My question is simple! How to get maximum (Possible) privacy from ISP in case someone can’t or don’t want to use a vpn ?

Fir example, In some case tor browser is enough for many but they still need from a privacy from isp on other activities on mobile.

  • lock@lemmy.ml
    link
    fedilink
    arrow-up
    2
    ·
    2 days ago

    If you want the most privacy focused ISP, check out Cape. You can view the post I made about this company.

  • shortwavesurfer@lemmy.zip
    link
    fedilink
    arrow-up
    34
    arrow-down
    1
    ·
    4 days ago

    Switch DNS to a provider that supports DoH or DoT is about the only thing you can really do.

    Without using a VPN or proxy, your ISP is going to be able to do DPI and know what connections you make. There really is no way around that.

    • sunzu2@thebrainbin.org
      link
      fedilink
      arrow-up
      4
      ·
      4 days ago

      Can’t they still do DPI on VPN network to know what yoke re doing, ie watching netflix, pornhub and playing cod

      • DontTakeMySky@lemmy.world
        link
        fedilink
        arrow-up
        5
        ·
        4 days ago

        I think they might be able to guess that you’re watching a video based on the traffic patterns, but unlikely they can tell what site it’s coming from.

  • Boomkop3@reddthat.com
    link
    fedilink
    arrow-up
    9
    arrow-down
    1
    ·
    edit-2
    4 days ago
    1. private, secure dns, so they don’t know the domains you’re visiting
    2. https everywhere, so they can’t see any of the data you’re sending or receiving

    All that’s left is what ip’s you’re connecting to. Which is useless half the time, especially since most websites are behind cloudflare or some other anti-ddos proxy already.

    Also, don’t use the web browser that came with your phone. Some manufacturers and isp’s might enjoy adding tracking into those. Some, like Apple, even got caught not encrypting amy of that.

    Side note:

    • https everywhere is pretty much the standard in modern web browsers
    • an adblocker can still help a lot in blocking trackers
    • a secure dns you can find in your browser settings
    • greyfox@lemmy.world
      link
      fedilink
      English
      arrow-up
      4
      ·
      4 days ago

      Even with https if you aren’t on TLS 1.3 the SNI (server name indicator) is not encrypted so the hostname you are trying to access would be visible to your ISP.

      Forcing your browser to only use TLS1.3 would fix that but who knows how many sites it would break.

      • Boomkop3@reddthat.com
        link
        fedilink
        arrow-up
        4
        ·
        4 days ago

        Oh, good catch! I have to say I don’t usually look at what specific tls version websites use. I’ll be paying attention to this for a bit

  • truthfultemporarily@feddit.org
    link
    fedilink
    arrow-up
    7
    arrow-down
    4
    ·
    4 days ago

    The only thing you gain from VPN is that the target server does not know your IP.

    HTTPS is safe anyway and as such also the content of what you do.

    The only other way you may leak information are DNS queries.

    • alyx@reddthat.com
      link
      fedilink
      arrow-up
      7
      ·
      4 days ago

      without encrypted client hello (which isn’t really adopted) the hostname ist submitted in plaintext, unencrypted. so the ISP can totally see which websites you‘re going to, even it you use a secure dns server

    • sarcasm3425@lemmy.caOP
      link
      fedilink
      arrow-up
      1
      ·
      4 days ago

      What to do about dns queries? In the privacyguides video i saw when we use a encrypted dns isp only see the ip address. So queries are hidden right ?

        • tjoa@feddit.org
          link
          fedilink
          arrow-up
          2
          ·
          4 days ago

          Couldn’t you run a DNS resolver that pings the authoritative servers directly? Yes initial requests will be slower

            • tjoa@feddit.org
              link
              fedilink
              arrow-up
              2
              ·
              4 days ago

              True but it seems to me that it’s an advantage to have your IP logged in this more decentralized way. most resolvers also cache the answers so it would be only logged the first time you visit a website.

  • xiao@sh.itjust.works
    link
    fedilink
    arrow-up
    3
    arrow-down
    2
    ·
    4 days ago

    It does not answer the question but this application has been useful to me in the past.

    https://invizible.net/en/

    InviZible Pro combines the strengths of Tor, DNSCrypt, and Purple I2P to provide a comprehensive solution for online privacy, security, and anonymity.

    To start using InviZible Pro, all you need is any Android phone. Just run all three modules and enjoy safe and comfortable internet surfing. However, if you want to get full control over the application and your internet connection – no problem! Provided access to a large number of both simple and professional settings. You can flexibly configure InviZible Pro itself, as well as its modules – Tor, DNSCrypt, Purple I2P and Firewall to satisfy the most non-standard requirements.

    InviZible Pro is an all-in-one application. After installation, you can remove all of your VPN applications and ad blockers. In most cases, InviZible Pro works better, more stable, faster than free VPNs. It does not contain ads, bloatware code and does not spy upon the users.