Comment by protocolture

Comment by protocolture a day ago

29 replies

GEOIP providers often sell a database of known VPN/Proxy endpoints. They take the approach of shoot first, ask questions later. Using one of these databases bans a lot of legitimate ip addresses that have seen been the source of known VPN or proxy traffic.

Its not perfect ofc, but its not meant to be. Its usually just used as a safety blanket for geoblocked intellectual property, like netflix.

wkat4242 5 hours ago

For low-volume stuff you can always get a non-expiring 4G/5G bundle eSIM and tunnel through that. Because 4G/5G roaming always tunnels traffic through the home country, and then emerges from CGNAT so it can't be identified as foreign traffic.

But those data packages are expensive and not available with each wanted origin country. Also you need hardware on your side. But it is an option, just saying.

itake a day ago

I connect to my residential ISP in the USA via VPN all the time and have never had issues with being blocked for VPN use.

Maybe they mean commercial VPN providers that run on the cloud?

  • oefrha a day ago

    You know perfectly well what blocking VPN access means in common verbiage. I don't understand the motivation of these "hey look my WireGuard connection to home isn't blocked, you guys don't know the true meaning of VPN" comments that inevitably pop up in these discussions. Like come on, this is a tech forum, you're not impressing anyone for knowing the technical definition of VPN and how to set up WireGuard.

    • kotaKat a day ago

      To flip that though, what about just using those sketchy-ass malware-laden "residential IP" VPN providers and route your traffic through someone else's hacked up VPN running on a Fire TV stick they bought off JimBob for $200?

    • TZubiri a day ago

      Here's me making a similar argument a month or so ago

      https://news.ycombinator.com/item?id=45926849

      Besides the political implications, I think we should try to find an objective taxonomy, it's clear that privacy VPNs and network security VPNs are different products semantically, commercially and legally, even if the same core tech is used.

      Possibly the configuration and network topology is different even, making it a technically different product, similar to how a DNS might be either an authorative server for a TLD, an ISP proxy for an end user, a consumer blacklist like pihole, or an industrial blacklist like spamhaus. It would be a non trivial mistake to conflate any pair of those and bring one up in an argument that refers to the other.

    • delusional a day ago

      The exhausting "well actually" masks a corrosive argument, that if you can't enforce the rules in a rigid and rigorous fashion, the rule is fiat.

      It's not that he doesn't know the difference. He's making the argument that since there's no _technical_ difference there can be no legal difference.

      • jijijijij 19 hours ago

        Yeah, it's an ignorant and arrogant take on the legal system.

        In most places the law is exercised pragmatically, interpreted by presumed intention. That's why legal precedent is important. You likely won't convince any judge being anal about the wording (maybe if the law gets applied for the first time). You can derail anything semantically. Furthermore, despite apparent belief, laws are frequently formulated in such a way that a particular wider term is extended to help interpretation. Eg. "It is prohibited to use a VPN in a way capable and intended to obscure one's physical internet access point identification". (Not a lawyer, not a native speaker, don't get anal with this wording, either.) I very much doubt any legally binding document would even use the term 'VPN' primarily to describe the technical means for anonymization, but rather describe it functionally.

      • Mashimo a day ago

        If you block the commercial VPN services, you increase the burden of entry. You block the 99%. It's not a legal discission, it's a business decision.

      • zinekeller a day ago

        And this is rather an anemic take. The (proposed) UK VPN ban that was recently discussed here have a definition on what exactly is a "VPN" for the purposes of the ban (basically "VPNs generally advertised to normal consumers") but a lot simply shouted "ssh go brr" (and definitely did not read the proposed law). These "let's go techical" thinking never flies with the poeple who makes such legislation, and in (probably unpopular!) opinion we should talk to them in terms that they can understand. Yes, we don't want that law, but having a purist take would probably alienate regular people.

        It doesn't really matter that a single person has found a loophole because many, many other people don't have such a luxury, and that's what the lawmakers are aiming for.

    • fragmede a day ago

      Tailscale is really not that hard to set up. There's an Apple TV app for it, even. And who doesn't have some friend in another state or country that would like an Apple TV?

      • gruez a day ago

        Your friends don't find it uneasy that you can be tunneling illegal activities through their internet connection and have the FBI knocking at their door in a few months?

      • cyberrock a day ago

        Obviously not everyone have friends in all of the countries they want to tunnel to (or want to ask them). Otherwise these VPN services wouldn't exist.

      • positr0n a day ago

        I live a thousand miles from another country. No I don't have friends in another country and I don't even know anyone with friends in another country except immigrants or spouses of immigrants.

      • politelemon a day ago

        I am concerned that this comment reads like an advert, it's completely unnecessary and out of touch.

  • protocolture a day ago

    >I connect to my residential ISP in the USA via VPN all the time and have never had issues with being blocked for VPN use.

    Bit of a non sequitur, you would have to outline your entire usage pattern to even submit that as N=1.

    GEOIP providers dont sit on your home network. They do accept data from third parties, and are themselves (likely) subscribed to other IP addressing lists. Mostly they are a data aggregator, and its garbage in > garbage out.

    If someone, say netflix, but other services participate, flag you as having an inconsistent location, they may forward those details on and you can get added to one of these lists. You might see ip bans at various content providers.

    But the implementation is so slapshod that you can just as likely, poison a single ip in a CGNAT pool, and have it take over a month for anyone to act on it, where some other users on your same ISP might experience the issue.

    These things can also be weighted by usage, larger amounts of traffic are more interesting because it can represent a pool of more users, or more IP infringement per user.

    You can also get hit from poor IP reputation, hosting a webserver with a proxy or php reverse shell, or a hundred other things.

    (Also, larger ISPs might deal with a GEOIP provider selling lists of VPN users that include their IP address space, legally, rather than just going through the process of getting the list updated normally. This means the GEOIP providers can get skittish around some ISPs and might just not include them in lists)

    • zinekeller a day ago

      There is even a single company in the unique position to actually tell where exactly(-ish, considering CGNAT exists) where an IP address is located: Google. They do use the "enhanced location" data on Android devices to pinpoint where an IP is, so a single Android device can actually change fings for Google (and YouTube).

    • mycall a day ago

      > You can also get hit from poor IP reputation, hosting a webserver with a proxy or php reverse shell, or a hundred other things.

      or in my case, have a VM on same subnet as other poor actors and thus get bad rep from others.

  • Lapel2742 a day ago

    >Maybe they mean commercial VPN providers that run on the cloud?

    I just tried it with a well known commercial VPN and I had no problems accessing the site and its music content.