Phony VPN Services Are Cashing In On America's War On Privacy (vice.com)
Reader Freshly Exhumed writes: Nicholas Deleon at Motherboard reveals a run-in with scammers who are already hard at work taking advantage of newly signed legislation that allows Internet Service Providers to sell your online privacy, including your web browser history, to the highest bidder without your consent. Relatedly, Tim Berners-Lee would prefer people to protest in the streets rather than take technical measures such as TOR and VPN. For those intent on using VPN, TorrentFreak has their latest reviews of VPN anonimity practices, with the caveat that the info is submitted by the VPN companies themselves on a "trust us" basis.
Some folks seem to be doing that with VMs. They will run VPN A on the main OS, then run a VM and inside that VM open VPN B's connection. Idea is that VPN B will tunnel through the VPN A connection to VPN B's exit point.
How well that works or how effective it is, I could not say. At least to a first glance it does not seem like too bad an idea though.
Just remember, most of the "private", "secure" email services turned out to be either direct honeypots or, even if legit at first, taken over later by the NSA or other agencies, with money and/or threats, and turned into a honeypot, as revealed by wikileaks papers. VPN will probably be the same
It's not difficult to roll your own VPN solution if you have some knowledge of BSD/Linux. This is really and truly the only way to ensure trust and even then it is not 100%. OpenVPN is not hard to install and configure but I am sure it is not immune from would-be intruders.
Umm, how does that help? I do have a VPN server to remote in to my home network and access services, shares, and other resources I don't make publicly visible (which is almost everything--that I don't, I mean), but you seem to be missing the part where the type of VPN this article is talking about is for people who wish to disguise their network traffic from home (and elsewhere) by sending it over a VPN to a remote server, often in another country--the problem being that it's not always apparent if you can trust that server.
R.Mo