A lot of companies are going to cause you grief if you try to checkout via any kind of system which purports to offer anonymity. PayPal for instance will likely kill your account. Merely having your IP come from a different location than the billing address may get you flagged- so VPN's aren't necessarily going to work either.

The real question is who/what are you trying to protect against. If it is a specific ISP or country you might be able to thwart spying at that level by using a VPN. However if the VPN is located in or the company has people located in the same country as you all bets are off. The same can be true for countries which are cooperative with your country. VPN providers will succumb to at least government pressures if pressed to reveal your 'identity' (real public IP address anyway) where there is some connection. The United States is a difficult country to thwart for example As it is tangled in many many other nations affairs.

If your trying to buy something your government doesn't permit you to then VPN + Tor is probably the answer. Tor was designed for anonymity. However if you reveal who you are or leak little clues via what you say all bets are off. For example if your the only Tor user around they'll be able to identify you more easily after you've let out some detail of location. Just look at how the FBI agents tracked a Harvard bomb threat suspect down despite the user posting via Tor. They didn't need absolute proof to suspect the person they identified as a probable suspect. The FBI simply sought the records that Harvard kept of all users activities on its network. I'm taking an educated guess here, but Harvard probably kept a log of IP addresses that users connected to and timestamps of these connections. The FBI then merely searched for IP addresses of Tor nodes and identified the user who had been on Tor at the university (as it was a threat toward the university there was a good chance it was made by someone attending the university). After which they could get a search warrant and/or question the one or two suspects tied to that IP address. The solution to this problem would have been to use VPN + Tor or a Tor bridge. The government will have a much harder time connecting a user as they'll first have to identify all VPN users at the university and then seek the IP logs from the VPN provider to identify weather or not the VPN user connected to Tor. Now if the user had used VPN + Tor + a Tor bridge there would be a significantly more difficult time as the information held by the VPN provider would not be a public Tor node. The same would be true if the user had merely used a Tor bridge. However the student might have been identified still as a Tor user merely by the fact he had connected to the Tor project's web site to download Tor. If it wasn't done immediately (that is the threat around the time of the Tor download) then there would probably be a lot more students that the FBI would have had to interview in order to narrow down a suspect. It would probably also have been more difficult had he downloaded Tor via another means like through Debian's repository. There would then be no tie to him having downloaded Tor (probably- this assumes they only logged the IP addresses- and were not retaining other info linke URLs).



Reply via email to