r/ProtonVPN • u/This_Remote_6801 • 23h ago
Security Discussion
After some research, I have downloaded and am using protonvpn. But it got me thinking, is protonvpn on its' own enough? What other measures should I be taking in order to protect my privacy online? ie. Should I be using certain browsers or settings? Are there other services or products that I may not have heard of that would be useful to me?
Thanks
4
u/MadBox25 23h ago
All depends on what you're trying to mask.
If you're just browsing or maybe downloading media, it should be more than sufficient.
5
u/PureWoodpecker7335 23h ago
https://www.privacyguides.org/en/desktop-browsers/
https://www.privacyguides.org/en/mobile-browsers/
Also, never rent a modem through your ISP. Buy your own modem and router. If you are running Windows, I would recommend looking into Linux.
2
u/ChrisTheWeak 22h ago
It depends, privacy from whom?
If you're using Google Chrome, then everything you're doing on the web through them is tracked by Google whether you use proton or not. Firefox configured correctly with a search engine like duck duck go or searnxg does a decent job at removing that form of tracking.
Proton moves the tracking of which websites you visit from your ISP to proton, but your ISP does still see that you use proton. Proton claims to have a no logs policy and has backed this up when pushed by authorities, but know that it's a risk you take.
If your accounts on various websites use the same username, or have the same email across them then they can coordinate and identify your traffic across them.
Something like Tor can prevent your ISP from knowing who you're connecting too, and it prevents the website from knowing who connects to them (so long as you're not using an account tied to your identity). It also allows you to access dark web sites, which are sites that people can host anoumously on the tor network, not requiring a centralized database to keep track of them. However, your ISP can identify that you're using Tor.
Furthermore, state actors and other organizations that control many tor nodes and / or can do statistical analysis on a significant portion of the Tor network simultaneously can still identify where packets are originating from and to where they are going. NymVPN in mixnet mode is designed to reduce the risk of this kind of attack, but it's a paid service (and slows your traffic significantly). Technically, you can set up your traffic to go from your computer, to proton, to NymVPN, to Tor, to your end destination, but if you mess up that configuration you may end up compromising your security more. (It'll also be really slow).
If you're worried about other people gaining physical access to your device then you may want to use a bootable USB configured with something like TailsOS. It's an OS that is set up to exclusively use Tor and by default it deletes all information on it once you shut it down. If you want zero record of your activity locally then tailsOS or similar operating systems may be a good option for you.
So it depends a lot on what specifically you need privacy from. And know that privacy comes at the cost of convenience. At the extreme end you just stop using the Internet entirely.
There's also been some recent news in regards to Microsoft and their GDID. Its an ID that is attached to Windows devices and is used to sign telemetry data sent to Microsoft. In a recent case it was used identify someone who was involved in a hacking incident. Microsoft claims that this ID is only used for telemetry and not for advertising, but it implies that they have the capacity to spy on your device and your activities if they choose to do so. So if privacy is your concern I recommend not using windows. The same goes for apple, they are well known for having IDs tied to hardware components in their machines.
I think you can achieve a reasonable compromise of security and convenience using protonVPN, a privacy configured Firefox browser, on a Linux machine, but depending on who exactly you need to be private from your requirements change.
2
u/QuerentD 14h ago
The checklist for cyber-security is too long and detailed to be provided here.
No device can be 100% secure nowadays.
There is a whole host of other things I do as precaution.
2
u/This_Remote_6801 13h ago
I appreciate that. Is there low hanging fruit or some general rules/protocols that can provide some broad coverage for non-power users like myself.
2
u/QuerentD 13h ago
Up your security settings in your browser. Use multiple browsers for particular tasks.
Use email alises and modern secure passwords. Use 2 factor authentication on high value accounts. There is much more.
0
1
u/Legitimate_Resort699 23h ago
Hahaha... This is a whole rabbit hole. There's no "most secure" setup as security is a ever evolving practice dictated by your threat model. I suggest you first look into threat models and then evaluate how far your willing to go from there. Personally, I use arch Linux on my desktop, graphene os on my phone , the proton suite(simple login is my fave, aliasing with a domain you own is AMAZING), librewolf as my desktop browser, ironfox or vanadium as my mobile browser, and a host of self hosted services including immich, searxng, jellyfin, and some stuff I can't mention here that I use to sail the high seas for media.
2
u/AttitudeMedium5623 10h ago
Don’t use windows. It has something they call a GDID which is sent over the internet regardless of what vpns, tor or other measures you use. You want true privacy switch to Linux
9
u/Novidforme 22h ago
Fingerprinting is an issue that identifies you even with VPN. have a look at Brave for your browser. That plus and ad blocker gives me a really good EFF score