Yes! In fact ISPs can use fingerprinting techniques to match websites with known data transmission patterns (ping, badwidth, packet timing, etc) to guess what websites you might be accessing even through an encrypted vpn. Some vpns (like mullvad and probably others) will throw in false data packets to thwart this type of fingerprinting.
Can your ISP see a spike in your internet usage even if you are using a VPN?
Submitted 14 hours ago by Patnou@lemmy.world to [deleted]
Comments
kayzeekayzee@lemmy.blahaj.zone 13 hours ago
Dionysus@leminal.space 10 hours ago
As everyone else has said, yes.
There are tools that conduct random traffic patterns out the VPN though continuously to obfuscate your usage…
Basically you make sure none of your traffic transits anything except the VPN, including DNS. The tool pulls random spikes of traffic, just junk in different sizes, anyone watching will only see the VPN traffic.
Think of it this way, you want to mail stuff, and your neighbor can run over and look at the outbound labels on your boxes, so instead you mail everything to a proxy service who then remails it.
They can still see you mail things though… Right?
So instead you send thousands of boxes filled with different weights of junk to the proxy with directions to dump most of them, and your real shipments are mixed in there, the neighbors won’t know which box is real and which is junk or if it’s all real, they just won’t know.
The key is to maintain a consistent randomness, making it difficult to pin down.
MentalEdge@sopuli.xyz 12 hours ago
Of course.
Lots of cybercrime has been solved by law-enforcement by matching traffic logs based on timestamps and throughput.
grue@lemmy.world 11 hours ago
Or at least, publicly claiming to have done that and selling it to a jury as plausible, even if the actual thing that tipped them off was something else secret and inadmissible.
wizardbeard@lemmy.dbzer0.com 13 hours ago
Your ISP will be able to see the usage, and will almost certainly be able to tell that it is VPN usage. They won’t be able to tell what you’re doing or where you’re truly connecting to, just that you transferred whatever quantity of encrypted data with the VPN company at whatever time.
dreamy@lemmy.blahaj.zone 12 hours ago
They won’t be able to tell what you’re doing or where you’re truly connecting to…
I mean, they technically can. There are really simple tools that allow doing this.
gedaliyah@lemmy.world 12 hours ago
Yeah, I remember some case where a college student was caught while using the school’s network because they new the times and filesizes of something. I don’t remember the exact details though.
NarrativeBear@lemmy.world 11 hours ago
DNS over HTTPS is for security and not privacy. Your ISP can still see what websites you visit.
Zedd_Prophecy@lemmy.world 7 hours ago
Yes, use any other DNS other than your provider. Adgaurd at minimum, PI hole with advanced lists is better. Both even better.
NarrativeBear@lemmy.world 6 hours ago
I agree using something like Cloudflare or Quad9 is better then not using it at all, and making sure to turn on DNS over HTTPS is massive benefit. But as shown in my previous linked video even with this turned on a ISP can see DNS queries.
DNS over HTTPS helps with security but not privacy from your ISP.
Lasherz12@lemmy.world 10 hours ago
Yes. VPN still uses your data, more of it in fact because encrypted secure tunnel files are generally larger than the original data and also cached data on the ISP network are no longer called, so more goes to the greater internet.
LodeMike@lemmy.today 10 hours ago
Ys
gastroglizzy@piefed.social 14 hours ago
Yes. Encrypted traffic is still traffic and can still be measured.
BooBees@fedinsfw.app 14 hours ago
And even captured. Just not read by any normal organization.
Brkdncr@lemmy.world 14 hours ago
Or read at a later date when an encryption vulnerability is discovered
randomdude@thelemmy.club 14 hours ago
some do go deeper with dpi, and if u are sus then there is something called 3 eyes/5 eyes and so on