VPN – Eraser https://eraser.heidi.ie Secure Erase Files from Hard Drives Tue, 08 Sep 2020 09:26:43 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.2 https://eraser.heidi.ie/wp-content/uploads/2019/07/cropped-eraser-avatar-32x32.png VPN – Eraser https://eraser.heidi.ie 32 32 VPN Kill Switch 101: What It Is, And How It Works https://eraser.heidi.ie/vpn-kill-switch-101-what-it-is-and-how-it-works/ Mon, 07 Sep 2020 11:41:31 +0000 https://eraser.heidi.ie/?p=1445

If you’re already using a VPN, it means you’re keen on your privacy. While getting a VPN is the first step in protecting your online identity and activities, there are unforeseen risks that lie ahead, and potentially lead to your identity being unmasked and online activity tracked. One of the major threats is the VPN connection dropping due to network issues, which can leave your IP address exposed. That’s where the VPN Kill Switch kicks in.

What Is A VPN Kill Switch?

It goes by different names. Some VPN providers call it the Internet Kill Switch. CyberGhost labels it ‘Connection Guard’. With ExpressVPN, it’s been called the ‘Network Lock Kill Switch’. They all function on the same principle.

Basically, the Kill Switch is a feature that will automatically shut down your internet connection immediately you’re disconnected from the VPN service. That way no data will be sent over the network until you enable the VPN. If the Kill Switch has been turned off, then the internet connection would still be used as normal even when you’ve not connected to the VPN. 

There are two general modes of how the Kill Switch operates:

  • You can have an Active Skill Switch that detects the moment you lose the connection to the VPN service, which sends the information to the device and stops it from connecting to other networks. 
  • On the other hand, a Passive Kill Switch doesn’t wait for information from the VPN server. Immediately it loses the signal from the VPN server, it will automatically stop your device from sending out traffic.

In a nutshell, with a Kill Switch activated: 

Lost VPN Connection = No Internet Connection 

Why Do You Need A VPN Kill Switch?

The moment your network connection drops, your device will default back to its assigned public IP address. All your activity from that point onwards can be traced back to you. What’s worse is that you may not know it has even happened. For instance, those who remain connected to the VPNs for a long time – like when downloading torrents, they may not be around the computer to notice the drop in connection, and the device with default to the public connection without you knowing it. 

As an extra security measure, the VPN Kill Switch ensures that there will be no chance of your IP getting accidentally exposed in case the security of the internet connection is compromised. Since hacking a VPN server is not feasible, hackers opt to use cookies, spyware and malware, waiting for the VPN connection to drop for them to attempt mounting an attack on the phone, computer or network. It may also be a surveillance issue, for those in authoritarian regimes where online activities are constantly being monitored, and you don’t want an IP leak putting you in Big Brother’s line of sight. 

Say you were in the middle of an online transaction, whistle-blowing, or browsing a geo-restricted website, and then your VPN connection drops – even without your interference. This exposes your IP address, thus location. The site will notice that you’re reaching it from an unpermitted zone, and lock you out. Whatever activity you were doing at that time, be it accessing documents, streaming some entertainment or educational material, or even downloading a media file,  it will instantly get halted. 

Mainstream VPN providers come with the Kill Switch feature, from ExpressVPN, CyberGhost and NordVPN, to Private Internet Access and IPVanish. The mode of operation may vary based on the particular advances and capacity of the provider, but the gist of it is the same. For the mentioned ones, the Kill Switch will kick in immediately there is an interference with your internet connection. 

Is The VPN Kill Switch Automatic?

This varies depending on the VPN provider. For instance, with ExpressVPN, the Kill Switch will be activated the moment you make a connection since it has been enabled by default.  For others like VyprVPN, you’ll need to access the settings of the application to activate it. 

For some of the VPN providers, you also get to tweak the Kill Switch settings, to select when you want the feature to kick in. For instance, VyprVPN allows you to toggle between two settlings: ‘Application Level’ – the  Kill Switch is activated when the internet connection is disrupted while you’re running the application; and ‘System Level’ – here the Kill Switch will be active as long as you’ve been logged into the VPN, even when you don’t have the application itself running. 

Why Would You Get Disconnected?

Disruptions to your internet connection can happen due to a myriad of reasons. Don’t fret, you don’t need to get into geek-mode and start worrying about them, as long as the VPN installation process was properly followed. You may need to tweak some of the settings to suit your particular situation though. For instance, when it comes to the selected VPN protocol with ExpressVPN, switching from UDP (default setting) to TCP protocol may result in better connection stability. 

A common issue is a weak signal from your ISP, or a congested network. This is bound to affect the stability of your connection to the VPN provider. This also includes situations when you’re accessing the internet through a Wi-Fi connection, where if it is unstable then it will definitely affect the performance of the VPN service. 

The antivirus, firewall or anti-spyware of your device may also be interfering with the operation of the VPN service. In this case, you should include the VPN connection and an exception in the settings of the particular antivirus or antimalware program, whitelisting it. 

Conclusion

You use a VPN to protect your online identity, preventing your IP address, personal information and internet traffic from being exposed.  The VPN Kill switch will reinforce your defence, ensuring that there will be zero possibility of a data leak from your device. This is more critical if you use a connection for long periods, since it makes you more prone to issues that come with VPN network reliability.

Need a VPN?

]]>
What Is VPN Obfuscation And How Does It Protect You? https://eraser.heidi.ie/what-is-vpn-obfuscation-and-how-does-it-protect-you/ Fri, 04 Sep 2020 13:18:48 +0000 https://eraser.heidi.ie/?p=1439

So you’ve got the core elements covered. You’ve set up the VPN connection, and your data is private and secure. Your internet traffic won’t be traced back to you, and the information sent over the VPN tunnel is encrypted. Your identity is safe. However, there’s just one ‘problem’. Your ISP and government have the tools needed to detect that you’re using a VPN. Sure, they can’t read the traffic itself and know what you’re accessing or sending over the internet, but it does put you on their watchlist. Governments keen on identifying VPN traffic want to gather intelligence on what persons in their territories are up to – and in authoritarian regimes they go further to ban VPNs altogether. For the ISPs, it usually comes down to issues related with copyrights. 

There are regions where VPN users are even fined. For instance, in China, you must register with the government before being permitted to use a VPN, and in Chongqing province, VPN users failing to meet the legal requirements are fined $2,210.  In Iran, it can land one in prison for up to a year, and the population is restricted to just a couple of government-approved VPNs. Turkey and Belarus regimes are strict on internet usage, and within the UAE and Oman one can only pick from the list of ‘approved’ VPNs. Russia actively cracks down on VPN providers, with Putin legislation banning VPNs already in effect

So, you don’t want Big Brother to know you’re using a VPN service. That’s where VPN obfuscation comes in. 

What Is VPN Obfuscation?

It’s basically masking your internet traffic so that it hides that you’re using a VPN, and instead shows that data from your device is ordinary internet traffic. It comes by different names, including ‘stealth VPN’ and “VPN obfuscation”. Some providers have their unique names for it, like “NoBorders mode” with Surfshark VPN and “Chameleon protocol” when using VyprVPN.

It doesn’t change your traffic, but rather masks it, obscuring it from anyone looking to pinpoint VPN traffic. That way you can continue transferring the encrypted data, but also circumvent blocks that have been placed for VPN traffic, making your internet usage indistinguishable from the rest of the general public.

How VPN Obfuscation Works

When connecting to the internet and exchanging data over networks, the protocols used have their distinctive signatures. Third parties analysing the data packets can detect the signature. 

For instance, the most common VPN protocol, OpenVPN, has its digital signature. When the third party is analysing your connection, be it a government body, hacker, or the ISP you’re using, methods like the deep packet inspection are used.

VPN obfuscation comes in to dupe those analysing the traffic into believing that you’re using normal data packets, while in actual sense the VPN is still transmitting the encrypted data packets over its secure tunnel. 

Different methods can be used when masking the traffic. The goal is generally to add an encryption layer that makes the VPN traffic look like regular traffic. These include: 

This is part of the Tor Project, which was developed due to Tor traffic being blocked in territories like China. It will obfuscate the Tor traffic, preventing it from being detected.

While Obfsproxy was primarily developed for being used with Tor, you can also use it with OpenVPN. The setup uses different pluggable transports to hide the OpenVPN traffic, which will vary based on the block that is to be circumvented. For instance, obfs4 is one of the pluggable transports used with OpenVPN traffic, where it scrambles the traffic and makes it essentially look like nothing meaningful. 

This is open-source software that routes the VPN traffic through a TLS/SSL tunnel. Anyone snooping on the data packets will think that it is regular HTTPS traffic, because the TLS/SSL is one of the encryptions that is used by HTTPS.

Here, the OpenVPN traffic is disguised using the simple XOR cipher, which replaces the values of the bits of data, that way the data packet inspection methods will not detect the OpenVPN signature. Speaking of which, malware developers have also taken advantage of this to prevent their malicious code from being detected. The simplicity of the cipher means that it doesn’t always offer much protection especially from authoritarian governments cracking down on VPN usage. 

Mainstream VPN providers also offer obfuscation features as part of their services. These include:

  • ExpressVPN, which is renowned for even bypassing restrictions in countries like China that have loads of blocks, and has over 2000 servers for its network.
  • NordVPN, that also enables you to bypass the VPN blocks including regional firewalls like the Great Firewall and circumventing all regional geo-restrictions. 
  • SurfShark, with its over 1000 servers spread across over 61 countries, and where you get to obfuscate your VPN traffic by using the “NoBorders” feature
  • PrivateVPN, where you’ll need to enable the “Stealth VPN” feature, after which no one will detect that you’re connected to a VPN. 
  • Hotspot Shield that features fast connection speeds and relays your traffic through the “Catapult Hydra” protocol to ensure that it is secure and discreet. 
  • VyprVPN, where the feature is available by switching to the Chameleon protocol, obfuscating 256-bit OpenVPN encrypted traffic then transmitting it using port 443.

How VPN Obfuscation Protects You

Here are the benefits of VPN obfuscation, and how it keeps you safe from prying eyes:

  1. Bypassing government censorship

For territories with heavy restrictions on internet usage – like China, Iran, Pakistan, Egypt and North Korea, VPNs are widely used. Here, the governments block traffic to specific sites, like the “Great Firewall” of China that prevents users from accessing and using sites like Twitter, Pinterest, Google, The New York Times, Facebook and WhatsApp. As such, people turn to VPNs, where the content of the traffic is encrypted. The VPN, in turn, routes its traffic through secondary servers, that way when one is inspecting it, the traffic would be seen to have been directed to the VPN server, and not the banned website. However, the government knows this. The regimes are well aware that its citizens are using VPNs to circumvent the blocks. So they put in measures to block the VPN traffic. 

Governments can block VPN traffic in different ways. For instance, if they know the VPN server, they’ll simply block the traffic that is directed to it. This is why VPN providers keep on changing servers. Port 1194 that is usually used by OpenVPN traffic, can also be blocked. Techniques like Deep Packet Inspection (DPI) can be used, where they’ll detect the OpenVPN signature, and block the traffic. With obfuscation, where the VPN traffic is disguised as ordinary internet traffic, one will be able to bypass these measures.

  1. Bypass network blocks

For those in commercial facilities, educational institutions, offices and the like, some of the network administrators may have put in place detection measures that will identify VPN traffic. With obfuscation, you can circumvent them, and proceed using the VPN as normal.

  1. Prevent your ISP from throttling your internet speed

ISPs have a tendency to throttle one’s internet speed, especially when they detect that you’re making downloads, streaming or accessing specific websites. Sure, with ordinary VPN usage, the ISP will no longer get to see your specific internet content, or the websites you’re visiting. However, they may know that you’re using a VPN service, and slow down your speed. 

Note that the encrypting/decrypting measures that come with using VPNs, plus routing the internet traffic through different servers, means that the traffic will be slower than normal internet connections. However, when the ISP is throttling VPN traffic indiscriminately, it will be much slower. VPN obfuscation helps in protecting you from this. 

  1. Extra layer of privacy

The VPN already protects your identity and maintains your privacy, and obfuscating the traffic takes this a step further. That way in addition to your data being encrypted and your IP hidden, your traffic will be indistinguishable from the rest of the population using the internet. 

NEED A VPN?

]]>
What Is Double VPN, And Should You Use It? https://eraser.heidi.ie/what-is-double-vpn-and-should-you-use-it/ Fri, 04 Sep 2020 11:48:47 +0000 https://eraser.heidi.ie/?p=1431

This security feature is available with a few VPN companies, and is usually included in the top-tier packages. What does it mean? Should you cough up some extra cheddar to get it? In this article, we will break down Double VPN, and explain what you get from the extra layer of protection.

Double VPN 101: How It Works

First, the basic VPN connection. When you connect to your VPN server it becomes the intermediary between your device and the internet, passing your data through a secure tunnel. The data to and from the internet is encrypted, that way third parties will not be able to decipher it. 

Device >>> VPN Server 01 >>> Internet

Here, outgoing data is encrypted on your device (the laptop, smartphone, tablet, etc), then sent to the VPN server, where it is decrypted and sent to the target website, online service or app. 

Incoming data reverses this – it is encrypted on the server, and decrypted on your device. 

With Double VPN, a second server is added to this path.

Device >>> VPN Server 01 >>> VPN Server 02 >>> Internet

This means that you get a second layer of encryption. The second server can even be in a different city or continent. 

With this path, there are two approaches:

  • This first is Nested Double VPN. Here, for outgoing data:
  1. It is encrypted on your device twice. 
  2. This data is sent to the first VPN server, which removes one layer of encryption. 
  3. The result is then sent to the second VPN server, where the other layer of encryption is removed.
  4. The fully decrypted data is then sent to the destination website. 

Incoming data follows the reverse process. Each server encrypts the data it receives, and your device decrypts both layers of encryption. 

  • For the second approach, the data is not encrypted/decrypted twice on the end user device. Instead, for the outgoing traffic: 
  1. The device applies a single layer of encryption to the data. 
  2. This layer is removed at the first VPN, and the data is taken through a second round of encryption
  3. The data is then sent to the second server for decryption. 

This means that the data passing through the tunnels will only have a single layer of encryption, and both servers will be able to view the unencrypted traffic. 

This second approach is less common, and nested Double VPNs are more popular given that they provide the most private and secure configuration. 

Can more servers be added to the chain? Yes. This is referred to as VPN server cascading or VPN server chaining, where you get to have triple, quadruple or even more VPN setups. At every subsequent server, the IP is changed, and the data gets decrypted and re-encrypted before being sent along.

Why All The Fuss?

Well, while encrypting data gives you anonymity, since your ISP or any other third-party snooping on the traffic will find it difficult to decrypt, scrambling already-encrypted data makes it twice as difficult, and not worth the time, energy or money it would take to do so. 

In addition, neither of the VPN servers themselves can see both the source and destination of the internet traffic at the same time. While the first VPN sees that the encrypted data is coming from your device, it cannot tell where the data is going past the second VPN, meaning it won’t know the destination website. On the other hand, while the second VPN will decrypt the data and send it to the destination site, it will only know that it came from the first server, and not the original device that sent it. This gives the user an extremely high level of anonymity, and secures the data. 

What’s more, issues that would result from normal VPN connections – like the occasional IP and DNS leaks, will not be a concern here. Even if there is a leak due to a disruption in connection with the server, and the third part gets to unscramble some bits of data, this would only direct them to the location of the first server, and you will still have the second server clocking your identity. If the security of one of the servers is compromised, then the data getting to the second server will still be encrypted, meaning that third parties will not be able to read it.

Who Gets To Benefit From Double VPN?

Anyone who really wants to protect their privacy and anonymity. These are the likes of whistle-blowers, political activists, and citizens in locations where there are high levels of internet censorship. For instance, there are counties with authoritarian regimes that are forceful, cracking down hard on online freedom of speech. The Double VPN enables you to ensure that the chances of your online activities being traced through your network connection are virtually non-existent. 

The Disadvantages Of Double VPN

All that encrypting and decrypting is bound to weigh on your internet speed. Watching live broadcasts and buffering movies can be slow and frustrating. Certainly, it also depends on the speed that you get from the ISP provider. So, if you opt for Double VPN, ensure that you have sufficient bandwidth to accommodate it. 

Next is the price. As mentioned, this security feature is usually included as one of the top-tier packages with the VPN provider. Providers may also choose to separate the security options within the package, allowing you to use the default VPN normally and switch to the Double VPN when the need for the extra security arises. 

NEED A VPN?

]]>