akaggie05 said:
To OP or anyone else asking about public VPN services, what is the objective you're trying to accomplish?
One thing that I use a VPN for is to restrict access to my ssh servers.
If you leave them open to the world, they get hit hard. Several years ago, I used to see up to 1.3 million hits per server per month. At that time, I bounced anything that was not from the US and that worked fine for a while.
Later, I made the servers IPv6 only. We didn't get hit very much, but we couldn't always get an IPv6 address to connect.
Currently, access to the ssh service is whitelisted. It is only available from local IPv4 and IPv6 addresses and from selected IPv4 and IPv6 endpoints on the VPN service that we use.
Since doing that, we haven't even seen one attempt to log on from an unauthorized source. Not one.
I wasn't worried about people guessing passwords. We already limited ssh access to using ssh keys only. Actually, three different ssh keys to connect -- "AutheniticationMethods publickey,publickey,publickey" in the /etc/ssh/sshd_config" file.
Furthermore, only one obscure account on each computer even has a password and that account is used only for the purpose of logging in from the console.
With s/key, we can log directly into any user account from the console. If you aren't familiar with s/key, it uses six individual, short passwords . Every time you log in with it switches to another set of six individual passwords for the next login. For example, if the current required s/key password is "LIEN BYTE GOER RACK SAID LOT", then the next might be "CLAY JOE LINK RUBE BEAD TUM", and then "CALF BEAT JUDE BETA HACK BURG" the time after that.
In addition to that, we use PerSource penalties if an unathorized person does connect and try to log in. When they fail, it then blocks logins from that address for 14 days and each try thereafter adds 14 more days up to a maximum of 180 days.
Using the VPN whitelist to restrict access accomplishes two things:
1) It helps keep the /var/log/authlog file from filling up. For what it's worth, the authlog file and several other files on our computers are flagged sappend (system append) so that entries may be added to the log, but not deleted. If an attacker should get in and try to hide their attempt by editing the log, the only way they can do this is to log in at the console and drop the system to single user mode to remove the sappend flag. Without restricting it to VPNs, the logs would fill up and we would run out of space.
2) My main concern, though, is the potential that if a zero day exploit should be discovered in the ssh daemon, an attacker might be able to gain access without logging in. While that possibility is limited, it isn't zero. By limiting access to a specific set of endpoints on the VPN, it would be much more difficult for an attacker to take advantage of a zero day exploit of the ssh service. For example, I can require incoming connections to go through that VPN's addresses in Phoenix, Boston, Salt Lake City, or McAllen so that even if you use the VPN to try to connect to my servers, any attempt to connect from any other city on the VPN will fail.
---
We also use a VPN for another purpose. With the VPN, I can test my network from the internet side to make sure it works as expected.
---
By the way, my cell phone is on a VPN with an IP address from Oslo, Norway via Switzerland -- outbound traffic from my cell phone goes to Switzerland and then to Norway, and then to wherever it needs to go. Incoming goes the reverse.
Why? Because I can. It is very rare for me to use my cell phone for the internet except to check my e-mail or my calendar. The impact to me is virtually zero.
---
One common use for a VPN is to get around country restrictions to access streaming channels. For example, if you are a British soccer fan travelling outside the UK, you can still access the soccer games on the BBC network.