asking for the kind that vpn hides tor and not the other way
i have a framework with whonix in qubes using tor browser (real one i think not brave) and idk if im safe.
i want to use wifi in public (food places and schools) and be hard to spy on and not have anything blocked (videos are blocked). my home network is also phoning home because my family is using a google wireless access point (cant change it they dont like having internet down for more than 5 seconds)
would vpn and tor fix this? should i pick just one? or is there a better way? (all things have to be on device since you cant change someone elses network)
You should be good with just a VPN. Tor over VPN (not the other alway round!) makes sense if you want to hide your use of Tor from whoever is watching, and especially if you use Tor Browser for something you want to hide, the timing of when you open and close Tor Browser could be correlated with the thing you’re doing. Overkill for just watching videos in privacy.
Never use tor with a VPN because it can make you easier to identify on the tor network.
Edit: https://support.torproject.org/tor-browser/general/vpn-with-tor/
Also, it is only fine to use a VPN with tor if you know what you are doing.
i heard you can if you use vpn to hide tor and not tor to hide the vpn
do you mean easier to identify by advertisers, malicious nodes, or isp/gov?
(i dont know what im doing yet)
I use Mullvad + Tor myself from time to time. So I read through the article to understand what issues might come up. Turns out it’s actually advantageous in most cases with a few exceptions. If you use Mullvad (0 logs) and pay through monero/cash/vouchers (no money trail) you’re (slightly) better off.
I’m not sure the topic is really about privacy, but if your threat model requires a VPN + Tor, you’re already screwed.
The government can see the metadata of your requests. With enough metadata they can identify what you’re doing. Adding a second layer doesn’t really change that.
What metadata are you talking about?
They can see the timing and packet size for your requests to the VPN server, as well as what your VPN provider is. On the VPN’s end they can see what sites the users (collectively) are visiting, the packet sizes, and the timing. That information alone is enough to identify who is doing what with reasonable accuracy.
This is before issues of using the government’s massive resources to brute-force encryption, possible government backdoors in VPN servers, and browser fingerprinting.
There are various steps that can be taken to mitigate this, and this of course assuming the government has access to the ISP’s metadata from both your network and the server’s network (not a stretch, but not necessarily guaranteed).
A VPN is basically just a replacement ISP. They see everything your ISP traditionally sees.
Many ISPs are already selling your traffic data. So if you trust that your VPN isn’t selling that data, then you’ll be more private using them. And if the VPN is in a different country, then your government is less likely to be able to force the VPN to give up data.
You can defend against timing attacks and other traffic correlation attacks too, using techniques like cover traffic.
cover it with what?
You just need a vpn. Based on your other tech support threads you need the one with the fewest ways to mess up (I do too). You should try mullvad. If it turns out that you have to shuffle around different servers too often and can’t tolerate being blocked, switch to a geofencing bypass style vpn like nord or something.
Bear in mind I’m recommending mullvad because it’s really hard to use it in an unsafe way, which it unique in the vpn world. If you go with something else you’ll have to make sure you understand the choices you’re making which is often a tall order.
ill try it 👍
No, combining them is pointless.
Can you elaborate? A VPN would hide their IP address from the entry node which is a good thing, right?
The point is if you want to hide the fact you use tor, while yes it will hide you from the entry node, the beauty of the tor system is it has more than one point of failure, using a VPN makes the VPN a single point of failure since knows who you are and what website you are going to. That being said, I’m to lazy to split tunnel when I feel like using Tor, my traffic doesn’t really need that level of animinity anyways
I think Mental Outlaw did a good video on the subject. I’ve also seen several good talks that cover it from conferences like Defcon. They’ll do a much better job than I could in a comment.
Just do one



