I don’t use a VPN, even on public WiFi, because I don’t use any unsecured protocols (except for occasional public HTTP). Am I being naïve?

Oct 16, 2017 · 5:15 AM UTC

17
1
2
Replying to @stilkov
Meta Data Collection. DNS injection.
Replying to @stilkov
There are some man in the middle moves that can happen, so like all things security, defence in depth. (Btw I don’t use VPN )
Replying to @stilkov
Using a VPN means relying on some faceless ISP you don't know while using public WiFi means relying on some faceless ISP you don't know.
3
2
3
Replying to @stilkov
You may be susceptible to: DNS poisoning DNS filtering / restrictions MiTM if your client doesn’t use pinning
Replying to @stilkov
If you don’t pin public keys (e.g. innoq.com) it’s easy to intercept/MIM connections. In the end it boils down to basic trust…
1
Replying to @stilkov
Since I was in China 12 years ago I’ve setup a private SSH/VPN server but I just use it for mails and calendar, browsing and developing w/o
1
Replying to @stilkov
With a well managed VPN you could avoid entire classes of attacks: typosquatting, DNS spoofing and mitm for example @GardionHQ
Some open WiFi system inject JS Content into your HTTPS via MITM. This is a „service“ to show time left in free WiFi... and obvious not safe
1
I use Own VPN, so I connect to home network (to access NextCloud) and for surfing, it is also helpful against GEO blocking