Join the discussion

Write your take first — we'll ask for email only when you're ready to publish.

  • Hacker News
  • > In the name of “online safety”, the fundamental rights of both freedom of expression and privacy appear to be under imminent threat.

    The current UK government don't actually care about children, if they did then they would actually investigate the child SA gangs, or holding people to account on the Epstein lists. We have seen other countries such as Australia [1] "magically" have the same idea at the same time, so this is likely a global group influencing this push.

    > The current proposal to ban people under 16 - who also have the rights to freedom of expression and privacy - from some (as yet not fully delineated) social media services is likely to result in wide-spread verification.

    This is the real objective, it will be just like the UK porn verification [2]. To express yourself online, you will soon need to associate your activity with your real identity. With the discussion of clamping down on VPNs, it won't be long before you need to verify your ID just to connect to the internet.

    This has been a long time coming. Years ago you could buy a sim card with money already on it, use it, and then throw it away. Now you need to associate some credit card or ID with the sim card and perform some verification process.

    > And so, for the first time, I am considering locating something (perhaps a WireGuard node, or a SOCKS proxy, or a recursive DNS server / DNS proxy, or perhaps all of them) somewhere on the Internet outside the UK, so that I can route some traffic through that, as needed, to maintain my access to the web.

    It won't be enough. At some point the UK government will just mandate that they should be allowed to perform deep packet inspection, and then there will be nowhere left to hide. These changes are also being rolled out everywhere - which Country do you trust to run your data through?

    I remember the New Zealand Christchurch attack on a mosque, and how multiple governments around the world pressured Facebook to remove it entirely [3]. They were more worried about people seeing and sharing the attack, than the attack itself. The manifesto was entirely banned [4], and people were left entirely dependent on the state to convey a narrative about the attack.

    I have a feeling that this all fell out of the "Christchurch Call" [5]. I don't think this recent push spearheaded by them, but I believe it had a large influence on the efforts now ongoing.

    [1] https://www.bbc.com/news/articles/cwyp9d3ddqyo

    [2] https://www.ofcom.org.uk/online-safety/protecting-children/a...

    [3] https://www.bbc.co.uk/news/business-47620519

    [4] https://www.theguardian.com/world/2019/mar/24/censor-bans-ma...

    [5] https://www.christchurchcall.org/

  • So many of the outrageous things the UK government is doing, which seem most inexplicable, can be explained by one simple principle - successive governments over the last 30 years have turned this nation into a tinderbox, the purpose of the state and the judiciary in particular has become singular in its effort to prevent a spark from igniting the whole thing. Though they will become ever more authoritarian and tyrannical in their efforts, defenders dilemma applies - eventually, inevitably, they will fail and all hell will break loose. Plan accordingly.
  • I agree with everything you have said. I feel so very, very blessed to have had the experience of this world developing that I have had - from my first 300bps BBS connection at probably around age 8 or 9, through 28.8, 56K, ISDN, DSL & up to the gigabit fibre I type this from, I have always from basically from day 1 communicated with other people over a network. It's almost as intrinsic to my being as actual speech at this point. Maybe even more so on many days. But where we are now and headed to, is just so very, very wrong. It's so wrong it shouldn't even need explanation.

    I've seen and experienced all manner of things the state would deem verboten, especially for younger eyes, whether it be the anarchists cookbook sparking my enthusiasm for chemistry and engineering, warez igniting my love of software development or the inescapable porn, memes, and other shit that's filled my screen for decade after decade. I've managed to make it through unscathed, dare I say even somewhat publicly respectable... I'd vote for my kids and any others having my childhood over the toxic stazi-esque nightmare we seem to currently find ourselves in. I LOVED my childhood growing up with the internet, CD-R's, Napster, etc. it inspired me & helped create the life I live today, but now all the kids using tech just look like methed out zombies.

    It's also really funny reflecting on this & realising how very little I ever used or valued anything like Facebook, Instagram, etc. whereas things like BBS's, IRC, Discord, Telegram, etc. with random strangers and some shared interests is where I've always felt at home.

  • From a UK politics perspective I don't really get this.

    New labour certainly have an authoritarian streak. I remember when they tried to introduce ID cards but there was a load of push back. But they are also somewhat friendlier to 'the youf' but this seems squarely aimed at the Daily Mail brigade.

    It just seems like they're trying to out conservative, the Conservatives.

    Maybe I'm trying to make sense out of something that isn't?

  • Been using a VPN on my phone and PC for 20 years. Always use non-UK exit points
    by nly
  • I route a bunch of mine via a proxy server of my own that is hosted outside the EU. This gives me access to Japanese websites and other things.
  • > And so, for the first time, I am considering locating something (perhaps a WireGuard node, or a SOCKS proxy, or a recursive DNS server / DNS proxy, or perhaps all of them) somewhere on the Internet outside the UK, so that I can route some traffic through that, as needed, to maintain my access to the web.

    Good luck, it will probably impossible as admins fed up with AI scraper bots increasingly choose to outright blanket ban anything not being a residential or business line. There's a reason why there are so many "ethically sourced proxies" aka people installing software on their smart TVs and whatnot that comes with an "monetization SDK" by one of the numerous VPN providers. That's the dirty secret behind a lot of the "bypass youtube/netflix/whatever region lock" VPNs.

  • What's dirty about it?
  • The camp who think VPNs and Tor are a solution to government policies feel like disinformation at times.

    VPNs are trivial to ban, the IP space is well known, Wireguard is easily to fingerprint and block.

    It will be a cat and mouse game, if the government looses this they'll simply make it illegal to be caught using a VPN including Tor. Which is on the table.

    The only way this changes is a less crap party, but almost all including Reform are in favour of more censorship.

  • They aren't the solution to bad policy but they are an unfortunately necessary part of regular internet use now.
  • Really?

    https://www.theguardian.com/politics/2025/jul/28/reform-uk-v...

    https://www.msn.com/en-gb/news/uknews/reform-pledges-to-scra...

    https://www.independent.co.uk/news/uk/home-news/nigel-farage...

    Zia Yusuf : "... criticised sections of the legislation that allow ministers to direct regulator Ofcom to modify its rules setting out how companies can comply with requirements to crack down on illegal or harmful content, saying it was “the sort of thing that I think (Chinese president) Xi Jinping himself would blush at the concept of”."

    And the more radical Restore say this:

    https://www.restorebritain.org.uk/restore_civil_liberties

  • I have submitted this before, but for those maybe a bit uncomfortable with setting up a VPS to act as an exit node for Wireguard, my article covers most things:

    https://psyonik.tech/posts/a-guide-for-wireguard-vpn-setup-w...

    For this particular use case, I would probably suggest something like OVH/Scaleway as they have nodes in France so physical distance between UK and "somewhere else" is low which will affect latency. If you're willing to wait longer and go further, I recommend Infomaniak (Switzerland - they have nodes in Geneva I think/Zurich). Hetzner (a crow favorite) hasn't been that good for me while I was in the UK, I was getting dropped packets even after switching a few VPSes, but might've just been something temporary.

  • “The Net interprets censorship as damage and routes around it.”

    -- John Gilmore (probably https://quoteinvestigator.com/2021/07/12/censor/)

  • The problem is that the world is increasingly transitioning from the Internet to regional internet.

    There are companies that have gotten very good at virtual border control while selling stuff to e. g. the chinese and russians that are allegedly in talks with the UK govt.

  • There is no "Net" any more. There probably never was really. The internet protocols were designed for resilience from the start. A key to that is packet-switching over circuit-switching. But this thing we call the "internet" today? This thing where more and more nodes can't even speak directly to each other and nobody even cares (see IPv6)? This thing where 90% of traffic goes to a few large multinationals? It's not that. We have no resistance to censorship.
  • I’m already using policy based routing on UniFi to send OSA censored websites, imgur for example, via Mullvad VPN - it works for the most part, but for any IPv6 websites it completely breaks as UniFi doesn’t support policy based routes for IPv6.

    If the government blocks Mullvad then I’ll just switch to Wireguard on a Helsinki based VPS via Hetzner.

  • are you manually maintaining the list of 'OSA censored' sites? Sounds great, just I'm lazy :')
  • Surely it won't be long before every hyper scalar and even medium sized hosting companies ip address ranges will end up in the block lists for every "questionable" website that is feeling the "chilling effects" from these UK laws?

    I used to run my own mail server back until about 2014 or 2015, end even then it was practically impossible to reliably send mail to any of the major email providers from and ip address from Linda/AWS/Hetzner/DigitalOcean et al. I'm pretty sure porn sites and unmoderated web forum type thing that have lawyers advising them will soon be blocking not just UK ip addresses, but the bulk of the easy to identify VPN services and VPS providers.

  • I've set up a socks5 "proxy multiplexer" that routes requests to different upstream proxies based on the request hostname. For example reddit routes via a VPS in Dublin, and imgur routes via Tor. I believe socks5 is the ideal layer to do the multiplexing at, for web traffic, because the request hostnames are visible to the multiplexer even if ECH/ESNI is in use. It was a oneshot vibecoded solution but it's been pretty solid thus far, so maybe I should open-source it.

    I wrap the outbound sock5 traffic in mTLS, so it should look "normal" to anyone packet sniffing (not obvious proxy/VPN traffic), even though stealthiness isn't part of the threat model at the moment.

  • Please do open source it, I'd be interested in running something similar.
  • For browser traffic another alternative is proxy autoconfig scripts to put the proxy routing logic in JS.
    by lmz
  • Perhaps consider putting it in public domain instead of using an "open source" license?

    There's a decent legal ethical argument that LLM output isn't copyrightable, and for me a "one shot vibe code" definitely _isn't_ "your creative work", so the copyright that open source licenses rely on probably doesn't exist there.

    I wonder if a new category of "non copyrighted shared source code" needs to exist for people who use Gan AUI to create genuinely useful software which would ne a net positive to society if shared, but that doesn't risk murkying the waters and undermining the copyright basis that licenses like GPL and Apache and BSD and MIT rely on?

  • Australia isn't different, but homelab is my jam so solutions were implemented :)

    1. Nginx Proxmox LXC container with domains that require digital ID such as X. I can easily add or remove domains to it via Ansible.

    2. Mullvad VPN server/client setup on OPNSense

    3. OPNSense Firewall rules with aliases from the local lists from step 1

    4. Every time I access X or whatever, OPNSense firewall rule redirects that traffic via the Mullvad VPN Gateway bypassing the digital ID enforcement

    5. I host Pihole + Unbound recursive DNS so I have full control over my DNS. Recursive DNS uses the 13 root nameserver, I do not use public DNS such as Google or whatever, in fact, they are all blocked.

    My data under my control.

  • When I tried implementing something like this at some point, I found it impossible to actually implement reliably because DNS resolution changes all the time.

    Unless you dynamically add rules as you resolve DNS requests and before responding to them, which seems painful to pull off.

    Or do you point DNS records for the relevant domains at a proxy server, and have that server inspect SNI, look up the actual DNS records, and then tunnel the traffic? But this would rely on SNI which isn't a requirement (although it's probably always there...).

  • Side note, I do agree with under 16 being denied access to social media.

    Spend 5 minutes on X, Instagram or even worse Snapchat for you to see what these minors are doing. A lot generation, all for likes.

    GenZ is so cooked, by the time they reach their 30s, damn.

    Gen Alpha being born within the digital and AI world is even more cooked.

  • >I do not use public DNS such as Google or whatever, in fact, they are all blocked.

    Honestly surprised that works given Google loves to hardcode DNS queries using their DNS Resolver into many things (Google TV, Android, etc).

    I'm assuming you are using NAT Redirection (Port 53), blocking DNS over TLS - DoT (TCP Port 853), using SNI FIltering to block DNS Over HTTP (DoH). Not sure how you handle Encrypted Client Hello.

  • I'm considering the same thing. I've done the "contact your MP" thing, but it's a waste of time. You just receive a pre-written letter from some minimum wage assistant (or maybe just a bot).

    It's either that or I just consider the internet dead and move on. It's nothing like it was 20 years ago anyway. There are other things to do. Many books to read and places to go. We had something really cool and we were lucky to experience it while it lasted, but it's gone now.

  • > We had something really cool and we were lucky to experience it while it lasted, but it's gone now.

    You can also recreate a smaller network and enjoy it as a silo, disconnected from the Internet, at times.

    There's no need to be off the grid 24/7 to feel the relief.

    It's deeply relaxing to pull the (Internet) plug (I do, literally, physically remove one ethernet cable from a switch right underneath my monitor and I've then got several machines happily communicating only on the LAN: no more Internet).

    Maybe I'm having fun with my latest acquisition: modelling parts to fix stuff left and right around the house by 3D printing them (I bought a 3D printer for that: I had many things I needed to fix and I knew I'd be able to fix them properly by printing adequate parts). No need for the Internet to model, slice and 3D print.

    Such an activity does feel like the computing of yore: it takes me back to a time when it was me and a 8-bit machine. Creating stuff "by code" (which now take physical form at home, which 11-years old me would have find utterly mindboggling btw).

    > There are other things to do. Many books to read and places to go.

    And hobbies. As a kid from the eighties I love cars from the late 80s/very early 90s: not much electronics, not spying on you. Sure they're a bit of gaz guzzlers but then half the fun is fixing stuff on them and the other half is talking about them with other enthusiasts: there's no need to drive 10 000 kilometers a year with those.

    When you take time to disconnect a bit from the Internet, then I'd say when you're online (like I'm now) it all feels way more tolerable.

    No need to go full luddite IMO but YMMV.

  • >Many books to read and places to go

    You cannot travel into the US without providing access to your Social Media accounts. Pretty likely you get denied if you say "I don't have social media".

  • Depends on your MP. I have received surprisingly detailed responses to some of my past letters.

    If they can't be arsed to answer you, then you shouldn't be arsed to vote for them, at least in my opinion.