31 votes

What server location should I use for a VPN?

I'm asking "I" in the sense that I'd personally like an answer to this question, but really this is more about using VPNs in general.

Currently, I just use the server with the lowest latency because that gives me the least friction.

However, thinking about the GDPR in the EU, or California's data privacy protections: should I be strategically choosing a server based on those? Is there any benefit to having my traffic routed through a jurisdiction like that, or does that not really matter?

EDIT: To further clarify: will all the different websites out there log less data or treat my data differently if they believe my traffic is coming from the EU/California?

18 comments

  1. [6]
    bitwyze
    Link
    What are you trying to use the VPN for? Accessing region-locked content? Pick one in a country where that content is available. Masking your IP address when torrenting? Ideally pick a server...

    What are you trying to use the VPN for?

    Accessing region-locked content? Pick one in a country where that content is available.

    Masking your IP address when torrenting? Ideally pick a server geographically close to you so the latency isn't horrible. In ProtonVPN, you can also specifically pick servers that are optimized for P2P networking.

    IMO, the location of the node your data travels to doesn't matter for privacy reasons, it's more about your VPN provider and whether they log where your data is going.

    If you're really concerned about the privacy of your data, you can set up a VPN at home and use that. I've built a stupid simple wireguard VPN at home with about 10 lines of config (figuring out those lines was a little tricky, admittedly) and it was rock solid - the only reason I replaced it is because I upgraded my router to a ubiquiti cloud gateway that has the server baked in.

    23 votes
    1. [5]
      LewsTherinTelescope
      Link Parent
      Question from the uninformed (me): if you set up a VPN on your home network and are the only one using it, what privacy does it bring?

      Question from the uninformed (me): if you set up a VPN on your home network and are the only one using it, what privacy does it bring?

      3 votes
      1. [4]
        bitwyze
        Link Parent
        When my phone or laptop is connected to public WiFi, the Internet service provider there (as well as anyone sniffing packets on the network) doesn't know where my traffic is truly going, they just...

        When my phone or laptop is connected to public WiFi, the Internet service provider there (as well as anyone sniffing packets on the network) doesn't know where my traffic is truly going, they just see it's going to my home IP address.

        Also, when I'm connected to my VPN, my devices get the benefit of the pihole server I have running on my home network, so ad-blocking on-the-go :-)

        7 votes
        1. [2]
          0x29A
          (edited )
          Link Parent
          I'm sure you know this, but for additional clarity to the discussion in case there's any confusion from readers about the different setups- a VPN self-hosted inside your home network (and not a...

          I'm sure you know this, but for additional clarity to the discussion in case there's any confusion from readers about the different setups- a VPN self-hosted inside your home network (and not a DIY one in a VPS or a service by a VPN company) is going to provide basically zero usefulness / extra privacy for someone accessing the internet from home specifically though since the endpoint is going to be the same IP as your real home IP... someone wanting to avoid their ISP's snooping or get any other VPN upsides for home-originating traffic will get no benefit from that setup

          so i think such a setup only works for someone very specifically looking to only get an extra layer of protection when on public / non-home internet locations and to specifically route that traffic back through their home network. for those that don't trust their home ISPs, this is actually sending even more data through them

          the other options will be better for someone that wants to add an extra privacy layer for any traffic originating from their home network

          14 votes
          1. bitwyze
            Link Parent
            Correct. I don't much care about Verizon collecting my data. What I do care about is me or my wife being out on hotel WiFi or something, open up a banking app, and getting targeted by some sniffer...

            Correct. I don't much care about Verizon collecting my data. What I do care about is me or my wife being out on hotel WiFi or something, open up a banking app, and getting targeted by some sniffer on the network. I know the data itself is encrypted because it's being accessed via HTTPS, but it's an extra layer of security.

            7 votes
        2. LewsTherinTelescope
          Link Parent
          Ah I see, it's to route everything from non-home networks back to home. Makes sense, thanks!

          Ah I see, it's to route everything from non-home networks back to home. Makes sense, thanks!

          1 vote
  2. [3]
    creesch
    Link
    With what reason are you using a VPN if I might ask? In a lot of cases people don't seem to trust their provider, but with a lot of the VPN providers you are for the most part adding latency to...

    With what reason are you using a VPN if I might ask? In a lot of cases people don't seem to trust their provider, but with a lot of the VPN providers you are for the most part adding latency to your experience and effectively a second ISP. Since a VPN doesn't hide your traffic overall, it just makes you enter the internet from a differnet location.
    Many big websites also track VPN endpoint ips and make it more difficult to use the website (often citing abuse coming through VPN endpoints)

    Choosing a specific geo location can be a genuine benefit. I know for a fact that me signing up for a service in the EU and using it in the EU often comes with less intrusive advertising bullshit people outside the EU will get. Sometimes you get that benefit by just using the service from that location, but often it is based on where you have signed up.

    So, in many cases for people in first world countries using a VPN doesn't provide that much of a privacy benefit. If you have an extremely shitty internet provider who is known to do all sorts of shenanigans on their traffic a VPN can be a valid choice to simply bypass most of that. In that case the choice of VPN provider matters more than the exit node.

    If you do get additional benefits then really depends on a lot of other factors, not just the location.

    8 votes
    1. [2]
      kfwyre
      Link Parent
      cc: @bitwyze Basically what you said. I'm in the US where ISPs are awful with their customer data. I figure my home internet, where I spend the bulk of my time, has a LOT to say about me as an...

      cc: @bitwyze

      Basically what you said. I'm in the US where ISPs are awful with their customer data. I figure my home internet, where I spend the bulk of my time, has a LOT to say about me as an individual, so shifting the trust from my ISP (a known bad actor) to a (hopefully trustworthy?) VPN company feels like the right thing to do.

      I don't really use it to get around geoblocks or anything like that. It's essentially entirely because I don't trust my ISP.

      Like you identified, I often have to drop it or change servers on account of services blocking VPNs, but I figure, even then, 90% VPN usage is better than 0%.

      5 votes
      1. Protected
        Link Parent
        If it's just for keeping your ISP in the dark it can be literally anywhere. You can use a commercial outfit, but you can also run your own on any internet-connected device, such as a rented...

        If it's just for keeping your ISP in the dark it can be literally anywhere. You can use a commercial outfit, but you can also run your own on any internet-connected device, such as a rented server, an office, a friend's home or even your phone if it has a different ISP. Aim for geographic proximity as long as the server is on a different (trustworthy) ISP.

        Commercial VPN providers that don't keep logs have the added benefit of intermingling your traffic with a bunch of other people's (who are using the same endpoint) which improves anonimity, although make sure your setup doesn't leak any information via DNS or fingerprinting.

        4 votes
  3. infpossibilityspace
    Link
    The location matters less compared to what logs the VPN provider collects. A provider which doesn't collect any logs and uses ramdisks for their servers (the operating system is stored in RAM and...

    The location matters less compared to what logs the VPN provider collects. A provider which doesn't collect any logs and uses ramdisks for their servers (the operating system is stored in RAM and is destroyed when turned off) means you don't have to worry about government requests because they don't have anything to give.
    For example, Mullvad reportedly fulfils both of these and if you don't want to give them any payment info you can mail them some cash.

    6 votes
  4. [5]
    preposterous
    Link
    I use Mullvad because they’re the only ones I trust to do what they say (no logs etc). I use their Albania servers to have no ads on YT on my iPhone. But they have to many POPs that they’ll almost...

    I use Mullvad because they’re the only ones I trust to do what they say (no logs etc). I use their Albania servers to have no ads on YT on my iPhone. But they have to many POPs that they’ll almost certainly have one you want.

    4 votes
    1. [2]
      shu
      Link Parent
      I used to think Mullvad is ok, too, but then one of their founders donated ~450.000€ to a far-right populist party. https://tildes.net/~society/1uvd/mullvad_ceo_gives_452_000_to_the_%C3%B6rebro_party

      I used to think Mullvad is ok, too, but then one of their founders donated ~450.000€ to a far-right populist party. https://tildes.net/~society/1uvd/mullvad_ceo_gives_452_000_to_the_%C3%B6rebro_party

      3 votes
      1. preposterous
        Link Parent
        I didn’t know that, it’s unfortunate…

        I didn’t know that, it’s unfortunate…

        1 vote
    2. [2]
      bugsmith
      Link Parent
      What makes you trust Mullvad and not, say, Proton or IVPN?

      What makes you trust Mullvad and not, say, Proton or IVPN?

      1 vote
      1. preposterous
        Link Parent
        They’ve been around a long time, offer anonymous payments, are (were?) linked to the pirate party.

        They’ve been around a long time, offer anonymous payments, are (were?) linked to the pirate party.

  5. Bauke
    Link
    I'd say for day to day usage, unless you're using a specific location to circumvent some geographic restriction, use the country you live in as your server location. That way if you're logging...

    I'd say for day to day usage, unless you're using a specific location to circumvent some geographic restriction, use the country you live in as your server location. That way if you're logging into government services or your bank account or similar important thing, they don't think something is up because the location looks weird.

    As far as there being a benefit to having it routed through a certain jurisdiction, I don't think it really matters.

    3 votes
  6. snake_case
    Link
    I use a VPN from Germany and I definitely notice an increase in those popup cookie requests. Thing is, sites don't really use cookies any more, the whole thing is just noise on my screen now, so I...

    I use a VPN from Germany and I definitely notice an increase in those popup cookie requests.

    Thing is, sites don't really use cookies any more, the whole thing is just noise on my screen now, so I actually thought about changing my location to somewhere without those laws.

    3 votes
  7. UniquelyGeneric
    Link
    First, choose a VPN provider you trust. I used to suggest Mullvad, but their CEO’s political involvement has made me more wary of their business practices. Regardless, they’re one of the the few...

    First, choose a VPN provider you trust. I used to suggest Mullvad, but their CEO’s political involvement has made me more wary of their business practices. Regardless, they’re one of the the few VPN providers to have proven their no logging stance.

    Second, be aware of what you are exposing on the wire. Notably, who is the intended recipient? How much do you trust them? Many websites gleefully share your data via trackers they purposefully embed on their own site. Some VPNs claim to Adblock these; in my experience having your own browser extension for adblocking is going to be far more effective (uBlock Origin is the de facto standard, but I also prefer uBlock Matrix to selectively grant access). Most browser extensions are not trustworthy either. Your own browser choice might be another consideration since it’s the agent exchanging information on your behalf. Firefox is good, but don’t assume its default configuration provides comprehensive coverage for your use case.

    Lastly, geographic IP location matters to some degree, but not in the way you might be anticipating. Data privacy laws can get very specific in interpretation, and this doesn’t always mean a VPN exit node has any bearing. For example, California’s primary data privacy law explicitly protects California residents, not visitors. A savvy business could make that distinction based on your account/billing info and not your IP address. Conversely, the EU protects those physically located within its jurisdiction, and doesn’t make residency a requirement. In practice, this nuance is beyond most companies’ capabilities so you can generally assume they use IP address geolocation for applying privacy protections. If you’re not logged in, the EU will have the most protections for your web browsing, but you will have to suffer through a consent popup on every website you visit. California does not require you to opt-in to data sharing, so you would avoid the cookie pops, but not benefit from the data protections unless you are sending GPC opt-out signals from your browser (DuckDuckGo has this by default, Firefox must be manually set). In my opinion this is not worth your time unless you know what you’re doing, and even then it may still not be worth the trouble for the privacy gain (this is assuming you are already using a VPN with an adblocker). I’d choose a local VPN connection if your actual intent is blending in with the crowd, and it has a benefit of lower latency to boot.

    There’s a lot more that goes into data privacy (e.g. what credentials are you using to login to a service?) that could be a post of its own, but since you’re specifically asking about server location I wanted to share the more relevant details to improving your privacy posture. VPN location is not high on the list of concerns imho.

    3 votes