Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wouldn't use of VPN bypass their ability to collect my browsing habits?

If difference in cost of service > cost of monthly VPN, this might be an interesting loophole.



Sadly using a VPN for general usage is getting more difficult.

Many sites block traffic from known VPN providers (PCPartPicker.com just leaves an unhelpful message similar to " we are down right now" of you connect over some VPN providers), and sites like Netflix are blocking all VPNs they can in an effort to stop people from watching things outside their region.

I used to run my whole house through a VPN 24/7, but now I need to only turn it on when I know it won't cause issues.


What about data center IPs? A pay-by-the-hour VPS can be cheaper than any VPN service. I've been using one recently and it hasn't been flagged by any site I care about.


I had a bank account locked to the "show up in a branch with id" level for this.


So explain that if it happens again you intend to switch banks.


Not me. I'm very happen when this happens. When it comes to identity, it's far easier to deal with false positive than theft. For example, my credit card gets flagged for fraud every holiday when I go on a gift card purchasing spree. I have no problem with this.


Do you happen to know/would you mind explaining how Netflix detects VPN usage? Is it through timing measurements?


I believe they just keep a list of known VPN IP addresses. (How they get them in the first place I'm not sure).

It's a wackamole game for sure, but its annoying enough to be a problem, especially for the less technical.

I know I can buy my own VPS and tunnel through that, but now that's another machine I need to maintain, secure, and pay for.


> (How they get them in the first place I'm not sure).

I don't work for Netflix or Hulu. But why couldn't staff there just sign up for VPN services, log in, note the IP address(es) in use and then block those?

Buying a monthly subscription to a few VPN providers seems like a cheap and easy way to solve this.

> I know I can buy my own VPS and tunnel through that

It would be pretty easy for a provider to block access from a VPS. Data center providers have well known blocks of IP addresses, which are static, and it's pretty unlikely that there are any actually humans in a data center watching Netflix.

It would be pretty trivial for Netflix to decide to block certain IP ranges they know to be used by VPS providers to prevent this.


I installed openvpn on a server. Netflix still managed to block my access so maybe they are checking patterns or something.


It's also easy to discover and blacklist the IP address ranges of known server providers.


Ahh, that's way less interesting of a mechanism than I thought. Thanks for explaining!


My question would rather be what about https traffic? Are users forced to install a comcast root certificate?


VPN Is heavyweight I just use a Amazon machine and open a ssh tunnel.


That's not nearly as fast as a real VPN client, though. I used to do the same and it just didn't work well. Nowadays I have an ultra-cheap (3€ per YEAR, from lowendspirit) VPS in the US (it doesn't even have a public IPv4, just 20 forwarded ports) on which I run OpenVPN. I also run another OpenVPN server on my primary server which is a 6€ per month root server in France (kimsufi/OVH).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: