4 comments

  • irenaeus 3 minutes ago
    Not sure what the impossibility is. VPN's have a set of exit relays. If traffic is coming from one of those exit relays, it's coming from a VPN, so adult websites can be required to block traffic from those exit relays. What am I missing?
    • llama052 0 minutes ago
      I would think that requiring adult websites to essentially block all VPN traffic to be pretty heavy handed and hardly a solution. Especially considering there are many reasons to use a VPN.
    • gambiting 1 minute ago
      It's impossible to have a full and complete list of VPN exit nodes, for the simple reason that no company publishes the full list, and also technically if you set up an OpenVPN server on digital ocean and connect to that you're also using a VPN but no one would know your address is hosting a VPN server.
  • JSR_FDED 50 minutes ago
    The church of LDS is no stranger to technical impossibilities
    • roughly 45 minutes ago
      There are a category of things that are technically impossible until a burly man threatens to break your arm if you don't do them, and a category of things that are still impossible.

      Doesn't help your arm, but when they're asking for things in that second category, it doesn't help them either.

      • cwillu 41 minutes ago
        But until you've broken their arm, you can't know which category you're in.
        • not_a_bot_4sho 35 minutes ago
          Wait, we're the burly man?
          • recursive 5 minutes ago
            I've always aspired to be burly. This is great news.
          • roughly 7 minutes ago
            weird when people make that swap without noticing it, huh?
  • SoftTalker 46 minutes ago
    > platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely

    Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.

    • not_a_bot_4sho 30 minutes ago
      Kinda.

      I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)

      I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying

      • manquer 0 minutes ago
        [delayed]
      • alnwlsn 22 minutes ago
        My home internet is on a CGNAT, so I experience a lot of the same. Ironically, sometimes a VPN will get through.
    • TeMPOraL 23 minutes ago
      All it would take is for a major ISP in Utah to route everyone through a VPN, and boom, it's the same picture.
    • ad_fontes 39 minutes ago
      Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.
    • ranger_danger 35 minutes ago
      Not when the definition of VPN is subjective. I could proxy/VPN through a friend's house and nobody would ever know it wasn't them.
      • irenaeus 0 minutes ago
        This requires a lot of extra work though, and extra work is downward pressure on the behavior (underage people looking at pornography) that the state of Utah is trying to exert downward pressure on.

        The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.

      • codedokode 28 minutes ago
        Yes but isn't it suspicious that all your traffic goes to the friend's house and not to Facebook and Reddit? If you claim it is not a VPN does it mean your friend is providing illegal unlicensed hosting? That's even worse.
        • malfist 16 minutes ago
          > does it mean your friend is providing illegal unlicensed hosting

          Since when do you have to pull permits to put a server on the web?

        • ranger_danger 3 minutes ago
          "Suspicious" is not illegal, and neither is hosting.
        • iAMkenough 18 minutes ago
          Split tunnel is a thing, and in that instance the platform required to comply (like a porn site) doesn’t have any way to see all your traffic to determine if it’s a VPN/proxy connection or not.
    • codedokode 30 minutes ago
      You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.
  • usernomdeguerre 37 minutes ago
    >As we’ve said time and time again: the internet will always route around censorship.

    Is this still true, or has it become a truism? It seems nations like Iran and China (and events like Kashmir come to mind) have progressed the state-of-the-art and playbook to where we can't actually say it definitively will route around it.

    Now seeing that the US and EU are flirting with these similar restrictions it's making me wonder how we'll be able to keep hold of these principles.

    Maybe my concern with that adage is ultimately its passive voice, since it takes 'active' action by people to give us those options, and will probably take more actions by more people to keep it alive now.

    • tialaramex 4 minutes ago
      The thing China can do, and does do: Kill your network connections, whether that's a TCP session, your ability to send or receive packets with some particular IP addresses, or at the extreme armed men show up and now it's not an Internet problem.

      Things China can't do: Magically "downgrade", "decrypt" or "intercept" the secure protocols we use every day like HTTPS. Facts won't budge, the technology we are using does what it says on the tin.

      The Internet can't route around you being thrown off a tall building by men with guns, but the IETF has for some years considered it to be extremely important to design the network protocols to prevent these shenanigans. BCP # 188 "Pervasive Monitoring is An Attack"

    • nemomarx 27 minutes ago
      Is China that successful at it lately? I see a lot of posters and info from China getting around the great firewall, and my understanding was that they don't really care if 1% of users do that so long as it mostly holds and only the technical minded or really fixated will see it.

      So there is a route around censorship, but maybe the public doesn't really care about it.

      • jason1cho 7 minutes ago
        I'm not sure whether it's 1% or 0.1% or only Xi Jinpin can access YouTube. China can adjust the surveillance level dynamically. It's a matter of cost and effect.
      • Scaled 11 minutes ago
        There is also the difficult reality that the government doesn't need to block vpn entirely, but just make it a credible risk of being detected. If you have to worry about the state police barging into your home, you are likely to decide it isn't worth the risk and self-regulate.
    • TeMPOraL 16 minutes ago
      It's never been true.

      The layer 2 and 3 of ISO/OSI stack does indeed "route around censorship". But the Internet as we know it is all Layer 7, and it's as centralized as it gets.

      That's why regulators often aim straight at Layer 7 entities - companies providing consumer services over the web. Because no matter how unblockable the route between you and some server is, it doesn't mean anything when the server itself is refusing to talk to you.

    • snohobro 18 minutes ago
      I’m pretty sure with Iran, and I assume other authoritarian nations, the state controls what traffic can and cannot leave their borders. When they go dark, they just effectively cut off access to the outside world entirely. Sure they may have their own state run servers that provide some services, but then they can inspect and manage all traffic being routed inside the country. Don’t have to try and find the VPN if there’s just no traffic.

      I suppose Utah could impose some sort of strategy here, but would be so burdensome and anti-American I’m not sure they could pull it off. Instead of a blacklist of sites dictated by the site provider, you go the other way where all Utah ISPs maintain a whitelist of IPs permitted to Utah citizens. Any traffic attempting to reach a non-white listed IP, would be rejected.

    • TJSomething 34 minutes ago
      It seems like Utah could do mostly do this by intercepting all consumer traffic.
      • jason1cho 5 minutes ago
        Just buy the surveillance equipment from Russia and get it done.
      • iAMkenough 8 minutes ago
        With some sort of whitelist of IP addresses that consumers, travelers, and business executives are allowed to connect to while in the state?

        A VPN/proxy could exist at almost any single address at any given time.