Bit of an uphill fight with captchas everywhere. Do people here conduct all online activity over VPN whenever possible? Only for the sensitive stuff? Or perhaps the inverse because the bank already knows you? Maybe when travelling or getting around region blocking? Something else?

The one provided by my work aside, I realized that I don’t have any consistent rules around using VPN. Except sometimes, you know, when downloading ISO’s for my favorite distos.

      • webghost0101@sopuli.xyz
        link
        fedilink
        arrow-up
        0
        ·
        18 days ago

        I have a router with opnsense which has q plugin for wireguard making things quite easy for me.

        A router is usually also always online and sits at the center of a network so it is the best place for it but there is nothing stopping someone from setting it up with commandline on a home device.

        https://www.wireguard.com/quickstart/

        There are many online video guides that cover different ways to do it (like docker)

        In all casss you first setup a main server on the device that stays home and from it you generate a peer per device you want to connect. (A bunch of settings/codes) Sometimes a peer is a qr code that your device can scan (wireguard app for some devices) otherwise you have to manualy type.

        Once set you can just leave it on. The only exception i found is some apps for local payments, presumably because they require both devices to report the same location to perform a transaction.

      • webghost0101@sopuli.xyz
        link
        fedilink
        arrow-up
        0
        ·
        18 days ago

        I get the idea but all of it depends on placing your trust in some company who’s entire business model is to sell you privacy.

        If you live in an area with such heavy censorship then can you trust the business that is legally allowed to advertise and sell to you?

        I personally think such company is way more likely to sell my data on the dark web then the government has resources to investigate what web domains i have visited.

        • Alavi@programming.dev
          link
          fedilink
          arrow-up
          0
          ·
          18 days ago

          They aren’t legally allowed to advertised and sell. Having them installed and selling them is a crime. (China, Iran, many other countries)

          • webghost0101@sopuli.xyz
            link
            fedilink
            arrow-up
            0
            ·
            18 days ago

            It is a valid use case. But thats not my usecase by far, which is what was asked.

            My comment is slightly directed at people i know irl that are not very technological and believe that surfing the web is inherently not safe, but completely safe one you pay to connect to name_tm.

            My apologies if it felt condescending for people who have good reason to tunnel outside there local jurisdiction.

  • artyom@piefed.social
    link
    fedilink
    English
    arrow-up
    0
    ·
    19 days ago

    Pretty much always. If someone blocks my VPN, I just don’t go there or don’t use that. Sucks but it is what it is. I’m just not willing to enter your site bareback.

  • Da Oeuf@slrpnk.net
    link
    fedilink
    arrow-up
    0
    ·
    19 days ago

    Mine is on pretty much all the time. Capchas are indeed annoying, but I’m choosing to see that as something which helps me to be more intentional about my use of the internet.

    My bank and government portal don’t seem to care about it, even if my traffic is coming from a random country on the other side of the world because I’ve forgotten to route through one of my VPN’s domestic servers. Online freelancing platforms, on the other hand, have instantly banned my accounts, and I’ve had problems with corporate social media (which I try and use for my business).

    • webghost0101@sopuli.xyz
      link
      fedilink
      arrow-up
      0
      ·
      19 days ago

      Whats this with vpns using capatchas?

      My client device having the right encryption key is the authenticator for me.

      • some_kind_of_guy@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        edit-2
        18 days ago

        Most sites can tell if you’re using a VPN. It depends on the site, but this can cause sites to treat your visit as suspicious and throw up their defenses. This includes use of CAPTCHA. Some sites (e.g. Reddit) don’t work at all if your traffic exits from a known VPN.

  • Zedd_Prophecy@lemmy.world
    link
    fedilink
    English
    arrow-up
    0
    ·
    19 days ago

    I have a VPN configured at the router. I use a PI-hole with a lot of restrictions and lists to run my own DNS and downstream DNS is Adgaurd. Several machines I let bypass the VPN umbrella and they have local clients they can switch on at will. I’d like to make a Linux firewall too but not with prices where they are now. These days you have to distrust everything.

  • Commiejones@lemmygrad.ml
    link
    fedilink
    arrow-up
    0
    ·
    19 days ago

    I leave mine on almost all the time. If a website takes a little longer to load “Oh no” its a half second instead of milliseconds. it really doesn’t change my life much.

  • manuallybreathing@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    19 days ago

    I use a VPN 99% of the time, i turn it off when i need to access archive.org, or watch something on the public braordcasters streaming platform

    yeah sure the captchas are annoying but it’s not like websites load within 10 seconds anymore

    I only wish protonVPN was a good as the one i used previously, but i cancelled it cause it had ties to israel

  • NauticalNoodle@lemmy.ml
    link
    fedilink
    arrow-up
    0
    ·
    19 days ago

    98% of the time. I hate having to turn it off to look at my local grocery store’s website but I have done it before.

  • realbadat@programming.dev
    link
    fedilink
    arrow-up
    0
    ·
    19 days ago

    General activity goes out the VPN always. My self hosted setup, lab stuff, and work stuff gets different connections out (logically, not physically).

  • thanksforallthefish@literature.cafe
    link
    fedilink
    arrow-up
    0
    ·
    19 days ago

    Permanently on. Anything I can’t access without it I generally find an alternate with very few exceptions. I have a quarantine virtual machine I use for the couple of websites that are worth making an exception for.

  • chicken@lemmy.dbzer0.com
    link
    fedilink
    arrow-up
    0
    ·
    19 days ago

    Mostly just for torrents, one machine on my local network is always using a VPN to connect to the external internet. I would use it for more things like private web browsing, but without substantial additional setup I think my web browsing is guaranteed to be fingerprinted regardless of whether I conceal my IP so until I bother to set that up it doesn’t seem like there is much point.

    • hirihit640@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      0
      ·
      19 days ago

      Do not try to do anti-fingerprinting yourself. Cobbling together your own configuration will only make you stand out more. Use a pre-configured browser from a reputable company. This way you blend in with everybody else using the same browser. And don’t install extensions either unless you really know what you’re doing. Extensions usually change your fingerprint.

      Use Tor Browser for browsing over Tor, Mullvad Browser for everything else. Librewolf is fine for when you don’t care about hiding your fingerprint, like when you are logging into email and bank accounts.

        • hirihit640@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          19 days ago

          If you enable Javascript there’s still some crazy ways you can be tracked beyond the normal fingerprinting techniques. Stuff like mouse and keyboard tracking. Or looking at your behavior (what posts you view the longest, which photos you zoom into).

          Disabling Javascript (using Tor Browser in the Safest setting) is the safest. Second to that, is enabling Javascript for websites you trust. You can use the NoScript extension to allow some scripts while blocking others. Usually you only need to allow scripts from the website itself, and block ones from third-parties like Google.

          What were the issues you ran into?

          • lemmingsareawesome@sh.itjust.works
            link
            fedilink
            arrow-up
            0
            ·
            19 days ago

            i disable javascirpt and use safest setting

            I use invidious to check if google is tracking me (i get recommended videos i like on the first page so i know its not behavoir fingerprint)

            • bleustenns@lemmy.ml
              link
              fedilink
              arrow-up
              0
              ·
              13 days ago

              I’m not sure Google is tracking you via Invidious recommendations. I think whatever instances are popular just get used by people with the same general content interests, so those IP addresses get served that sort of content.

      • willington@lemmy.dbzer0.com
        link
        fedilink
        arrow-up
        0
        ·
        18 days ago

        fonts, screen resolution, many things can affect fingerprint.

        The solution is not “a browser from a reputable company.”

        It will be a browser designed by security professionals to spoof fingerprints, along with a “crawler” that analyzes the current blend of fingerprints already out there, crawling not web pages but the request headers instead, and canvas outputs, etc.

        I don’t think such a browser plus infrastructure exist yet, but they will. It is inevitable.

        Such a browser will output garbage yet plausible and believable fingerprints that maximize ambiguity.

        • hirihit640@sh.itjust.works
          link
          fedilink
          English
          arrow-up
          0
          ·
          18 days ago

          What makes you think the Tor Browser and Mullvad Browser are not made by “security professionals”? Have you used either of them? They already have defenses against font, screen resolution, and many other fingerprinting vectors.

          Also, “plausible and believable” fingerprints were already considered by Tor Browser and Mullvad Browser, and I believe are actively in use by Brave Browser. I forget why Tor Browser and Mullvad Browser opted to instead give everybody the same fingerprint, but there was a reason for it.

          • willington@lemmy.dbzer0.com
            link
            fedilink
            arrow-up
            0
            ·
            17 days ago

            Of these Tor is the best for protecting identity, however Tor produces a recognizeably Tor-like fingerprint, which for my preference is not ideal.

            So for example Tor browsers can all be denied access, because Tor, not the individual user, but the kind of browser used, can still be identified.

            My ultimate latent goal isn’t to only protect the anonymity of a security-conscious user, but to poison all fingerprinting data so that the entire technique is abandoned as useless.

            • hirihit640@sh.itjust.works
              link
              fedilink
              English
              arrow-up
              0
              ·
              17 days ago

              Adversarial methods like that won’t work. Google will know when their data starts getting poisoned. Their ad targeting will lose effectiveness, their profit margin impacted. And they will tweak and tighten their trackers until they can squeeze out a good fingerprint again. In the end Google simply rolls out Web Environment Integrity, and consumers won’t be able to use the web unless they prove their identity. If you want to fight big tech, this is the endgame they will push toward. If you want to play a cat and mouse game with big tech, big tech wins in the end since they have all the money.

              Tor Browser recognizes this. So Tor Browser just erases any existing identifiers, while accepting that websites can identify Tor users and block them if they want. It’s a very explicit signal that “this is a user that cares about privacy”, and it’s up to the website to accept that user or not. If a website doesn’t care, then usually it will work fine in Tor Browser. If a website does care and tries to block Tor users, then Tor Browser doesn’t bother fighting it. There are better places for them to focus their energy.

              Ultimately if you want the web to be private, the only solution is to convince everybody else to want the same. Websites won’t block privacy-seeking users, if everybody is a privacy-seeking user. Then, even big tech will have to concede.

              • willington@lemmy.dbzer0.com
                link
                fedilink
                arrow-up
                0
                ·
                17 days ago

                Just fundamentally, to fight, you have want to win.

                You are arguing to stop fighting on the basis of a supposedly improper desire. Wanting small bite sized things is proper. Wanting something audacious is not. Your kind of argument could work in theory if my desire is unserious. That’s just psychology, not technology.

                The scariness and the capabilities of an adversary is never, on their own, a proper reason to not fight.

                The valid reasons can be: a deeply reasoned and deeply felt long term change in priorities, or a tactical hiatus to rest, regroup, reload. These are completely internal affairs, meaning, a serious person cannot be casually argued either into or out of these. I would check in with my soul to know whether or not to fight. Not with strangers on the net.

                People fight to satisfy a certain hunger, and not because it looks easy or is a popular thing.

                • hirihit640@sh.itjust.works
                  link
                  fedilink
                  English
                  arrow-up
                  0
                  ·
                  17 days ago

                  But there’s strategy to this. What I’m saying is that it’s more productive for privacy advocates to spend their efforts convincing others that privacy is important, or pushing for privacy-friendly regulation, rather than trying to fight a war of attrition with big tech.