This is a very brief blog blurb linking the original Tech Radar article that got fairly extensive discussion on HN a week and a half ago [0]. Potentially quite an important one though so a second go around may still be very justified for those who missed it last time. Amidst a lot of negative moves around the net recently it's nice to see some sanity at least once in awhile.
Ever I'd hope not, but it would make sense to check if a discussion was already started a week ago and add to it rather than start separate ones constantly for each new piece of news - but not as a strict requirement, just an ask. After enough time there tends to be additional development/information which makes using the old conversations useless.
For most of the people on this board, they'd do better to spend that time touching grass as opposed to searching for something that people might have talked about anywhere from 1min - 365+ days ago.
Perhaps people missed that, and would like to start a new discussion?
It didn't know there was a quota on discussions of any particular topic, perhaps we should give out tickets to the event in the future to ensure no-one misses their opportunity to join the discourse?
Reposts is one thing, but the person I replied to was gatekeeping the discussion.
If the post is flagged, that does the job of solving that for us, but telling people not to start a discussion on a subject "because we've been there before" is S tier gatekeeping, and that's what I was opposing.
Yeah I'd hate for multiple comments re-hashing the exact same comments that people already made before, but sometimes there's value in it...I'm sure you'd agree?
If I were a governmental body I would do everything I could to keep citizens using paid VPN's and big CDN's. Money trails are easy to follow and the majority of people are just paying with their bank. It makes people feel safe and more likely to expose certain behaviors. Paid VPN's can say they do not have logs whilst having real time lawful intercept API's. A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions.
Ban VPN's and people will fall back to the myriad of open source alternatives that can be a bit harder to peel back and get logs assuming any exist in the first place. This was a thing some time ago. Many of the malware and pirate groups were sharing Tinc meshes though as expected there would at times be one person in the group that would be the weakest link and expose the entire group. Expand the numbers of people doing this and the probability of a few groups using decent operational security will increase. This probably deserves it's own write-up.
> A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world.
This is backward.
How many ISPs do you have to choose from? Only a couple because there is limited and local infrastructure. How many have business entities in your country? All of them, because it’s a physical location based business.
How many VPN providers (not counting resellers) do you have to choose from? How many are not located in your country?
Most people aren’t using VPNs to commit crimes so significant that they need to be intercepted and unmasked by global law enforcement. Most just want privacy, but if crimes are committed it’s usually piracy or something similar. If we were seeing situations like you’re thinking where police are piercing through VPNs, we’d be seeing evidence of it. Parallel construction theories aren’t going to cover everything for all of time.
You’re also underestimating the difficulty of coordinating criminal investigations across countries. It’s really hard to arrange this and legally expensive. If VPN providers were getting constant requests from countries everywhere to intercept traffic it wouldn’t be a secret. We’d be hearing stories from VPN companies advertising it loudly as one of their selling points for being located in a country which doesn’t require international cooperation.
Governments would also be making moves to block payments or connections to VPNs in those exempt countries, diverting people to their compromised VPNs.
It’s not 4D chess. Connecting to a VPN in another country isn’t completely unbreakable legally, but the reason governments are going after it is because it makes it so much harder or impossible to unmask that it interferes with goals of being able to unmask internet users doing things they don’t want.
Instead of backward I would say it's looking in from a different window. Both your dilemma and the one I described can both be true. I am not suggesting to not use a VPN but rather load-balance and cycle through a mesh of user-provided VPN's that do not have a money trail so that neither your local ISP nor a big juicy centralized provider have your data.
As for disclosure of people being busted I would expect gag orders, the violation and prosecution of which can in some cases be worse than whatever the crime may have been. In the USA judges can hold people for contempt.
Of all possible scenarios this seems one of the least bad. Government is less likely to sell you out and they can't really use the information to prosecute you legally without revealing "oh btw we were behind that VPN", which is kind of a one time trick.
Add to that that half of these companies are registered in obscure offshore locations where it is practically impossible to even find out who are the ultimate owners.
No need to roll your own. There are many open source VPN's, proxies and much more. When dozens, hundreds or thousands of people share and forward load balance their traffic across hundreds of self hosted networks it gets a lot harder to perform attestation and attribution. The reason to cycle through many VPN/proxy networks would be the assumption that a percentage of them are vigilante owned and operated.
That's the easy part. The harder part is to encourage people to be fearless, keep their mouth shut and let their lawyers do all the talking.
The term "rolling your own" as it applies to the internet means writing your own code. For example, "rolling your own encryption" would mean writing your own protocols, algorithms, ciphers, hash formulas, etc...
Hosting something on someone else's servers is "server or VPS renting". Self hosting implies running something on your own servers you own and fully control.
So lets run with they mean running it on a VPS. That is still better than all the delicious eggs in one big basket but it's also risky as there is a money trail and most VPS providers can live-clone, live-migrate a VM to capture and perform forensics all memory contents without impacting performance. If going this route I would try to get one of the cheap "gaming" physical servers and try to find a way to pay that is hard to track. One can at least update the firmware, change all the IPMI accounts and lock it down a little bit.
On a bigger scale one can get their own colocation space. KimDotCom for example had a massive colo in Equinix in Ashburn, VA that ran for a very long time.
Interesting theory. My own theory is that the big corporations want to siphon off more data from people. That is, I think, the main agenda. See android recently stating that everyone has to give up their age. Next step will be ID (though probably, in order to verify the age, one has to give up the ID anyway, so age sniffing could be called ID sniffing).
For what it's worth, two or more things can be true or even partially true. I think all options should be on the table to discuss potential mitigations. Incentives and incentive driven laws can be difficult to prove out. Probably best to just find mitigating options and controls.
I guess accessing a streaming service without permission is considered a copyright violation, but blanket-blocking them based on copyright infringement will be legally difficult now...
This looks like a very narrow ruling regarding copyright. It doesn't guarantee that EU bureaucrats won't try to ban VPNs that don't verify user age (for starters to make NPCs support the bans, then they will inevitably attempt to enforce some kind of KYC or logging to "catch terrorists and pedos".)
In fact this makes it more likely. Now that a court has ruled that current copyright law does not make a VPN provider liable, the European Council (all heads of state of European countries) will propose a law that makes VPN providers liable for copyright-infringing traffic
In particular for "hot" topics like this people should use the search function at the bottom of every HN page before rushing into post.
The last thing everyone needs is yet another duplicate post with hundreds of comments re-hashing the exact same comments that people already made before. It is not helpful for anyone.
The writer is a relatively prominent UK developer; he certainly hasn't missed that the UK isn't in the EU.
You're likely referring to the line "Hopefully this draws a simple line in the sand for the UK government, ..."; the strictest interpretation of the metaphor is certainly muddled, but it is common in the UK to look to EU rulings and policy discussions for comparison to our own - politicians will be aware of them and will use them to help decide whether or not to test things in our own courts.
VPNs are just tools that sketchy people use for sketchy means. There's no legitimate use for someone who isn't trying to break the law. Allowing these tools let's underage people access porn, and do all manner of undesirable behaviors like accessing region locked content.
I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites.
There are of course some people on the other side who think VPNs are a guarantee of privacy and secrecy on the internet, but that's pretty rare in my anecdatal experience. I largely blame the rampant ads on podcasts for this view.
Probably should have put a `>` before the first paragraph, because it reads like an 8/8 bait and most people won't continue to the next one.
Regarding the misleading podcast claims, at least all the podcast and youtube ads made the VPNs popular on the mass market so now they are more difficult to be silently outlawed.
I think an issue VPNs face is that while your first paragraph is not objectively true, it ends up being truer than I might like because the other use cases are not well covered. If you've got one of the things the HN gestalt would call a non-sketchy use case, you've also got the problem that it's rather hard to verify that any VPN you are using actually fulfills your goals. They can say they do, but you have a very hard time proving it.
On my current fiber provider, I'm already behind a very large CGNAT install. To a large degree, de facto that's already a lot of the "non-sketchy" use cases for VPN covered for me. IP addresses are already one of the weaker signals for tracking people as it is. Mobile networks have been letting you shift IPs for years just by how they work. Other internet providers that don't slap thousands of people at a crack behind one IPv4 with CGNAT didn't necessarily guarantee stable IP addresses, hence the need for dynamic DNS for decades.
The hole VPNs plug is necessary, but not even remotely sufficient if you are trying to actually protect yourself from some attack. Slapping a default Windows 11 install on a VPN to a first approximation protects you from nothing.
And since the "non-sketchy" uses are rather dubious, that really does sort of leave just the sketchy ones. I don't think it's a coincidence that when they pay a YouTuber to advertise them, the YouTuber generally ends up talking vaguely about the protections but fairly concretely about the sketchy uses, with screen shots showing them using Netflix in a different country. The companies know what they're getting used for and what they can provide.
VPN is what a smart person uses when they are at an internet cafe or somewhere else with public internet where you can’t trust that the traffic isn’t sniffed by someone for giggles and your bank credentials are going to leak.
Let’s say a hacker hooks up the hotel internet to a firewalla and opens a free wifi spot. You log in and it sees from your traffic that you’re a customer of ABC bank and Gmail and ATT from the traffic - next thing you know you get a text message from your “bank” that someone has stolen your credentials in “XYZ Arizona” and you have yourself a phishing attack. The exposure scenarios are only limited by the imagination of humans and modern LLMs.
This doesn't seem novel in any way, given the amount of data available online you can already be targeted by fake bank texts, no need for the free wifi hotspot.
I just use my home router as VPN to not care if the 100 apps om my phone have a working encryption. I also use it to access my home services so that they are not exposed to the internet. I also use it to limit exposure on my VMs on a cloud hoster.
Not only that, but the iOS and Android APIs for HTTP requests make it really difficult to accidentally use unencrypted HTTP:
* By default, only secure connections are allowed
* You have to enumerate allowed exceptions to this policy in your app manifest XML / Info.plist
* Exceptions are only permitted for specific use cases where mandatory encryption is infeasible, like browsers, podcast players, embedded device clients (which will also require the local network access permission), etc. If you're shipping a banking app and you exempt your own site from encryption, App Review will tear you a new one.
Redundancy is not detrimental to security and privacy. On the contrary, having more layers would protect you in case one of them fails (zero-day, bugs, etc.)
If there's a zero-day in TLS there would be a huge amount of problems that a VPN wouldn't protect you against. Even if you're using a VPN (or just a trusted ISP from your home), as soon as your data leaves their hands it would be vulnerable.
Like, suppose I want to send a physical letter to my bank. I can either ensure it can't be opened (using TLS), or I can get a trusted mailman to bring it to the mail central (using a VPN or trused ISP), but only one of those measures are going to protect me against a malicious mailman carrying it from the mail central to the bank.
I’d expect the mail carrier who goes from the mail center to the bank to be slightly more trustworthy than the one who visits me off in the middle of nowhere. Or at least, if that carrier is untrustworthy, it is a big problem for a lot of rich people who have the time and money to think about this sort of stuff.
Or saying that his view is also shared by people he considers intelligent, and thus can only be rejected by others, who first need to proof to him, that they are actually intelligent. Aka. an indirect ad hominem.
If the poster agreed with the opinion, they wouldn’t have included “actually” (indicating that they think the reader will be feeling incredulous at that point) and “otherwise intelligent.”
Yes correct, I vehemently disagree with people who say things like the first paragraph. I definitely should have been more clear that that was not my opinion, but it's too late to edit now
Meta: your first paragraph could really use a quotation indicator / mark. I suspect it was intentional: the ragebait was very effective on me before reading the rest of your comment (I was ready for defend my usage of tailscale to access my iot stuff).
I use a VPN to have access to my HomeAssistant instance at home, where I can control every aspect of the house. Without this, I would have to pay for a domain name, manage the certificates, and exposing myself to external attacks. So, for me, a VPN reduces massively the attack surface.
There is this law, where if you don't see the purpose of something, is probably because you never needed it. Which is fine, but don't gatekeep others wanting to use them.
Edit: OP forgot to format text, so my anger should be directed to however said the quote...
Yes agreed. I use tailscale for the same purpose, and it's so much simpler than having to properly ingress everything from the internet. I have a few older devices on the LAN that have reached EOL as well and would be a terrible idea to expose them directly to the internet (not so much because I don't want someone turning off my light, but more so I don't end up as part of a botnet)
>I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites
This is an illusion we really need to remove from our collective consciousness. Running a popular website while being an ops genius, being a neurosurgeon who saves lives every day or being the world's best architect doesn't mean someone has sound opinions on topics right outside their area of expertise.
In fact, nowadays it seems to be all about appeals to authority which IMHO makes us more ignorant because many people seem to not think critically anymore. Instead, it's just "an expert said so" - then you look into the "expert" and in many cases they either aren't actually an expert or they're a paid shill. But that's a topic for some other day.
I want to applaud your choice to not include anything like quotes here. That would be misleading because it isn’t an actual literal quote. And, we’re too used to just skimming posts here before jumping right in to argue against them.
I wanted to respond with something of substance (I still don't understand if it was a paraphrase or not) but every reply here is a meta reply, so hello to all fellow meta reply guys.
Maybe put some quotes around that first paragraph. Seems like some people downvote you before they get to the part where you reveal you don't think that way
His whole comment contains a view, that some people, including elected officials hold. I don't see an aspect, that actually hints, that he means that in a sarcastic way(, besides that he is on HN).
> I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites.
First of all: thank you for using the word say, rather than think or believe or anything of that ilk. Too many of these discussions reduce to attributing or misattributing motivations to people.
That said, I still have issues with that statement. Let's assume that you are talking about an intelligent person who works in tech. Chances are something was taken out of context because they probably know what VPNs are for and that they have legitimate uses. Sometimes they miss context because they are not expressing their ideas clearly. Sometimes we miss context because we hear something we violently oppose to, and ignore the rest.
Another issue is that categorizing and vilifying people genuinely doesn't help the cause. At best, people will ignore the counter points. At worse, it will push people further away. We have to listen and educate based upon issues that are relevant to the audience.
Simplistic responses like, "freedom of speech" won't solve anything because those words have lost meaning. Too many people scream "freedom of speech" to excuse what they are saying, while they are active in suppressing the freedom of speech of others. Too many people use the freedom of speech as a tool to intimidate others, to restrict the speech or legal actions of others, because they are more interested in imposing their values on others rather than challenging the values of others. We should be illustrating ways that freedom of speech are relevant using examples that are relevant to the people we are speaking to. In the case of framing freedom of speech for people who are concerned with abortion: pro-life people may respond better to presenting freedom of speech as a safe stage to promote the sacredness of life, while pro-choice people may respond better to framing the freedom of speech as a safe way to seek out information relating to getting an abortion.
Likewise, people can see through simplistic attacks like accusing others of using children for leverage in an argument. Most of the people who say "think of the children" are trying to dismiss people who are trying, legitimately, to protect a vulnerable class. There are plenty of good reasons why the policy mechanisms to protect a vulnerable class may be objectionable, yet framing one's opposition with a reductionist interpretation of intent pushes people apart when they ought to be seeking out better solutions. For example: two people may agree that underage access to porn has to be dealt with, but disagree on the role that VPNs play in circumventing restrictions. So talk about how VPNs are not an age-based access control mechanism. Talk about the misclassification of information about gender and sexuality as pornography, assuming it is relevant to who you are talking to. Talk about the other benefits that VPNs offer in maintaining a free society. In other words, get them on your side and start seeking out better solutions.
I considered it, but it wasn't a direct quote so quotes felt misleading. It was a paraphrase of opinions I've heard expressed by various people in the past
Why do online services need to know where I am? Why does my ISP need to know who I'm communicating with? For me, VPNs are about reducing privacy leakage. Most of the internet collects, aggregates, and sells knowledge about their users, and VPNs are an important tool for withholding that.
It is a sort of LAN network over the Internet. That way, you can connect to devices as if you were in the local network, but having them exposed to the internet.
Traffic is encrypted so there is noone knowing what you are sending, they can still trace that is coming to/from a specific node.
Primary use I have for it is hosting internal services that I don't want on the public internet - do the same at work, it reduces the attack surface hugely
That is the exact thing , I asked that because its primary a personal choice, and I support EU regulator decision on it, If you need VPN for usage like keeping your personal information intact its perfect but if someone else is using for other purpose then again it should personal choice rather than government regulation ( this might not sound good to some).
I know what you mean, but I think most people are not thinking of it in this way. They are thinking of VPN as a service provided by companies such as Nord VPN, and mostly used to get around region locked content or keep your ISP from being aware you are downloading things you shouldn't be.
They do work on Netflix, just not the large commercial VPNs.
If you setup your own VPN with an exit at a residential address, it will work fine. There are some commercial offerings around this. Just as soon as you start needing exits that aren't in data-centres the cost skyrockets.
Answers are there ! that was the whole point of my question, using or not using should be Personal choice not government Ban , everything on internet has pros and cons.
My ISP Comcast (rebranded to Xfinity to avoid all the negative associations with it's actual name) does man in the middle attacks on HTTP connections and injects javascript code into webpages. I actually had this happen to the steam browser back in ~2013 and I had to restart it. But they still do it today in 2026. I don't use a commercial VPN because I host from home. But I do tunnel my HTTP browsing to a remote VPS I rent.
I just loaded up Bluesky this morning to discover it demanding proof of my age bc I live in Texas. First thing I did was turn on my out-of-state vpn and try again. not today, satan!
Instead of an out-of-state vpn, why not an out-of-state home? Why do people put up with the lack of freedom there? People complain about European countries but then praise states like Texas.
(Realistically, moving is easier said than done, of course.)
I'm not sure what to say that doesn't repeat myself. I can add to my prior comment that many Republican-run states, including Texas, restrict freedom of speech and other freedoms in many ways.
Hurray and good. A technology shouldn’t be treated as unlawful simply because it can be used to bypass restrictions. Restrictions which are stupid in the first place in the majority.
I hope VPNs are not becoming the next battleground between online safety and civil liberties. I'm sick of the current ongoing attacks on civil liberties in the Western World under the fake veil of online safety.
Why is something like ublock origin not enough for your needs? Is it more about the principle of not wanting to share any fingerprint across the Internet, or some specific tracking concern?
You can't do much with VPNs these days, almost any website now has antibot systems and it's actually kid's play to detect whether you are on VPN or not.
Jup, if you are using any mainstream VPN provider (the ones shilled on every tech YouTube channel) or anything that results in a datacenter IP, it is trivial to discover and block.
There is a big discrepancy here. EU courts babble about lawful xyz. While they are doing so, national legislation goes downhill, e. g. mandatory age sniffing and other restrictions to come (I claim the age sniffing will come on the OS level, Google recently announced Android will do so, so you can already see the corporate agenda being pushed into democracies here). So I consider the EU courts to just act as decoy, aka "look how everything is legal". Well, a few years later, VPN will be banned. And the EU courts will be in agreement with that.
Are you implying the EU court is (secretly) cooperating with national legislative bodies to implement surveillance tools while pretending to uphold civil liberties?
This is a very brief blog blurb linking the original Tech Radar article that got fairly extensive discussion on HN a week and a half ago [0]. Potentially quite an important one though so a second go around may still be very justified for those who missed it last time. Amidst a lot of negative moves around the net recently it's nice to see some sanity at least once in awhile.
----
0: https://news.ycombinator.com/item?id=48997221
Yeah, please could everyone not pile in and start re-hashing the extensive comments that have already been made only a week and a half ago.
Whatever you're thinking of posting has almost certainly already been said more than once on the original HN discussion.
Is this StackOverflow now, where it's forbidden to discuss something if someone else had a similar discussion before?
Ever I'd hope not, but it would make sense to check if a discussion was already started a week ago and add to it rather than start separate ones constantly for each new piece of news - but not as a strict requirement, just an ask. After enough time there tends to be additional development/information which makes using the old conversations useless.
For most of the people on this board, they'd do better to spend that time touching grass as opposed to searching for something that people might have talked about anywhere from 1min - 365+ days ago.
Part StackOverflow, part Reddit ... it's getting dicey around here.
Perhaps people missed that, and would like to start a new discussion?
It didn't know there was a quota on discussions of any particular topic, perhaps we should give out tickets to the event in the future to ensure no-one misses their opportunity to join the discourse?
> It didn't know there was a quota on discussions of any particular topic
It’s in the FAQ: https://news.ycombinator.com/newsfaq.html#reposts
“Are reposts ok?
If a story has not had significant attention in the last year or so, a small number of reposts is ok. Otherwise we bury reposts as duplicates.”
Alternately, here are comments by moderator dang that mention reposting: https://hn.algolia.com/?dateRange=all&page=0&prefix=true&que...
Reposts is one thing, but the person I replied to was gatekeeping the discussion.
If the post is flagged, that does the job of solving that for us, but telling people not to start a discussion on a subject "because we've been there before" is S tier gatekeeping, and that's what I was opposing.
Sometimes reposts get the attention of the second-chance pool: https://news.ycombinator.com/item?id=26998308
I had one such post that deserved comments but didn't get any, then someone reposted it and dang put the original back into the pool.
Gatekeeping through the voting system is preferable to gatekeeping by random comments, if you feel you must gatekeep.
Yeah I'd hate for multiple comments re-hashing the exact same comments that people already made before, but sometimes there's value in it...I'm sure you'd agree?
https://news.ycombinator.com/item?id=49109440#49109857
Is it even preferable to necro an 8-day old topic? New developments are going to lead to new talking points, right?
With due the greatest respect: it is not up to you to decide on what others deem worthy of commenting or not.
Let’s dig through your comment history and apply the same standard.
Very odd take. Let's not discourage open discussion. I've not seen whatever original HN thread you're referring to.
If I were a governmental body I would do everything I could to keep citizens using paid VPN's and big CDN's. Money trails are easy to follow and the majority of people are just paying with their bank. It makes people feel safe and more likely to expose certain behaviors. Paid VPN's can say they do not have logs whilst having real time lawful intercept API's. A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions.
Ban VPN's and people will fall back to the myriad of open source alternatives that can be a bit harder to peel back and get logs assuming any exist in the first place. This was a thing some time ago. Many of the malware and pirate groups were sharing Tinc meshes though as expected there would at times be one person in the group that would be the weakest link and expose the entire group. Expand the numbers of people doing this and the probability of a few groups using decent operational security will increase. This probably deserves it's own write-up.
> A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world.
This is backward.
How many ISPs do you have to choose from? Only a couple because there is limited and local infrastructure. How many have business entities in your country? All of them, because it’s a physical location based business.
How many VPN providers (not counting resellers) do you have to choose from? How many are not located in your country?
Most people aren’t using VPNs to commit crimes so significant that they need to be intercepted and unmasked by global law enforcement. Most just want privacy, but if crimes are committed it’s usually piracy or something similar. If we were seeing situations like you’re thinking where police are piercing through VPNs, we’d be seeing evidence of it. Parallel construction theories aren’t going to cover everything for all of time.
You’re also underestimating the difficulty of coordinating criminal investigations across countries. It’s really hard to arrange this and legally expensive. If VPN providers were getting constant requests from countries everywhere to intercept traffic it wouldn’t be a secret. We’d be hearing stories from VPN companies advertising it loudly as one of their selling points for being located in a country which doesn’t require international cooperation.
Governments would also be making moves to block payments or connections to VPNs in those exempt countries, diverting people to their compromised VPNs.
It’s not 4D chess. Connecting to a VPN in another country isn’t completely unbreakable legally, but the reason governments are going after it is because it makes it so much harder or impossible to unmask that it interferes with goals of being able to unmask internet users doing things they don’t want.
Instead of backward I would say it's looking in from a different window. Both your dilemma and the one I described can both be true. I am not suggesting to not use a VPN but rather load-balance and cycle through a mesh of user-provided VPN's that do not have a money trail so that neither your local ISP nor a big juicy centralized provider have your data.
As for disclosure of people being busted I would expect gag orders, the violation and prosecution of which can in some cases be worse than whatever the crime may have been. In the USA judges can hold people for contempt.
Yes that's pretty much it. You sign to not talk about it, and the obligatory no pirating ever again clause.
Most of the big VPN companies known from advertisments all over the internet are probably honeypots of the usual countries.
Of all possible scenarios this seems one of the least bad. Government is less likely to sell you out and they can't really use the information to prosecute you legally without revealing "oh btw we were behind that VPN", which is kind of a one time trick.
Parallel construction has been a thing for a very long time to get around this.
Not probably - most of them are confirmed.
Which ones are confirmed and where's the evidence?
Add to that that half of these companies are registered in obscure offshore locations where it is practically impossible to even find out who are the ultimate owners.
coughs in agressive nord vpn ads
if you didn't roll it yourself you need to assume that someone is snooping on you
maybe mullvad is legit but their leadership keeps leaning to dubious causes
No need to roll your own. There are many open source VPN's, proxies and much more. When dozens, hundreds or thousands of people share and forward load balance their traffic across hundreds of self hosted networks it gets a lot harder to perform attestation and attribution. The reason to cycle through many VPN/proxy networks would be the assumption that a percentage of them are vigilante owned and operated.
That's the easy part. The harder part is to encourage people to be fearless, keep their mouth shut and let their lawyers do all the talking.
by rolling your own they don't mean write a VPN from scratch, but host a VPN on a VPS.
The term "rolling your own" as it applies to the internet means writing your own code. For example, "rolling your own encryption" would mean writing your own protocols, algorithms, ciphers, hash formulas, etc...
Hosting something on someone else's servers is "server or VPS renting". Self hosting implies running something on your own servers you own and fully control.
So lets run with they mean running it on a VPS. That is still better than all the delicious eggs in one big basket but it's also risky as there is a money trail and most VPS providers can live-clone, live-migrate a VM to capture and perform forensics all memory contents without impacting performance. If going this route I would try to get one of the cheap "gaming" physical servers and try to find a way to pay that is hard to track. One can at least update the firmware, change all the IPMI accounts and lock it down a little bit.
On a bigger scale one can get their own colocation space. KimDotCom for example had a massive colo in Equinix in Ashburn, VA that ran for a very long time.
If you did roll it yourself, you definitely aren't anonymous because there is only one user of the VPN IP address.
What do you mean with "leaning to dubious causes?" I was under the impression mullvad was fine.
https://news.ycombinator.com/item?id=48717469
The point of VPNs often is hiding in the mass. Rolling your own kind of defeats that purpose.
Even very basic browser fingerprinting will still identify you. The IP address is just one of many data points.
The point isn’t to hide yourself from the destination.
It’s to hide along the journey there.
Fingerprinting is usually insufficient for law enforcement.
Interesting theory. My own theory is that the big corporations want to siphon off more data from people. That is, I think, the main agenda. See android recently stating that everyone has to give up their age. Next step will be ID (though probably, in order to verify the age, one has to give up the ID anyway, so age sniffing could be called ID sniffing).
For what it's worth, two or more things can be true or even partially true. I think all options should be on the table to discuss potential mitigations. Incentives and incentive driven laws can be difficult to prove out. Probably best to just find mitigating options and controls.
The age thing is because of laws mandating it
This will also come in handy, when ISPs in Spain turn off VPNs when football plays on the screen:
https://www.techradar.com/vpn/vpn-privacy-security/la-ligas-...
I guess accessing a streaming service without permission is considered a copyright violation, but blanket-blocking them based on copyright infringement will be legally difficult now...
This looks like a very narrow ruling regarding copyright. It doesn't guarantee that EU bureaucrats won't try to ban VPNs that don't verify user age (for starters to make NPCs support the bans, then they will inevitably attempt to enforce some kind of KYC or logging to "catch terrorists and pedos".)
In fact this makes it more likely. Now that a court has ruled that current copyright law does not make a VPN provider liable, the European Council (all heads of state of European countries) will propose a law that makes VPN providers liable for copyright-infringing traffic
Discussion on 21-jul-2026 https://news.ycombinator.com/item?id=48997221 141 comments
Yeah.
In particular for "hot" topics like this people should use the search function at the bottom of every HN page before rushing into post.
The last thing everyone needs is yet another duplicate post with hundreds of comments re-hashing the exact same comments that people already made before. It is not helpful for anyone.
TIL there's a search function at the bottom of every HN page. Only took me 10 years to find out it exists!
Isn't the parent comment almost a duplicate of your other comment?
https://news.ycombinator.com/reply?id=49109868
Writer seems to overlook the issue of the UK no longer being in the EU
The writer is a relatively prominent UK developer; he certainly hasn't missed that the UK isn't in the EU.
You're likely referring to the line "Hopefully this draws a simple line in the sand for the UK government, ..."; the strictest interpretation of the metaphor is certainly muddled, but it is common in the UK to look to EU rulings and policy discussions for comparison to our own - politicians will be aware of them and will use them to help decide whether or not to test things in our own courts.
VPNs are just tools that sketchy people use for sketchy means. There's no legitimate use for someone who isn't trying to break the law. Allowing these tools let's underage people access porn, and do all manner of undesirable behaviors like accessing region locked content.
I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites.
There are of course some people on the other side who think VPNs are a guarantee of privacy and secrecy on the internet, but that's pretty rare in my anecdatal experience. I largely blame the rampant ads on podcasts for this view.
Probably should have put a `>` before the first paragraph, because it reads like an 8/8 bait and most people won't continue to the next one.
Regarding the misleading podcast claims, at least all the podcast and youtube ads made the VPNs popular on the mass market so now they are more difficult to be silently outlawed.
Oops yes, definitely should have done that. Looks like it's too late to edit though
Haha, if it wasn't even on purpose that makes it more funny.
Your comment was even dead for a while, before I (and others?) vouched for it.
A whole thread could have been prevented with " and ", haha
Putting a '>' would make it look like it's a quote from the article, which it isn't.
Well yeah, it's a strawman, but not unattached to reality.
Lol your comment made me do a double take, I had stopped reading after the first sentence
I think an issue VPNs face is that while your first paragraph is not objectively true, it ends up being truer than I might like because the other use cases are not well covered. If you've got one of the things the HN gestalt would call a non-sketchy use case, you've also got the problem that it's rather hard to verify that any VPN you are using actually fulfills your goals. They can say they do, but you have a very hard time proving it.
On my current fiber provider, I'm already behind a very large CGNAT install. To a large degree, de facto that's already a lot of the "non-sketchy" use cases for VPN covered for me. IP addresses are already one of the weaker signals for tracking people as it is. Mobile networks have been letting you shift IPs for years just by how they work. Other internet providers that don't slap thousands of people at a crack behind one IPv4 with CGNAT didn't necessarily guarantee stable IP addresses, hence the need for dynamic DNS for decades.
The hole VPNs plug is necessary, but not even remotely sufficient if you are trying to actually protect yourself from some attack. Slapping a default Windows 11 install on a VPN to a first approximation protects you from nothing.
And since the "non-sketchy" uses are rather dubious, that really does sort of leave just the sketchy ones. I don't think it's a coincidence that when they pay a YouTuber to advertise them, the YouTuber generally ends up talking vaguely about the protections but fairly concretely about the sketchy uses, with screen shots showing them using Netflix in a different country. The companies know what they're getting used for and what they can provide.
VPN is what a smart person uses when they are at an internet cafe or somewhere else with public internet where you can’t trust that the traffic isn’t sniffed by someone for giggles and your bank credentials are going to leak.
How would your banking credentials leak? Every banking app uses encryption. In fact, I'd wager every app uses encryption nowadays.
Let’s say a hacker hooks up the hotel internet to a firewalla and opens a free wifi spot. You log in and it sees from your traffic that you’re a customer of ABC bank and Gmail and ATT from the traffic - next thing you know you get a text message from your “bank” that someone has stolen your credentials in “XYZ Arizona” and you have yourself a phishing attack. The exposure scenarios are only limited by the imagination of humans and modern LLMs.
This doesn't seem novel in any way, given the amount of data available online you can already be targeted by fake bank texts, no need for the free wifi hotspot.
I've also argued this on the past, it just seems redundant, but people eat the VPN ads like they were gospel.
I just use my home router as VPN to not care if the 100 apps om my phone have a working encryption. I also use it to access my home services so that they are not exposed to the internet. I also use it to limit exposure on my VMs on a cloud hoster.
Not only that, but the iOS and Android APIs for HTTP requests make it really difficult to accidentally use unencrypted HTTP:
* By default, only secure connections are allowed
* You have to enumerate allowed exceptions to this policy in your app manifest XML / Info.plist
* Exceptions are only permitted for specific use cases where mandatory encryption is infeasible, like browsers, podcast players, embedded device clients (which will also require the local network access permission), etc. If you're shipping a banking app and you exempt your own site from encryption, App Review will tear you a new one.
thats why we have https and certs. VPN is redundant
Redundancy is not detrimental to security and privacy. On the contrary, having more layers would protect you in case one of them fails (zero-day, bugs, etc.)
If there's a zero-day in TLS there would be a huge amount of problems that a VPN wouldn't protect you against. Even if you're using a VPN (or just a trusted ISP from your home), as soon as your data leaves their hands it would be vulnerable.
Like, suppose I want to send a physical letter to my bank. I can either ensure it can't be opened (using TLS), or I can get a trusted mailman to bring it to the mail central (using a VPN or trused ISP), but only one of those measures are going to protect me against a malicious mailman carrying it from the mail central to the bank.
I’d expect the mail carrier who goes from the mail center to the bank to be slightly more trustworthy than the one who visits me off in the middle of nowhere. Or at least, if that carrier is untrustworthy, it is a big problem for a lot of rich people who have the time and money to think about this sort of stuff.
TLS exists.
Logging into my work computer, to work in the company network: yeah very sketchy.
That isn't the one they're banning. The law isn't as autistic as nerds think it is.
Exactly. I disagree with the law, but it's obviously not about corporate VPNs
Many people reading this are going to stop at the first sentence without realizing you're paraphrasing a position you apparently don't agree with.
That's amazing. I didn't even realize but it seems I read the first paragraph and the last sentence, concluded "moron" and scrolled down.
It's only because of your comment that I re-read the their post.
What is the sign, that he does not?
"I have actually heard otherwise intelligent people say things just like that"
Meaning the poster finds it surprising that intelligent site operators would honestly think that.
Or saying that his view is also shared by people he considers intelligent, and thus can only be rejected by others, who first need to proof to him, that they are actually intelligent. Aka. an indirect ad hominem.
If the poster agreed with the opinion, they wouldn’t have included “actually” (indicating that they think the reader will be feeling incredulous at that point) and “otherwise intelligent.”
Yes correct, I vehemently disagree with people who say things like the first paragraph. I definitely should have been more clear that that was not my opinion, but it's too late to edit now
Eh, I think I disagree. We should support a convention of reading all of the paragraphs to the posts we are responding to, not just the first one.
Yes that would be the ideal! I do hope we can reach that some day
Meta: your first paragraph could really use a quotation indicator / mark. I suspect it was intentional: the ragebait was very effective on me before reading the rest of your comment (I was ready for defend my usage of tailscale to access my iot stuff).
I use a VPN to have access to my HomeAssistant instance at home, where I can control every aspect of the house. Without this, I would have to pay for a domain name, manage the certificates, and exposing myself to external attacks. So, for me, a VPN reduces massively the attack surface.
There is this law, where if you don't see the purpose of something, is probably because you never needed it. Which is fine, but don't gatekeep others wanting to use them.
Edit: OP forgot to format text, so my anger should be directed to however said the quote...
Yes agreed. I use tailscale for the same purpose, and it's so much simpler than having to properly ingress everything from the internet. I have a few older devices on the LAN that have reached EOL as well and would be a terrible idea to expose them directly to the internet (not so much because I don't want someone turning off my light, but more so I don't end up as part of a botnet)
This is going to get some interesting responses by people commenting immediately after only reading the first paragraph.
>I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites
This is an illusion we really need to remove from our collective consciousness. Running a popular website while being an ops genius, being a neurosurgeon who saves lives every day or being the world's best architect doesn't mean someone has sound opinions on topics right outside their area of expertise.
In fact, nowadays it seems to be all about appeals to authority which IMHO makes us more ignorant because many people seem to not think critically anymore. Instead, it's just "an expert said so" - then you look into the "expert" and in many cases they either aren't actually an expert or they're a paid shill. But that's a topic for some other day.
I want to applaud your choice to not include anything like quotes here. That would be misleading because it isn’t an actual literal quote. And, we’re too used to just skimming posts here before jumping right in to argue against them.
> Allowing these tools let's underage people access porn
You can't imagine how much crime I committed in my teenage years. You don't wanna end up like me, punks! Stay off that crap!
I wanted to respond with something of substance (I still don't understand if it was a paraphrase or not) but every reply here is a meta reply, so hello to all fellow meta reply guys.
Region locking content is the undesirable behavior. Accessing it is very desirable.
I'm genuinely considering whether the people replying to you are bots now.
Bots wouldn't miss the middle paragraph.
Maybe put some quotes around that first paragraph. Seems like some people downvote you before they get to the part where you reveal you don't think that way
TIL every corp in the world are sketchy people for using VPN.
That isn't what they're banning, and you know it.
Of course, but if the argument is VPN = Bad, then it feels a bit deaf to ignore use cases for VPN…which is exactly why this law didn’t pass.
This is the must absurd take possible. Most business use VPNs for their day to day operations.
I think you need to read the second sentence.
His whole comment contains a view, that some people, including elected officials hold. I don't see an aspect, that actually hints, that he means that in a sarcastic way(, besides that he is on HN).
You guys really need to finish reading the comments before you reply...
"I have actually heard otherwise intelligent people say things just like that" I think that is the indicator.
His second sentence is "There's no legitimate use for someone who isn't trying to break the law."
I'm not trying to break the law, I use it for my corporate usage, therefore it is legitimate use.
What are you trying to say?
I think they're trying to say you need to read the whole comment before taking it apart.
> What are you trying to say?
Pretty sure they meant “second paragraph” instead of “second sentence”.
Yeah, basically. To me it sounded like he was doing a sarcastic quote, then shutting that opinion down.
yes, assuming your laws are like "Only blue eyed males are allowed to have internet"
This is the dumbest thing I've read in a while
You didn’t manage to read the entire comment, did you?
"You don't have to eat the whole egg to know that it is rotten." (G. B. Shaw)
How do you think you can work from home with a VPN for access of the companies network?
Edit: missed the second paragraph
> I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites.
First of all: thank you for using the word say, rather than think or believe or anything of that ilk. Too many of these discussions reduce to attributing or misattributing motivations to people.
That said, I still have issues with that statement. Let's assume that you are talking about an intelligent person who works in tech. Chances are something was taken out of context because they probably know what VPNs are for and that they have legitimate uses. Sometimes they miss context because they are not expressing their ideas clearly. Sometimes we miss context because we hear something we violently oppose to, and ignore the rest.
Another issue is that categorizing and vilifying people genuinely doesn't help the cause. At best, people will ignore the counter points. At worse, it will push people further away. We have to listen and educate based upon issues that are relevant to the audience.
Simplistic responses like, "freedom of speech" won't solve anything because those words have lost meaning. Too many people scream "freedom of speech" to excuse what they are saying, while they are active in suppressing the freedom of speech of others. Too many people use the freedom of speech as a tool to intimidate others, to restrict the speech or legal actions of others, because they are more interested in imposing their values on others rather than challenging the values of others. We should be illustrating ways that freedom of speech are relevant using examples that are relevant to the people we are speaking to. In the case of framing freedom of speech for people who are concerned with abortion: pro-life people may respond better to presenting freedom of speech as a safe stage to promote the sacredness of life, while pro-choice people may respond better to framing the freedom of speech as a safe way to seek out information relating to getting an abortion.
Likewise, people can see through simplistic attacks like accusing others of using children for leverage in an argument. Most of the people who say "think of the children" are trying to dismiss people who are trying, legitimately, to protect a vulnerable class. There are plenty of good reasons why the policy mechanisms to protect a vulnerable class may be objectionable, yet framing one's opposition with a reductionist interpretation of intent pushes people apart when they ought to be seeking out better solutions. For example: two people may agree that underage access to porn has to be dealt with, but disagree on the role that VPNs play in circumventing restrictions. So talk about how VPNs are not an age-based access control mechanism. Talk about the misclassification of information about gender and sexuality as pornography, assuming it is relevant to who you are talking to. Talk about the other benefits that VPNs offer in maintaining a free society. In other words, get them on your side and start seeking out better solutions.
flagged for intentional ragebait, if this wasn't ragebait you would have used quotes
I considered it, but it wasn't a direct quote so quotes felt misleading. It was a paraphrase of opinions I've heard expressed by various people in the past
First question that need to asked from everyone including ownself , why you need VPN?
Why do online services need to know where I am? Why does my ISP need to know who I'm communicating with? For me, VPNs are about reducing privacy leakage. Most of the internet collects, aggregates, and sells knowledge about their users, and VPNs are an important tool for withholding that.
It is a sort of LAN network over the Internet. That way, you can connect to devices as if you were in the local network, but having them exposed to the internet.
Traffic is encrypted so there is noone knowing what you are sending, they can still trace that is coming to/from a specific node.
https://femboy.beauty/P1iUdl
You must be blessed to live in a country that has no website blocks.
Primary use I have for it is hosting internal services that I don't want on the public internet - do the same at work, it reduces the attack surface hugely
That is the exact thing , I asked that because its primary a personal choice, and I support EU regulator decision on it, If you need VPN for usage like keeping your personal information intact its perfect but if someone else is using for other purpose then again it should personal choice rather than government regulation ( this might not sound good to some).
I know what you mean, but I think most people are not thinking of it in this way. They are thinking of VPN as a service provided by companies such as Nord VPN, and mostly used to get around region locked content or keep your ISP from being aware you are downloading things you shouldn't be.
Bypassing censorship is the biggest one. No, they don't work on Netflix. But they work on many things.
They do work on Netflix, just not the large commercial VPNs.
If you setup your own VPN with an exit at a residential address, it will work fine. There are some commercial offerings around this. Just as soon as you start needing exits that aren't in data-centres the cost skyrockets.
Privacy from ISP
Bypass censorship
Get treated the same by websites when traveling
Avoid bad laws
Gain good laws
Answers are there ! that was the whole point of my question, using or not using should be Personal choice not government Ban , everything on internet has pros and cons.
Is that really a question that needs to be asked in 2026?
My ISP Comcast (rebranded to Xfinity to avoid all the negative associations with it's actual name) does man in the middle attacks on HTTP connections and injects javascript code into webpages. I actually had this happen to the steam browser back in ~2013 and I had to restart it. But they still do it today in 2026. I don't use a commercial VPN because I host from home. But I do tunnel my HTTP browsing to a remote VPS I rent.
They also block 3rd-party DNS in many cases, forcing you to use theirs so they can sell your activity more completely.
I just loaded up Bluesky this morning to discover it demanding proof of my age bc I live in Texas. First thing I did was turn on my out-of-state vpn and try again. not today, satan!
FYI, this recently changed to only apply to the mobile app. Browser access and 3rd party apps are not restricted.
That explains why I only discovered it now. I usually use my laptop wth a browser, not an app.
Instead of an out-of-state vpn, why not an out-of-state home? Why do people put up with the lack of freedom there? People complain about European countries but then praise states like Texas.
(Realistically, moving is easier said than done, of course.)
A VPN is 5 dollars. People are not as privileged as you assume and very few chose their location based on age verification laws.
European countries have restrictions on freedom of speech which is a strongly held value in America.
I'm not sure what to say that doesn't repeat myself. I can add to my prior comment that many Republican-run states, including Texas, restrict freedom of speech and other freedoms in many ways.
Rich people aren't restricted, middle class people want those restrictions, and poor people can't leave.
I assume you're not America, because people outside the USA think literally the exact same thing about Americans.
People with my HHI level don't experience any of the negative effects of Republican policies except for the ones externalized to the entire USA.
And people without my HHI can't afford to leave.
You might as well wonder why people still live in Hungary when it's part of the EU and they could all move to Germany or Sweden.
To bypass geo-locked content and age restrictions of course. What else???
> VPNs in particular have been tossed around as something that the UK government would like to ban (citation needed/lacking!)
It was widely covered (like at https://www.express.co.uk/news/uk/2217934/vpn-ban-table-july...) and tech sec. Liz Kendall is on the record with BBC talking about July.
Yeah. And Jess Phillips was calling for that and much more draconian measures (e.g. on device scanning).
Hurray and good. A technology shouldn’t be treated as unlawful simply because it can be used to bypass restrictions. Restrictions which are stupid in the first place in the majority.
I hope VPNs are not becoming the next battleground between online safety and civil liberties. I'm sick of the current ongoing attacks on civil liberties in the Western World under the fake veil of online safety.
privacy is a right, until you don't have a voice to say so.
I don't connect to internet without VPN nowdays. Too much tracking today.
Why is something like ublock origin not enough for your needs? Is it more about the principle of not wanting to share any fingerprint across the Internet, or some specific tracking concern?
uBlock origin is not effective at preventing tracking without changing IP address and using an anti - fingerprint browser like Mullvad's.
Your webbrowser is not the only application connected to the internet
Server side tracking.
How are you not blocked by banking, shopping, even sometimes google search?
Just change servers. Never had a problem with any of those and I have a VPN on my router covering all devices.
Use Brave search instead, Google search has terrible a privacy policy.
There are inconveniences, but some protection is better than no protection. Trying to protect your privacy online is not a zero-sum game.
You can't do much with VPNs these days, almost any website now has antibot systems and it's actually kid's play to detect whether you are on VPN or not.
You can do a lot. Cloudflare doesn't want to ban all VPNs, not yet.
Can't do much without a VPN, it's scary out there.
Jup, if you are using any mainstream VPN provider (the ones shilled on every tech YouTube channel) or anything that results in a datacenter IP, it is trivial to discover and block.
The detection tech has been around forever: https://focsec.com/
Week old post OP;
[dupe] Discussion on source: https://news.ycombinator.com/item?id=48997221
There is a big discrepancy here. EU courts babble about lawful xyz. While they are doing so, national legislation goes downhill, e. g. mandatory age sniffing and other restrictions to come (I claim the age sniffing will come on the OS level, Google recently announced Android will do so, so you can already see the corporate agenda being pushed into democracies here). So I consider the EU courts to just act as decoy, aka "look how everything is legal". Well, a few years later, VPN will be banned. And the EU courts will be in agreement with that.
It's a step-by-step strategy.
Are you implying the EU court is (secretly) cooperating with national legislative bodies to implement surveillance tools while pretending to uphold civil liberties?
The EU court is just saying the law currently doesn't make them liable. I assume this oversight will be rectified quickly.
The UK government recently said it was not going to ban VPNs
https://www.independent.co.uk/extras/indybest/gadgets-tech/v...