libera/#maemo/ Wednesday, 2021-10-20

sicelowho else has reasonably 'safe' free vpn - like riseup vpn for example?13:38
KotCzarnyi just run openvpn at home (static ip, good symetrical bandwidth etc)13:39
KotCzarny*openvpn server13:40
siceloi don't have access to that kind of setup :-)13:40
KotCzarnywell, you asked who has :)13:40
KotCzarnycheck out surfshark, i think they were quite cheap13:41
sicelohehe, well ... if you are offering to let me connect to your openvpn13:41
KotCzarnyaccording to their webpage: Plan includes: No Logs Policy13:42
KotCzarny~4usd/mon13:43
KotCzarnyas a bonus they aim to provide netflix capable endpoints ;)13:43
KotCzarnyat least they did some time ago13:44
KotCzarnySurfshark is owned by a company in the British Virgin Islands, which doesn't fall under 14 Eyes Jurisdiction. There are areas around the globe that have signed an agreement with US authorities to collect and share information.13:46
siceloi was looking for something i could run on my laptop only once in a while. on Android i find Riseup VPN usable enough the few times that I need it. let me see if i can build it for my debian system13:51
MaxdamantusIf I want to connect to things over a remote host I have access to, I just use ssh with either port forwarding or the dynamic proxy.14:03
MaxdamantusIf I really needed a VPN, I'd still do that over ssh, using tun/tap. I know you can at least do that reasonably easily using socat.14:03
MaxdamantusLooks like openssh itself has support for tun.14:04
siceloyeah. normally i used simple ssh dynamic proxy. but i no longer have access to a remote ssh server, and today my government has evidently censored parts of the internet, hence the sudden/immediate need to connect via another vpn/proxy14:07
KotCzarnybest course of action is to have some vm or dedi server (ovh, hetzner, whatever) for cheap14:12
KotCzarnythere are also free plans on aws and google i think14:12
KotCzarnyyou would need to recreate after few months but free is free14:12
KotCzarnythen you can create your own vpn/sshd14:13
sicelommm, these guys not only blocked access to some parts of the internet, but also are throttling connection speeds14:21
KotCzarnyback to the 90s14:25
KotCzarnysetup squid proxy for home :)14:25
KotCzarnymaybe even compressing one14:25
MaxdamantusNot squid.14:26
MaxdamantusShould be using end-to-end TLS connections nowadays.14:26
bencohsicelo: I dunno what kind of budget you're aiming for, but I'd highly recommend renting a server/vps from one of the cheap european hosters14:26
KotCzarnyyou can setup squid as ssl bumping one too14:27
bencoh(although it would probably be bad latency-wise, but still)14:27
MaxdamantusWhat, by trusting its MITM cert?14:27
Maxdamantusor does "SSL bumping" mean you connect to it unencrypted and it connects using SSL?14:28
Maxdamantusthat has other security issues.14:28
Maxdamantusanyway, bedtime.14:28
sicelobencoh: will consider that14:29
joerghttps://hackaday.com/2021/10/20/kicad-team-releases-warning-regarding-domain-name/19:09

Generated by irclog2html.py 2.17.0 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!