17 comments

  • xoa 1 hour ago
    This is a very brief blog blurb linking the original Tech Radar article that got fairly extensive discussion on HN a week and a half ago [0]. Potentially quite an important one though so a second go around may still be very justified for those who missed it last time. Amidst a lot of negative moves around the net recently it's nice to see some sanity at least once in awhile.

    ----

    0: https://news.ycombinator.com/item?id=48997221

    • traceroute66 1 hour ago
      Yeah, please could everyone not pile in and start re-hashing the extensive comments that have already been made only a week and a half ago.

      Whatever you're thinking of posting has almost certainly already been said more than once on the original HN discussion.

      • wlesieutre 8 minutes ago
        Is this StackOverflow now, where it's forbidden to discuss something if someone else had a similar discussion before?
      • alias_neo 48 minutes ago
        Perhaps people missed that, and would like to start a new discussion?

        It didn't know there was a quota on discussions of any particular topic, perhaps we should give out tickets to the event in the future to ensure no-one misses their opportunity to join the discourse?

      • kthartic 4 minutes ago
        Very odd take. Let's not discourage open discussion. I've not seen whatever original HN thread you're referring to.
      • dpoloncsak 22 minutes ago
        Yeah I'd hate for multiple comments re-hashing the exact same comments that people already made before, but sometimes there's value in it...I'm sure you'd agree?

        https://news.ycombinator.com/item?id=49109440#49109857

        Is it even preferable to necro an 8-day old topic? New developments are going to lead to new talking points, right?

      • stronglikedan 51 minutes ago
        Gatekeeping through the voting system is preferable to gatekeeping by random comments, if you feel you must gatekeep.
      • shevy-java 50 minutes ago
        With due the greatest respect: it is not up to you to decide on what others deem worthy of commenting or not.
      • Forgeties79 30 minutes ago
        Let’s dig through your comment history and apply the same standard.
  • Bender 1 hour ago
    If I were a governmental body I would do everything I could to keep citizens using paid VPN's and big CDN's. Money trails are easy to follow and the majority of people are just paying with their bank. It makes people feel safe and more likely to expose certain behaviors. Paid VPN's can say they do not have logs whilst having real time lawful intercept API's. A handful of VPN providers become a one stop shop to get the data of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions just as a few big DNS over HTTPS providers become a one stop shop to get the DNS of what used to be hundreds or thousands of ISP's all over the world in many jurisdictions.

    Ban VPN's and people will fall back to the myriad of open source alternatives that can be a bit harder to peel back and get logs assuming any exist in the first place. This was a thing some time ago. Many of the malware and pirate groups were sharing Tinc meshes though as expected there would at times be one person in the group that would be the weakest link and expose the entire group. Expand the numbers of people doing this and the probability of a few groups using decent operational security will increase. This probably deserves it's own write-up.

    • trvz 1 hour ago
      Most of the big VPN companies known from advertisments all over the internet are probably honeypots of the usual countries.
      • inigyou 23 minutes ago
        Not probably - most of them are confirmed.
      • AmazingTurtle 13 minutes ago
        coughs in agressive nord vpn ads
      • sparkling 42 minutes ago
        Add to that that half of these companies are registered in obscure offshore locations where it is practically impossible to even find out who are the ultimate owners.
      • red-iron-pine 51 minutes ago
        if you didn't roll it yourself you need to assume that someone is snooping on you

        maybe mullvad is legit but their leadership keeps leaning to dubious causes

        • Bender 31 minutes ago
          No need to roll your own. There are many open source VPN's, proxies and much more. When dozens, hundreds or thousands of people share and forward load balance their traffic across hundreds of self hosted networks it gets a lot harder to perform attestation and attribution. The reason to cycle through many VPN/proxy networks would be the assumption that a percentage of them are vigilante owned and operated.

          That's the easy part. The harder part is to encourage people to be fearless, keep their mouth shut and let their lawyers do all the talking.

          • pluto_modadic 3 minutes ago
            by rolling your own they don't mean write a VPN from scratch, but host a VPN on a VPS.
        • mrln 20 minutes ago
          What do you mean with "leaning to dubious causes?" I was under the impression mullvad was fine.
        • inigyou 23 minutes ago
          If you did roll it yourself, you definitely aren't anonymous because there is only one user of the VPN IP address.
        • adrianN 41 minutes ago
          The point of VPNs often is hiding in the mass. Rolling your own kind of defeats that purpose.
          • sparkling 36 minutes ago
            Even very basic browser fingerprinting will still identify you. The IP address is just one of many data points.
            • lkjdsklf 23 minutes ago
              The point isn’t to hide yourself from the destination.

              It’s to hide along the journey there.

            • adrianN 29 minutes ago
              Fingerprinting is usually insufficient for law enforcement.
    • shevy-java 48 minutes ago
      Interesting theory. My own theory is that the big corporations want to siphon off more data from people. That is, I think, the main agenda. See android recently stating that everyone has to give up their age. Next step will be ID (though probably, in order to verify the age, one has to give up the ID anyway, so age sniffing could be called ID sniffing).
      • Bender 16 minutes ago
        For what it's worth, two or more things can be true or even partially true. I think all options should be on the table to discuss potential mitigations. Incentives and incentive driven laws can be difficult to prove out. Probably best to just find mitigating options and controls.
      • lkjdsklf 22 minutes ago
        The age thing is because of laws mandating it
  • lII1lIlI11ll 45 minutes ago
    This looks like a very narrow ruling regarding copyright. It doesn't guarantee that EU bureaucrats won't try to ban VPNs that don't verify user age (for starters to make NPCs support the bans, then they will inevitably attempt to enforce some kind of KYC or logging to "catch terrorists and pedos".)
    • inigyou 20 minutes ago
      In fact this makes it more likely. Now that a court has ruled that current copyright law does not make a VPN provider liable, the European Council (all heads of state of European countries) will propose a law that makes VPN providers liable for copyright-infringing traffic
  • HelloUsername 1 hour ago
    Discussion on 21-jul-2026 https://news.ycombinator.com/item?id=48997221 141 comments
    • traceroute66 1 hour ago
      Yeah.

      In particular for "hot" topics like this people should use the search function at the bottom of every HN page before rushing into post.

      The last thing everyone needs is yet another duplicate post with hundreds of comments re-hashing the exact same comments that people already made before. It is not helpful for anyone.

  • ibejoeb 48 minutes ago
    > VPNs in particular have been tossed around as something that the UK government would like to ban (citation needed/lacking!)

    It was widely covered (like at https://www.express.co.uk/news/uk/2217934/vpn-ban-table-july...) and tech sec. Liz Kendall is on the record with BBC talking about July.

  • Arshad-Talpur 56 minutes ago
    First question that need to asked from everyone including ownself , why you need VPN?
    • mnahkies 41 minutes ago
      Primary use I have for it is hosting internal services that I don't want on the public internet - do the same at work, it reduces the attack surface hugely
      • Arshad-Talpur 17 minutes ago
        That is the exact thing , I asked that because its primary a personal choice, and I support EU regulator decision on it, If you need VPN for usage like keeping your personal information intact its perfect but if someone else is using for other purpose then again it should personal choice rather than government regulation ( this might not sound good to some).
      • fl4regun 37 minutes ago
        I know what you mean, but I think most people are not thinking of it in this way. They are thinking of VPN as a service provided by companies such as Nord VPN, and mostly used to get around region locked content or keep your ISP from being aware you are downloading things you shouldn't be.
    • inigyou 17 minutes ago
      Bypassing censorship is the biggest one. No, they don't work on Netflix. But they work on many things.
    • Jtarii 43 minutes ago
      https://femboy.beauty/P1iUdl

      You must be blessed to live in a country that has no website blocks.

    • Cider9986 19 minutes ago
      Privacy from ISP

      Bypass censorship

      Get treated the same by websites when traveling

      Avoid bad laws

      Gain good laws

      • Arshad-Talpur 16 minutes ago
        Answers are there ! that was the whole point of my question, using or not using should be Personal choice not government Ban , everything on internet has pros and cons.
    • stronglikedan 49 minutes ago
      Is that really a question that needs to be asked in 2026?
    • superkuh 33 minutes ago
      My ISP Comcast (rebranded to Xfinity to avoid all the negative associations with it's actual name) does man in the middle attacks on HTTP connections and injects javascript code into webpages. I actually had this happen to the steam browser back in ~2013 and I had to restart it. But they still do it today in 2026. I don't use a commercial VPN because I host from home. But I do tunnel my HTTP browsing to a remote VPS I rent.
    • KPGv2 53 minutes ago
      I just loaded up Bluesky this morning to discover it demanding proof of my age bc I live in Texas. First thing I did was turn on my out-of-state vpn and try again. not today, satan!
      • zabriel_goss 42 minutes ago
        FYI, this recently changed to only apply to the mobile app. Browser access and 3rd party apps are not restricted.
      • mmooss 25 minutes ago
        Instead of an out-of-state vpn, why not an out-of-state home? Why do people put up with the lack of freedom there? People complain about European countries but then praise states like Texas.

        (Realistically, moving is easier said than done, of course.)

        • Cider9986 17 minutes ago
          A VPN is 5 dollars. People are not as privileged as you assume and very few chose their location based on age verification laws.

          European countries have restrictions on freedom of speech which is a strongly held value in America.

    • dncornholio 42 minutes ago
      To bypass geo-locked content and age restrictions of course. What else???
  • freedomben 1 hour ago
    VPNs are just tools that sketchy people use for sketchy means. There's no legitimate use for someone who isn't trying to break the law. Allowing these tools let's underage people access porn, and do all manner of undesirable behaviors like accessing region locked content.

    I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites.

    There are of course some people on the other side who think VPNs are a guarantee of privacy and secrecy on the internet, but that's pretty rare in my anecdatal experience. I largely blame the rampant ads on podcasts for this view.

    • yreg 1 hour ago
      Probably should have put a `>` before the first paragraph, because it reads like an 8/8 bait and most people won't continue to the next one.

      Regarding the misleading podcast claims, at least all the podcast and youtube ads made the VPNs popular on the mass market so now they are more difficult to be silently outlawed.

      • freedomben 33 minutes ago
        Oops yes, definitely should have done that. Looks like it's too late to edit though
        • yreg 1 minute ago
          Haha, if it wasn't even on purpose that makes it more funny.

          Your comment was even dead for a while, before I (and others?) vouched for it.

      • jaapz 1 hour ago
        A whole thread could have been prevented with " and ", haha
      • Narishma 1 hour ago
        Putting a '>' would make it look like it's a quote from the article, which it isn't.
        • yreg 1 hour ago
          Well yeah, it's a strawman, but not unattached to reality.
      • lightningdev1 1 hour ago
        Lol your comment made me do a double take, I had stopped reading after the first sentence
    • jerf 42 minutes ago
      I think an issue VPNs face is that while your first paragraph is not objectively true, it ends up being truer than I might like because the other use cases are not well covered. If you've got one of the things the HN gestalt would call a non-sketchy use case, you've also got the problem that it's rather hard to verify that any VPN you are using actually fulfills your goals. They can say they do, but you have a very hard time proving it.

      On my current fiber provider, I'm already behind a very large CGNAT install. To a large degree, de facto that's already a lot of the "non-sketchy" use cases for VPN covered for me. IP addresses are already one of the weaker signals for tracking people as it is. Mobile networks have been letting you shift IPs for years just by how they work. Other internet providers that don't slap thousands of people at a crack behind one IPv4 with CGNAT didn't necessarily guarantee stable IP addresses, hence the need for dynamic DNS for decades.

      The hole VPNs plug is necessary, but not even remotely sufficient if you are trying to actually protect yourself from some attack. Slapping a default Windows 11 install on a VPN to a first approximation protects you from nothing.

      And since the "non-sketchy" uses are rather dubious, that really does sort of leave just the sketchy ones. I don't think it's a coincidence that when they pay a YouTuber to advertise them, the YouTuber generally ends up talking vaguely about the protections but fairly concretely about the sketchy uses, with screen shots showing them using Netflix in a different country. The companies know what they're getting used for and what they can provide.

    • 1718627440 1 hour ago
      Logging into my work computer, to work in the company network: yeah very sketchy.
      • inigyou 20 minutes ago
        That isn't the one they're banning. The law isn't as autistic as nerds think it is.
    • chmod775 1 hour ago
      Many people reading this are going to stop at the first sentence without realizing you're paraphrasing a position you apparently don't agree with.
      • idonotknowwhy 1 hour ago
        That's amazing. I didn't even realize but it seems I read the first paragraph and the last sentence, concluded "moron" and scrolled down.

        It's only because of your comment that I re-read the their post.

      • 1718627440 1 hour ago
        What is the sign, that he does not?
        • yreg 1 hour ago
          "I have actually heard otherwise intelligent people say things just like that"

          Meaning the poster finds it surprising that intelligent site operators would honestly think that.

          • 1718627440 1 hour ago
            Or saying that his view is also shared by people he considers intelligent, and thus can only be rejected by others, who first need to proof to him, that they are actually intelligent. Aka. an indirect ad hominem.
            • bee_rider 1 hour ago
              If the poster agreed with the opinion, they wouldn’t have included “actually” (indicating that they think the reader will be feeling incredulous at that point) and “otherwise intelligent.”
              • freedomben 31 minutes ago
                Yes correct, I vehemently disagree with people who say things like the first paragraph. I definitely should have been more clear that that was not my opinion, but it's too late to edit now
                • bee_rider 18 minutes ago
                  Eh, I think I disagree. We should support a convention of reading all of the paragraphs to the posts we are responding to, not just the first one.
    • dzink 1 hour ago
      VPN is what a smart person uses when they are at an internet cafe or somewhere else with public internet where you can’t trust that the traffic isn’t sniffed by someone for giggles and your bank credentials are going to leak.
      • cbg0 1 hour ago
        How would your banking credentials leak? Every banking app uses encryption. In fact, I'd wager every app uses encryption nowadays.
        • dzink 48 minutes ago
          Let’s say a hacker hooks up the hotel internet to a firewalla and opens a free wifi spot. You log in and it sees from your traffic that you’re a customer of ABC bank and Gmail and ATT from the traffic - next thing you know you get a text message from your “bank” that someone has stolen your credentials in “XYZ Arizona” and you have yourself a phishing attack. The exposure scenarios are only limited by the imagination of humans and modern LLMs.
          • cbg0 39 minutes ago
            This doesn't seem novel in any way, given the amount of data available online you can already be targeted by fake bank texts, no need for the free wifi hotspot.
        • dorkypunk 42 minutes ago
          I've also argued this on the past, it just seems redundant, but people eat the VPN ads like they were gospel.
        • kenniskrag 51 minutes ago
          I just use my home router as VPN to not care if the 100 apps om my phone have a working encryption. I also use it to access my home services so that they are not exposed to the internet. I also use it to limit exposure on my VMs on a cloud hoster.
        • kmeisthax 49 minutes ago
          Not only that, but the iOS and Android APIs for HTTP requests make it really difficult to accidentally use unencrypted HTTP:

          * By default, only secure connections are allowed

          * You have to enumerate allowed exceptions to this policy in your app manifest XML / Info.plist

          * Exceptions are only permitted for specific use cases where mandatory encryption is infeasible, like browsers, podcast players, embedded device clients (which will also require the local network access permission), etc. If you're shipping a banking app and you exempt your own site from encryption, App Review will tear you a new one.

      • Group_B 1 hour ago
        thats why we have https and certs. VPN is redundant
        • f6v 1 hour ago
          Redundancy is not detrimental to security and privacy. On the contrary, having more layers would protect you in case one of them fails (zero-day, bugs, etc.)
          • streetfighter64 59 minutes ago
            If there's a zero-day in TLS there would be a huge amount of problems that a VPN wouldn't protect you against. Even if you're using a VPN (or just a trusted ISP from your home), as soon as your data leaves their hands it would be vulnerable.

            Like, suppose I want to send a physical letter to my bank. I can either ensure it can't be opened (using TLS), or I can get a trusted mailman to bring it to the mail central (using a VPN or trused ISP), but only one of those measures are going to protect me against a malicious mailman carrying it from the mail central to the bank.

            • bee_rider 12 minutes ago
              I’d expect the mail carrier who goes from the mail center to the bank to be slightly more trustworthy than the one who visits me off in the middle of nowhere. Or at least, if that carrier is untrustworthy, it is a big problem for a lot of rich people who have the time and money to think about this sort of stuff.
      • Hikikomori 1 hour ago
        TLS exists.
    • PetitPrince 1 hour ago
      Meta: your first paragraph could really use a quotation indicator / mark. I suspect it was intentional: the ragebait was very effective on me before reading the rest of your comment (I was ready for defend my usage of tailscale to access my iot stuff).
    • bee_rider 57 minutes ago
      I want to applaud your choice to not include anything like quotes here. That would be misleading because it isn’t an actual literal quote. And, we’re too used to just skimming posts here before jumping right in to argue against them.
    • outime 1 hour ago
      >I have actually heard otherwise intelligent people say things just like that, including site operators who run nontrivial websites

      This is an illusion we really need to remove from our collective consciousness. Running a popular website while being an ops genius, being a neurosurgeon who saves lives every day or being the world's best architect doesn't mean someone has sound opinions on topics right outside their area of expertise.

      In fact, nowadays it seems to be all about appeals to authority which IMHO makes us more ignorant because many people seem to not think critically anymore. Instead, it's just "an expert said so" - then you look into the "expert" and in many cases they either aren't actually an expert or they're a paid shill. But that's a topic for some other day.

    • quietfox 1 hour ago
      This is going to get some interesting responses by people commenting immediately after only reading the first paragraph.
    • f6v 1 hour ago
      > Allowing these tools let's underage people access porn

      You can't imagine how much crime I committed in my teenage years. You don't wanna end up like me, punks! Stay off that crap!

    • xpct 54 minutes ago
      I wanted to respond with something of substance (I still don't understand if it was a paraphrase or not) but every reply here is a meta reply, so hello to all fellow meta reply guys.
    • dec0dedab0de 1 hour ago
      Region locking content is the undesirable behavior. Accessing it is very desirable.
    • sharperguy 1 hour ago
      I'm genuinely considering whether the people replying to you are bots now.
      • idonotknowwhy 1 hour ago
        Bots wouldn't miss the middle paragraph.
    • wongarsu 1 hour ago
      Maybe put some quotes around that first paragraph. Seems like some people downvote you before they get to the part where you reveal you don't think that way
    • Markoff 1 hour ago
      flagged for intentional ragebait, if this wasn't ragebait you would have used quotes
    • testfrequency 1 hour ago
      TIL every corp in the world are sketchy people for using VPN.
      • inigyou 18 minutes ago
        That isn't what they're banning, and you know it.
    • asdfsa32 1 hour ago
      This is the must absurd take possible. Most business use VPNs for their day to day operations.
      • MSFT_Edging 1 hour ago
        I think you need to read the second sentence.
        • 1718627440 1 hour ago
          His whole comment contains a view, that some people, including elected officials hold. I don't see an aspect, that actually hints, that he means that in a sarcastic way(, besides that he is on HN).
          • tiagod 11 minutes ago
            You guys really need to finish reading the comments before you reply...
          • mulr00ney 1 hour ago
            "I have actually heard otherwise intelligent people say things just like that" I think that is the indicator.
        • NotHereNotThere 1 hour ago
          His second sentence is "There's no legitimate use for someone who isn't trying to break the law."

          I'm not trying to break the law, I use it for my corporate usage, therefore it is legitimate use.

          What are you trying to say?

          • f6v 1 hour ago
            I think they're trying to say you need to read the whole comment before taking it apart.
          • latexr 1 hour ago
            > What are you trying to say?

            Pretty sure they meant “second paragraph” instead of “second sentence”.

            • MSFT_Edging 1 hour ago
              Yeah, basically. To me it sounded like he was doing a sarcastic quote, then shutting that opinion down.
    • cyanydeez 1 hour ago
      yes, assuming your laws are like "Only blue eyed males are allowed to have internet"
    • sajithdilshan 1 hour ago
      This is the dumbest thing I've read in a while
      • anon48293 1 hour ago
        You didn’t manage to read the entire comment, did you?
        • soco 41 minutes ago
          "You don't have to eat the whole egg to know that it is rotten." (G. B. Shaw)
    • croes 1 hour ago
      How do you think you can work from home with a VPN for access of the companies network?

      Edit: missed the second paragraph

  • raychis 44 minutes ago
    Hurray and good. A technology shouldn’t be treated as unlawful simply because it can be used to bypass restrictions. Restrictions which are stupid in the first place in the majority.

    I hope VPNs are not becoming the next battleground between online safety and civil liberties. I'm sick of the current ongoing attacks on civil liberties in the Western World under the fake veil of online safety.

  • m00dy 42 minutes ago
    You can't do much with VPNs these days, almost any website now has antibot systems and it's actually kid's play to detect whether you are on VPN or not.
    • inigyou 16 minutes ago
      You can do a lot. Cloudflare doesn't want to ban all VPNs, not yet.
    • Cider9986 17 minutes ago
      Can't do much without a VPN, it's scary out there.
    • sparkling 37 minutes ago
      Jup, if you are using any mainstream VPN provider (the ones shilled on every tech YouTube channel) or anything that results in a datacenter IP, it is trivial to discover and block.

      The detection tech has been around forever: https://focsec.com/

  • ChrisArchitect 44 minutes ago
    Week old post OP;

    [dupe] Discussion on source: https://news.ycombinator.com/item?id=48997221

  • ofou 1 hour ago
    privacy is a right, until you don't have a voice to say so.
  • shevy-java 51 minutes ago
    There is a big discrepancy here. EU courts babble about lawful xyz. While they are doing so, national legislation goes downhill, e. g. mandatory age sniffing and other restrictions to come (I claim the age sniffing will come on the OS level, Google recently announced Android will do so, so you can already see the corporate agenda being pushed into democracies here). So I consider the EU courts to just act as decoy, aka "look how everything is legal". Well, a few years later, VPN will be banned. And the EU courts will be in agreement with that.

    It's a step-by-step strategy.

    • OKRainbowKid 46 minutes ago
      Are you implying the EU court is (secretly) cooperating with national legislative bodies to implement surveillance tools while pretending to uphold civil liberties?
      • inigyou 16 minutes ago
        The EU court is just saying the law currently doesn't make them liable. I assume this oversight will be rectified quickly.
  • dana321 56 minutes ago
    The UK government recently said it was not going to ban VPNs

    https://www.independent.co.uk/extras/indybest/gadgets-tech/v...

  • creatacc 1 hour ago
    I don't connect to internet without VPN nowdays. Too much tracking today.
    • cbg0 1 hour ago
      Why is something like ublock origin not enough for your needs? Is it more about the principle of not wanting to share any fingerprint across the Internet, or some specific tracking concern?
      • Cider9986 15 minutes ago
        uBlock origin is not effective at preventing tracking without changing IP address and using an anti - fingerprint browser like Mullvad's.
      • HelloUsername 1 hour ago
        Your webbrowser is not the only application connected to the internet
      • idonotknowwhy 1 hour ago
        Server side tracking.
    • idonotknowwhy 1 hour ago
      How are you not blocked by banking, shopping, even sometimes google search?
      • Cider9986 13 minutes ago
        Just change servers. Never had a problem with any of those and I have a VPN on my router covering all devices.

        Use Brave search instead, Google search has terrible a privacy policy.

      • piyuv 1 hour ago
        There are inconveniences, but some protection is better than no protection. Trying to protect your privacy online is not a zero-sum game.
  • egorthinks 55 minutes ago
    [dead]
  • helloakariq 1 hour ago
    [dead]
  • wseadowntown 44 minutes ago
    [dead]