IT manager Michael Dear explains why virtual private networks aren’t at all private when it comes to protecting your identity or online behaviour
I would like to start this column with two statements.
The first is, I donโt care. When it comes to peopleโs proclivities, that is. Do whatever you want so long as it isnโt illegal or hurting someone. Believe me, Iโve been doing this job long enough that I have almost certainly seen it before.
Instead, I’d rather you were honest. I firmly believe in the idea of IT/user confidentially as I want to help and definitely donโt want to judge. Your mileage may vary with who you are getting help from, but my rates are reasonable.
Second, if it isnโt your computer then donโt trust it. By definition, your work computer or mobile are not yours; theyโre owned and managed by your employer, so donโt play or do anything on them that isn’t required by work. I donโt trust my work devices and I manage them! Let me put it another way: if youโre not happy to have your computer screen projected into a public place with your face and details attached so that everyone passing can see it, then donโt do it on a work device.
So with that out of the way, letโs talk about VPNs. In the UK, a piece of legislation has come into effect that means websites with โadultโ content must confirm UK-based visitors are over 18 before granting access. There are many ways this can be done, such as handing over credit card details and uploading a copy of government-issued ID, but people are rightly wary of doing this. Thatโs why people have started to ask about VPNs, especially when services that require personal data checking canโt hold on to the records they’re meant to keep secure.ย
There has been a noticeable increase in the adverts for VPNs, so what are they, how do they work and are there any downsides?
What are VPNs?
In general I like VPNs. I use them regularly. But, and itโs a big but here, I also understand what they do and donโt do.
Most people think that using a VPN means you are untraceable, a ghost-like actor on the internet, and that just isnโt true. Letโs say youโre trying to get around a simple geo block, be that outside of the UK and wanting to access BBC iPlayer or in the UK wanting to access US Netflix. Youโre using the VPN to appear to be in a different location. I suspect some people imagine the VPN as a pipe that transports over the internet and comes out somewhere else. I know thatโs how I explain it when doing staff training, but itโs a lie. A useful lie, but a lie nonetheless.
Letโs go back to our example above where youโre using a VPN to access a TV site in another country. The trouble is that the โinternetโ is not a single thing but a mixture of services and protocols that have built up over time. Programs take care of this complexity for you, hiding the hundreds of three- and four-letter acronyms that are in use.
You use two different protocols to access a website. One is DNS, which (for instance) translates the name bbc.co.uk into an address 123.132.12.2. Once you have the address, your browser uses that to connect to the server that hosts the website and uses HTTP to download the webpage. Iโm deliberately trying to keep this high level; just remember DNS does addressing and HTTP does websites.
The DNS question
Your DNS server address is typically given to you by your ISP, and in the UK your ISP must hold a record of IP-plus-query for a length of time for the authorities. They can then request this data, so all the sites you visit are logged to the router in the house. You donโt have to use your ISPโs DNS and you can change it, but for most people the default is to use the ISPโs choice.
Letโs assume that you are only sending website traffic over a VPN. When you start your VPN, this will use DNS to look up the name-to-address of the VPN server; your ISP now has a record that youโre using a VPN, but because you havenโt changed your DNS settings you will continue to use the ISP DNS server. That means the ISP continues to get a record of what you are looking up, but now so does the VPN provider through the connection to the web servers. You have in effect doubled the amount of logging of what you are doing.
You can get around this by using something called DNS over HTTP. Most browsers have this option under privacy and security settings. DNS over HTTP submits the browserโs DNS requests over an encrypted connection, and that would go over the VPN which is where the logging would say the request came from.
However that doesnโt stop you being tracked or located, because as soon as you sign into Microsoft/Google/A.N.Other site, they capture your information. They donโt care that you suddenly moved IP address via your VPN: the second you loaded your browser they knew who you are and carried on tracking you.
How to avoid being tracked
So there are ways to use VPNs but they donโt stop tracking. If you want to do that, remember that the worst tracking stems from ad firms who appear in the โallow cookiesโ boxes on websites: if you want privacy this is the place to start every time. The reason itโs annoying is because itโs so powerful. Using a VPN to move geographically does work in part, but it doesnโt stop you being tracked and logged. Most likely, youโre increasing the footprints that you leave by doing this.
What do I suggest?
- Remember on the internet everything is tracked and remembered there is no โghost modeโ. You have to hide in plain sight. To try and be a ghost is very difficult; one wrong move and youโre found, as many cyber criminals have found to their cost.
- Consider switching from your ISPโs default DNS settings. Go into your router and change its DNS entry to one of these: 1.1.1.1 (Cloudflare), 8.8.8.8 (Google) or 9.9.9.9 (IBM). These are massive and you can hide in the dross. If you want to experiment further, look at services like NextDNS or OpenDNS and use these for your DNS search as they allow you do all sorts of funky stuff that can be useful.
- Enable DNS over HTTP in your browser, and then do the above in your browser โ and that means every browser you use.
- Donโt use a free VPN. Remember, youโre letting a VPN provider track you, just as you do your ISP, so you need trust in your choice. Proton has the best reputation among the free provides, but I donโt use them and never have. Remember, if itโs free then you need to ask how do they run the service and pay for the bandwidth it needs? The most likely answer is by monitoring you and selling that information on.
I could go on but this article is already way too long. So I will simply finish by saying be careful out there: someone is watching.
More articles by Michael Dear