back
177 comments
This is a very brief blog blurb linking the original Tech Radar article that got fairly extensive discussion on HN a week and a half ago [0]. Potentially quite an important one though so a second go around may still be very justified for those who missed it last time. Amidst a lot of negative moves around the net recently it's nice to see some sanity at least once in awhile.

----

0: https://news.ycombinator.com/item?id=48997221

Yeah, please could everyone not pile in and start re-hashing the extensive comments that have already been made only a week and a half ago.

Whatever you're thinking of posting has almost certainly already been said more than once on the original HN discussion.

If I were a governmental body I would do everything I could to keep citizens using paid VPN's and big CDN's. Money trails are easy to follow and the majority of people are just paying with their bank. It makes people feel safe and more likely to expose certain behaviors. Paid VPN's can say they do not have logs whilst having real time lawful intercept API's. A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions.

Ban VPN's and people will fall back to the myriad of open source alternatives that can be a bit harder to peel back and get logs assuming any exist in the first place. This was a thing some time ago. Many of the malware and pirate groups were sharing Tinc meshes though as expected there would at times be one person in the group that would be the weakest link and expose the entire group. Expand the numbers of people doing this and the probability of a few groups using decent operational security will increase. This probably deserves it's own write-up.

> A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world.

This is backward.

How many ISPs do you have to choose from? Only a couple because there is limited and local infrastructure. How many have business entities in your country? All of them, because it’s a physical location based business.

How many VPN providers (not counting resellers) do you have to choose from? How many are not located in your country?

Most people aren’t using VPNs to commit crimes so significant that they need to be intercepted and unmasked by global law enforcement. Most just want privacy, but if crimes are committed it’s usually piracy or something similar. If we were seeing situations like you’re thinking where police are piercing through VPNs, we’d be seeing evidence of it. Parallel construction theories aren’t going to cover everything for all of time.

You’re also underestimating the difficulty of coordinating criminal investigations across countries. It’s really hard to arrange this and legally expensive. If VPN providers were getting constant requests from countries everywhere to intercept traffic it wouldn’t be a secret. We’d be hearing stories from VPN companies advertising it loudly as one of their selling points for being located in a country which doesn’t require international cooperation.

Governments would also be making moves to block payments or connections to VPNs in those exempt countries, diverting people to their compromised VPNs.

It’s not 4D chess. Connecting to a VPN in another country isn’t completely unbreakable legally, but the reason governments are going after it is because it makes it so much harder or impossible to unmask that it interferes with goals of being able to unmask internet users doing things they don’t want.

Most of the big VPN companies known from advertisments all over the internet are probably honeypots of the usual countries.
Interesting theory. My own theory is that the big corporations want to siphon off more data from people. That is, I think, the main agenda. See android recently stating that everyone has to give up their age. Next step will be ID (though probably, in order to verify the age, one has to give up the ID anyway, so age sniffing could be called ID sniffing).
Discussion on 21-jul-2026 https://news.ycombinator.com/item?id=48997221 141 comments
Yeah.

In particular for "hot" topics like this people should use the search function at the bottom of every HN page before rushing into post.

The last thing everyone needs is yet another duplicate post with hundreds of comments re-hashing the exact same comments that people already made before. It is not helpful for anyone.

This looks like a very narrow ruling regarding copyright. It doesn't guarantee that EU bureaucrats won't try to ban VPNs that don't verify user age (for starters to make NPCs support the bans, then they will inevitably attempt to enforce some kind of KYC or logging to "catch terrorists and pedos".)
In fact this makes it more likely. Now that a court has ruled that current copyright law does not make a VPN provider liable, the European Council (all heads of state of European countries) will propose a law that makes VPN providers liable for copyright-infringing traffic
This will also come in handy, when ISPs in Spain turn off VPNs when football plays on the screen:

https://www.techradar.com/vpn/vpn-privacy-security/la-ligas-...

I guess accessing a streaming service without permission is considered a copyright violation, but blanket-blocking them based on copyright infringement will be legally difficult now...

VPNs are just tools that sketchy people use for sketchy means. There's no legitimate use for someone who isn't trying to break the law. Allowing these tools let's underage people access porn, and do all manner of undesirable behaviors like accessing region locked content.

I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites.

There are of course some people on the other side who think VPNs are a guarantee of privacy and secrecy on the internet, but that's pretty rare in my anecdatal experience. I largely blame the rampant ads on podcasts for this view.

Probably should have put a `>` before the first paragraph, because it reads like an 8/8 bait and most people won't continue to the next one.

Regarding the misleading podcast claims, at least all the podcast and youtube ads made the VPNs popular on the mass market so now they are more difficult to be silently outlawed.

I think an issue VPNs face is that while your first paragraph is not objectively true, it ends up being truer than I might like because the other use cases are not well covered. If you've got one of the things the HN gestalt would call a non-sketchy use case, you've also got the problem that it's rather hard to verify that any VPN you are using actually fulfills your goals. They can say they do, but you have a very hard time proving it.

On my current fiber provider, I'm already behind a very large CGNAT install. To a large degree, de facto that's already a lot of the "non-sketchy" use cases for VPN covered for me. IP addresses are already one of the weaker signals for tracking people as it is. Mobile networks have been letting you shift IPs for years just by how they work. Other internet providers that don't slap thousands of people at a crack behind one IPv4 with CGNAT didn't necessarily guarantee stable IP addresses, hence the need for dynamic DNS for decades.

The hole VPNs plug is necessary, but not even remotely sufficient if you are trying to actually protect yourself from some attack. Slapping a default Windows 11 install on a VPN to a first approximation protects you from nothing.

And since the "non-sketchy" uses are rather dubious, that really does sort of leave just the sketchy ones. I don't think it's a coincidence that when they pay a YouTuber to advertise them, the YouTuber generally ends up talking vaguely about the protections but fairly concretely about the sketchy uses, with screen shots showing them using Netflix in a different country. The companies know what they're getting used for and what they can provide.

VPN is what a smart person uses when they are at an internet cafe or somewhere else with public internet where you can’t trust that the traffic isn’t sniffed by someone for giggles and your bank credentials are going to leak.
Logging into my work computer, to work in the company network: yeah very sketchy.
Many people reading this are going to stop at the first sentence without realizing you're paraphrasing a position you apparently don't agree with.
Meta: your first paragraph could really use a quotation indicator / mark. I suspect it was intentional: the ragebait was very effective on me before reading the rest of your comment (I was ready for defend my usage of tailscale to access my iot stuff).
This is going to get some interesting responses by people commenting immediately after only reading the first paragraph.
>I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites

This is an illusion we really need to remove from our collective consciousness. Running a popular website while being an ops genius, being a neurosurgeon who saves lives every day or being the world's best architect doesn't mean someone has sound opinions on topics right outside their area of expertise.

In fact, nowadays it seems to be all about appeals to authority which IMHO makes us more ignorant because many people seem to not think critically anymore. Instead, it's just "an expert said so" - then you look into the "expert" and in many cases they either aren't actually an expert or they're a paid shill. But that's a topic for some other day.

I want to applaud your choice to not include anything like quotes here. That would be misleading because it isn’t an actual literal quote. And, we’re too used to just skimming posts here before jumping right in to argue against them.
I use a VPN to have access to my HomeAssistant instance at home, where I can control every aspect of the house. Without this, I would have to pay for a domain name, manage the certificates, and exposing myself to external attacks. So, for me, a VPN reduces massively the attack surface.

There is this law, where if you don't see the purpose of something, is probably because you never needed it. Which is fine, but don't gatekeep others wanting to use them.

Edit: OP forgot to format text, so my anger should be directed to however said the quote...

> Allowing these tools let's underage people access porn

You can't imagine how much crime I committed in my teenage years. You don't wanna end up like me, punks! Stay off that crap!

I wanted to respond with something of substance (I still don't understand if it was a paraphrase or not) but every reply here is a meta reply, so hello to all fellow meta reply guys.
Region locking content is the undesirable behavior. Accessing it is very desirable.
I'm genuinely considering whether the people replying to you are bots now.
Maybe put some quotes around that first paragraph. Seems like some people downvote you before they get to the part where you reveal you don't think that way
TIL every corp in the world are sketchy people for using VPN.
yes, assuming your laws are like "Only blue eyed males are allowed to have internet"
How do you think you can work from home with a VPN for access of the companies network?

Edit: missed the second paragraph

flagged for intentional ragebait, if this wasn't ragebait you would have used quotes
This is the must absurd take possible. Most business use VPNs for their day to day operations.
This is the dumbest thing I've read in a while
There is a big discrepancy here. EU courts babble about lawful xyz. While they are doing so, national legislation goes downhill, e. g. mandatory age sniffing and other restrictions to come (I claim the age sniffing will come on the OS level, Google recently announced Android will do so, so you can already see the corporate agenda being pushed into democracies here). So I consider the EU courts to just act as decoy, aka "look how everything is legal". Well, a few years later, VPN will be banned. And the EU courts will be in agreement with that.

It's a step-by-step strategy.

The UK government recently said it was not going to ban VPNs

https://www.independent.co.uk/extras/indybest/gadgets-tech/v...

You can't do much with VPNs these days, almost any website now has antibot systems and it's actually kid's play to detect whether you are on VPN or not.
Week old post OP;

[dupe] Discussion on source: https://news.ycombinator.com/item?id=48997221

First question that need to asked from everyone including ownself , why you need VPN?
> VPNs in particular have been tossed around as something that the UK government would like to ban (citation needed/lacking!)

It was widely covered (like at https://www.express.co.uk/news/uk/2217934/vpn-ban-table-july...) and tech sec. Liz Kendall is on the record with BBC talking about July.

Writer seems to overlook the issue of the UK no longer being in the EU
privacy is a right, until you don't have a voice to say so.
Hurray and good. A technology shouldn’t be treated as unlawful simply because it can be used to bypass restrictions. Restrictions which are stupid in the first place in the majority.

I hope VPNs are not becoming the next battleground between online safety and civil liberties. I'm sick of the current ongoing attacks on civil liberties in the Western World under the fake veil of online safety.

I don't connect to internet without VPN nowdays. Too much tracking today.