Bonum Certa Men Certa

Virtual Private Networks (VPNs) Suppress Usage of GNU/Linux and Have Historically Cemented Microsoft's Monopoly (Windows) for No Real Security Gains

posted by Roy Schestowitz on Nov 07, 2023

Is a bunch of bloat (or 'hacks') in the networking stack the best one can do?

Adult gorilla eating

THE awkward subject of VPNs was explored here and even extensively covered at one point in the Sirius series, which isn't over by the way (it is connected to another ongoing series). VPNs are a 'hack', not true security, and any time I installed a VPN at the server side, not just the client side, I was left wondering what the true motivation was. Like firewalling, it makes false assumptions and it does not deal with the real issues, such as back doors or a lack of encrypted (properly, end-to-end) connections.

Proprietary VPNs are the worst; over the years I've encountered or had to deal with nearly a dozen VPNs, with some officially lacking GNU/Linux support or just spewing out some outdated binary file that does not work or barely works. In the Free/libre fold we have bloated hack like OpenVPN or something more elegant such as Wireguard. Some have rightly "earned" their share of condemnation. This complicates upgrades of routers, operating systems, and kernels.

I myself have seen institutions rejecting BSD and GNU/Linux users just by the mere choice of some proprietary VPN. Who made the choice? Who made this decision? And what for? It's easy to 'punish' or massively inconvenience people who choose operating systems without back doors. Later you get people saying stuff like, "I still need to dual boot (or use virtual machines) because.... something VPN..."

Suffice to say, such a requirement for a VPN necessarily means you impose back doors on people, i.e. the very opposite of security.

As one associate noted the other day, VPNs are "bullshit", especially proprietary ones. They are used as not just an additional cost sink but also as a further means to block access (by not supporting) non-Microsoft systems.

20+ years ago I worked at Manchester Computing where I helped university staff, mostly lecturers, gain access to VPNs, sometimes over dial-up. Some of them needed online access to the library from home, bypassing weird paywalls that could instead be replaced by authentication, not IP-based restrictions. What a bizarre and arcane setup, even by standards of that time...

The harder part was helping staff that used GNU/Linux (many technically-proficient professors already did back then) and we were instructed that, if someone used BSD, then they probably already know what they're doing and thus in no need of assistance. So the level of support for non-Windows users was appalling by design. Why even use such VPNs in the first place? They protected nothing. It was expensive snake-oil and it's unclear who brought it into the university (maybe some kickbacks involved).

As an associate of ours explained, any security-conscious network administrator would avoid money-wasting boondoggles like Cisco and use Wireguard or OpenVPN instead. However, that would allow equal access from the GNU/Linux and even the BSDs, in addition to saving money and work. However, the empire builders send money to the vendors instead since the vendors depend on the empire builder for the continued cash flow. Whereas employees might dare to push back on various matters.

Back in the 1990s, VPNs were not used because they were a waste of effort and there was already a better, zero-trust solution built around the kerberization of online services.

"I suspect," the associate noted, "that once Microsoft killed Kerberos and made its integration with Windows impossible, people (aka Microsoft drones) had no choice but to roll out VPNs. Again intentionally choosing bad VPNs had the desirable side effect of blocking non-windows systems."

LDAP/OpenLDAP was used in conjunction with Kerberos, we're told, as combined or used in conjunction they could obviate the need for anything like a VPN. Not only were they another way to undo the "necessity" of VPNs as access walls, they worked across platforms and did not introduce the bloat (which inevitably brings bugs and severe holes with it).

The other day I recalled that clients of Sirius complained about access policies. One person in particular noted that, even when former staff was removed from VPN, the unix user accounts remained on their systems. That was in 2011.

Sirius conflated VPNs with access control. It was not about security or privacy; heck, channeling one's traffic through a company server was a corridor to mass surveillance, even in one's own home. This rendered VPNs a tool or instrument for oppressive surveillance, exactly the opposite of what VPNs are nowadays marketed for.

In short, VPNs are usually not necessary. Those who promote them typically don't know what they're doing. VPNs are 'patchworks'.

If someone is trying to shoehorn some proprietary VPN into your company/employer, be sure to check if there are kickbacks (bribes) involved or some profound conflict of interest.

Other Recent Techrights' Posts

Windows in Åland Islands: From 100% to Less Than Half
Åland Islands lost the sense of urgency to move to GNU/Linux
Not Just Slow News But Also Late News (Julian Assange Landing in Thailand)
Why did AP take so long (nearly a week) to release these?
[Meme] Smart Alec Poettering
How many Microsofters can the Debian Project withstand?
Getting Rid of Microsoft Does Not Go Far Enough
Microsoft already has many problems. One day Microsoft won't exist anymore. But that does not guarantee users' freedom.
Alyssa Rosenzweig's LibrePlanet Talk About Freeing the Apple GPU
Alyssa Rosenzweig is the graphics witch behind the reverse-engineered drivers for the Apple GPU. She previously led Panfrost, the free drivers for Arm Mali GPUs powering devices like the Pinebook Pro. She graduated in 2023 with a Computer Science degree from the University of Toronto and now writes free software full-time.
Links 30/06/2024: LLMs Under Fire and Dictatorship of the Old
Links for the day
[Meme] Walking Outside the Guardrails of the Walled Gardens Built by Monopolies
So-called "advertiser-unfriendly" material was never a problem for Wikileaks
 
Johannes Åsgård on Making the Raspberry Pi More Free With librerpi
Johannes (also known as dolphinana)
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, June 30, 2024
IRC logs for Sunday, June 30, 2024
200 This Week
Monday started with 40 articles/pages and this is #200
Press Complicity and Public Apathy All Along Enabled 14 Years of Illegal, Arbitrary Detention and Coercion Into Plea Bargain of Julian Assange on Brink of Death
They basically blackmailed him into letting the US 'win' the argument
At the End Journalism a Crime (If It Involves Accessing or Gaining Access to Documents Marked "Confidential" or "Classified" by Those Looking to Hide Their Misconduct/Crimes)
At least in the US, especially where the imperialism is at stake
Links 30/06/2024: Tensions in Korea and Japan, Criminalisation of Sleeping Outdoors
Links for the day
100% Slop/Spam From linuxsecurity.com
This is the kind of stuff that's killing the Web faster
Gemini Links 30/06/2024: Murdoch and Ideal OS
Links for the day
In the First 6 Months of 2024 Thailand Moved to GNU/Linux, Not to Windows Vista 11
maybe users moved from Vista 10 and 11 to GNU/Linux, seeing where Microsoft was heading with forced hardware "upgrades"
Eko K. A. Owen, New Outreach and Communications Coordinator for the FSF
Nice to see many new additions to the FSF's team
Microsoft Has Slaves and Enablers, Not Partners
Obligatory meme too
Tobias Platen Covered Freedom-To-Play Games in LibrePlanet 2024
Freedom-To-Play games using Taler
[Meme] Opening a 'Webapp' With 'Only' 4 GB of RAM
Until 2020 none of my PCs ever had more than 2 GB of RAM
Destination 'Five Percent'
We reckon GNU/Linux can break the 5% barrier some time by the end of this year, even without counting Chromebooks
A Crisis of Online Journalism
Almost a week ago a journalist was forced to plead guilty for an act of journalism
Germany One of Many Countries Where Microsoft's Bing Lost Market Share After All That LLM Nonsense (Bing Chat and Further Rebrands/Renames)
openai.com traffic plunged 60% last month
Microsoft’s Latest Antitrust Scrutiny
4 new stories
Microsoft Layoffs, Mass Plagiarism, and More
outrage included
GNU/Linux Climbed 0.25% This Month (in statCounter)
Around midday on Tuesday we'll start seeing preliminary data for July
Ilya Gulko Introduces Pollyanna
"Pollyanna is a web framework that makes it easy to create your own libre social space, such as a social network or blog."
'FSFE': Underage Labour, GAFAM Fronting, and Identity Theft to Undermine the FSF's Current Fundraiser
looking to raise funds at the same time as the FSF
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Saturday, June 29, 2024
IRC logs for Saturday, June 29, 2024
Links 29/06/2024: Astronauts at Risk, Ukraine Updates
Links for the day
Fedora and Red Hat Leftovers
mostly redhat.com
Microsoft is Now Googlebombing or Spamming 'Open Source' and 'Linux' to Promote Proprietary Surveillance, Azure
Notice the title and the image, what's being promoted etc.
Seychelles: GNU/Linux Doing OK
Seychelles cannot be considered poor
This War Crime Footage, Nothing Political Per Se, Is What They Made Julian Assange Plead Guilty To (War Criminals Not Convicted, Only Those Who Expose Them)
Wikileaks' Julian Assange: Exposing the US Military Crimes
Gemini Protocol Isn't Even Remotely "Dead"
"Lupa knows of 505,000 (half a million!) working Gemini URLs at present, up from about 425,000 this time last year"
About 10 New Free Software Foundation (FSF) Members Per Day
The total changed from 46 to 47 while typing the article
20 Years Passed, Let's Go Even Faster Now
We are hoping to bring more original stories
Vista 11 Adoption Unusually Low in Germany and It's Going Down, Not Up
This is not happening only in Germany
Kevin Korte on Computers Being Allowed to Make Decisions Based on Cryptic Algorithms and Proprietary/Secret Data
It uses buzzwords where none are needed
[Meme] Garbage In, Garbage Out (linuxsecurity.com)
It is neither Linux nor security, just chatbot-generated slop
Microsoft-Invaded CISA Spreads Anti-Free Software FUD (as If Proprietary Software Has No Memory Safety Issues), Brittany Day Uses Chatbots to Amplify and Permutate the Microsoft FUD
linuxsecurity.com became an anti-Linux spam site
Microsoft Laying Off Staff in an Act of Retaliation and Union-Busting
retaliatory layoffs at Microsoft
Gemini Links 29/06/2024: Content Drowning in 'Goo' and LLM Slop
Links for the day
Windows Lost Almost 92% Market Share in Egypt
From over 99% to just over 7%
In Ecuador, GNU/Linux Adoption Surged From Under 1% to Over 4% in About 3 Years
Not even counting Chromebooks
LibrePlanet: Cultivating Backups (of Recordings)
an appeal to recover some of these talks
Microsoft/Windows Machines Are Turned Off (or Windows Deleted/Decommissioned) in Web Servers, as the "Market Share" Collapse Continues
Taking full history into account, this is a decrease of over 90% in some cases
Corwin Brust Hosting Freedom: A Behind-the-scenes Tour With the GNU Savannah Hackers
"the "smiling faces" behind it."
Android at 90% or More in Chad
Windows below 2%
David Wilson: Cultivating a Welcoming Free Software Community That Lasts
"a feeling of shared ownership for all users."
Julian Assange Might Continue Wikileaks, But Certainly Not Yet (Recovery Time Needed)
And probably at a symbolic capacity only
Bringing in 12 Santas and Taking 13 Out (Old Interview With Julian Assange)
Julian Assange's life inside the Ecuadorian embassy
Neil Plotnick on GNU/Linux in the High School Classroom
uploaded to the LibrePlanet instance of MediaGoblin
Asia Appears to be Fastest to Adopt GNU/Linux
the home of a considerable majority of the world's population
Alexandre Oliva's LibrePlanet 2024 Talk About "Software Enshittification"
in spite of technical difficulties encountered while recording
What They Used to Do With Mono They Now Do With Systemd (Lower and Deeper Down Than Userspace)
Now we have a project started primarily by Red Hat (and managed by Microsoft GitHub, which is proprietary) being managed by Microsoft and primarily serving Microsoft and IBM
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Friday, June 28, 2024
IRC logs for Friday, June 28, 2024