Like it or not, bad actors use VPNs as well, and for some businesses the adverse selection caused by VPNs basically makes banning VPNs a no-brainer (eg. due to fraud).
Like it or not, bad actors use VPNs as well, and for some businesses the adverse selection caused by VPNs basically makes banning VPNs a no-brainer (eg. due to fraud).
But I guess blocking $$$ corporate visitors should be fine by you as well.
Practically: The economics probably check out, but bear in mind that it's not one-sided; this will cost you legitimate users.
Death by a thousand anti-fraud cuts. In the end it's a perfect dystopia.
Should I be able to walk around stores wearing balaclavas? Sure, robbers wear balaclavas, but innocent people do too.
It makes sense to filter out bad actors, but relying on vpn usage as the only signal for untrustworthiness is unwise.
It seems like the problem isn't payment fraud or nefarious activity but "fraud" in the form of people not sharing as much personal data as spyware operators would like.
And guess what the bank will most likely be doing to mitigate that liability shift. It's heuristics all the way down.
The optimal amount of fraud is non-zero.
Also in an age of CGNAT, state enforced ISP level tracking and blocking. Blocking at the IP level is just lazy. It's like blocking a person because they come from the same town as someone else.