back
19 comments
At one end, who but a competitor will be in a better position to explain why their competition sucks.

At the other end, who but a competitor will be in a more biased position to explain why their competition sucks.

Most of these company blogs feel like guerilla marketing, and even when I agree with them, they leave an odd taste in the mouth.

Yeah, this one seems to be a lot of FUD. That's not unusual, sowing distrust seems to be a big component of VPN marketing.

One one hand, yeah, Google could suddenly decide to use your VPN traffic for tracking. On the other hand, couldn't any VPN provider?

The latter might also be why Google is rolling out their VPN: they don't necessarily want that data but they also don't want anyone else (competitors) to have a monopoly on it.

It could also just be at that VPN's are growing in usage and are a good business to be in. It builds on 3 growing parts of Google (Cloud, Fi and Pixel products). However, this is the boring answer and not as exciting as the "monetize your data" narrative
> in a more biased position

It's not their bias against competitors that's my issue, it's their bias in believing that VPN is a credible long term solution to the privacy problems they highlight.

It's right there in their basic premise. I only use VPNs for one reason: to securely connect to a remote location and participate as a local client on their network.

For protecting your own privacy you're going to need an _entirely_ different set of tools.

Could you please suggest tools other than a VPN for protecting privacy? I am guessing this would be along the lines of adblockers and custom browser configurations.

I am told VPNs may not be that great for blocking newer forms of advertising tracking (owing to advances in fingerprinting) -- but I have very little on hand to substantiate this notion.

There is a big continuum between better privacy and better convenience. You have to find a balance that works for your needs.

Some recommendations, from across this continuum:

Use a VPN, from a company that you trust.

Firefox - use containers to get some separation between services.

NoScript - for blocking JS. This takes some time to get used to but is definitely worth it. After you have a whitelist going, it is much less painful.

uBlock Origin - for blocking ads. This one is a super low hanging fruit.

Privacy Badger - occasionally catches some trackers missed by Firefox and uBlock Oigin.

Decentraleyes - to avoid big CDNs.

OpenDNS instead of your ISP’s or Google’s DNS. Or consider setting up a Pihole.

Switch your search engine to DuckDuckGo.

Tor (or even Tails) - significantly more privacy, but at a much higher convenience cost.

The biggest privacy win will be no longer using services from companies that don’t respect your privacy. This is doubly true of mobile. Many people cannot go without a smartphone (I still use a smartphone) but it’s worth considering whether you can drop it.

Thank you!

I hadn't heard of Decentraleyes, the project looks great.

As you mention, tracking of smartphones is more troubling. I was dismayed to learn how many applications were tracking me via Facebook identifiers. For this reason, I restrict most apps from accessing 'cellular data' and 'background app refresh' on my iPhone in hopes this might help mitigate the problem. And the tracking done via bluetooth + bluetooth beacons by companies such as Gimbal is insidious.

Doesn't the network you connect to have certain level of privacy guarantees? Could you then not use the concept of a "network" to build a privacy sandbox?
I can't count how many stories lately I have read where some algorithm determined that someone's google account was in violation of one of google's rules and it will not tell them what is wrong specifically, and there is essentially no hope of appeal either because that is automated as well.

And someone looses other things that seem unrelated. Do something weird or uncommon with google adsense, loose your google drive too.

Personally, I haven't experienced this kind of bs yet. But at this point, I don't want to take chances with using another google service that could suddenly shutoff with no explanation and no hope to resolve the issue and taking out who knows what else at the same time.

Markiplier has 27 million subscribers. He asked people to post emoji to vote in the chat.

Users that did were banned without appeal. Reinstated, but only after massive outcry.

The risk grows exponentially with each Google product one uses, including ones you don’t know about. Presumably including automated ML systems internal to Google to establish whether an account is kosher.

Because of the exponential increase in risk and unresolved uncertainty I just don’t consider the risk to be worth it.

Decide on your threat model. VPN from large, established company like Google is great option if you are looking to secure your surfing on various hotspots.

For small VPN providers you need to do the homework. Who owns the business, what’s their business model, privacy policy, how they handle information security etc.

A major concern that will likely be a part of the threat model of everyone considering using Google VPN is that it will be tied to your Google account. Given the frequency of Google account bans with no recourse, the possibility that your surfing will be used as a new input to the “should this account be nuked?” algorithm is very real. If you are someone who depends on a Google service tied to the same account you plan to surf on, this is a pretty scary threat, even if you don’t buy the arguments made in the article.
The VPN term repurposing is so weird. There's no PN about this kind of setup.
I think you use Google VPN because I like the idea of supporting companies that aren’t already a dominant force in the industry. The same reason I shop at local stores rather than the big boxes.
Reading the title made me giggle--the 'P' in VPN is privacy.

You should really only use a VPN from a company whose main, top, only focus and business model is your privacy.

Technically it's private, not privacy. The original point of VPNs is to be in a different _private_ network, like a LAN, "virtually", instead of locally.

The privacy thing was just added on by simply sending all of your traffic over the tunnel, in the hope that the VPN exit router monitors less than your local one.

Right, but if one end is in Google-scale infrastructure rather than a network I control, is that still private?
Yes, similar to a skyscraper being private property. It's private as in 'non-public internet', not as in 'only few humans have access/knowledge'.
I just updated my Google One app to get the version that supports VPN. It's a huge privacy win to not have Comcast or my mobile data provider see my traffic.