You're a great HN user and commenter and your contributions are much appreciated! I don't want to come across like a bag of bricks but if you would use this feedback to fine-tune a bit, that would be appreciated.
(You may be right that other commenters were breaking the guidelines worse, but we just don't come close to seeing everything, and a lot of what we do see happens by random access.)
Example 1. I run Blockada on my Android phone, so I can block every ad even in apps and I can more or less firewall them (the outside calls). Blockada runs as a local VPN and unfortunately Android allows only one active VPN. So it's either Blockada or Wireguard. I'm with Blockada but I might occasionally want to disable it and enable Wireguard. I never did it yet because:
Example 2. WireGuard does not run everywhere. My little home ARM based server has a Linux kernel with some special driver to manage its hardware (it's pretty common on non-Raspberry ARM devices) and WireGuard does not run on it. It requires a newer kernel that I still cannot upgrade to and maybe I will never be able to. So I don't have anything to VPN to.
I might eventually put online a Raspberry, even an old model 3, as a bastion host on the home end of the VPN, but then it would be something else to care about and to power. It's not worth the mind share and the wattage so far.
https://news.ycombinator.com/item?id=45926849
Besides the political implications, I think we should try to find an objective taxonomy, it's clear that privacy VPNs and network security VPNs are different products semantically, commercially and legally, even if the same core tech is used.
Possibly the configuration and network topology is different even, making it a technically different product, similar to how a DNS might be either an authorative server for a TLD, an ISP proxy for an end user, a consumer blacklist like pihole, or an industrial blacklist like spamhaus. It would be a non trivial mistake to conflate any pair of those and bring one up in an argument that refers to the other.
It's not that he doesn't know the difference. He's making the argument that since there's no _technical_ difference there can be no legal difference.
It doesn't really matter that a single person has found a loophole because many, many other people don't have such a luxury, and that's what the lawmakers are aiming for.
It's going to be interesting when the majority of the UK accesses the internet via VPN because of the increasingly ridiculous hoops that the UK makes them go through, and the government tries to stop them while also allowing VPNs to be used by the tech sector.
I agree, these are two separate legal processes powered by the same technology. But the internet doesn't have any awareness of legality (thankfully) so we're stuck with only the technical meaning.
I doubt that.
The tech is the same, though. That's the point.
It’s not taking about IPsec tunnels between networkers, or a connection back to your home. It’s talking about surfshark
The point, again, is that the tech is the same, and there's no method for determining what purpose the VPN is being used for.
In most places the law is exercised pragmatically, interpreted by presumed intention. That's why legal precedent is important. You likely won't convince any judge being anal about the wording (maybe if the law gets applied for the first time). You can derail anything semantically. Furthermore, despite apparent belief, laws are frequently formulated in such a way that a particular wider term is extended to help interpretation. Eg. "It is prohibited to use a VPN in a way capable and intended to obscure one's physical internet access point identification". (Not a lawyer, not a native speaker, don't get anal with this wording, either.) I very much doubt any legally binding document would even use the term 'VPN' primarily to describe the technical means for anonymization, but rather describe it functionally.
I do actually give VPN access to my mother that is not technically competent but I have full access to her computer and locked her down as much as possible
But no, Tailscale did not pay me for this comment. I do happen to know someone that works there though.
Entirely missing the point that setting up a VPN exit node on your own or someone else's connection is a crazily esoteric super weird nerdy thing outside of communities like HN, and Tailscale on an Apple TV box will not only work but automatically update itself with no intervention on your part, and that the person whose house it is in needs extremely minimal technical skill to do what you tell them to over the phone.
Thanks again, devilbunny
You're very welcome.