‹ BackHN Continuity

Thread

Court agrees with EFF: Utah's VPN law demands a technical impossibility

802 points · 405 comments · hn_acker

  1. SoftTalker · · focus · HN ↗
    > platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely

    Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.

    1. not_a_bot_4sho · · focus · HN ↗
      Kinda.

      I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)

      I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying

      1. alnwlsn · · focus · HN ↗
        My home internet is on a CGNAT, so I experience a lot of the same. Ironically, sometimes a VPN will get through.
      2. manquer · · focus · HN ↗
        Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists <a href="https:&#x2F;&#x2F;mullvad.net&#x2F;en&#x2F;servers.so" rel="nofollow">https:&#x2F;&#x2F;mullvad.net&#x2F;en&#x2F;servers.so trivial to block them without blocking all of Azure&#x2F;GCP&#x2F;AWS[1]

        There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.

        The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).

        Netflix are&#x2F;were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.

        [1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.

        1. [deleted] · · focus · HN ↗

          [deleted]

        2. kevincox · · focus · HN ↗
          That list is the IPs users connect to. It is entirely distinct from the list of IPs the VPN traffic egresses from. I doubt believe that they publish their egress ranges.
          1. buckle8017 · · focus · HN ↗
            It&#x27;s almost always in the same &#x2F;24.
        3. VanTheBrand · · focus · HN ↗
          Don’t think there was ever a time since Netflix started streaming where they only licensed global rights to shows. For their own originals they get global rights but the majority of their content is licensed and has always been slightly different in different territories.
      3. Aurornis · · focus · HN ↗
        That&#x27;s not the same. You get blocked because the IP address you&#x27;re coming from is associated with a VPN list, not because they&#x27;re analyzing the traffic in detail.

        The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it&#x27;s probably not someone&#x27;s home internet connection.

        1. a4isms · · focus · HN ↗
          &gt; If you get 100 different users connecting from a single IP, it&#x27;s probably not someone&#x27;s home internet connection.

          Or, their so-called &quot;smart&quot; TV is acting as a proxy without their informed consent.

          1. someonebaggy · · focus · HN ↗
            One of the positive side effects of smart TV proxies: IP addresses become useless information.
        2. medvidek · · focus · HN ↗
          &gt; If you get 100 different users connecting from a single IP, it&#x27;s probably not someone&#x27;s home internet connection.

          In some parts of the world hiding (NAT) entire neighborhoods behind one public IP is normal practice.

Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.