Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

How does a VPN affect internet security?


  • Please log in to reply
3 replies to this topic

#1 Warthog-Fan

Warthog-Fan

  • Members
  • 293 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Endicott, NY
  • Local time:10:03 AM

Posted 05 October 2016 - 09:56 PM

Gentlepersons,

 

As I understand it, a VPN provides encryption of internet traffic between my computer and the VPN server, protecting me from a third party "evesdropping" on my internet activity in a place like, say, Starbucks or any other public wi-fi spot. It also protects against having my IP address read by others so my internet activity can't be tracked. These seem like good things.

 

I recently purchased a license to run VPN software from a company called Private Internet Access. (It was recommended by Bleeping Computer Deals). My computer is set up with three accounts: an Administrator account, and two User accounts that my wife and I use for our everyday computer usage. I never use the Administrator account unless necessary, because I've read on these forums that the Administrator account's higher level of privileges make it much easier for malware to gain access to the computer.

 

Private Internet Access states that their software will ONLY run reliably on an Administrator account. So the way I see it, in order to use this VPN software, I have to run it on an account that is highly vulnerable to attack, when compared to a User account. Since the VPN server only passes data through itself to my computer, I don't see how the VPN software can keep malware from gaining access to my computer. If this is true, I think it's time for me to call Private Internet Access and ask for my money back.

 

Do any of you have opinions on this? Does anyone know of VPN software that WILL run on a computer's User accounts?

 

Thanx in advance.



BC AdBot (Login to Remove)

 


#2 jacklai

jacklai

  • Members
  • 13 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:02:03 PM

Posted 05 October 2016 - 10:27 PM

I'm thinking that the VPN provider can get our information



#3 technonymous

technonymous

  • Members
  • 2,499 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:07:03 AM

Posted 06 October 2016 - 12:50 AM

Gentlepersons,

 

As I understand it, a VPN provides encryption of internet traffic between my computer and the VPN server, protecting me from a third party "evesdropping" on my internet activity in a place like, say, Starbucks or any other public wi-fi spot. It also protects against having my IP address read by others so my internet activity can't be tracked. These seem like good things.

 

I recently purchased a license to run VPN software from a company called Private Internet Access. (It was recommended by Bleeping Computer Deals). My computer is set up with three accounts: an Administrator account, and two User accounts that my wife and I use for our everyday computer usage. I never use the Administrator account unless necessary, because I've read on these forums that the Administrator account's higher level of privileges make it much easier for malware to gain access to the computer.

 

Private Internet Access states that their software will ONLY run reliably on an Administrator account. So the way I see it, in order to use this VPN software, I have to run it on an account that is highly vulnerable to attack, when compared to a User account. Since the VPN server only passes data through itself to my computer, I don't see how the VPN software can keep malware from gaining access to my computer. If this is true, I think it's time for me to call Private Internet Access and ask for my money back.

 

Do any of you have opinions on this? Does anyone know of VPN software that WILL run on a computer's User accounts?

 

Thanx in advance.

A VPN alone is not going to protect you from Malware. You're correct though that running limited User account gives that extra layer of protection because the admin policies are in force. That makes it a whole lot harder for a virus to get elevated to the point it can install, mess with the registry and create services. You never want to run a system without a good antivirus/firewall suite anyways. I don't think it would be totally impossible to setup the VPN to run under User. You could set it up as logged in as Admin giving the VPN's services the access it needs at the same time enforcing polices. Users generally do not have access to mess with services or any other administrative tools. As far as being out at Public area's such as a coffee shop's a VPN will protect you from middle man attacks and the privacy of your data in transit. Not to mention the GEO IP location. Another step further beyond what you have done with limited User account, VPN, Virus scanners, you could browse the net entirely behind a Virtual Machine, or Live CD OS with a throw away account. A VM is extremely powerful and is like a time machine. If you get infected just wipe the VM out and reload the saved base file.



#4 Didier Stevens

Didier Stevens

  • BC Advisor
  • 2,705 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:04:03 PM

Posted 06 October 2016 - 07:17 AM

A lot of VPN providers offer PPTP VPN, and that type of VPN does not require software to run on your Windows machine.

OpenVPN requires software on Windows, and maybe their software does that.

 

But most software that requires admin rights should be designed as follows: the part that requires admin rights should be implemented as a Windows service that runs under an admin account, and the other part (often the GUI) runs as a normal user. Maybe they support that too, you have to check with them.

 

As said by technonymous, VPN does not protect you from malware. FYI: there are VPN offerings from security companies that offer VPN + malware scanning of your traffic, but such products are often marketed under another name than VPN.


Didier Stevens
http://blog.DidierStevens.com
http://DidierStevensLabs.com

SANS ISC Senior Handler
Microsoft MVP 2011-2016 Consumer Security, Windows Insider MVP 2016-2019
MVP_Horizontal_BlueOnly.png

 

If you send me messages, per Bleeping Computer's Forum policy, I will not engage in a conversation, but try to answer your question in the relevant forum post. If you don't want this, don't send me messages.

 

Stevens' law: "As an online security discussion grows longer, the probability of a reference to BadUSB approaches 1.0"





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users