Remix.run Logo
▲ SoftTalker 5 hours ago

> platforms are left with an impossible choice: completely block all VPN traffic nationwide or withdraw access from Utah entirely

Is it even possible to reliably know that a connection is from a VPN? Anyone can proxy through a random hosting provider.

▲happyPersonR 4 hours ago | parent | next [-]

Requires the vpn provider to snitch and possible tag the ip frames or http frames lol

Folks would just host their own vpns various places and this would be pointless ….

▲unglaublich 3 hours ago | parent | next [-]

It's all just an effort to control the 90%.

▲pkilgore 3 hours ago | parent [-]

It lawfare against porn. They don't want these companies to exist. They want it to be impossible to comply with the law to shut them down.

▲bigbuppo 3 hours ago | parent | next [-]

It's lawfare against Constitutionally-protected speech. The "for the children" bit is just an appeal to emotion.

/Same as it ever was

▲pimeys 3 hours ago | parent | prev | next [-]

Why are people so upset about porn? It's probably still the biggest portion of internet traffic. Kind of like human nature, don't you think?

▲lokar 2 hours ago | parent | next [-]

Assuming you are really asking, the two largest objections:

- religious/cultural. My beliefs forbid this, it makes people bad/worse in some hard-to-define way, so no one should be allowed to do it. Sometimes with an emphasis that the sellers are luring good people into sin/ruin.

- it harms women. Many of the participants are trafficked or coerced in some way (and further abused). The profits from the industry encourage more of this. It “warps” the mind of men who use it, leading them to mistreat and abuse women.

I see elements of truth in all these, but IMO they are ultimately not compelling, prohibition is unworkable and unduly infringes on willing participants and consumers.

▲UltraSane an hour ago | parent | next [-]

The "porn harms women" argument really seems to infantilize women and assumes that women can never want or enjoy sex for the sake of sex.

▲jonahx 28 minutes ago | parent | next [-]

This is not the claim. The claim is that, empirically, many (or enough) of the women who end up in porn are underage, trafficked, or psychologically coerced (due to poverty, drug addiction, abuse, etc) such that the choice is not really the free choice of willing participant.

I am all for individual freedoms, but I've read enough about this issue, and seen enough documentaries, that I think the claim is very well-founded. Of course, some porn stars are just willing adults doing something they want to do, but there are many who are not.

▲lokar 10 minutes ago | parent | next [-]

I’ve seen two arguments:

Women who do not provide fully informed and voluntarily consent are harmed

Porn makes some (or many, or all) men who consume it treat some (or many, or all) women badly

▲UltraSane 20 minutes ago | parent | prev [-]

> The claim is that, empirically, many (or enough) of the women who end up in porn are underage, trafficked, or psychologically coerced (due to poverty, drug addiction, abuse, etc) such that the choice is not really the free choice of willing participant.

The main point of contention becomes what "enough" constitutes. Almost no women in commercial porn is underage as all countries that legally allow its production also require strict proof of age for the people actually having sex.

▲lokar an hour ago | parent | prev [-]

Some argue it harms all women who participate in, but others argue it harms some women who participate, which seems undeniable.

▲fwip 26 minutes ago | parent [-]

True, and this is probably true of all work. Retail work has probably harmed many more women than sex work (by virtue of being much more common).

▲throwinthisaway 2 hours ago | parent | prev [-]

Frankly I believe the whole “warps the mind of men to abuse women” is total nonsense.

I’ve watched plenty of porn in my life, probably a bit more than average. I’ve never done anything out of the norm or unwanted to woman, let alone abuse one.

I think shitty people will be shitty people and it’s just a really easy thing to point at instead of taking responsibility for it. It’s also a convenient plausible sounding correlation for people who already want to ban porn to use.

▲BobaFloutist 43 minutes ago | parent | next [-]

If you change the argument to "can warp the mind of some men", it becomes much harder to falsify.

▲lokar 2 hours ago | parent | prev | next [-]

I can see the argument for a “correlation vs causation “ argument, but I’m not a social scientist.

▲schrodinger 2 hours ago | parent | prev [-]

Agreed. It’s like the argument that video games cause shooters.

Umm, I played plenty of GTA growing up and I’ve never stolen a car. People are actually very good at separating fantasy from reality, believe it or not.

▲GolfPopper an hour ago | parent | prev [-]

>Kind of like human nature, don't you think?

That's one reason why traditionists in power usually crack down on any sort of pornography or alternate sexuality. Sex is a huge driver for human behavior. And established power structures would prefer that the only way for anyone to get sex is via compliance with the existing power structures. It's not something where the establishment is ever going to be able to perfectly control things, but if they can make it more difficult to get any sort of sexual gratification that doesn't align with their preferred social structure that gives the establishment an advantage in holding on to power.

▲miohtama an hour ago | parent | prev | next [-]

The UK is doing it.

Ofcom is investigating PornHub even after PornHub installed age checks as Ofcom claims age checks not “robust” (read: VPN ban). So hand over your id to see porn.

https://x.com/moo9000/status/2102726344975040565?s=20

▲pessimizer 3 hours ago | parent | prev [-]

They don't care about porn. The people who would vote for it in Utah do, and that's why Utah is being used as a vehicle by other people to bolster the need to root all computers.

▲EA-3167 3 hours ago | parent [-]

How can you be that paranoid about one thing and so gullible with another? We’re surrounded by phones, cameras, smart cars, IoT, microphones and most people are on social media too.

The government demonstrably has the ability to break into your comms and data without going through any of this. Instead of a libertarian conspiracy theory have you considered that politicians chase power and re-election?

Taking a stand and making major changes is hard to pull off, costs a lot of political resources, and can backfire horribly. Doing symbolic, popular crap that’s popular with the (admittedly thick and ignorant) majority is an easy win. Moral outrage is an easy win. “Think of the children” is an easy win.

Ed: Corrected “comma” to “comms”

▲HeatrayEnjoyer 3 hours ago | parent [-]

Break into your comma? Google-fu is letting me down on this one

▲0cf8612b2e1e 3 hours ago | parent [-]

I assume auto correct for “coms” or “communications”?

▲mmooss 3 hours ago | parent | prev | next [-]

> Folks would just host their own vpns various places and this would be pointless

In the real world, very few people have that capability.

▲mey 3 hours ago | parent [-]

Do you have a friend/family out of state? Do they have a commodity router? Many have such a feature built in.

Less savvy individuals/business would also have no reason to obey these laws.

See https://en.wikipedia.org/wiki/Evil_bit

▲mmooss 2 hours ago | parent [-]

The limitation isn't access to the technology. There is endless OSS, it's probably built into many standard OSes, and there are many available products and projects that will deploy the whole thing for you.

The limitation is technical skill, even having enough skill to know that this is a solution.

▲sparkling 3 hours ago | parent | prev | next [-]

Detection can be based on the IPs themselves, no packet tricks required. Plenty of services can do that: https://focsec.com/

Now of course, if your VPN is a home-lab style VPN where you are connecting to a little wireguard box sitting in your own home, that is a totally different story.

▲compiler-guy 3 hours ago | parent [-]

And still required by Utah law.

▲campbel 2 hours ago | parent | prev [-]

You can do for free with tailscale exit nodes. Just have a friend in a different location host for you or buy some compute space somewhere

▲stingraycharles 37 minutes ago | parent [-]

Yes that’s the point the parent was making, although I don’t even think Tailscale is the easiest option if all you want is a relay.

▲not_a_bot_4sho 5 hours ago | parent | prev | next [-]

Kinda.

I use VPN most of the time. My work requires it, and I like Mozilla VPN for personal privacy. (Note: it has ad blocking DNS built in which is nice!)

I occasionally get blocked by websites or services, especially streaming apps, if I'm on VPN. I suspect they're just looking out for Amazon/Microsoft/etc IP address blocks. It's very annoying

▲Aurornis 4 hours ago | parent | next [-]

That's not the same. You get blocked because the IP address you're coming from is associated with a VPN list, not because they're analyzing the traffic in detail.

The simplest methods block known datacenter IP ranges like you thought. More will score it based on several heuristics and a reputation over time. If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.

▲a4isms 3 hours ago | parent [-]

> If you get 100 different users connecting from a single IP, it's probably not someone's home internet connection.

Or, their so-called "smart" TV is acting as a proxy without their informed consent.

▲manquer 5 hours ago | parent | prev | next [-]

Mozilla VPN runs on Mullvad who are transparent and publish active server and IP lists https://mullvad.net/en/servers.so trivial to block them without blocking all of Azure/GCP/AWS[1]

There are also third party providers of IP annotations to classify known VPN address ranges that content providers typically subscribe to blanket block providers.

The reason for this aggressive approach is streaming apps all need your IP as core signal for tagging your region and all content licensing is region locked (even on YT).

Netflix are/were the most relaxed about it , and for long time would only buy content if they got global distribution rights, but not anymore. Many VPN ads specifically used to market that you can watch Netflix geolocked content.

[1] IME they block DC IPs too although not needed for blocking professional VPN, even self hosted OpenVPN on cloud box usually gets flagged.

▲VanTheBrand 13 minutes ago | parent | next [-]

Don’t think there was ever a time since Netflix started streaming where they only licensed global rights to shows. For their own originals they get global rights but the majority of their content is licensed and has always been slightly different in different territories.

▲kevincox 4 hours ago | parent | prev | next [-]

That list is the IPs users connect to. It is entirely distinct from the list of IPs the VPN traffic egresses from. I doubt believe that they publish their egress ranges.

▲buckle8017 3 hours ago | parent [-]

It's almost always in the same /24.

▲ 4 hours ago | parent | prev [-]
[deleted]
▲alnwlsn 5 hours ago | parent | prev [-]

My home internet is on a CGNAT, so I experience a lot of the same. Ironically, sometimes a VPN will get through.

▲semiquaver 3 hours ago | parent | prev | next [-]

Right, all you see is the IP address. And anyone in the world can set up an “individual” VPN just for them on a cheap VPS or cloud server anywhere else in the world. There’s no technical way to accomplish what they’ve mandated, only something approximating it like “block all connections from known commercial VPN services”.

▲ad_fontes 5 hours ago | parent | prev | next [-]

Depends on how you define "reliably". You can get pretty damn close by triangulating on traffic patterns and browser fingerprinting. There is a lot of research in this area. But it'll never be perfect.

▲TeMPOraL 5 hours ago | parent | prev | next [-]

All it would take is for a major ISP in Utah to route everyone through a VPN, and boom, it's the same picture.

▲irenaeus 5 hours ago | parent | next [-]

Yeah but the state of Utah could just tell them to knock it off because they're the state.

▲michaelbuckbee 4 hours ago | parent | prev [-]

Isn't this kind of what Apple's Private Relay is?

▲mahboi 4 hours ago | parent | prev | next [-]

It's hard to find a proxy or VPN that isn't flagged as such. People pay extra for residential proxies.

▲SV_BubbleTime 3 hours ago | parent [-]

I’ve been using different VPNs for years for work. I’m starting to come around to the value of a residential proxy service.

It’s starting to get annoying that things aren’t working. They’re shooting themselves in the foot though.

If they didn’t block VPNs, they would at least know what category to group them in.

▲babelfish 3 hours ago | parent | prev | next [-]

It seems like withdrawing from Utah is the obvious option

▲gwbas1c 3 hours ago | parent | next [-]

That was what the law attempted to do: Ban porn in Utah.

There is a very vocal anti-porn group in Utah. They do things like put up massive billboards that say "[Store name] sells porn." (Which is basically free advertising instead of shaming.)

▲ 3 hours ago | parent | prev [-]
[deleted]
▲greyface- 2 hours ago | parent | prev | next [-]

TCP MSS < 1500 bytes can be a tell, although it will sometimes falsely identify non-"VPN" tunnels.

▲eptcyka 2 hours ago | parent [-]

There are sooo many people out there who are clamped to something far lower than 1500. MTUs below 1280 are not that exotic either.

On the other hand, using Masque for TCP transfers will probably fool a server to believe the MSS is 1500.

▲ 4 hours ago | parent | prev | next [-]
[deleted]
▲LoganDark 2 hours ago | parent | prev | next [-]

> Is it even possible to reliably know that a connection is from a VPN?

No, it's not possible. You can only try to identify known protocols or suspicious patterns of data, timing or entropy. Theoretically, with a big enough collaboration, you could hide a VPN behind shaping traffic patterns and request order towards hundreds of different servers, and there's just no method of traffic analysis that can possibly identify that without prior knowledge.

Like, some firewalls try to identify an absence of connections outside the VPN, or an abnormal volume of data over a sustained period of time. But all that goes out the window when, say, you are connecting to hundreds of real servers at all times and only exchanging, say, basic HTTP requests with each one. For all they know you just have a million browser toolbars installed. They wouldn't know if the choice of request, order and timing encodes information because they wouldn't be able to prove what the client's intentions are in sending it or what the servers do with it.

If you tried to identify it, you would block every real connection.

I believe some VPN providers are beginning to play with things like this, but the problem is really that it's impossible to provide this. It only really works when you run it yourself, because that's the only way others don't know. So they're having to settle for compromises, like Mullvad's DAITA, which still uses a single server but tries to avoid showing tells of a VPN connection as opposed to something else like streaming.

▲codedokode 5 hours ago | parent | prev | next [-]

You do not need to know "reliably". You can block everything remotely suspicious, and in case someone is blocked by mistake, they can file an application with all necessary documentation proving the connection is not a VPN.

▲llama052 5 hours ago | parent [-]

Sounds like the great firewall of China. Pretty wild how much we are regressing in the states to say this out loud.

Let’s block traffic on the internet blindly just in case someone is looking at an adult website.

▲hn_acc1 4 hours ago | parent [-]

Next it will be illegal for anyone to visit an adult website from some states, even with proof of age, kinda like Prohibition..

▲fc417fc802 an hour ago | parent [-]

We should also restrict access to foreign fake news websites that spread destabilizing propaganda. We can include an exception for academics, and thus will require a new accreditation and licensing scheme for them. Naturally we will then want to implement common sense guardrails for their conduct ... /s

▲ranger_danger 5 hours ago | parent | prev | next [-]

Not when the definition of VPN is subjective. I could proxy/VPN through a friend's house and nobody would ever know it wasn't them.

▲EvanAnderson 4 hours ago | parent | next [-]

A lot of law is adjudicated based on the intent, not the black-and-white definition. Proxying your traffic thru a friend's house (VPS in another location, etc) would be considered a "VPN" by a court. Definitional hacks, for the most part, don't fly with judges.

To handle the matter technically Utah would need a "great firewall of Utah" and a legislative mandate that all ISPs route thru it. Somehow they'd have to factor-in signals from cellular sites neighboring states and satellites.

▲irenaeus 5 hours ago | parent | prev | next [-]

This requires a lot of extra work though, and extra work is downward pressure on the behavior (underage people looking at pornography) that the state of Utah is trying to exert downward pressure on.

The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.

▲Rohansi 4 hours ago | parent [-]

> The inability to immediately and perfectly eliminate a behavior is not a good enough reason to be against any attempt to eliminate that behavior.

So if you are legally required to block all VPN users and then fail to actually block all VPN users what is stopping you from being punished for not complying with the law?

▲fc417fc802 an hour ago | parent | next [-]

Common sense on the part of the judge presumably. Best effort and common practice will enter into it. Lots of regulation is like that.

▲mahboi 4 hours ago | parent | prev [-]

Yeah, that's the problem. But if they changed the law to not require all users to be blocked, it'd still have the outcome they want.

▲codedokode 5 hours ago | parent | prev [-]

Yes but isn't it suspicious that all your traffic goes to the friend's house and not to Facebook and Reddit? If you claim it is not a VPN does it mean your friend is providing illegal unlicensed hosting? That's even worse.

▲malfist 5 hours ago | parent | next [-]

> does it mean your friend is providing illegal unlicensed hosting

Since when do you have to pull permits to put a server on the web?

▲iAMkenough 5 hours ago | parent | prev | next [-]

Split tunnel is a thing, and in that instance the platform required to comply (like a porn site) doesn’t have any way to see all your traffic to determine if it’s a VPN/proxy connection or not.

▲codedokode 4 hours ago | parent [-]

If you cannot determine the traffic type, you can block it and wait until someone appears with proper documentation and explains what they were sending.

▲iAMkenough 3 hours ago | parent [-]

That's what the judge agreed with: it's unreasonable to require you to block all Internet traffic with the assumption it's all VPN traffic until proven otherwise.

Under Utah's law as written, a private business has to assume any single IP address could be operating a VPN/proxy.

▲ranger_danger 5 hours ago | parent | prev | next [-]

"Suspicious" is not illegal, and neither is hosting.

▲ 5 hours ago | parent | prev | next [-]
[deleted]
▲zen928 4 hours ago | parent | prev [-]

Why would that be suspicious?

▲gorgoiler 3 hours ago | parent | prev [-]

The classic: ping the endpoint address, then “ping” the code. If the IP address comes back in 30ms but the JavaScript responds in 330ms, then the client is probably 300ms further away than they say they are claiming.

▲zbentley 13 minutes ago | parent [-]

Or they’re on a computer that’s doing something intensive, swapping, or in low power mode. Or they have a browser extension that does stuff before scripts run. Or their cache is emptier than usual and they’re spending a long time doing an initial fetch of the latest ad tracking package your site installed. The list goes on. That’s far too noisy a signal to decide block-or-not based on. Good enough to try to sell someone faster gear, maybe, but not more than that.