zlacker

[return to "VPN use surges in UK as new online safety rules kick in"]
1. crossr+P01[view] [source] 2025-07-28 13:11:51
>>mmaria+(OP)
Since it's about VPNs - what are good VPNs for someone looking for safety/privacy but not anonymity or even IP hiding?

Not even for streaming. But for general "safety while on the Internet" when the devices (Mac, iPhone) are mostly on public or not-so-secure WiFi (at the residence or on the go). Plan is to keep it always ON or almost always ON.

Not necessarily for the UK.

(Other than Mullvad)

◧◩
2. jnwats+z21[view] [source] 2025-07-28 13:23:50
>>crossr+P01
The best VPN is to host your own. I used Digital Ocean. They have preconfigured droplet images for OpenVPN access server. The droplet even serves a client pre-configured with the connection settings.

It took me all of 10 minutes to set up.

◧◩◪
3. TheDon+241[view] [source] 2025-07-28 13:35:45
>>jnwats+z21
In the year of our lord 2025, don't use OpenVPN. Use wireguard.
◧◩◪◨
4. iainme+Pn1[view] [source] 2025-07-28 15:44:04
>>TheDon+241
Please give a bit more detail and justification when you give opinions like this.

Otherwise it sounds like you’re saying everybody already knows which one is good and which one is bad -- but if everybody knew, you wouldn’t need to say anything, right?

◧◩◪◨⬒
5. zahllo+sQ1[view] [source] 2025-07-28 18:27:23
>>iainme+Pn1
I am not the original poster, but there are a few reasons to pick Wireguard.

Performance is better due to the in-kernel drivers, UDP design and crypto choices. If you're simply looking for the fastest option wireguard is it.

Openvpn's protocol is somewhat more janky than wireguard. It looks tls-like but then does its own transport thing. It has a lot of flexible options and ciphersuite choices meaning you could very well pick something less than ideal. The complexity of the code makes an undiscovered bug slightly more likely.

The downside of wireguard, mitigated by some VPN providers, is that it is UDP-only. You may find environments where you cannot tunnel out this way, even if you try to impersonate QUIC by running the remote port on 443. Mullvad has a udp-to-tcp proxy as part of their client and server to work around this.

[go to top]