I hope I don't live to see you turn into every other shady VPN service.
I hope I don't live to see you turn into every other shady VPN service.
I suppose this is inevitable to some degree with any VPN service, it's part of the deal for more privacy, you have to share an IP with potential sources of abuse. But it seems to have gotten really bad recently to the point that I end up server hoping throughout the day because different websites will have blocked different mullvad servers - to complicate matters some of their newer server IPs hosted by another company are misidentified as russian and blocked by many sites and services.
I'm not blaming Mullvad, but it's changed my use of their service from a set and forget to a constant reminder that i'm on a VPN... I don't know what the solution is beyond some crude cycling of IPs.
Welcome to the world of Tor users. People who value online dignity need to work together against privacy hostile web technologies. My present bugbear is Cloudflare, who seem to do a lot to disrupt privacy respecting technologies. Ultimately though, the power lies with web service designers. One can no longer pretend "I didn't know" when turning over delivery to some cheap (free) but shady CDN who then blocks millions of legitimate users because they don't want to be tracked and spied on.
One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.
Bam - I am anonymous, but have (mostly) proven I am a real person with (mostly) reasonably good intentions.
I joined HN for one or two reasons. To research a book. But also to promote my last book. Anyone can post here with a throwaway, yet I didn't want to be an interloping dick who felt entitled to hit and run posting links to my own vanities... so I decided; join, contribute, participate, earn. After a few months I don't feel bad about plying my own wares a little. Reputation (social capital) is natural and ancient and doesn't really need crypto.
Most of the Web isn't that though. As an information system, as Sir Tim first coined it, it's a publishing machine: You advertise a service, I send "requests", you send "responses", we part ways without complications. Quick anonymous sex on the beach. So-called Web2.0 f-cked that massively. Web2.0 wants to exchange phone numbers. And once the surveillance capitalist creeps latched on to stalking everyone around the neighbourhood... well here we are.
I think what some Web3.0 people think is that crypto can repair some kind of "middle ground", where Web2.0 type behaviours can take place but anonymously and under conditions controlled by "stakes". I think this won't work for psychological and game theoretical reasons we can't get into here. Instead I think we need to repair the Web1.0 layer at least, and since transport level security and anonymity have become necessary in a post-Snowden era, for me that means getting rid of the selective prejudice inflicted by systems like Cloudflare.
Its a put up or shutup kinda system. Fund your wallet with $100, hold it, and we will let you post that reaction to a news article after its been held continiusly for 30 days, and automatically delete is as soon as its unfunded.
"Sinners look just like saints, so it's necessary to punish all, to
destroy the riches of the many in order that wicked few do not
escape."
Is that a fair framing of the "ethics" of what you said? (I'm not
attributing that as 'your' argument, I understand you're kinda just
trying to 'explain' something as you see it).Do you think this kind of thinking can continue to stand if technology is ever going to be fair and useful to everyone? Or do we just accept that technology always amplifies as least as many problems and injustices as it solves?
I'm trying to map the technical explanations people give onto what may be going on for them at "ethical reasoning" level.
You're welcome to add your interpretation of course.
You probably guessed I'm looking to distinguish a Bentham from Mill sort of utilitarianism.
A reasonable challenge would probably be fine. But so many sites block, or sometimes use obnoxious unfair challenges.
I added some of my own experience here: https://news.ycombinator.com/item?id=31252676
If an army is attacking your border and somebody walks through them saying, "It's okay, I'm totally legitimate!" that person is probably still going down in the crossfire. Enter from the direction where the attacks aren't coming from and your odds will increase significantly.
Ultimately, companies will either adopt a very strict security policy on their own or they will respond to the problems that they are experiencing. If you are a US only company and you start getting malicious traffic from Romania, it's fairly common to just block all of Romania. When you're using tools like Maxmind for network identification, VPNs and Tor are just another traffic source that you can choose to block if it's causing you problems.
What I'm getting is that you consider the "attack" an immediate mortal threat and the granularity of tools and techniques for discerning enemy/friendly identity and behaviour are lacking. The principle ethical stance is really self-preservation.
> "It's okay, I'm totally legitimate!" that person is probably still going down in the crossfire.
Nice analogy. I may have to steal that :)
Given that we can't rely on identity [1], can we improve analysis and response to behaviour?
[1] I see in an earlier response you talk a bit about fingerprinting, and of course anyone serious about privacy will modulate OS and browser FPs without malicious intent.
For example, at the site where I worked we needed much stricter protection but we didn't want to bother the established users of the site...so we setup trust scores and implemented stricter controls on a sliding scale. The higher your trust score, the less strict we would be with our policies.
As a brand new user, your score was a flat 0. You could boost it by verifying a credit card, phone number and address (without using a VPN/Tor). Successful transactions rewarded your score. Transactions with established users are more valuable than transactions with other new users, etc.
All the security was virtually invisible to the established users and it worked like a charm.
Regarding the fingerprinting, at the time that we were doing this anti-fingerprinting technology barely existed. We had some other tricks in the bag too to fingerprint based on behavior. It was a lot of fun working on that stuff though. Very much a cat and mouse game.
ssh bruteforce top 5 offenders:
147 (Tor: 0) TENCENT-NET-AP-CN
133 (Tor: 0) DIGITALOCEAN-ASN
31 (Tor: 0) CHINANET-BACKBONE
17 (Tor: 0) BAIDU
13 (Tor: 0) CHINANET-SH-AP
Overall there where 737 unique IPs from 241 ASNs and 1 was a Tor node.
access log top 5 offenders:
76 (Tor: 0) DIGITALOCEAN-ASN
58 (Tor: 0) CONTABO
54 (Tor: 0) AMAZON-AES
50 (Tor: 0) KAZTELECOM-AS
34 (Tor: 0) CORBINA-AS
Overall there where 1672 unique IPs from 618 ASNs and 4 where Tor nodes.
I spent a recent chunk of my career combating fraud on a niche-eBay style site and the people trying to defraud other users, pay with stolen credit cards, login with phished credentials, etc were consistently trying to hide their origin.
Until we started using fingerprinting techniques to track them across multiple accounts and IPs, we had no way to spot this. It was a shock to me when I realized there were legitimate uses for fingerprinting technology because I'd always associated it with ad networks and trackers. They're fairly necessary for combating fraud though.
When we stopped letting any untrusted users run a credit card if their connection couldn't be trusted, our charge backs virtually stopped. That experience makes me completely understand sites scrutinizing anonymized traffic.
HTML isn't cached by default with cloudflare
In the end they are going to drive their honest non-abusive customers elsewhere.
The reality is that "anonymous payment" is kind of pointless, it's basically never the payment method that determines abuse potential as abusers have all kinds of ways of making payment anonymously even when only e.g. cc is accepted. What matters is the level of time and effort put into monitoring usage.
To be honest, on a pure sniff test your traffic coming from DO is probably more suspicious. There are lots of legitimate uses of commercial VPNs. There are not many legitimate users of consumer web-browsing from DO.
I am currently hosting head scale with an exit node on hetzner, and sometimes i am banned from websites.
But back when I used contabo it was a rareity to get blocked, even though its a more "shady" host, maybe because its not as well known ?
Online stores are more likely to flag your purchase as suspicious on the admin side(e.g the Shopify console)
You will run into captchas and prompts for authentication more often
You may not be able to log into some of your more sensitive services(like banking)
Streaming sites will block your server eventually
Even if you spin your own wireguard instance on any major cloud provider you're going to run into the same issues.
I'm not sure a VPN provides much utility when you're already punching your (billing|shipping) address and CC number into a website - that is, unless you're using a drop site for your packages, which definitely will make you look like someone who has stolen CC digits and is trying to cash in on them.
And i, very happily, continue on without those 'many websites'. Of which, there are actually, very, very few for me. Nevertheless - fuck 'em; and not missed.
1) if you do this for unauthenticated websites you are bad and I will not use you
2) if you do this for authenticated websites (especially if I pay you) I will stop using you and you will lose my money.
The most I will accept is a captcha (because it's 2022 and this is where we are)
As a Swede, it's easy to remember, but I can see why it can seem a tad esoteric to native English-speakers :)