← Back to context

Comment by SoftTalker

6 hours ago

> platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely

Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.

Requires the vpn provider to snitch and possible tag the ip frames or http frames lol

Folks would just host their own vpns various places and this would be pointless ….

  • Detection can be based on the IPs themselves, no packet tricks required. Plenty of services can do that: https://focsec.com/

    Now of course, if your VPN is a home-lab style VPN where you are connecting to a little wireguard box sitting in your own home, that is a totally different story.

  • You can do for free with tailscale exit nodes. Just have a friend in a different location host for you or buy some compute space somewhere

    • Yes that’s the point the parent was making, although I don’t even think Tailscale is the easiest option if all you want is a relay.

Kinda.

I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)

I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying

  • That's not the same. You get blocked because the IP address you're coming from is associated with a VPN list, not because they're analyzing the traffic in detail.

    The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.

    • > If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.

      Or, their so-called "smart" TV is acting as a proxy without their informed consent.

  • Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists https://mullvad.net/en/servers.so trivial to block them without blocking all of Azure/GCP/AWS[1]

    There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.

    The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).

    Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.

    [1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.

    • Don’t think there was ever a time since Netflix started streaming where they only licensed global rights to shows. For their own originals they get global rights but the majority of their content is licensed and has always been slightly different in different territories.

    • That list is the IPs users connect to. It is entirely distinct from the list of IPs the VPN traffic egresses from. I doubt believe that they publish their egress ranges.

      1 reply →

  • My home internet is on a CGNAT, so I experience a lot of the same. Ironically, sometimes a VPN will get through.

Right, all you see is the IP address. And anyone in the world can set up an “individual” VPN just for them on a cheap VPS or cloud server anywhere else in the world. There’s no technical way to accomplish what they’ve mandated, only something approximating it like “block all connections from known commercial VPN services”.

Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.

It seems like withdrawing from Utah is the obvious option

  • That was what the law attempted to do: Ban porn in Utah.

    There is a very vocal anti-porn group in Utah. They do things like put up massive billboards that say "[Store name] sells porn." (Which is basically free advertising instead of shaming.)

It's hard to find a proxy or VPN that isn't flagged as such. People pay extra for residential proxies.

  • I’ve been using different VPNs for years for work. I’m starting to come around to the value of a residential proxy service.

    It’s starting to get annoying that things aren’t working. They’re shooting themselves in the foot though.

    If they didn’t block VPNs, they would at least know what category to group them in.

TCP MSS < 1500 bytes can be a tell, although it will sometimes falsely identify non-"VPN" tunnels.

  • There are sooo many people out there who are clamped to something far lower than 1500. MTUs below 1280 are not that exotic either.

    On the other hand, using Masque for TCP transfers will probably fool a server to believe the MSS is 1500.

> Is it even possible to reliably know that a connection is from a VPN?

No, it's not possible. You can only try to identify known protocols or suspicious patterns of data, timing or entropy. Theoretically, with a big enough collaboration, you could hide a VPN behind shaping traffic patterns and request order towards hundreds of different servers, and there's just no method of traffic analysis that can possibly identify that without prior knowledge.

Like, some firewalls try to identify an absence of connections outside the VPN, or an abnormal volume of data over a sustained period of time. But all that goes out the window when, say, you are connecting to hundreds of real servers at all times and only exchanging, say, basic HTTP requests with each one. For all they know you just have a million browser toolbars installed. They wouldn't know if the choice of request, order and timing encodes information because they wouldn't be able to prove what the client's intentions are in sending it or what the servers do with it.

If you tried to identify it, you would block every real connection.

I believe some VPN providers are beginning to play with things like this, but the problem is really that it's impossible to provide this. It only really works when you run it yourself, because that's the only way others don't know. So they're having to settle for compromises, like Mullvad's DAITA, which still uses a single server but tries to avoid showing tells of a VPN connection as opposed to something else like streaming.

You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.

  • Sounds like the great firewall of China. Pretty wild how much we are regressing in the states to say this out loud.

    Let’s block traffic on the internet blindly just in case someone is looking at an adult website.

Not when the definition of VPN is subjective. I could proxy/VPN through a friend's house and nobody would ever know it wasn't them.

  • A lot of law is adjudicated based on the intent, not the black-and-white definition. Proxying your traffic thru a friend's house (VPS in another location, etc) would be considered a "VPN" by a court. Definitional hacks, for the most part, don't fly with judges.

    To handle the matter technically Utah would need a "great firewall of Utah" and a legislative mandate that all ISPs route thru it. Somehow they'd have to factor-in signals from cellular sites neighboring states and satellites.

  • This requires a lot of extra work though, and extra work is downward pressure on the behavior (underage people looking at pornography) that the state of Utah is trying to exert downward pressure on.

    The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.

    • > The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.

      So if you are legally required to block all VPN users and then fail to actually block all VPN users what is stopping you from being punished for not complying with the law?

      2 replies →

  • Yes but isn't it suspicious that all your traffic goes to the friend's house and not to Facebook and Reddit? If you claim it is not a VPN does it mean your friend is providing illegal unlicensed hosting? That's even worse.

The classic: ping the endpoint address, then “ping” the code. If the IP address comes back in 30ms but the JavaScript responds in 330ms, then the client is probably 300ms further away than they say they are claiming.

  • Or they’re on a computer that’s doing something intensive, swapping, or in low power mode. Or they have a browser extension that does stuff before scripts run. Or their cache is emptier than usual and they’re spending a long time doing an initial fetch of the latest ad tracking package your site installed. The list goes on. That’s far too noisy a signal to decide block-or-not based on. Good enough to try to sell someone faster gear, maybe, but not more than that.