India mulling over banning VPNs forever
medianama.com
medianama.com
This is about individuals, and blocking most consumer VPN services is not that difficult. Naive DNS filtering would work against the leading VPN providers domains.
Or maybe just RDP to a rented windows VM and go from there.
Ultimately they want to go for the low hanging fruit with little effort. Blocking common VPN servers takes a few minutes to do and maintain. Anything more and you've got to spend real money on packet inspection on possibly an entire country's bandwidth.
I guess people could use SSL VPN and pretending to be HTTPS, but the detector might be able to detect patterns and realize it's not HTTPS traffic.
Ofcourse you can block IPs of popular VPN providers decreasing accessibility but it'd be impossible to stop it completely.
Though this would easily restrict the majority of non-tech savvy individuals while doing nothing
Wikipedia [1] documents some methods.
[1] https://en.m.wikipedia.org/wiki/Great_Firewall#Blocking_meth...
Note, it probably requires installing or configuring network bottlenecks for filtering. Getting the topology correct is harder than the actual filtering, which is a standard feature on enterprise and isp networking hardware.
State of the Art is the Chinese GFW -- it can do things like:
* look for keywords in tcp packets and reset connections
* block whole protocols based on attributes (such as encryption parameters), Tor is always playing cat and mouse here and generally blocked
* detect if an encrypted ssh session is being used to tunnel traffic, and reset the connection at both sides with a TCP Reset flag.
* modify http traffic to send malicious js to browsers to attack other servers