this post was submitted on 10 Nov 2023
100 points (99.0% liked)

Privacy

32506 readers
978 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

I use ProtonVPN for everything, and I've started noticing more and more sites simply blocking me if I try to connect to them through ProtonVPN. As much as it sucks, I've more or less become acclimated to having to deal with an increased number of captchas while using a VPN; but I'm pretty angry about being blocked outright. There are at least two broad blocking tactics. First, some sites will say that my network traffic looks suspicious and/or that they simply block traffic from certain IP addresses. But second, and far more maddeningly, some sites tell me that my username and password combo are incorrect when I'm using a VPN. But I know this to be a blatant lie because (1) I use a password manager that auto-fills login forms with credentials that match the domain name, and (2) such sites accept my credentials when I visit them without the VPN connection.

What the hell can we do about this shit? Do I have to run my own VPN to avoid sharing an IP address with other people and thus getting blocked? I really don't want to do that because I have neither the time nor expertise, and I like that connecting through a VPN provider makes my IP address much less significant. I'm aware that this is connected to the broader conversation about WEI and other methods for determining whether requests are legitimate or not, and I'm sure that businesses of all sizes are reeling from massive increases in bot and AI activity. But solutions that end up punishing legitimate users are not good or valid solutions.

all 36 comments
sorted by: hot top controversial new old
[–] [email protected] 38 points 1 year ago (2 children)

far more maddeningly, some sites tell me that my username and password combo are incorrect when I’m using a VPN

[–] [email protected] 2 points 1 year ago

Tbf, the banks knows your information is correct and you're using a vpn.

This is the banks way of saying " hey jackass turn off your VPN and come back..."

I suspect many people who run vpns full time, constantly forget to turn them off....

[–] [email protected] 26 points 1 year ago (1 children)

That's an inherent problem with shared connections.

The thing with sites telling you that your login is incorrect is also sometimes intentional, so people trying to brute-force logins won't realize they're getting blocked or just that their attempt was incorrect.

And yes, the only possibility is to try a different server that hasn't been abused, or run your own.

[–] [email protected] 3 points 1 year ago

This is what 2FA is for

[–] [email protected] 17 points 1 year ago

The real solution is to avoid these sites when possible

But this practice tells you what we all needed to know... They won't serve u unless they can track you.

Vote with us feet cattle

[–] [email protected] 15 points 1 year ago (1 children)

We need laws that prevent companies from discriminating by how you look. Websites should only be able to deny customers based on how they act. A simple innocent GET from a user with a VPN IP should not be legally permissible reason to deny them.

[–] [email protected] 1 points 1 year ago (2 children)

That thing where they claim the username/password combo is wrong?

That sounds like a really good idea if the site thinks the reason they're a lot of different lock-on attemps from that one ip is because its a hacker with a list of stolen credentials.

Basically just tell them their list is fake and "go away and stop bothering our customers, please."

[–] [email protected] 1 points 1 year ago

I've had this exact scenario happen with my Amazon account. One the one hand its annoying, but on the other I don't want them to make it easier for someone in another country to order stuff using my account and credit card.

[–] [email protected] 0 points 1 year ago (2 children)

Thats not a good idea because these systems false-positive all the time.

If my first login attempt has the correct username, correct password, and correct totp token, then I should always be let in. That's literally how auth works.

[–] [email protected] 3 points 1 year ago

Yes! 100% agree with this and your law proposal!

[–] [email protected] 1 points 1 year ago

You're right!

(Still think they might be doing just that, some of them.)

[–] [email protected] 15 points 1 year ago (3 children)

This is extra maddening with my banking app recently. I even set up split tunneling for it, but it still somehow figures out the VPN. The problem is, it doesn't let me do ATM withdrawals nor generate one-time virtual cards. Ironically, it still let's me view full details of my physical card...

So just disconnect from VPN? Oh, not so fast. It remembers that VPN was used at some point, and I'll have to deactivate the app and then reactivate it without ever connecting to VPN.
Since I have to deactivate and reactivate it daily, immediately when needed, this has led me to decreasing the security by using virtual card reader for 2FA kept on same device as opposed to using physical one and keeping it at home as I used to before this BS.

This is what I mean by the physical 2FA card reader:

Yes, that's the only thing at hand I had to cover the card number :)

[–] Sanguine 10 points 1 year ago

Lmfao at the arch sticker. Also use arch btw.

[–] [email protected] 2 points 1 year ago (1 children)

Just make another user profile and dont put a vpn on it (assuming android)

Also it still knows you're using vpn because split tunnel still uses the VPN provider's DNS server, so sounds like they are also checking who you DNS provider is.

They sound like complete scumbags. Switch banks lol.

[–] [email protected] 1 points 1 year ago (1 children)

I use NextDNS. That's also used when I am connected to VPN. It seems to not be the problem. Maybe some Android service it talks with, I don't know.

Unfortunately, MIUI disabled the multi-user option for some reason.

[–] [email protected] 1 points 1 year ago (1 children)

You desperately need to use a custom rom. You have virtually zero mobile privacy until you do

[–] [email protected] 1 points 1 year ago (1 children)

I know. Especially after the last motherboard replacement. It used to run EUXM version, but now it runs MIXM. EUXM is version for EEA, and it has to comply with stuff like GDPR, so you get (optional) prompts for consent on data processing everywhere. Well, MIXM is the global variant, and this simply doesn't exist.

Anyway, I don't want to void my warranty by flashing custom ROM. After all, this phone already had not 1, but 2 in-warranty motherboard replacements, and there's still time (6 months) for more.
Poco X3 Pro's motherboard has it coming from both software and hardware. From software side, MIUI updates have high chance of hard-bricking the MOBO. From hardware side, the CPU has issues with cooking itself to death.

Yeah...

[–] [email protected] 2 points 1 year ago

damn bro. you've been through the wringer. just simplify your life and get a new phone. Pixel 6a for Graphene maybe.

[–] [email protected] 2 points 1 year ago

Oof. That really sucks.

[–] [email protected] 14 points 1 year ago (2 children)

Proton VPN advised me to switch to a different server when one is blocked by a website. That usually works for me. I haven't had the username and password problem though. I think the only sites I've had to turn my VPN off for were credit reference agencies.

[–] [email protected] 3 points 1 year ago

This has been working for me. Sometimes it's just the country I randomly connected to and need to pick another random one.

[–] [email protected] 12 points 1 year ago (3 children)

I don't know if it even works, but have you considered relying on their Stealth protocol? While its absence on Linux ~(and~ ~Windows)~ means that you might not even be able to make use of it in the first place, I'm still interested to know if it makes any difference.

[–] [email protected] 20 points 1 year ago* (last edited 1 year ago)
[–] [email protected] 6 points 1 year ago

Oh, this is great! I didn't know about the Stealth protocol. It's helped me log into at least one previously stubborn site! Thanks for sharing! 💯

[–] [email protected] 2 points 1 year ago (1 children)

While its absence on Linux (and Windows) means that you might not even be able to make use of it in the first place...

Welp, time to run a proxy server on your phone.
In Termux there's 4 as far as I am aware. Squid, polipo, privoxy and tinyproxy. I use tinyproxy because it's pretty simple to set up. Just check the man page.
Alternatively there's app called "Android proxy server" in Google Play Store, which is the simplest solution

If you decide to use basic authentication, keep in mind that it's not encrypted. It's transported in base64. So definitely don't reuse passwords, as if you should do that otherwise anyway. If you really don't want someone else to connect to it, just leave it on localhost and use SSH tunnel.

[–] taladar 2 points 1 year ago (1 children)

If you decide to use basic authentication, keep in mind that it’s not encrypted. It’s transported in base64.

You should be using https anyway so that should not matter.

[–] [email protected] 1 points 1 year ago

I am talking about basic authentication to HTTP proxy. Useful on multi-user LAN networks.

[–] [email protected] 7 points 1 year ago* (last edited 1 year ago)

You can't hide behind a VPN and access the entirety of the net. There will always be some site that will block you. It's just par for the course. Unwinnable battle.

[–] [email protected] 4 points 1 year ago

I use a Firefox container tied to a socks proxy on my router to bypass VPN for tricky sites. Yeah I know not the answer you're looking for but some things have to be done (banking, health insurance) and if they already know my home address there's little reason to hide the IP address

[–] [email protected] 2 points 1 year ago

Solution: run your own VPN on a VPS. Write a configuration file/script to rotate IPs/machines so you're not stuck on one IP all the time.

Vultr and DO have hourly pricing and a good API for one to do so

[–] [email protected] 2 points 1 year ago

We wouldn't need VPNs in the first place (for the modern use cases) except that security and IT guys started blocking or limiting content based on user IP address.

That needs to stop entirely, it's a defective feel good security measure that is easily defeated by an attacker willing to spend a few bucks for a new IP.

Fortunately VPN tech is very flexible, so there are ways to get yourself a dedicated IP that nobody else can use, solving the problem and defeating those IT guys.

[–] [email protected] 0 points 1 year ago (1 children)

Chain your vpn to another VPN that actually uses real domestic client IP's then u just look like a normal user to webstites

[–] [email protected] 3 points 1 year ago (1 children)

Which VPN providers use domestic client IPs?

[–] [email protected] 3 points 1 year ago

the every expensive botnet type