• Spends most of article telling you why they probably aren’t necessary.

    Ends with 4 examples why they’re useful, which are the main reasons they’re used to begin with.

    • 3 years

      I feel like the opening sentences explained the reasoning behind the article sufficiently, even when there are plenty of valid use cases for them. This was mostly a response to manipulative marketing tactics:

      Virtual Private Networks, or VPNs, are popular services for (supposedly) increasing your security and privacy on the internet. They are often marketed as all-encompassing security tools, and something that you absolutely need to keep hackers at bay. However, many of the selling points for VPNs are exaggerated or just outright false.

      They’re not the only ones pointing this out, either. Tom Scott released a video on the topic a few years ago to explain his thoughts VPN sponsorships

      • Your comment in no way negates my observation. If the clickbait title of the article was “You probably don’t need a VPN to avoid market tracking” or something similar, you’d have a point.

        • 3 years

          I was simply adding information your comment had left out, it wasn’t negating information at all. So congrats on getting the point, not everyone is trying to argue 🎉

  • Another reason to use a VPN is that ISPs have every motive to sell your browsing data and they do. Unlike many other groups tracking you, your ISP inherently has your meatspace name, address, and payment information making their data easily collatable and very valuable.

    If you use the default DNS on their provided router they can even tell if someone purchased an XBox, Playstation, or any other smart device just from update and telemetry lookups.

    As the article says, by using a VPN youre using someone else’s ISP making that info worthless.

    If your threat model includes preventing ad networks from gathering data, a VPN absolutely is a tool to prevent that. Do you have to pay for a service? Probably not if you’re technical enough; a VM in a data center is probably sufficient.

    • You could also just set your DNS to one of the many free DNSSEC providers. That’s even more secure because there are fewer middle men who can track you. After all, while your ISP may not be able to see that DNS traffic, if you arn’t using DNSSEC anyway then your VPN and their upstream provider can.

      Besides, nearly all tracking nowadays uses third party browser fingerprinting, which a VPN does nothing about. Practically, a VPN is far more security theater than actual security.

      Also, isn’t it funny that sending all your data though a second nation where it no longer legally counts as Amarican internet traffic became really well advertised right after a major scandal came out where the NSA was illegally monitoring American traffic, and more protections were put in place to keep them from doing it again?

      You don’t even need the VPN company to be in on it, a group like the NSA can pretty easily compromise a “no logs” VPN’s technical infrastructure or that of their upstream provider, and they’re even got people who feel like they have something to hide to self select for it to cut down on the amount of boring traffic in the first place.

      • 3 years

        This is absolutely not what DNSSEC is. DNSSEC provides authenticity of the response, not privacy. You’re describing a means of encrypted name resolution, like dns-over-tls, dns-over-https, etc.

    • Do you have to pay for a service? Probably not if you’re technical enough; a VM in a data center is probably sufficient.

      Where are you getting free VM hosting?

      also, i feel like most of your argument is rendered moot with encrypted dns solutions like DoH.