• 0 Posts
  • 51 Comments
Joined 1 year ago
cake
Cake day: June 8th, 2023

help-circle













  • The best thing to do is not trust your vps. You can use different credentials than those you normally would, connect through a vpn to obscure your identity (questionably useful depending on how you paid) and use public/private key pairs where no private key material or certificates end up on your vps.

    I’m not sure of a true “zero trust” method to secure a virtualized computer when someone else has lower level software access and physical control over the hardware it’s running on.





  • that’s not how it works.

    your vpn doesn’t do anything to mitigate broswer fingerprinting. websites use browser fingerprinting to identify a unique browser no matter the ip its connecting from. when i connect through mullvad’s french server, it identifies my browser just like when i connect through any other server.

    most of the time those sites even clock that i’m connecting through a vpn.

    a computer that is connected to some vpn and downloads a torrent while also visiting a website that fingerprints their browser will not have the two conflated unless the attacker can match traffic coming out of the vpn and traffic going into the computer.

    that information wouldn’t be useful to an attacker unless they also had access to the website that fingerprinted the browser and were part of the torrent swarm so they could actually say yes, browser 12345 and user 34567 downloading The_Mummy_CrAcK_DeNuVo.mp4 are the same person and they were at this ip that corresponds to this router at this physical location and when we confiscate their computer we can verify their browser has the fingerprint, open and shut case, book em’ dano.

    if you disconnect from your vpn intermittently it actually makes those checks easier because then the attacker can say “look, browser 12345 is coming from both the french mullvad node and from this little coffee shop in taipei! get em!”

    a single vpn proxy can’t protect you from a hypothetical hostile whole ass internet.