My question is simple! How to get maximum (Possible) privacy from ISP in case someone can’t or don’t want to use a vpn ?

Fir example, In some case tor browser is enough for many but they still need from a privacy from isp on other activities on mobile.

  • Switch DNS to a provider that supports DoH or DoT is about the only thing you can really do.

    Without using a VPN or proxy, your ISP is going to be able to do DPI and know what connections you make. There really is no way around that.

    1. private, secure dns, so they don’t know the domains you’re visiting
    2. https everywhere, so they can’t see any of the data you’re sending or receiving

    All that’s left is what ip’s you’re connecting to. Which is useless half the time, especially since most websites are behind cloudflare or some other anti-ddos proxy already.

    Also, don’t use the web browser that came with your phone. Some manufacturers and isp’s might enjoy adding tracking into those. Some, like Apple, even got caught not encrypting amy of that.

    Side note:

    • https everywhere is pretty much the standard in modern web browsers
    • an adblocker can still help a lot in blocking trackers
    • a secure dns you can find in your browser settings
    • alyx ( alyx@reddthat.com ) 
      link
      fedilink
      arrow-up
      5
      ·
      1 year ago

      without encrypted client hello (which isn’t really adopted) the hostname ist submitted in plaintext, unencrypted. so the ISP can totally see which websites you‘re going to, even it you use a secure dns server

    • The only thing you gain from VPN is that the target server does not know your IP.

      Not necessarily true. A VPN also prevents the ISP from collecting data on all of your connections. Currently ISPs (in the US at least) collect and sell what sites you visit even if they can’t see the data due to HTTPS. Additionally, some have implemented, but then removed due to backlash but may implement again some day, MitM attacks on HTTPS connections in order to insert ads. Using a trusted DNS server that they don’t also intercept can help avoid this, though. With a VPN the ISP won’t see any of this, only the connection to the VPN server and have no way to insert themselves as long as they don’t intercept the VPN connection itself before it’s established.