silent_water [she/her]

  • 28 Posts
  • 2.22K Comments
Joined 3 years ago
cake
Cake day: October 26th, 2021

help-circle



  • under most cases, they only have this data via DNS. it’s encrypted once the actual https request is made - only the destination ip address is available at that point. so encrypting DNS and securing that is probably more important than the protection a VPN provides. if you use a VPN without some form of DNS encryption, you’re trading one ISP you don’t trust for a second you shouldn’t trust but inappropriately are. DNS anonymization is an extra step you can and should take to ensure you’re not trusting your DNS provider, either - it works by tunneling encrypted DNS requests through shared, public relays.

    what you actually need a VPN for is to mask your ip address to the website you’re visiting and to mask the ip address you’re visiting from your ISP. these are important considerations but it’s useless if you don’t first protect DNS, ensure you can’t be tracked via cookies/be fingerprinted, and ensure you’re only connecting to websites over https.

    VPNs are an important and useful tool but they’re not the first or best tool for digital hygiene. you have to tackle each layer, one at a time. start at the top and work down the hierarchy.