirements, it is difficult to say. >>> >>> Will a VPN be overkill? Would you be better off with openSSH to log in >>> remotely? >>> >> >> If you use SSH only the SSH connection will be encrypted, the way I read >> the OP's question is that all traffic should be encrypted through the VPN. > > You can tunnel things through an SSH. See the -X option (to tunnel an > X connection) and all the -L and -R options to proxy a socket. > > As a simple-to-set-up VPN, SSH is unbeatable. It has its downsides, mind > you; the SSH protocol isn't optimised for such things. But if you're using > SSH day-to-day, then starting with it and re-thinking once you reach some > bandwidth/latency limit is a very sensible path. > > For the occasional customer with some (stupid Java) app which can't live > without a GUI (go figure!), I do regularly tunnel X11 VNC over SSH. Works > like a charm. Another interesting approach is VirtualGL over ssh: https://virtualgl.org/About/Introduction In some cases works really smoothly. Best, Alex
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2020-12-08 14:00 +0100 |
| Message-ID | <BjKKZ-5lD-3@gated-at.bofh.it> |
| In reply to | #229448 |
On Tue, 8 Dec 2020 09:43:31 +0100 <tomas@tuxteam.de> wrote: > On Tue, Dec 08, 2020 at 08:12:09AM +0100, john doe wrote: > > On 12/8/2020 1:50 AM, Charles Curley wrote: > > >On Mon, 7 Dec 2020 23:27:25 +0200 > > >ellanios82 <ellanios82@gmail.com> wrote: > > > > > >> - any suggestions please , for a handy VPN for everyday use : no > > >>specific purpose, but only to add a little more privacy ?? > > > > > >With no requirements, it is difficult to say. > > > > > >Will a VPN be overkill? Would you be better off with openSSH to log in > > >remotely? > > > > > > > If you use SSH only the SSH connection will be encrypted, the way I read > > the OP's question is that all traffic should be encrypted through the VPN. > > You can tunnel things through an SSH. See the -X option (to tunnel an > X connection) and all the -L and -R options to proxy a socket. > > As a simple-to-set-up VPN, SSH is unbeatable. It has its downsides, mind > you; the SSH protocol isn't optimised for such things. But if you're using > SSH day-to-day, then starting with it and re-thinking once you reach some > bandwidth/latency limit is a very sensible path. Yes - I don't do X tunneling, but I frequently do LocalForwarding (usually via config file stanzas) to securely access insecure local HTTP services (e.g., OpenWrt and Home Assisstant GUIs). It's a lot simpler than configuring each one to use HTTPS, or setting up a reverse proxy. I do use Wireguard for general remote access, though. Celejar
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2020-12-08 10:50 +0100 |
| Message-ID | <BjHN7-3yw-5@gated-at.bofh.it> |
| In reply to | #229435 |
[Multipart message — attachments visible in raw view] — view raw
On Lu, 07 dec 20, 23:27:25, ellanios82 wrote: > Hi List :) > > > - any suggestions please , for a handy VPN for everyday use : no specific > purpose, but only to add a little more privacy ?? This is quite vage. VPNs are generally used for two purposes: 1. Connect a remote system (e.g. a laptop) to the "home" network (home server, company network, etc.). This is its originally intended use. Once the VPN tunnel is configured one can work remotely as if directly connected to the "home" network (barring speed penalties). This is especially useful in case some of the used services should never be exposed to the internet (e.g. NFS or Samba). 2. Access the internet from a different point in the world This done for some increase in privacy[1] and/or to pretend you are in a different location (country) and/or to hide your traffic from your ISP. Unless you have access to a system on the internet to set up your own VPN server you have to rely on (paid) VPN providers. Tor is also an option for this use case. Which of the above would apply for you? > - and , is this a reasonable idea ? Depends on the use case (see above) and/or your country and/or your ISP, internet connection speed, VPN provider etc. [1] a VPN will just hide your public IP address and the traffic between you and the exit point. It doesn't do anything about your browser user agent, cookies and many other methods you can still be identified and traced on the internet, if this is what you are worried about. Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2020-12-08 11:20 +0100 |
| Message-ID | <BjIga-3Y0-21@gated-at.bofh.it> |
| In reply to | #229454 |
[Multipart message — attachments visible in raw view] — view raw
On Ma, 08 dec 20, 11:44:36, Andrei POPESCU wrote: > On Lu, 07 dec 20, 23:27:25, ellanios82 wrote: > > Hi List :) > > > > > > - any suggestions please , for a handy VPN for everyday use : no specific > > purpose, but only to add a little more privacy ?? > > This is quite vage. VPNs are generally used for two purposes: > > 1. Connect a remote system (e.g. a laptop) to the "home" network > (home server, company network, etc.). Or connect two remote company or home networks, of course. The rest still stands. > This is its originally intended use. Once the VPN tunnel is > configured one can work remotely as if directly connected to the > "home" network (barring speed penalties). > > This is especially useful in case some of the used services should > never be exposed to the internet (e.g. NFS or Samba). > > 2. Access the internet from a different point in the world > > This done for some increase in privacy[1] and/or to pretend you are > in a different location (country) and/or to hide your traffic from > your ISP. > > Unless you have access to a system on the internet to set up your own > VPN server you have to rely on (paid) VPN providers. > > Tor is also an option for this use case. > > Which of the above would apply for you? > > > - and , is this a reasonable idea ? > > Depends on the use case (see above) and/or your country and/or your ISP, > internet connection speed, VPN provider etc. > > [1] a VPN will just hide your public IP address and the traffic between > you and the exit point. It doesn't do anything about your browser user > agent, cookies and many other methods you can still be identified and > traced on the internet, if this is what you are worried about. > > Kind regards, > Andrei > -- > http://wiki.debian.org/FAQsFromDebianUser Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2020-12-08 13:30 +0100 |
| Message-ID | <BjKhX-5b7-1@gated-at.bofh.it> |
| In reply to | #229454 |
On Tue, 8 Dec 2020 11:44:36 +0200 Andrei POPESCU <andreimpopescu@gmail.com> wrote: > 2. Access the internet from a different point in the world > > This done for some increase in privacy[1] and/or to pretend you > are in a different location (country) and/or to hide your traffic > from your ISP. > > Unless you have access to a system on the internet to set up your > own VPN server you have to rely on (paid) VPN providers. > > Tor is also an option for this use case. > > Which of the above would apply for you? > > > - and , is this a reasonable idea ? > > Depends on the use case (see above) and/or your country and/or your > ISP, internet connection speed, VPN provider etc. > > [1] a VPN will just hide your public IP address and the traffic > between you and the exit point. It doesn't do anything about your > browser user agent, cookies and many other methods you can still be > identified and traced on the internet, if this is what you are > worried about. > This application is also useful with a home VPN server, if you're not trying to hide anything, but just want to use the Net reasonably safely from an unsafe location e.g. Internet cafe. You can tailor a set of firewall rules to allow nothing in or out except DNS, DHCP and HTTP (normally a local web login is required), not forgetting the tunnelling protocol port out. A VPN client will normally have a switch to route everything through the tunnel to achieve this. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2020-12-09 11:00 +0100 |
| Message-ID | <Bk4qm-19c-11@gated-at.bofh.it> |
| In reply to | #229462 |
[Multipart message — attachments visible in raw view] — view raw
On Ma, 08 dec 20, 12:27:40, Joe wrote: > > This application is also useful with a home VPN server, if you're not > trying to hide anything, but just want to use the Net reasonably safely > from an unsafe location e.g. Internet cafe. You can tailor a set of > firewall rules to allow nothing in or out except DNS, DHCP and HTTP > (normally a local web login is required), not forgetting the tunnelling > protocol port out. A VPN client will normally have a switch to route > everything through the tunnel to achieve this. Sorry, I must be dense. How is this improving safety compared to accessing the internet from my home network? Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2020-12-09 11:30 +0100 |
| Message-ID | <Bk4Tn-1yG-19@gated-at.bofh.it> |
| In reply to | #229533 |
On Wed, 9 Dec 2020 11:49:45 +0200 Andrei POPESCU <andreimpopescu@gmail.com> wrote: > On Ma, 08 dec 20, 12:27:40, Joe wrote: > > > > This application is also useful with a home VPN server, if you're > > not trying to hide anything, but just want to use the Net > > reasonably safely from an unsafe location e.g. Internet cafe. You > > can tailor a set of firewall rules to allow nothing in or out > > except DNS, DHCP and HTTP (normally a local web login is required), > > not forgetting the tunnelling protocol port out. A VPN client will > > normally have a switch to route everything through the tunnel to > > achieve this. > > Sorry, I must be dense. How is this improving safety compared to > accessing the internet from my home network? > > It isn't. It's improving safety compared to surfing the web from public wifi or other untrusted network. It then uses your home Internet connection for surfing the web, etc., which should be safer. Only local DHCP, DNS and HTTP must be allowed to the local network initially, and once the VPN is up, even these are routed through the encrypted tunnel. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2020-12-09 12:00 +0100 |
| Message-ID | <Bk5mq-1IH-1@gated-at.bofh.it> |
| In reply to | #229537 |
[Multipart message — attachments visible in raw view] — view raw
On Mi, 09 dec 20, 10:21:46, Joe wrote: > On Wed, 9 Dec 2020 11:49:45 +0200 > Andrei POPESCU <andreimpopescu@gmail.com> wrote: > > > On Ma, 08 dec 20, 12:27:40, Joe wrote: > > > > > > This application is also useful with a home VPN server, if you're > > > not trying to hide anything, but just want to use the Net > > > reasonably safely from an unsafe location e.g. Internet cafe. You > > > can tailor a set of firewall rules to allow nothing in or out > > > except DNS, DHCP and HTTP (normally a local web login is required), > > > not forgetting the tunnelling protocol port out. A VPN client will > > > normally have a switch to route everything through the tunnel to > > > achieve this. > > > > Sorry, I must be dense. How is this improving safety compared to > > accessing the internet from my home network? > > > It isn't. It's improving safety compared to surfing the web from public > wifi or other untrusted network. It then uses your home Internet > connection for surfing the web, etc., which should be safer. Let me rephrase that: how is connecting to the internet from some public hot-spot decreasing my security? I can think of possibly messing with DNS queries (use "own" DNS server instead, maybe with DNSSEC) and possible some attacks are easier via the local network (e.g. by other hot-spot users or local staff). Other that that, as far as I'm aware, the biggest threat are the servers I access with my client software (typically web sites accessed with a browser), in which case it doesn't make any difference whether I access them via some VPN and/or (home) firewall. (Assuming one doesn't run NFS, Samba, etc. *listening* software on the laptop in which case stopping those and/or running a firewall would be indicated.) Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | Joe <joe@jretrading.com> |
|---|---|
| Date | 2020-12-09 12:10 +0100 |
| Message-ID | <Bk5w5-21p-1@gated-at.bofh.it> |
| In reply to | #229539 |
On Wed, 9 Dec 2020 12:49:44 +0200 Andrei POPESCU <andreimpopescu@gmail.com> wrote: > On Mi, 09 dec 20, 10:21:46, Joe wrote: > > On Wed, 9 Dec 2020 11:49:45 +0200 > > Andrei POPESCU <andreimpopescu@gmail.com> wrote: > > > > > On Ma, 08 dec 20, 12:27:40, Joe wrote: > > > > > > > > This application is also useful with a home VPN server, if > > > > you're not trying to hide anything, but just want to use the Net > > > > reasonably safely from an unsafe location e.g. Internet cafe. > > > > You can tailor a set of firewall rules to allow nothing in or > > > > out except DNS, DHCP and HTTP (normally a local web login is > > > > required), not forgetting the tunnelling protocol port out. A > > > > VPN client will normally have a switch to route everything > > > > through the tunnel to achieve this. > > > > > > Sorry, I must be dense. How is this improving safety compared to > > > accessing the internet from my home network? > > > > > It isn't. It's improving safety compared to surfing the web from > > public wifi or other untrusted network. It then uses your home > > Internet connection for surfing the web, etc., which should be > > safer. > > Let me rephrase that: how is connecting to the internet from some > public hot-spot decreasing my security? > > I can think of possibly messing with DNS queries (use "own" DNS > server instead, maybe with DNSSEC) and possible some attacks are > easier via the local network (e.g. by other hot-spot users or local > staff). > > Other that that, as far as I'm aware, the biggest threat are the > servers I access with my client software (typically web sites > accessed with a browser), in which case it doesn't make any > difference whether I access them via some VPN and/or (home) firewall. > > (Assuming one doesn't run NFS, Samba, etc. *listening* software on > the laptop in which case stopping those and/or running a firewall > would be indicated.) > I suppose it may depend on where you are. In the UK, public wifi normally uses no encryption, because there are no local staff who can help with problems. So any unencrypted protocol you use can be overheard. -- Joe
[toc] | [prev] | [next] | [standalone]
| From | Stefan Monnier <monnier@iro.umontreal.ca> |
|---|---|
| Date | 2020-12-09 15:30 +0100 |
| Message-ID | <Bk8DE-3Or-9@gated-at.bofh.it> |
| In reply to | #229540 |
> I suppose it may depend on where you are. In the UK, public wifi
> normally uses no encryption, because there are no local staff who can
> help with problems. So any unencrypted protocol you use can be
> overheard.
Around here we have a mix:
- for small businesses (like coffeehouses or family-owned businesses),
it's typically WPA-PSK with the password displayed somewhere like at
the bottom of the menu, on the bathroom door, you name it (and/or
given upon request).
- for more "corporate" environments, it's typically an open wifi with
a "portal" where they get to show some advertisement and collect
email addresses.
Supposedly with WPA other machines connected to the same wifi can't see
your traffic, but often enough the AP is likely easy to hack into, so
it's safer to assume that your network packets are easy for someone
to see.
Nevertheless, I largely agree with Andrei that this is but a small part
of the potential attacks.
Stefan
[toc] | [prev] | [next] | [standalone]
| From | Andrei POPESCU <andreimpopescu@gmail.com> |
|---|---|
| Date | 2020-12-09 16:10 +0100 |
| Message-ID | <Bk9gm-4gJ-9@gated-at.bofh.it> |
| In reply to | #229540 |
[Multipart message — attachments visible in raw view] — view raw
On Mi, 09 dec 20, 11:00:41, Joe wrote: > > I suppose it may depend on where you are. In the UK, public wifi > normally uses no encryption, because there are no local staff who can > help with problems. So any unencrypted protocol you use can be > overheard. It doesn't matter much whether the public WiFi is using encryption or not. Any unencrypted communication over the internet is vulnerable. Period. Even if some segments[1] are somewhat protected, the segment between the router/firewall/VPN exit point and the server on the internet is still completely vulnerable. It's probably a good idea to always assume your system is connected directly to the internet. If you really need to run (vulnerable) listening services on it configure them to be stopped and/or firewalled whenever outside your home/company network. [1] in this case the segment between the laptop and the AP via WPA, or the segments between the laptop and the VPN exit point. Kind regards, Andrei -- http://wiki.debian.org/FAQsFromDebianUser
[toc] | [prev] | [next] | [standalone]
| From | Celejar <celejar@gmail.com> |
|---|---|
| Date | 2020-12-09 18:10 +0100 |
| Message-ID | <Bkb8u-5oq-9@gated-at.bofh.it> |
| In reply to | #229553 |
On Wed, 9 Dec 2020 17:04:43 +0200 Andrei POPESCU <andreimpopescu@gmail.com> wrote: > On Mi, 09 dec 20, 11:00:41, Joe wrote: > > > > I suppose it may depend on where you are. In the UK, public wifi > > normally uses no encryption, because there are no local staff who can > > help with problems. So any unencrypted protocol you use can be > > overheard. > > It doesn't matter much whether the public WiFi is using encryption or > not. > > Any unencrypted communication over the internet is vulnerable. Period. > > Even if some segments[1] are somewhat protected, the segment between the > router/firewall/VPN exit point and the server on the internet is still > completely vulnerable. > > It's probably a good idea to always assume your system is connected > directly to the internet. If you really need to run (vulnerable) > listening services on it configure them to be stopped and/or firewalled > whenever outside your home/company network. > > [1] in this case the segment between the laptop and the AP via WPA, or > the segments between the laptop and the VPN exit point. It's certainly true that "any unencrypted communication over the internet is vulnerable," but security is not black and white. Say we're talking about some sort of 0-day MITM vulnerability. Yes, you'll never be entirely safe insofar as you don't control the entire network path, but I might be (marginally?) more worried about random people having access to my network traffic via an unencrypted wireless connection than about the proprietor of that wireless network or the staff at my ISP. Unless my threat model includes state actors, in which case compromising my ISP might actually be easier and more straightforward for them ;) But of course, they could also just use the $5 wrench ... Celejar
[toc] | [prev] | [next] | [standalone]
Page 1 of 2 [1] 2 Next page →
Back to top | Article view | linux.debian.user
csiph-web