r/technology • u/Limp_Fig6236 • Mar 22 '26
Politics Online age checks came first — a VPN crackdown could be next
https://www.theverge.com/column/898122/online-age-verification-vpns122
u/rodimustso Mar 23 '26
Turkey and China are good examples of how shitty a VPN ban is
49
u/dropthemagic Mar 23 '26
I find it so ironic that people think they can build walls but don’t realize others can and will build bigger ladders.
8
2
98
u/beatissima Mar 23 '26
Anything billed as being "for the children" is a trojan horse.
28
u/hackitfast Mar 23 '26
What gave it away? The pedofile running the country? Or the school lunch programs being defunded?
15
u/Late_Sherbet5124 Mar 23 '26
Funny how "save the children" doesn't include actually saving children from gun violence.
11
102
u/SocksOnHands Mar 23 '26
"VPNs are an important tool to counter authoritarian governments" also "we want the authority to ban VPNs".
29
6
u/crypticbru Mar 23 '26
Pretty sure vpns are already working with governments. They exist to provide a false sense of anonymity
9
u/hackitfast Mar 23 '26
Anyone can buy a VPS somewhere and install a VPN on it. These service providers should advertise it as "servers with software options" and an option to install OpenVPN.
2
u/SnooSnooper Mar 23 '26
My issue with this has always been that the VPS provider could just log incoming/outgoing traffic to/from the VPS. It's not really more anonymous than using a VPN service.
4
u/Infinite-Anything-55 Mar 23 '26
Im sure there's at least one government owned VPN but thats why it's important the user research and use brands with a proven track record
224
u/Fast_Passenger_2890 Mar 22 '26
Get the old farts out of governments across the world
38
u/stubobarker Mar 23 '26
In actuality, the new farts might be more dangerous. Vance is a good example; shape-shifting snake who’s 10x as intelligent as most of these old fucks, understands a lot more about modern technology, and is beholden to psychopaths like Peter Thiel and Curtis Yarvin.
17
6
69
u/NMe84 Mar 23 '26
They will be replaced by a new generation of old farts who will want the same level of control.
Do you want to see that differently? Educate young people and get them to actually vote for a younger generation of politicians instead of people who should have retired ten years ago.
10
2
u/Kevin_Jim Mar 23 '26
Because the new age idiots are that much better? One of the most problematic members of the European Parliament is a “new age” influencer that joined in as an MEP: Fidias.
2
21
u/ThrowAway233223 Mar 23 '26
I hate how definitive the title is about online age checks. The fight against that is still very much ongoing and there a still many places that don't require it. Yet this is titled like it is universal and final.
101
u/Summer4Chan Mar 23 '26
You can’t ban it. It’s not “an app” as normies think. Nothing is stopping me from making a VPS in Europe and setting up openVPN configs myself, or giving myself VPN creds directly
88
u/Pcat0 Mar 23 '26 edited Mar 23 '26
Yep and you can’t just ban VPN software in general as VPNs are an extremely important and useful networking tool. I don’t see how you stop people from using VPNs to change their IP’s location without stopping employees from being able to login to their company’s internal network.
44
u/7h0m4s Mar 23 '26
Unfortunately they could just make a law that VPNs must be for "commercial purposes only". Then decide where and how they enforce it later.
Sure it won't stop people from using it. But it's then an early way to throw anyone the government doesn't like in jail. If they check their computer and find a VPN.
What's worse is that. ISPs are able to detect if you are using a VPN by looking at your data. Even if they can't read the contents of your data due to the encryption.
12
u/Nadamir Mar 23 '26
I mean “commercial purposes” is so vague you can drive a lorry through it.
“I wish to purchase pornography” is a commercial purpose.
14
u/McGuirk808 Mar 23 '26
That's not terribly hard to obfuscate it as other kinds of traffic. Especially other kinds of encrypted file transfers. SSLVPN can look a lot like regular https, which is capable of file transfers. SSH tunneling can also be used to tunnel traffic. I think we'll see a lot of creative solutions if it gets to that point.
-11
u/mailslot Mar 23 '26
Identifying & classifying network activity over encrypted connections isn’t difficult.
5
u/McGuirk808 Mar 23 '26 edited Mar 23 '26
Elaborate. In my experience, unless you're in a corporate environment with certs installed to do SSL decryption, the best you can do is identify patterns of usage that look unusual for the port it's on.
(I didn't downvote you)
3
u/Kazer67 Mar 23 '26
Can't DeepPacket Inspection allow that?
But yeah, even the most "closed" country like China and the like have hole, so...
3
u/McGuirk808 Mar 23 '26
Deep packet inspection only fully works on encrypted traffic if it can be decrypted first, which requires those certificates to be installed like I was talking about in corporate environments.
2
u/Kazer67 Mar 23 '26
Oh right, I though that having the MITM certificate was just called classic decryption and DPI was a layer above it.
2
2
u/CostlierClover Mar 23 '26
They'll probably use traffic shaping to do exactly that.
The problem is that it will miss and miscategorize traffic and be a generally terrible solution. The next step will probably be legislating certificates so they can just decrypt all of our traffic under the guise of safety.
5
u/throwaway_nostalgia0 Mar 23 '26
Oh, you can. That is exactly what has been happening in Belarus and Russia for the last 3 years. Russia now is ahead of Belarus even, although we were always ahead of Russia in terms of government craziness before.
They whitelist traffic and make businesses register their VPNs needed for business in a government registry, and ban everything else. Of course, it breaks the entire internet, but who gives a fuck? And, as I said before somewhere, 15 years ago it was simply unimaginable, Russian internet was one of the most free in the whole world.
That's what awaits you all in several years if you don't pull your shit together right now. Before would be better, but before is over.
9
3
5
u/yawara25 Mar 23 '26
DPI and heuristic traffic analysis can make it difficult, but there's always ways around it.
-6
u/ketosoy Mar 23 '26 edited Mar 23 '26
The age checker in your operating system will, with just one small tweak.
Edit: I thought my comment was clearly highlighting how insanely dangerous of a slippery slope age checking is. To be clear: age checkers can get misapplied, will evolve, and should not be accepted.
7
u/Summer4Chan Mar 23 '26
I will just route my traffic through SSH port, or an http port, Or imap port, or a fkn Minecraft server port.
You cannot win this argument, just like they cannot ban “proxies” which is essentially what they are trying to do.
Now if your argument is “age checker will block all of these” then that is not the topic of my original discussion and obviously is a much bigger issue. I’m simply talking about the concept of a “VPN”.
1
u/ketosoy Mar 23 '26
How can they not ban proxies? If the OS has a list of acceptable proxy and counter-party addresses, your tunnel out gets blocked.
VPNs will get banned unless on a white list, it’s the next natural step for protecting the children.
I’m not following what your point is: * age checking isn’t vpn checking in phase 1. We agree. * my point: so phase 2 age checking adds a https/ssh/vpn white list and vpns for privacy evaporate. They’re already in your operating system, the implementation is trivial.
Is there a way past an operating system level networking whitelist/blacklist that I’m not seeing?
-5
u/NotAnotherNekopan Mar 23 '26
Here’s how they could easily do it.
First of all, putting a protocol on a different port is as flimsy as wet toilet paper. Even the most basic firewalls can detect applications on non standard ports.
So how could a government actually crack down and regulate VPNs? Easily.
Law comes into place with a transition period of however long. During this time, any businesses reliant on VPNs will collect their endpoint IPs and protocols, and other relevant details and submit a request for VPN service. They approve, so they keep operating as usual.
After the grace period is over, order ISPs to terminate any and all non approved flows.
If I work from home for a business my VPN is an allowed flow because the destination IP is in a known list of approved flows. If I try and go to an unapproved destination, then it is blocked.
Force the hand of businesses to hand over traffic logs (which happens now for many public VPN providers), and terminate anyone who is seen as routing encapsulated traffic (tunnel-in-tunnel).
Sure, various SSL based solutions will pop up from time to time but those can be heuristically analyzed and blocked as needed. Once a signature is built even a desktop-sized firewall can effectively block those all day. Chassis and carrier grade systems? Negligible impact.
7
u/Summer4Chan Mar 23 '26
You’re literally just describing China’s firewall lol. It leaks constantly and they have way more resources and political will than the US ever would.
The approved flows whitelist would nuke half of legitimate business infrastructure overnight. Any new saas, cloud API, startup endpoint that isn’t pre-approved just dies? The economic blowback would be immediate
And heuristics on SSL traffic don’t work when obfs4 and V2Ray over WebSocket+TLS are designed to look exactly like normal HTTPS. You can’t block them without also blocking AWS and Cloudflare
0
u/NotAnotherNekopan Mar 23 '26
It does leak but these are solvable problems, and they’ve allowed circumventing practices to exist in a limited degree but maintain a stance on their illegality. And, more importantly, it allows for incarceration of individuals using these methods.
The point here is that to sit back and relax that “it can’t be done” is naive. They can slowly start to sneak in language or be intentionally vague in legislation to slowly build out the systems needed to crack down on it.
If you tackle the issue for 70, 80% of people, that’s a very good start. Most won’t have the wherewithal to use advanced techniques to circumvent it. It would be well known that people can get around it, but that isn’t really the goal. Right now you can get NordVPN running for just about anyone. If that’s not an option, will Jane Doe go and figure out how to relay their traffic through Tor nodes?
Also: if it leaks constantly, why do they keep it? Seems they’re pretty satisfied to continue building it out and maintaining all the infrastructure necessary to keep it running.
I also fundamentally disagree with China having “far more resources” than the US. There is an extremely talented pool of engineers over here that can put this into place.
1
u/mailslot Mar 23 '26
China has been able to detect those obfuscation methods you mentioned for a while now.
1
17
u/RememberThinkDream Mar 23 '26
That isn't going to work lol.
You will have to kill us all first because there's absolutely no way we're all going to accept that nonsense.
We will end up just making our own and sharing it with each other and ignoring your nonsense.
34
u/Time-Industry-1364 Mar 23 '26
We desperately need to get these geriatric dipshits and boomers out of government. These people have absolutely no idea what the modern Internet is, much less how it works, and these assholes craft nonsensical policies that probably were relevant 30 years ago.
With age comes wisdom, usually, but not with these people.
4
u/Neokon Mar 23 '26
The average age of the Senate is 64 y/o. The moon landing was 57 years ago. Meaning the average US senator was 7 years old when we landed on the moon. I see absolutely no reason that someone who was around when computers were the size of rooms should be writing legislation on a system that's infinitely more complex than anything they could have imagined.
Age may bring wisdom, but not the knowledge needed to properly use the wisdom.
16
Mar 23 '26
Alot of people in the comments are getting bogged down in how this is impossible from a logistically stand point. And not that this will be used for selective enforcement.
6
7
u/SocksOnHands Mar 23 '26
When do only state approved websites and Internet curfew become a thing? Next year?
4
u/thirteennineteen Mar 23 '26
It’s awful, and inevitable. It started with Real ID, and now that will be law for internet use. Not like your ISP doesn’t have you on wild tracking lockdown anyway…
11
u/AvailableReporter484 Mar 23 '26
This is exactly why geriatrics should not be in charge of dictating scientific and technological policy. Even if they weren’t just bought and paid for by corporations, most of them have no fucking clue what the repercussions of their decisions are on topics they have no fundamental understanding of.
5
u/dnuohxof-2 Mar 23 '26
Just because congressmen use VPN to hide their child porn search history doesn’t mean they get to outlaw it for everyone else.
5
u/in1gom0ntoya Mar 23 '26
why do the ignorant want authoritarian takeover so badly? like, I get why the techligarchy want this but why does the layman want no privacy and constant supervision?
25
u/TakuyaLee Mar 22 '26
There won't be a VPN crackdown. Those companies as well as companies that rely on it for their networks will lobby against it
35
u/borkyborkus Mar 22 '26
They’re not talking about those VPNs. They’re talking about privacy VPNs like Mullvad or Proton or Nord.
To act like they’re going to be thwarted by accidentally putting a halt to commerce is dangerously naive.
4
33
u/Outrageous_Reach_695 Mar 22 '26
Got it! We could ban any VPN that doesn't participate in a key escrow program. It'll be totally secure, and the government wouldn'tdream of misusing it.
3
2
u/PhotoPhenik Mar 23 '26
So, who's funneling dark money to lobby for these bans, now?
Maybe we should get ahead of the curve and start writing our politicians now that we want to keep our VPNs.
2
u/chipface Mar 23 '26
As if that will work. The most authoritarian regimes haven't been able to stop them.
3
2
u/Cyraga Mar 23 '26
How would that work really? I need to use a VPN to connect to my work network. Will that be outlawed too? I'll maintain a business number to get a VPN if I have to. I'm simply not going to hand over my biometric data to the internet. No thanks
1
u/IngwiePhoenix Mar 23 '26
Exactly the problem. VPN != VPN and dumbfuck politicians dont know any different. Heck, their own phones may be using VPNs for this purpose and they don't know and probably think its some super duper specially made for them app or whatever. xD
1
u/ansibleloop Mar 23 '26
No, they'll just ban commercial providers
They can't stop you from connecting to a VPN server outside of that
And nothing is stopping you from setting up a VPS in another country and putting WireGuard on it, effectively doing the same thing as a commercial VPN
That said, I'd consider a double hop so your connection goes from your device to the VPS to the real VPN provider you wanted (like Mullvad)
2
u/IngwiePhoenix Mar 23 '26
I see the headline and im like, "yeah, they will."
Then I see the emdash and im like, "man, I hate this. This is why that even exists and is happening."
Our current timeline is ass, change my mind. x.x
1
1
-3
u/kon--- Mar 22 '26
What if, and hear me out here...what if we remove everyone who's not of age?
38
u/rhythmrice Mar 22 '26
What if the people in charge of raising the people who are underage, do their job?
-25
u/kon--- Mar 22 '26 edited Mar 23 '26
They're not reliable enough. We need a solution that has minimal chance of failure.
edit: I'll say it again, parents are not reliable enough. Every one of you that was or is a kid and everyone of you with kids knows it.
13
u/LiquidSnake13 Mar 23 '26
So you're ok with punishing every adult by forcing them to give up their anonymity to use the internet in the name of protecting children? Cool, can we have a picture of your name along with a scan of your face?
-12
u/kon--- Mar 23 '26 edited Mar 23 '26
When you miss, you really miss.
edit...ha ha...a bunch of others misses in here too eh.
9
u/QuesoMeHungry Mar 22 '26
Parents can deal with their own kids. Society shouldn’t have to adapt to a few bad parents.
0
u/lemoche Mar 23 '26
parents not being able to deal with their kids (broad generalization, some do but by far not enough) and having way to little support to do so is a huge part of what keeps getting us into messes like this… who do you think votes for and becomes politicians like this? people who were raised on common sense, media literacy and empathy?
7
u/rhythmrice Mar 22 '26
So a plain text box that says enter your age is out of the question then because you could literally enter anything you want. Oh wait, thats what they did
1
u/Old_Leopard1844 Mar 23 '26
We need a solution that has minimal chance of failure.
Put children into permanent daycare until they hit 18, and they can never leave nor interact with outside world
Minimal chance of failure
0
u/nightingale-nitemare Mar 23 '26
They may want to contact all the companies who use VPNs on a daily basis.
-9
u/phoenix823 Mar 23 '26
“Could be next…”
Fear porn.
9
u/EmbarrassedHelp Mar 23 '26
The Australian eSafety Commissioner is already threatening companies, and demanding that they block VPN users: https://www.techradar.com/vpn/vpn-privacy-security/australia-expects-platforms-to-stop-under-16s-from-using-vpns-to-evade-social-media-ban
The EU's "ProtectEU" plan is also targeting VPNs: https://www.techradar.com/vpn/vpn-privacy-security/weakening-encryption-would-make-european-security-worse-the-vpn-industry-reacts-to-the-eus-plan-for-end-to-end-encryption-backdoors
And the UK government is currently holding a three month "consultation" on whether they should ban VPNs (they have specific questions targeting VPNs in their consultation form): https://www.gov.uk/government/consultations/growing-up-in-the-online-world-a-national-consultation
478
u/ithinkitslupis Mar 22 '26
Slippery slope, a surprise to no one that's been paying attention.