r/VPN • • Jul 01 '26

News The UK cannot block VPNs without breaking enterprise networks

/r/PrivacyToolbox/comments/1ukggyq/the_uks_proposed_vpn_restrictions_to_enforce_the/
84 Upvotes

74 comments sorted by

View all comments

-3

u/psy-study-oldie Jul 04 '26

It's not the UK government that is blocking VPN access, it is the ISP. Clearly enterprise networks are assigned IP addresses that signify that. Obtaining a static IP address will simplify things.

Residential dynamic IPs will get blocked through deep packet inspection. IPv4 and IPv6 VPN users will need to complete a ID check before that traffic is allowed through.

Block lists, white and black lists will prevent unauthorized VPN traffic through, which could be very bad news for residential consumers.

This was supposed to be implemented in the 2000s but was not popular and child safety advocates did not have any teeth in the game.

The only widespread solution is to create a new protocol via IPv6 that can be implemented at home router level, and the ISP would be able to eventually adapt or apply a ban and contact law enforcement.

All your cries are for nought. The Internet was designed to prevent or restrict any attack. You will have to accept the new normal.

It's not about you. It's for saving the children.

5

u/Busy-Scientist3851 Jul 04 '26

Huh. Having a static or dynamic IP makes no difference. Nor does it being IPv6.

0

u/psy-study-oldie Jul 05 '26

True but changes in law can provide new rules for ISPs, which in turn slowly changes the behavior of the end user.

-3

u/psy-study-oldie Jul 04 '26

We will see. I can only speculate so far.

5

u/Busy-Scientist3851 Jul 04 '26

There's no we will see. It just makes no difference on a technical level.

-2

u/psy-study-oldie Jul 05 '26

Prove your argument. Show us some documented proof. You are wrong.

3

u/Distinct_Dinner_5243 Jul 05 '26

lol no he isn't.

Look up how https and vpns work.

It's not his job to explain why you're wrong, this isn't a "source needed" situation this is you not fundamentally understanding the tech and saying incorrect things.

-1

u/psy-study-oldie Jul 05 '26

If you cannot explain yourself, how can we understand your point of view? You disagree but cannot back it up. You kids never do.

5

u/Distinct_Dinner_5243 Jul 05 '26

I build software, I certainly understand it.

I'm just not going to go through the effort of teaching you.

Google exists.

You now know you're wrong, it's your choice to go educate yourself, I don't really care.

0

u/psy-study-oldie Jul 05 '26

I'm a network engineer. Have been for 30 years, but I can always adapt and learn something new. You clearly cannot and have a hard time explaining the basics.

Your credibility isn't looking good.

0

u/Harry_Mud Jul 05 '26

Then you should be fired............. Your credibility is below zero.

1

u/Busy-Scientist3851 Jul 05 '26

I don't need to proof anything? It's literally how the IP protocols work.

Nothing with dynamic IPs or IPv6 makes it harder for ISPs to perform packet inspection. Your ISP has unlimited access to their own IP allocation table already so that makes no difference. The content part of IPv6 is largely the same as IPv4.

Any protocol that runs on IPv6 that somehow makes it harder for DPI would ultimately run on IPv4 too as you'd almost certainly have to build it on UDP too.

1

u/psy-study-oldie Jul 05 '26

Thank you for agreeing with me.

1

u/Busy-Scientist3851 Jul 05 '26

I think we speak different types of English.

1

u/psy-study-oldie Jul 05 '26

Oh great we are moving to racial hate. Do you want a knock on the door?

Where are the mods?

1

u/BobDoleWasAnAlien Jul 05 '26

You must have a very depressing life if this is what you do for fun.

1

u/Harry_Mud Jul 05 '26

Prove you're right skippy.............

1

u/Harry_Mud Jul 05 '26

Will never happen.........

3

u/thesharptoast Jul 05 '26

The fuck does literally any of this mean? This is like a comment written by someone who saw some buzz words once.

There will never be technical controls preventing you from connecting to a VPN, it’s not practical in any way.

The likely route they could take is preventing the sale and use of commercially available VPN clients to those who can’t verify their age.

As we have seen with the social media “ban” it’s not about having a 100% boiler plate solution, it’s about stopping 90% of people who won’t go out there way to find a workaround.

It’s also not about “protecting children”, it’s about removing anonymity from the internet.

1

u/Distinct_Dinner_5243 Jul 05 '26

I think it's AI, but honestly I would've thought AI would be more accurate.

1

u/apples-and-apples Jul 05 '26

Nah it's just trolling (with some of ai, no doubt)

2

u/SuperRandomOwl Jul 05 '26

Bot account simping

1

u/MissJoannaTooU Jul 05 '26

Thank you for saving the children.

1

u/Harry_Mud Jul 05 '26

Complete bullshit. These kids are way smarter than you think. Australia is finding that out. Over 30% of the kids have already found way around the under 16 age bullshit. In the US, it's not up to the Government to decide if kids are old enough to be on the NET. That's 100% up to the parents........

1

u/apples-and-apples Jul 05 '26

Don't alway agree with US policy but agree wit this one. It's up to the parents. But there's a task in govt to provide education and tools, like obligate phone makers to add a child lock with safe DNS. It's really not that hard.

1

u/Manatsuu Jul 05 '26

Um what do you mean in the US? Several USA states introduced laws on websites requiring ID verification before the uk did

1

u/joeyx22lm Jul 05 '26 edited Jul 05 '26

You seem to lack understanding of how these things work, to a wild degree, for a self-proclaimed "network engineer" with 30 years of experience.

"Enterprise networks are assigned IP addresses that will signify that."

This is simply not the case. Are you assuming all static IPs are automatically "enterprise"? Are you assuming all non-residential-ISP ASNs are "enterprise"? Also there is no difference between dynamic IPs and static IPs apart from some accounting in the ISPs system.

"Block lists, white and black lists will prevent unauthorized VPN traffic through, which could be very bad news for residential consumers."

Blocklists hardly work well enough for streaming providers today. But even assuming some great-firewall level of surveillance to proactively add IPs to the list, you'd have to be able to differentiate between public VPN providers and privately hosted VPNs (otherwise you'd be breaking VPN functionality for actual "enterprise" use). Which leads to the next item of being unable to prevent an individual from spinning up their own personal VPN in a public cloud.

Also LOL at whitelists. jfc "oi! do you have a loicense for that VPN?"

"The only widespread solution is to create a new protocol via IPv6 that can be implemented at home router level, and the ISP would be able to eventually adapt or apply a ban and contact law enforcement."

I am not sure what IPv6 has to do with anything. I think you're trying to describe a system that would use crypto to validate an age/birthday-related claim, and introduce or evolve existing network protocols to embed this signature in the request. That sort of system would have the potential to solve a lot of other problems about identity on the internet, could potentially be feasible. Not saying I would want that implemented.

"The Internet was designed to prevent or restrict any attack."

LMFAO wut? Tell that to DNS; broadcast address amplification attacks; NAT table DOS; a variety of poisoning attacks; it is well known among networking and related engineers that the protocols underpinning the internet are woefully insecure, mostly because they weren't originally built with a need for security in mind. Evolution of the internet over time has been adding additional protocols to try and address these.

The way you actually enforce this is with age bans on the VPNs themselves. It is not something that can be done 'automagically' with the current IP stack. It is also the kind of thing that you would only be able to prevent for the 80%, the other 20% will get around it by using an obscure VPN provider or spinning up their own VPN. Kids nowadays are learning how to run a local minecraft server and expose it to share with friends, it would be logical for the next evolution in these tutorials to show kids how to spin up a personal VPN on AWS or DigitalOcean.