I am not in a place where I can afford a VPN (do not start suggesting cheap VPNs to me istg), and in addition, you have to place a lot of trust in the VPN. Tribler seems promising, except… For the giant disclaimer that’s been on the site for years. That worries me. I am quite worried about getting scary letters from my ISP or something when torrenting.

Do not put yourself in danger. Our anonymity is not yet mature.

Tribler does not protect you against spooks and government agencies. We are a torrent client and aim to protect you against lawyer-based attacks and censorship. With help from many volunteers we are continuously evolving and improving.

Edit: Seems like there are a lot of issues below the surface as well… https://lemmy.dbzer0.com/post/19118584/10120234

And Lokinet, I2P, and GNUnet have their own massive problems… https://comment.ctrl.blog/discussion/tribler-onion-routed-bittorrent

ngl, kinda depressing that it’s like this…

Edit 2: I misread the article a bit, it’s not quite as dire as I thought it was initially, but the warning and the fact that only the core file-transferring features are anonymized at all… Is a bit disconcerting.

  • stupid_asshole69 [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    3
    ·
    edit-2
    18 hours ago

    If you aren’t gonna use a vpn then require encryption, disable dht and pex, use doh or dot and only use private trackers.

    Require encryption, distributed hash table and peer exchange are options in your client. Requiring encryption means a mitm observation of your traffic won’t show you are doing torrenting. Turning off dht and pex prevents someone who’s not a member of your tracker jumping into the swarm and clocking users. DNS over https or tls makes requests to get the ip of a website from the url encrypted, so a mitm observer can’t even see that you went to the bad website to ostensibly do bad things. Private trackers get you out of the low hanging fruit category where enforcement is usually focused.

    Of course, anyone who monitors traffic patterns will know you’re torrenting, so laws (or a change in laws or enforcement strategy) can still get you.

    If you read all this way and you want to know what the solution is, it’s not i2p or tor, it’s a vpn service. I know you said you don’t want that, but it’s the solution to your problem. You figured out yourself that i2p and tor don’t suit your needs already.

    Good vpns have infrastructure that makes it impossible to keep logs and will pass independent audits. They will also not have a history of turning over users data or otherwise acting badly.

    I use airvpn for torrenting. It works fine as long as you’re not in Italy.

    If you want to understand how a person can trust and afford a vpn, ask away. If you cannot or do not want to use a credit card, use a vpn service like mullvad or proton that accepts cash.

    E: edited for a typo

    • ScratchySoft@lemmy.dbzer0.comOP
      link
      fedilink
      English
      arrow-up
      1
      ·
      18 hours ago

      Sadly I am not in any private trackers. And while I know VPNs like ProtonVPN are fairly reliable, I’m hesitant to place much trust in them, nor do I have… Any income right now (things are a mess)…

      • stupid_asshole69 [none/use name]@hexbear.net
        link
        fedilink
        English
        arrow-up
        1
        ·
        17 hours ago

        Private trackers: they’re easy to get into. Ipt will probably temporarily open signups this month, mya is always open afaik and plenty of others have signups where you just have to take a test they give you the answers to. Once you’re in you just gotta maintain a ratio by seeding instead of just downloading all the time and climb the “tracker ladder” to get to the ones you want.

        Mya is the one most people start with now.

        On VPNs: you have to understand your own security, just like anything else. Ones like mullvad refuse to keep information about you (your login credentials are a random string of numbers and they do cash transactions similarly anonymized), and ones like proton allow you to use information that isn’t tied back to you (it’s your responsibility to make sure that information can’t be tied back to you!). It’s worth learning about them now even if you’re not in a position to pay for one because knowing will help you make good decisions when you are in that position.