Related
EFF is bringing the security and privacy of HTTPS Everywhere to an important new frontier: your Android phone. As of today, you can install HTTPS Everywhere on Firefox for Android (until now, it could only protect desktop browsers). With HTTPS Everywhere installed, Firefox for Android encrypts thousands of connections from your browser that would otherwise be insecure. This gives Firefox a huge security advantage over every other mobile browser available today.
This is exciting news, because HTTPS encryption allows smartphone users to safely download apps, browse the web, exchange emails and instant messages, sync data between devices, and countless other everyday tasks. As we carry around our phones and tablets, we often connect to unfamilar WiFi networks, putting our personal data at risk of being monitored, collected, and tampered with by anyone else on the same network, as well as Internet Service Providers, network operators, and government agencies. In fact, we discovered last week that NSA and GCHQ have been invisibly tracking and profiling users based on data leakage from smartphone apps.
HTTPS Everywhere guards agains these attacks in your browser by switching insecure HTTP connections to secure HTTPS connections whenever possible using thousands of URL rewrite rules. Whereas data sent to a server over HTTP can easily be read and modified by third parties, HTTPS uses strong encryption to guarantee data confidentiality and integrity.
Click to expand...
Click to collapse
https://www.eff.org/deeplinks/2014/01/making-the-mobile-web-safer-with-https-everywhere
Figured I'd share this with you guys. HTTPS Everywhere has been a great desktop Firefox addon, I'm really happy to see them finally get a mobile Firefox version out. Probably the best way this would protect people are when using public wifi, but of course the site you visit would have to offer some form of HTTPS/SSL for the addon to work. It basically just helps you get the most out of sites that do offer it (some sites, like Youtube for instance default to HTTP).
Hmmm.. interesting.... But does Https Everywhere still have the problem that because of it, pages in general load a lot slower?
I haven't noticed any slow down personally. All this does really is help sites that support HTTPS/SSL to some extent, but for whatever reason do not default to it when I user visits the page. And obviously they make sure the site doesn't get broken before adding it in their extension's site list.
There's a whole FAQ here too that might explain it better than I ever could. All I know is if Tor browsers use it along with Noscript, it's a good security add on. Way better than nothing.
https://www.eff.org/https-everywhere/faq
But the add on should also make use of their SSL Observatory, which is a measure in place to protect users:
The EFF SSL Observatory is a project to investigate the certificates used to secure all of the sites encrypted with HTTPS on the Web. We have downloaded datasets of all of the publicly-visible SSL certificates on the IPv4 Internet, in order to search for vulnerabilities, document the practices of Certificate Authorities, and aid researchers interested the web's encryption infrastructure.
Click to expand...
Click to collapse
https://www.eff.org/observatory
Lots of people are having trouble getting Orbot working on newer devices. To solve this I made Orxy: a compatible alternative free anonymous Tor proxy.
Orxy is an Orbot alternative that supports devices running the latest Android. Orxy protects network traffic using The Onion Router (Tor) network. Tor encrypts the data and sends it through random points across the world to hide where the connection started. For example, while using Orxy, a website you visit might think you're looking at it from another country. Use it the same way as Orbot: configure your apps to use the local proxy server settings. Instruction details on the play store page.
It has optional add-ons to get full Tor proxying without root, and to hide the Tor traffic in another a layer of encryption. Neither are required to use the app.
If Orbot is not working, I hope it helps get people their Tor back.
Available on Google Play
Legalese: It is produced independently from the Tor® anonymity software and carries no guarantee from The Tor Project about quality, suitability or anything else. Do not use without knowing the inherent risks and limitations of Tor. Use at your own risk.
Thanks....
It's Cool
Glad you like it, thanks for the support.
Promo for XDA readers:
https://rideem.io/from/orxify/for/xda gives out a code per day to get the orxify add-on free.
Greetings all and Happy Holidays.
Per some fellow XDA users request and also to compliment the great thread "[TUTO] How To Secure Your Phone," by: unclefab, I figured this would help...a thread on VPN.
I am also shocked to not see anything in the security forum about VPN! I did a search and NOTHING.
What is a VPN?
(Virtual Private Network)
A simple search on the web will give you the nitty gritty stuff on what a VPN is, but I'll just lay it out very simply.
A VPN takes your data connection and encrypts it so it protects your data from not only your ISP seeing your traffic, but also from middle man attacks. Say if you were at a cafe connected to their open (unsecured) public WiFi and you did some shopping online, which involved you entering in your credit card number, name, address, etc... Well, it doesn't take much for someone to intercept your sensitive data passing through the cafe's unsecured WiFi connection.
How it works:
Encrypts your Computer's/Phone's data ---> Connects it to your VPN's server (Exit Server) ---> Then it reaches the end destination (website). (Safe Passage)
ie...
Safely passes your Internet Data, through a ---> [TUNNEL] ---> ...that is encrypted so that all your data is not only anonymous, but also protected.
There are may VPN's service providers out there, however, they are not all created equal. I've spent a lot of time researching VPN's and have went to great lengths to find the best of the best. The criteria of what I was looking for is as follows:
Offshore Company. Something outside of the US.
Liked and approved by even the extreme private/security activists.
Reliability and Speed! Some VPN's can be very slow only allowing you to achieve 30-50% of your internet speed at best.
A wide choice of servers.
Able to pay anonymously.
A VPN THAT WORKS ON OUR ANDROID DEVICES!
Some VPN companies have their own Android VPN client, which makes things a breeze. Just launch, connect and violla....all your traffic is now safely tunneled.
For the companies that do not have their own Android VPN client, you'll have to use the app: OpenVPN, which can be a hit or a miss for those on KK 4.4. Let me explain...
When I was on my Note 3 on 4.3, OpenVPN worked flawlessly and my speeds were darn near 100% of my regular LTE speeds even connected to a VPN! Well, once KK 4.4 came around, it completely ruined everything in terms of being able to stay connected. KK 4.4 is and was a nightmare for OpenVPN users. Upgrading from 4.3 to 4.4 was the biggest mistake I have ever made in my Android world. Bottom line, KK 4.4 sucks.
The good news is, there are a few VPN companies that work flawlessly on KK 4.4. I'm using one at the moment and it stays connected just fine with awesome speeds!
Why you should use a VPN:
Well think about. You can go the whole nine yards in securing your phone, which is awesome, but then you'd still be tunneling all that traffic "unencrypted," over the internet .... this is counter-intuitive in every way that you look at it. It's like ordering a BIG MAC Extra value meal and getting a diet coke. I mean really? What's the point? Diet? No matter how you see it, you're going to get fat if you keep eating it and thinking a diet coke is going to take edge off of you getting fat. Sorry, it doesn't work that way....
Imagine a semi-trucks driving down the highway with some completely exposed and some locked and covered. Well you'll obviously be able to see the exposed cargo on all the trucks that are not contained yes? Whereas the ones that are covered and locked, you'd have no clue what's in there. This is how a VPN works....it covers your data/traffic so that no one can see or know what is inside of that container during transit...ie...it provides a safe passage of your data over the internet to the end destination.
Now a VPN will protect your data from point A to the end destination (website.) That website will only be able to see your "exit server," and not your ISP or your location, but of course your data.
Ex: You're in New York connected to the internet using a VPN ----> The VPN server you're connected to is in Texas ---> The website you're visiting is located and hosted in Canada.
In that example, your "encrypted" data/traffic is being routed through Texas and then to Canada where the website is hosted/located. Make sense?
Because you're connecting to a VPN server, this is why you have to know which ones to use so that you can trust your data routing through their servers. Not all VPN companies are created equal!
If you're interested to know which VPN's are best in general and for our Android devices, PM me and I'll share with you my research. I don't want to advertise anything on here to be in compliance with the forum rules.
I hope this helps!
To be continued....
You forgot to tell the data is not encrypted by the VPN between it's server and the website's server, you are only moving a problem from place A to place B. It may be better for you if this is what you are looking for but it doesn't add that much security.
How a VPN works : Your device data is encrypted FIRST, it leaves your device and goes to the VPN's server, it is DECRYPTED, and then it is relayed to the server you were trying to contact. Your data is less traceable but you're not anonymous, the VPN provider knows who you are and your DNS provider may still know what you are looking at if you the device leak DNS requests.
Your guide is missing details, anonymity and security is not easy and trying to simplify it too much you lost important parts users should not forget.
Regards
Magissia said:
You forgot to tell the data is not encrypted by the VPN between it's server and the website's server, you are only moving a problem from place A to place B. It may be better for you if this is what you are looking for but it doesn't add that much security.
How a VPN works : Your device data is encrypted FIRST, it leaves your device and goes to the VPN's server, it is DECRYPTED, and then it is relayed to the server you were trying to contact. Your data is less traceable but you're not anonymous, the VPN provider knows who you are and your DNS provider may still know what you are looking at if you the device leak DNS requests.
Your guide is missing details, anonymity and security is not easy and trying to simplify it too much you lost important parts users should not forget.
Regards
Click to expand...
Click to collapse
Misleading? I think you need to re-read the post. Here let me help you:
"A VPN takes your data connection and encrypts it so it protects your data from not only your ISP seeing your traffic, but also from middle man attacks. Say if you were at a cafe connected to their open (unsecured) public WiFi and you did some shopping online, which involved you entering in your credit card number, name, address, etc... Well, it doesn't take much for someone to intercept your sensitive data passing through the cafe's unsecured WiFi connection."
"Now a VPN will protect your data from point A to the end destination (website.) That website will only be able to see your "exit server," and not your ISP or your location, but of course your data."
"Ex: You're in New York connected to the internet using a VPN ----> The VPN server you're connected to is in Texas ---> The website you're visiting is located and hosted in Canada."
So you're going to argue the fact that a VPN wouldn't be affective in a cafe scenario like the example I've given in the post?
Any additional information is appreciated, but please don't come in here saying that it's misleading....
THE FACT IS...YOU'RE BETTER OFF WITH A VPN, than WITHOUT ONE. PERIOD.
It's about trust, the VPN server can do the middle man attack itself or one could do it somewhere between the VPN's server and the final destination.
Of course you're better with a VPN most of the time, but it's important to clearly state it's not captain america's shield neither. It's important to clearly tell at all cost that the data is encrypted only between you and the VPN's server.
Best regards.
The only way to ensure you are safe from MITM is to use end to end encryption, like SSL/TLS (https). Even if the MITM is using sslstrip, you'll be able to tell by the security popup in your browser when it asks you to trust the connection (which you shouldn't...)
VPN is useful for protecting you from someone sniffing the airwaves on an open network or for accessing services behind a firewalled network. (Like SMB/Windows File Sharing).
Like Magissa said, it isn't captain America's shield, and don't be fooled by a false sense of security. You have to trust the VPN provider, and it would be pretty easy for one to sniff your traffic or read logs...
iunlock said:
Greetings all and Happy Holidays.
Per some fellow XDA users request and also to compliment the great thread "[TUTO] How To Secure Your Phone," by: unclefab, I figured this would help...a thread on VPN.
I am also shocked to not see anything in the security forum about VPN! I did a search and NOTHING.
What is a VPN?
(Virtual Private Network)
A simple search on the web will give you the nitty gritty stuff on what a VPN is, but I'll just lay it out very simply.
A VPN takes your data connection and encrypts it so it protects your data from not only your ISP seeing your traffic, but also from middle man attacks. Say if you were at a cafe connected to their open (unsecured) public WiFi and you did some shopping online, which involved you entering in your credit card number, name, address, etc... Well, it doesn't take much for someone to intercept your sensitive data passing through the cafe's unsecured WiFi connection.
How it works:
Encrypts your Computer's/Phone's data ---> Connects it to your VPN's server (Exit Server) ---> Then it reaches the end destination (website). (Safe Passage)
ie...
Safely passes your Internet Data, through a ---> [TUNNEL] ---> ...that is encrypted so that all your data is not only anonymous, but also protected.
There are may VPN's service providers out there, however, they are not all created equal. I've spent a lot of time researching VPN's and have went to great lengths to find the best of the best. The criteria of what I was looking for is as follows:
Offshore Company. Something outside of the US.
Liked and approved by even the extreme private/security activists.
Reliability and Speed! Some VPN's can be very slow only allowing you to achieve 30-50% of your internet speed at best.
A wide choice of servers.
Able to pay anonymously.
A VPN THAT WORKS ON OUR ANDROID DEVICES!
Some VPN companies have their own Android VPN client, which makes things a breeze. Just launch, connect and violla....all your traffic is now safely tunneled.
For the companies that do not have their own Android VPN client, you'll have to use the app: OpenVPN, which can be a hit or a miss for those on KK 4.4. Let me explain...
When I was on my Note 3 on 4.3, OpenVPN worked flawlessly and my speeds were darn near 100% of my regular LTE speeds even connected to a VPN! Well, once KK 4.4 came around, it completely ruined everything in terms of being able to stay connected. KK 4.4 is and was a nightmare for OpenVPN users. Upgrading from 4.3 to 4.4 was the biggest mistake I have ever made in my Android world. Bottom line, KK 4.4 sucks.
The good news is, there are a few VPN companies that work flawlessly on KK 4.4. I'm using one at the moment and it stays connected just fine with awesome speeds!
Why you should use a VPN:
Well think about. You can go the whole nine yards in securing your phone, which is awesome, but then you'd still be tunneling all that traffic "unencrypted," over the internet .... this is counter-intuitive in every way that you look at it. It's like ordering a BIG MAC Extra value meal and getting a diet coke. I mean really? What's the point? Diet? No matter how you see it, you're going to get fat if you keep eating it and thinking a diet coke is going to take edge off of you getting fat. Sorry, it doesn't work that way....
Imagine a semi-trucks driving down the highway with some completely exposed and some locked and covered. Well you'll obviously be able to see the exposed cargo on all the trucks that are not contained yes? Whereas the ones that are covered and locked, you'd have no clue what's in there. This is how a VPN works....it covers your data/traffic so that no one can see or know what is inside of that container during transit...ie...it provides a safe passage of your data over the internet to the end destination.
Now a VPN will protect your data from point A to the end destination (website.) That website will only be able to see your "exit server," and not your ISP or your location, but of course your data.
Ex: You're in New York connected to the internet using a VPN ----> The VPN server you're connected to is in Texas ---> The website you're visiting is located and hosted in Canada.
In that example, your "encrypted" data/traffic is being routed through Texas and then to Canada where the website is hosted/located. Make sense?
Because you're connecting to a VPN server, this is why you have to know which ones to use so that you can trust your data routing through their servers. Not all VPN companies are created equal!
If you're interested to know which VPN's are best in general and for our Android devices, PM me and I'll share with you my research. I don't want to advertise anything on here to be in compliance with the forum rules.
I hope this helps!
To be continued....
Click to expand...
Click to collapse
which is the best VPN to use?
I've installed OpenVPN for Android and it works fine.
[VPN (Virtual Private Network) and why you should use it if you're serious ab...
TheMoroccan said:
which is the best VPN to use?
Click to expand...
Click to collapse
There's no concrete answer to that question. Your best bet is to use a VPN provider that's based outside of your country, preferably one that is less likely to corporate with your local law enforcement.
Agreed. Out of country, away from your government's reach... There are some offshore server farms in countries with lax laws... Those are usually tax havens also. Research
snapper.fishes said:
There's no concrete answer to that question. Your best bet is to use a VPN provider that's based outside of your country, preferably one with a less likely to corporate with your local law enforcement.
Click to expand...
Click to collapse
Thanks bro for the info.
VPN Do you use one, do you notice ?
Yes I know why using a VPN is a good idea, hides you location.
Have thought about using one but a few concerns.
Price .... something like Express VPN is not free
Does a VPN slow your device ?
VPNs are great for privacy and bypassing location locked content. Recommend them for everyone especially if you are on public wifi networks a lot.
Does it slow your phone? No
Does it slow your connection? Slightly - depends on the vpn service and server you are connected to.
ExpressVPN is not the only VPN service out there. You can also look into Nord, PIA, CyberGhost, Tunnelbear.
FYI - Free VPNs aren't really free. They limit your bandwidth, show ads on connection and possibly do store some of that data being transferred. Best option is to go with a well known paid one. It is worth the $5-$15 per month for the privacy.
Hunter3U said:
VPNs are great for privacy and bypassing location locked content. Recommend them for everyone especially if you are on public wifi networks a lot.
Does it slow your phone? No
Does it slow your connection? Slightly - depends on the vpn service and server you are connected to.
ExpressVPN is not the only VPN service out there. You can also look into Nord, PIA, CyberGhost, Tunnelbear.
FYI - Free VPNs aren't really free. They limit your bandwidth, show ads on connection and possibly do store some of that data being transferred. Best option is to go with a well known paid one. It is worth the $5-$15 per month for the privacy.
Click to expand...
Click to collapse
+1
I have been using VPN for years.
Performance impact hasn't been an issue since three or four phone generations ago.
It does have a small impact on battery usage.
Free VPN sucks. They rarely work when you need it, and when it does work the speed is all over the place.
Commercial VPN service quality varies depending on your ISP and how you plan on using it. The reputable VPN usually offers some kind of trial period so you can try them out and decide for yourself.
AstroDigital said:
VPN Do you use one?
Click to expand...
Click to collapse
Yes. I concur with the above statements.
Phishing, have a lot of attacks yesterday for example "iTunes" sent a receipt for an expensive pack, they wanted me to get mad and click on the link..... I am not that stupid.
Netflix, if they trace a VPN well they can simply block access. They know I am Canadian from my login I am not sure how VPNs can get around Netflix content block.
Torrents, never done them
China I never plan on going
Tell me even still, money no object want do you recommend
Thanks guys, I do not think I will bother.
Reasons for VPN
You can not be traced, do not do torrents.
Hacking my security guy says sure in theory on open WiFi but he has not seen the happen
Get international websites Netflix, well some claim this is possible
If you ever visit a place like China
Not sure it is worth the money.
AstroDigital said:
Thanks guys, I do not think I will bother.
Reasons for VPN
You can not be traced, do not do torrents.
Hacking my security guy says sure in theory on open WiFi but he has not seen the happen
Get international websites Netflix, well some claim this is possible
If you ever visit a place like China
Not sure it is worth the money.
Click to expand...
Click to collapse
1. Some VPN services offer torrent protection.
2. My parents got phished using wifi at the library. I rather go offline than use public wifi.
3. Only some VPN can do Netflix. It's not trivial but mine does.
4. VPN is absolutely necessary for visiting China. It's the ultimate testing ground of VPN's technical ability. There are rumors that the reason some VPN can work flawlessly in China is because they are phishing agencies of Chinese government.
I am trying Express VPN, seven day trial.
So far no big deal.
Yep, I use IPVanish. Very fast, hardly notice a speed difference on downloads (but it is slightly slower, to be expected) and web traffic. It does nothing to the speed of my phone.
I use it when I use my banking apps, downloads and location blocking.
I have an Asus router with a VPN Server so free for me. I can connect to it when I'm out or even overseas. The IP isn't identified as a VPN service to any streaming service. I can use it along with some other trickery to prevent my cell carrier from throttling certain content including video or tethering. My way of taking back net neutrality.
Testing Express VPN, first day it sucked 10% battery life.
Slightly slower downloads is ok, but the battery life on the One Plus 7 Pro is not great.
larsdennert said:
I have an Asus router with a VPN Server so free for me. I can connect to it when I'm out or even overseas. The IP isn't identified as a VPN service to any streaming service. I can use it along with some other trickery to prevent my cell carrier from throttling certain content including video or tethering. My way of taking back net neutrality.
Click to expand...
Click to collapse
Are you connecting using open vpn client?
Yes but PPTP with the built in Android VPN also works. I think OpenVPN can use custom ports so someone can't block VPN so easily.
Asus makes amazing Routers! Not quite as customizable as DDWRT but more reliable and they get regular updates.
VPN's are great for internet privacy!
I use VPN apps to protect my internet privacy from espionage. And I think you should too.
I've tried several FREE VPNs but to tell you the truth - they suck and they're slow!
Paid VPNs are much faster. It's better that you first go for a trial version and if you are satisfied with their performance then buy their services.
You shouldn't compromise on your internet safety especially if you make purchases.
I understand a lot of people in this forum buy phones online, and you definitely need protection when you are in the transaction process.
I would round off by suggesting that you should learn more about cybersecurity and internet privacy. I personally use PureVPN, they've been pretty good but everything has their downside, but overall they make you safe and that's what matters the most.
Today vpns are not as useful for privacy as all communication is generally already encrypted at the app level anyway. They are more useful for being able to route connections that are otherwise blocked.
larsdennert said:
Today vpns are not as useful for privacy as all communication is generally already encrypted at the app level anyway. They are more useful for being able to route connections that are otherwise blocked.
Click to expand...
Click to collapse
Still they make it quite a lot harder for your provider to track your usage and for websites and e.g. Facebook trackers to track usage back to you.
You are correct. Your browsing history is obscured. You also need to make sure you are not still using your cell carriers DNS server with the VPN or you'll be just calling them back again.
the vpn provider can see what you are doing so you have to ask yourself if you can trust them, what country are them based in and what are the laws there, and if the risk is acceptable.
if not set up a vpn on you router if it supports it, or on your home pc, i trust my local ISP with local laws more than a random company in another country.
I use and recommend PIA. They have an abundance of servers around the world. I don't notice a big difference in loading speed for average web browsing. One account covers all my computers and devices. They do not log user activity which is the biggest advantage for me. The cost is quite reasonable if you subscribe for 1 or 2 years.
tperki said:
I use and recommend PIA. They have an abundance of servers around the world. I don't notice a big difference in loading speed for average web browsing. One account covers all my computers and devices. They do not log user activity which is the biggest advantage for me. The cost is quite reasonable if you subscribe for 1 or 2 years.
Click to expand...
Click to collapse
Have you heard? PIA was bought out recently. Apparently the company that bought them are questionable at best. I still have some time left on my subscription but I am considering changing VPNs. I just love how easy PIA is.
Turbo VPN Premium Apk Unlimited VIP Ad Free
Turbo VPN Unlimited VIP Ad-Free Premium Latest Apk Free Download From VPNBrothers.com. Turbo Vpn, Turbo Vpn Vip Apk, Turbo VPN Mod Apk, Turbo Vpn Ad-Free Apk Latest Version Free Download. 100% free VPN! High VPN speed!
The best unlimited free VPN clients for android. Turbo VPN – Free VPN proxy, connect as a hare to unblock sites, WiFi hotspot secure and protect privacy. Fastest – Connect successfully as a hare with high VPN speed. Easiest – One tap to connect to the VPN proxy server.
Most Stable – Have lots of free cloud proxy server to provide better VPN service.Turbo VPN – Free VPN proxy, Bypass the firewalls as school free VPN proxy for school wifi and school computer. Protect your network traffic under WiFi hotspot Browse anonymously and securely without being tracked.
Enjoy private browsing. Works with WiFi, LTE, 3G, and all mobile data carriers. Encrypts data using OpenVPN protocols (UDP / TCP).
Free download this light android VPN APK now.
User Terms:
By downloading and/or using this product, you acknowledge and agree to the end-user license agreement and Privacy Statement.
For policy reasons, this service can not be used in China. We apologize for any inconvenience caused.
Turbo VPN Premium Apk Mod Info:
Turbo VPN Review:
Turbo VPN may be a China-based, mobile-only service that enjoys plenty of recognition on Android and iOS. Considering the domicile of this specific service (and the very fact that it solely runs on mobile devices) that will stop plenty of you in your tracks at once. If so: we tend to advocate another supplier based mostly during a country less hostile towards privacy like NordVPN.
That’s largely attributable to the free version, and it’s no surprise. Few suppliers out there offer you unlimited information measure and nine servers in eight countries with no strings hooked up. Well, apart from the annoying ads.
Turbo VPN conjointly contains a paid very important person arrange, cleans up the interface from advertising and boosts the network to twenty-nine servers in fifteen countries. And that’s not all. At first look, this service looks like an excellent decide for mobile users.
However, will it fare during an elaborate test? be a part of the United States as we tend to explore Turbo VPN and see if it’s value victimization on your phone or pill.
How To Download Turbo VPN for Free?
The answer of This question is very simple You just have to join Vpnbrothers telegram Channel or Visit vpnbrothers Website from your mobile browser by Typing the web address vpnbrothers.com and Download The Latest Version of this Apk and Install according to steps given Below or you may follow the Video tutorial Given in install instructions.
Apk Installation Instruction:
Download the Apk From Below Link
Allow the permission In Your Device
Click Install and Choose Your Server That’s All Set And Now you Can Enjoy It.
Thread closed.
Warez are not allowed in XDA.