GNU social JP
  • FAQ
  • Login
GNU social JPは日本のGNU socialサーバーです。
Usage/ToS/admin/test/Pleroma FE
  • Public

    • Public
    • Network
    • Groups
    • Featured
    • Popular
    • People

Conversation

Notices

  1. Embed this notice
    Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 30-Jun-2026 21:35:08 JST Tinker ☀️ Tinker ☀️

    All "privacy oriented" commercial VPNs are honeypots.

    You can't change my mind on that.

    Mullvad VPN has heavy marketing in Washington DC (their ads are plastered all across the metro stops frequented by government workers and foreign diplomats) for example.

    The whole "you need to hide something? here we'll hide it for you! Everyone that wants to hide something should put is all in this one consolidated place!"

    But they totally won't look at it.

    They swear.

    No logs, bro. I promise. I can look, but I won't. I could log, but I won't.

    So while Mullvad the company is showing their ass, asking what other VPN to hop to begs the question: Why are you using a commercial VPN?

    If it's to change your IP address to bypass porn restrictions in fundamentalist theocratic states, then cool. That's a solid use case.

    If it's for a nebulous reason like "for privacy" or "for security". Then you might want to see if that tool actually meets your specific threat modeling.

    #VPN #mullvad #mullvadVPN

    In conversation about 2 months ago from infosec.exchange permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 30-Jun-2026 21:35:05 JST Rich Felker Rich Felker
      in reply to
      • atom

      @470m @tinker TLS already prevents MITM attacks fully.

      In conversation about 2 months ago permalink
    • Embed this notice
      atom (470m@mstdn.social)'s status on Tuesday, 30-Jun-2026 21:35:07 JST atom atom
      in reply to

      @tinker I use a VPN to avoid MITM attacks on public WiFi and eduroam (cybersecurity students can be tricky, and a lot of networks I've come across have been kinda vulnerable), avoid the UK's internet restrictions, and use SkyTube (Google has crippled it in most countries, but switching my apparent location to, say, Vietnam usually works).

      I used to also use a VPN alongside Mullvad Browser for privacy reasons; but now that I've switched to Tor Browser, this is redundant.

      1/2

      In conversation about 2 months ago permalink
    • Embed this notice
      Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 30-Jun-2026 21:35:08 JST Tinker ☀️ Tinker ☀️
      in reply to

      Regarding the follow up question of "what should I use if no commercial VPN solves my issue"...

      ...that entirely depends on what you need a VPN for.

      For many folks, modern HTTPS (TLS) covers what many VPNs sought to address - namely, limiting who can see your secure traffic.

      For folks using public or non-personal wifi, the local router implementing wireless isolation prevents folks on your subnet from sniffing your traffic (https/tls helps here too).

      For folks wanting to hide their browsing habits - shifting the inspection of traffic from their ISP to some for-purpose honeypot may not be the best solution.

      Also, you'll always get the "spin up your own VPN" answer in these sort of threads, but as has already been pointed out this isnt something most folks can do (it is straightforward to do!!!! Iffff... you have the knowledge and experience.... which most folks don't have. They are focusing on other things in life, etc).

      Two big things to consider here:

      1) What are you actually trying to accomplish with a VPN? Specifics. Not just "increased privacy" or "increased security". What. Exactly. Are you trying to accomplish. And then sort out if a VPN actually does that thing for you. (Many are just snake oil promising to meet your valid desire for general health but dont actually do the thing they promise).

      2) There might not be a viable solution to your need. Sometimes the answer is "this proposed solution is a scam, and there is no alternative - no actual solution. You have a real need and there is no real thing to meet that need. Sorry."

      #vpn #mullvad #mullvadVPN

      In conversation about 2 months ago permalink
    • Embed this notice
      Rich Felker (dalias@hachyderm.io)'s status on Tuesday, 30-Jun-2026 21:45:48 JST Rich Felker Rich Felker
      in reply to
      • atom

      @470m @tinker That's just devices offering unauthenticated access to anything on the network. And using a VPN just changes *who* can access them (who's on the same "local" network with them); it doesn't fix the problem.

      In conversation about 2 months ago permalink
    • Embed this notice
      atom (470m@mstdn.social)'s status on Tuesday, 30-Jun-2026 21:45:49 JST atom atom
      in reply to
      • Rich Felker

      @dalias @tinker It's not HTTPS that I'm worried about. I may have mentioned the wrong type of attack.

      One example of a vulnerability I found was on the WiFi in my old student halls. The entire site was on one subnet, seemingly with no separation. I could ping PlayStations on the other side of the building and turn people's speakers on at 3AM, all from the comfort of my own room using nothing more than an Android tablet. This didn't fill me with confidence about other aspects of the network.

      In conversation about 2 months ago permalink
    • Embed this notice
      Tinker ☀️ (tinker@infosec.exchange)'s status on Tuesday, 30-Jun-2026 23:51:45 JST Tinker ☀️ Tinker ☀️
      in reply to
      • John

      @silent_john - And the answer is neither. Out of the frying pan and into the fire. It becomes a false dichotomy.

      Another way I've asked myself that similar questions is "do I trust a general business model of the ISP whose main money maker is providing general internet access and ALSO spies on me or do I trust a small niche corporation that purports to have a business model that is there to protect vulnerable individuals but allows for business and operational goals to attack that vulnerable individual."?

      Simply put, I don't trust the ISP. I really don't trust the VPN. So I find other solutions outside of the ISP to address specific security and privacy needs.

      In conversation about 2 months ago permalink
    • Embed this notice
      John (silent_john@mastodon.social)'s status on Tuesday, 30-Jun-2026 23:51:46 JST John John
      in reply to

      @tinker

      The question is, do you trust private VPNs or your ISPs/telcoms more?

      In conversation about 2 months ago permalink
      Rich Felker repeated this.
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Wednesday, 01-Jul-2026 16:16:45 JST Aral Balkan Aral Balkan
      in reply to

      @tinker The only VPN you can trust fully is one where you know and trust the person/people operating it personally. And how many people can say they do? I’m lucky enough to be friends with Peter who runs njal.la and will happily vouch for him but yes, a VPN is just someone else’s computer and folks need to understand that it does not inherently offer any sort of additional privacy or security, it just shifts the privacy/security concerns to the VPN provider.

      In conversation about 2 months ago permalink

      Attachments

      1. No result found on File_thumbnail lookup.
        Njalla — Worlds most notorious privacy provider for domains, VPS' and VPNs.
        Njalla — Considered the worlds most notorious &quote;Privacy as a Service&quote; provider for domains, VPS' and VPNs.
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Wednesday, 01-Jul-2026 16:24:51 JST Aral Balkan Aral Balkan
      in reply to

      @tinker The only thing I use one for is to secure my connection if I’m at a cafe, etc., with open (unsecured) WiFi. Believe it or not, they still exist. I usually pop it on even if the network is secured in public places as I don’t necessarily trust the random router I just connected to. But that’s it. (Then again, I don’t have actual problems like the person in the thread whose country is blocked from banking services so my use case is more of a nice to have.)

      In conversation about 2 months ago permalink
    • Embed this notice
      jfgg (jfgg@mastodon.social)'s status on Thursday, 02-Jul-2026 00:52:49 JST jfgg jfgg
      in reply to
      • Aral Balkan

      @aral @tinker

      Hi! I’ve been a user for a while, but I’ve read some things that worry me a bit. Since you’re familiar with him, I’ll venture to ask: where does he stand regarding the far right? And is it true that he operates out of Costa Rica, where he owes money to the state for unpaid taxes? Best regards, and thanks!

      In conversation about 2 months ago permalink
    • Embed this notice
      Aral Balkan (aral@mastodon.ar.al)'s status on Thursday, 02-Jul-2026 00:52:49 JST Aral Balkan Aral Balkan
      in reply to
      • Peter Sunde Kolmisoppi
      • jfgg

      @jfgg @tinker He’s anti fascist. I don’t know why the company is based there but he’s likely got a good reason. Not sure if you’re checking @peter at all these days, Peter? Thoughts?

      In conversation about 2 months ago permalink

Feeds

  • Activity Streams
  • RSS 2.0
  • Atom
  • Help
  • About
  • FAQ
  • TOS
  • Privacy
  • Source
  • Version
  • Contact

GNU social JP is a social network, courtesy of GNU social JP管理人. It runs on GNU social, version 2.0.2-dev, available under the GNU Affero General Public License.

Creative Commons Attribution 3.0 All GNU social JP content and data are available under the Creative Commons Attribution 3.0 license.