L
L
Leonid2022-03-23 11:36:47
VPN
Leonid, 2022-03-23 11:36:47

Which ones to increase the security of your VPN server?

I rented an inexpensive VPS from a Russian hoster in a data center (Europe).
Quickly installed and configured PiVPN ( WireGuard )
Good ping, normal speed - 2k video in YouTub looks good.
Everything is convenient, everything is beautiful, fast and good...

But what about security?
It's a Russian hoster with a data center in a European city...

How to secure yourself additionally?
Do they explicitly log all requests (traffic) from the VPN server?
Does WireGuard itself or Linux also leave traces inside itself?

Answer the question

In order to leave comments, you need to log in

3 answer(s)
C
CityCat4, 2022-03-23
@CityCat4

Do they explicitly log all requests (traffic) from the VPN server?

What is explicit is not proven, but it is better to assume that this is so.
The VPN from the Russian hoster lowered your anonymity ... :) Because where did you go to it from (that end of the tunnel that you have) - the hoster already knows - you hardly go to the face of the hoster's control through an additional VPN. And you have a label "uses VPN". And the traffic of your VPN also knows - well, if desired, of course, it didn’t bite him for nothing.
Machine (VPS, in the sense) at the host - at his disposal. Taking a snapshot is a matter of a few minutes. Reveal the root password - a few more minutes. Oops - and the hoster has your real IP (address of the second end of the tunnel) and keys :)
Of course, this is not automatic, but if necessary.
The relative reliability of the "VPS in yoben" scheme was connected precisely with the fact that the hoster is a foreigner and his Russian laws do not stick anywhere. Now it is practically impossible to pay for hosting in the same yobens as before in such a way that it is not possible to link the payment to your personality.
A scheme with access to tyrnet through a VPS in the Netherlands, for example, will work if you need to:
- get to sites blocking IP from the Russian Federation like analog devices
- get to sites blocked by RKN like twitter or insta (although you should be more careful with the latter - it is still on the list of extremist ones)
But this scheme will not work if there is an idea to write "any bad thing" for example, on VKontakte, supposedly from a Dutch IP - they will calculate it in a swoop.
A VPS that keeps VPN in yobens is not at all about anonymity (preventing the establishment of a connection between the vasyan login and the user's real name, as a rule, a set of administrative and technical measures), but about security (countering traffic interception and modification (a purely technical solution that can be used to increase anonymity in the complex, but in itself does not increase it in any way).

P
paran0id, 2022-03-23
@paran0id

What I did:

  • Hosting on digitalocean
  • openvpn
  • Non-standard ports
  • Blocking all found near-government Russian subnets (google)
  • psad, fail2ban, other standard measures

So far it works, but the fact that during the war with telegram servers were not banned by mask along with half of the digital ocean is pure luck. When they start fighting with vpn at the protocol level, I don’t even know what to do. Maybe I'll find a modified client and server, or I'll send traffic through the ssh tunnel. There are options, but they are all unreliable - you need to act according to the situation, and you should not expect guaranteed working options.

A
AlexVWill, 2022-03-23
@AlexVWill

I propose to immediately understand - VPN is not about anonymity, it's about security. This is a virtual private network, but if there is a server in this private network that is not administered or hosted by you, then there is no anonymity from the owner of the server. If anonymity is needed, then there are more other means, the same TOR for example.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question