Came across this controversial link where someone says that a VPS would be more secure than a VPN provider. From my understanding:
-Wouldn’t the VPS provider just see everything instead of a VPN provider? -Wouldn’t fingerprinting be straightforward, even if you use a hardened browser, since you have a single IP traceable directly to only one user?
ytcombinator doesn’t seem to take it seriously but I’m curious to hear what you all think about it.
I would argue a VPS is less secure than a trusted provider. Of course, the definition of what’s trustworthy is up to each person. The reason I say it’s less secure is for 2 reasons:
The belief that a VPN provider doesn’t help privacy is a myth. But it’s true that you can’t depend on the VPN being your only solution to privacy. There are more steps you must take beyond just a VPN, but it’s definitely a required step if you want to be truly private. As an analogy: if people said “drinking water won’t make you healthy” that’s not true… But it’s also only a part of what you need to be healthy and the statement’s only true if you ignore the other things you need.
Further on the privacy front for my personal opinion: I don’t think there’s a such thing as a trustworthy ISP with personal data since they definitely track everything you access and probably sell that data, but there are a few trustworthy VPNs who likely don’t do this. I’d rather take the risk in a VPN provider that is probably not doing what ISPs do, also allowing me to further enhance my anonymity online.
For me, I’ve been using Mullvad for about maybe 5 years now, along with a ton of other things I’ve setup for privacy. Haven’t seen a targeted ad in nearly that amount of time, websites always think I’m located somewhere else, and any data breaches I’ve been a part of where IP addresses are in the data are of no concern to me.
Be sure to also look into geo tracking. If the device you’re using is wireless, chances are Google and such can get your exact location if you’re exposing your browser or software to geo tracking on the web, or if you don’t spoof your Mac addresses. How they do this: the Google maps vehicle that drives around collects the locations of wireless devices and their Mac addresses, so that when you have geo enabled, they can pinpoint you down to a very close lat/long coordinate.
This is my personal takeaway as well. The article seems to insinuate that because VPNs by themselves don’t do anything meaningful for privacy, they’re useless. It seems defeatist, since one could take measures to mitigate fingerprinting. But like you said they’re only one of the important parts of maintaining privacy.
I am not more technically proficient than the average user. I have little experience in hosting anything, let alone hosting something that will tunnel all of my internet usage. I’d rather put my faith in my current provider to take the proper precautions and put more effort into things I feel comfortable with. It seems better to me than trusting an unknown VPS provider, my own skill and/or my awful ISP.