Don't Use a VPN with Tor

preview_player
Показать описание

Video references:
___________________________________________

📱Social Media📱
___________________________________________

💸Donate💸
___________________________________________
Like the channel? Please consider supporting me on Patreon:

Hacker Books:

My Build:

My Recording Equipment:

Рекомендации по теме
Комментарии
Автор

but surely by not using a VPN only shifts the logging vulnerability back to the service provider your using who will almost certainly be doing the same. or have i missed something?

UserName-fv
Автор

This is why you use your own VPN hosted on a VPS in a country that does not cooperate with the US justice system. You know, hypothetically.

Slickjitz
Автор

Good video, might be worth calling out that you can spin up your own vpn on one of many providers and configure the server yourself to dump logs. You could also build a service to watch for unknown patterns that will self destruct the server. The downside is the provider may be taking backend snapshots of the volume your server lives on, such as a SAN storage device as the underlying layer. I guess it comes down to knowing the environment you live on/in.

For portability, you could build a VPN docker image. This way if the container is compromised, you could just down the running container and spin up a new one. Again this would require services to monitor your VPN.

mitchodonnell
Автор

There is absolutely no VPN provider that you can trust will never collect logs. Even if they don't normally do, they *will* have to start collecting if asked by the proper authorities. That's what happened with Proton VPN not too long ago.

eaad
Автор

I really expectd a "LETS HAVE A WORD FROM OUR SPONSOR NORDVPN"

member
Автор

I'm confused. If you use a VPN, access tor, and they give up the logs, all the logs are gonna show is that you accessed tor, right?

jaycrowson
Автор

Some of these VPN companies can show court cases where they didn have logs to hand over to them and they were red team tested and still didn't have logs to hand over. Some of them are liars.

kythrathesuntamer
Автор

5:08 Can someone explain why the graphic shows the last hop is "Not encrypted by Tor" when it IS encrypted by Tor without the VPN?

LewisCostin
Автор

Doesn’t the traffic routed by the VPN still have the last layer of TOR encryption? How are logs any useful in that case?

Tetemovies
Автор

This doesn't make sense. If you use a VPN over tor and In this case stalk someone where it is a criminal offense. And the VPN keeps logs. Then what you're saying is that the VPN will turn those logs over the authorities.

But how is that any different than not using a VPN and your isp gives the logs to the authorities. Either way the authorities are gonna get what they need whether from the VPN provider or the isp provider.

rashad
Автор

Doesn't tor have tor bridges instead of using VPN that's a better way to use tor.

BabuMosahi
Автор

But the VPN provider (if they keep a log) would only see that you are connected to Tor but not what you are browsing right? that's how I understudy it

karraralhasan
Автор

I like how I just came from a video telling me I do need VPN and a TOR browser ='D

vinnieg
Автор

so you are advising to use just Tor directly?

dontreadmyname
Автор

A VPN knows that you accessed TOR, but how would they know what you were doing on it?

samwilliams
Автор

I understand everything you are saying. But IF the government owns a lot of nodes and maybe makes you somehow go through these nodes, doesn't that mean that your info is then also exposed to the government?

_matis_
Автор

I am not into OffSec but I love your content and have learned alot. You have brought alot of sunshine to the offsec world and we love you for it.

frodobe_tbaggin
Автор

What do you think of using a proxy chain vice a vpn?

raptorprecision
Автор

Using a VPN doesn’t appear to be any worse than not using a VPN and could be better. At least that is my takeaway from this

paulemge
Автор

you're saying that some nodes are being bought by "someone", isn't it the same as saying is not trustworthy?

XtremuZ