Bring back the good old Firewalls of yesteryear that used to be bundled with security suites instead of VPNs you cannot get access to the BBC website on VPNs either so I must think that it is a common issue Foo Fighter.
Everyone that uses a reasonably up-to-date operating system and/or a home NAT router has at least one firewall. VPNs serve a different purpose. I always use one online.
Overscan: VPNs are widely used by malicious actors. A lot of bad traffic comes from VPN IP addresses.
What is the source of your information? It is news to me.
While I suppose that some bad actors might use VPNs, I can't really see what advantage this would give someone attacking a web site. The ISP and the VPN provider always know the bad actor's IP address (and usually his name, billing address, and credit card number at the very least). The VPN provider is going to be more than a little sensitive to any activity that congests its network (VPNs are by nature slower and more vulnerable to heavy traffic) or implicates its own business. Besides, there are better ways to mask an attack The simplest approach is probably to use someone else's computer and identity. For example, DDoS and ransomeware attacks are often run via "bot farms" of hacked, unsecured third-party computers. And I personally know of a case where a small group of corproate employees set up a clandestine child porn site using company servers (they were arrested and fired).
So if a server does face a risk from VPN users, I suspect that the risk is low. Reverse proxy service (Cloudflare's main offering) is known to present quite significant risks to both web sites and users. Yet it is widely used, presumably because benefits to the site appear to outweigh risks.
A VPN is simply a network that encrypts network traffic between
its users and its servers. When a VPN user requests a URL outside the network, the server decrypts the user's request, requests and receives the site content from the undicated URL, encrypts the content, and then forwards the content to the user.
The VPN thus protects against common security threats like eavesdropping and
man-in-the-middle attacks. This is why most corporate network security measures include VPNs, sometimes even when crossing from subnet to subnet. VPNs:
* encrypt data in transit, making eavesdropping and man-in-the-middle attacks difficult to practically impossible
* mask the user's IP address (and sometimes the hardware MAC ID), making it harder to identify the user or target the user's computer.
Identity theft and privacy issues have since made VPNs important for individual security as well, especially for those targeted by politically repressive regimes.
Given the above, I doubt that corporate publishers, Google, and Cloudfare resist or refuse connections from VPNs. I think that Foo Fighter is right: VPNs, like script-blocking, make monetizing our personal information harder.
At its inception, Google came up with the idea that identifying users, tracking their preferences, targeting them with advertising, and selling their information on to others was the only way to make money on the internet. This is not so (the Duck Duck Go search engine makes money on search with static, untargeted, content-based ads). But data-protection is almost non-existent in the US and Google has made lots of money. So almost all businesses and content providers now make mass data
collection (rather than accuracy or usefullness) a core part of their business models.
Ivalue privacy. And violating it for marketing purposes--and, incrasingly, for political purposes--can cause serious problems, like mistaken identity, harassment, and identity theft. This is why:
* I use a NAT router that substitutes its own IP address and MAC ID for those of the computers on our network.
* I use a municipally owned internet provider that does not log user accesses.
* I use a VPN.
* I use a script blocker, NoScript, to disable script
by default and allow only the scripts that I need to make content that I want available.
* I register only for sites from which I get enough value to make compromising on security worthwhile.