logoalt Hacker News

SoftTalker • today at 5:02 PM • 13 replies • view on HN

> platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely

Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.


Replies

happyPersonR • today at 6:50 PM

Requires the vpn provider to snitch and possible tag the ip frames or http frames lol

Folks would just host their own vpns various places and this would be pointless ….

➕ show 4 replies
not_a_bot_4sho • today at 5:18 PM

Kinda.

I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)

I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying

➕ show 3 replies
semiquaver • today at 7:47 PM

Right, all you see is the IP address. And anyone in the world can set up an “individual” VPN just for them on a cheap VPS or cloud server anywhere else in the world. There’s no technical way to accomplish what they’ve mandated, only something approximating it like “block all connections from known commercial VPN services”.

ad_fontes • today at 5:09 PM

Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.

TeMPOraL • today at 5:25 PM

All it would take is for a major ISP in Utah to route everyone through a VPN, and boom, it's the same picture.

➕ show 2 replies
babelfish • today at 7:23 PM

It seems like withdrawing from Utah is the obvious option

➕ show 2 replies
mahboi • today at 6:07 PM

It's hard to find a proxy or VPN that isn't flagged as such. People pay extra for residential proxies.

➕ show 1 reply
greyface- • today at 7:58 PM

TCP MSS < 1500 bytes can be a tell, although it will sometimes falsely identify non-"VPN" tunnels.

➕ show 1 reply
LoganDark • today at 8:48 PM

> Is it even possible to reliably know that a connection is from a VPN?

No, it's not possible. You can only try to identify known protocols or suspicious patterns of data, timing or entropy. Theoretically, with a big enough collaboration, you could hide a VPN behind shaping traffic patterns and request order towards hundreds of different servers, and there's just no method of traffic analysis that can possibly identify that without prior knowledge.

Like, some firewalls try to identify an absence of connections outside the VPN, or an abnormal volume of data over a sustained period of time. But all that goes out the window when, say, you are connecting to hundreds of real servers at all times and only exchanging, say, basic HTTP requests with each one. For all they know you just have a million browser toolbars installed. They wouldn't know if the choice of request, order and timing encodes information because they wouldn't be able to prove what the client's intentions are in sending it or what the servers do with it.

If you tried to identify it, you would block every real connection.

I believe some VPN providers are beginning to play with things like this, but the problem is really that it's impossible to provide this. It only really works when you run it yourself, because that's the only way others don't know. So they're having to settle for compromises, like Mullvad's DAITA, which still uses a single server but tries to avoid showing tells of a VPN connection as opposed to something else like streaming.

codedokode • today at 5:19 PM

You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.

➕ show 1 reply
ranger_danger • today at 5:13 PM

Not when the definition of VPN is subjective. I could proxy/VPN through a friend's house and nobody would ever know it wasn't them.

➕ show 3 replies
gorgoiler • today at 7:07 PM

The classic: ping the endpoint address, then “ping” the code. If the IP address comes back in 30ms but the JavaScript responds in 330ms, then the client is probably 300ms further away than they say they are claiming.

➕ show 1 reply