Sorry, but you are wrong.
It's a 15 minutes task for good admin to start dropping VPN connections (not to block, but to interrupt every 5 minutes, but blocking is even easier).
One important info:
- ISP can't see your VPN traffic. But they can see that you are connecting to specific IP (VPN service's IP) at specific port. Once you're connected to VPN you probably pass ALL the connection through it. So ISP can see only single connection to single point. That is more than enough.
So how can they block VPNs:
1) Most VPNs uses standard VPN ports. Just dropping connections to that port is a good start.
2) Dropping connections to a servers when this is your (almost) only, long standing connection. This is a good moment to store that IP as VPN service IP.
3) Reverse DNS on IPs you're connecting to. A lot of services will reveal that they belongs to VPN services.
4) Public list of VPN IPs. Some provides them. Some are already noted somewhere on the internet.
ISPs can even share their databases with each other to be better at VPN dropping.
This is very easy thing to do.
It would be REALLY hard to hide your connection to a VPN service. One thing that came to my mind, to hide your VPN servers you would have to:
- use VPN services at random ports
- change VPN IP every few minutes at random factor, so dropped connections will occur anyway
- in the background you should keep direct (un-VPNed) connections to random servers at random ports, passing random data around (it will look encrypted just like VPN connection)
This would require huge infrastructure though. Really huge.
But still - if ISP notice behavior like that - it means you're probably trying to do something shady, like walk around their VPN dropping rules - so they could just throttle your connections even more, just in case :)
So in general - you're fu^Hat very bad situation. I'm from Europe. I'm "safe" now, but we are also going to have bad law for net neutrality soon.