Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • Every corporate I know of, uses VPNs. Especially when workers connect from home. Is the UK government really interested in going up against the majority of their business partners...?
  • It would not be hard to write laws to restrict one use but not the other. They may be the same tech but the use-cases are quite different.
  • A lot of corporations use crappy VPN-like MitM services like Zscaler.
  • There is nothing in this article that suggests the UK government are planning to ban VPNs.
  • It's not about a technical capability to encapsulate packets, it's about whether people use it to bypass censorship or not.
  • The government use VPNs. The ban will target individual use.
  • Laws don't apply to corporations. It'll only be used to punish individuals.
  • The great firewall of UK.
  • Hadrian’s Firewall
  • Feel like there ought to be some Sinn Fein backed point to point connection in Belfast that leverages the Good Friday Agreement to get around this.
  • Good thing Brexit happened to prevent government overreach.
  • Better then performing a social experiment on children.
  • Tbf the point was to prevent the EU 'overreach' i.e stopping us violating our own peoples human rights. We can violate them freely now. Success.
  • If you ban IPsec ESP people will start using WireGuard on random ports.

    If you ban WireGuard using DPI people will start using SSL VPNs.

    If you ban SSL you ban the entire internet.

  • They don't want perfection. They want to move things forward, for their definition of forward.

    If they ban bog standard VPNs and find out they're still being used, they'll punish the VPN companies.

    If the VPN companies create workarounds and avoid the punishment, they'll punish the payment processors.

    If the VPN companies start using esoteric workarounds and taking cryptocurrency for payment, then they've mostly won -- most people aren't going to deal with that shit.

    All the while, they'll still go after the social media/etc companies for allowing circumvention of age-gating. So the social media companies will crack down on our ability to visit their sites with any sort of privacy.

    My point: laws are all imperfect but can still have a huge effect. Pointing out work arounds doesn't change that.

    For context, I'm really disturbed by the recent move to punish people seeking privacy instead of the social media companies that are enabling this social media shit. They know who the companies are, since that's who they're going to punish for not age gating. But they'd (I'm talking about US based age-gating pushes as well) rather fuck with our privacy and make our PII more susceptible to data breaches than tell the social media companies to eat shit.

  • bruhghghbmphf, the VPNs! the VPNs! can't have those! What's that good sir? You say ssh? Do not shh me sir. Oh, SSH... yes, SSH, can't have that! It's elementary, any system which one accesses MUST report to parliament. Personally Identifiable Documents for General Evaluation Of Ne'er-do-wells. We'll call it the P.I.D.G.E.O.N. network.
  • It's never about the technical capability of the tool. This is a mistake technologists keep making. It's about what the average person thinks it does or uses it to do.
  • I'm very much in favour of blocking children from social media - it's an absolutely vile cesspit of cognitive addiction, bullying and social (and potential sexual) abuse. But none of it requires a mass-surveillance network to be put in place.

    Just for one example; it would be trivial for Apple and Google to put age estimation on my phone, verify it on opening the web browser and provide a zero-knowledge proof of age to websites in a way that does not reveal my identity. All the infrastructure is already there, and it's relatively trivial to turn it on. The downside is that this will only work for people who are older than about 25 because of the uncertainty of face-to-age recognition, but it would be a start.

    Another way to do it is for my bank, who know my age already, providing a similar credential that I can feed into the zero-knowledge proof engine on the phone.

    This was all done properly for the covid tracking apps, at a time when the phone providers actually wanted to do tracking with anonymity - this is a similar problem, and it's easily cracked by technical means.

    And you don't even need zero knowledge proofs if you perform on-device content detection - turn it on for kids, keep it off for adults. Modern phones have more than enough TPU capacity to do this.

    But none of the actual implementations I've seen are truly anonymizing, and they all rely on trusting some really dodgy companies with your identity and browsing habits. Yes, the more respectable ones have security and privacy policies that are audited, but will they always? The cynical answer is "no", because history shows that someone will always do something sooner or later if (a) it makes money, and (b) they can get away with it.

    Everything I see suggests that the desire for mass surveillance is the driver, and the "protect the children" front on this is a strategem by the people who are really driving this from behind the curtain. There are huge amounts of money to be made by capturing verifiable, blackmailable, personal data, and this is a magic money fountain for those who will be able to mine it.

  • In more sensible times, we'd run an ad campaign highlighting the dangers and informational campaigns for parents on what to do to prevent your children getting access to social media.

    Perfect is impossible, but if its stigmatised then the network effects stop being so punitive to children who have reasonable parents.

    it's the 10-80-10 rule: 10% of kids will still access social media, 10% will never... but 80% can be swayed.

  • In a way, the cack-handed way they've gone about this makes me slightly more optimistic. If we must have such a law, please let it be one which:

    * Creates a market for privacy tech of several million teenagers

    * Wastes police time chasing down social forums which kids are hosting abroad using their pocket money

    * Rubs the noses of the securirati in the fact that they've made it easier for terrorists to hide their comms among the thousands of teenage speakeasies

    This is not the 80's when comms tech required capital and man-years of engineering. Setting up forums online isn't even a high-school project.

    by ajb
  • At least we get to raise the next generation of IT geeks because they'll have to understand a bunch of networking basics to watch porn, and might get hooked on it. (on IT)
  • Israel will be making kill on this, they will unleash their free VPNs to the young people like they did to Iran. UK national security will be like Suisse cheese
  • I am sure a contract with Palantir to find these miscreants is just around the corner.
  • Or they will ask their AI to do that for them, learn very little about the networking stack in the process
  • Some context - Birmingham Mail is one of dozens of clickbait-driven publications owned by Reach plc.

    They're not a high quality source of news - they've more than decimated their journalism staff and replaced them with 'content' staff who are performance monitored on the number of clicks their articles generate.

    Content is syndicated in different accents across their range of papers from the national papers, The Mirror and The Daily Express down into a large number of notionally 'local' outlets.

    So, take it with a pinch of salt.

  • Yeah I've seen similar stories a few times this week and it's always one of the dodgy regional media sites. Shame it's getting so much traction here.
  • The article is based on a direct quote given to the BBC, which you can find the original article here: https://www.bbc.co.uk/news/articles/c9824zvpz9po

    The link is 100% true in this case.

  • I've been using a VPN in the UK on my laptop and phone exclusively for 20 years, and the state has been working with ISPs to make "connection records" for most of that time.

    On mobile a VPN isn't always effective in avoid geoblocks. Some apps are able to determine I'm in the UK and still ask for ID - reddit is one for example, if you stumble on to an adult subreddit. Using the web interface avoids this.

    The UK has also moved to force ISPs to block certain bittorrent search engines.

    The UK is not shy when it comes to invading your privacy or censoring the Internet.

    by nly
  • Mobile browsing should be considered high risk for most users except for the most mundane activities.
  • Company like this exist

    https://www.geocomply.com/