Site access issue using VPN

VPN is a responsible choice given internet threats.

  • Yes

    Votes: 13 81.3%
  • No

    Votes: 1 6.3%
  • Depends on the daily threat level

    Votes: 1 6.3%
  • Depends on cloudflare et al wanting to steal our personal data

    Votes: 1 6.3%

  • Total voters
    16

Foo Fighter

Cum adolescunt hominem verum esse volo.
Senior Member
Joined
19 July 2016
Messages
4,817
Reaction score
4,276
G'day, for several days now I have been denied access here due to cloudflare.

I use Norton VPN for security as frankly there are enough loonies out the to make this a sensible precaution. I switched OFF the vpn to see if this was the actor cloudflare does not like and presto, back in.

Question, why is cloudflare so anti vpn, trawling of personal data? Being an USA thing I would have thought not but these days anything can happen in the next half hour, possibly enough a labour-ed government. Oh, hang on a minute.....

Similar situation with tank.net although that site is more off and on tbh.

I much prefer to keep my vpn on if that is OK with you. Big snooty brother can suck his own ovaries...
 
Bring back the good old Firewalls of yesteryear that used to be bundled with security suites instead of VPNs you cannot get access to the BBC website on VPNs either so I must think that it is a common issue Foo Fighter.
 
I can access any bleep bleep cee site I need to, the ONLY sites I have an issue with is this one and tanknet.org.
Only been a problem over the last few day, it was fine before then.
 
I use Hot Spot Shield. Very potent.
I have purchased a without term access, for 5 computers, for 90€ (more or less, I don't remember exactly) several years ago. A very good deal.

I use it to download films and musics remaining hidden, as we are very controled in France and may have to pay a fine in case of...
 
G'day, for several days now I have been denied access here due to cloudflare.

I use Norton VPN for security as frankly there are enough loonies out the to make this a sensible precaution. I switched OFF the vpn to see if this was the actor cloudflare does not like and presto, back in.

Question, why is cloudflare so anti vpn, trawling of personal data? Being an USA thing I would have thought not but these days anything can happen in the next half hour, possibly enough a labour-ed government. Oh, hang on a minute.....

Similar situation with tank.net although that site is more off and on tbh.

I much prefer to keep my vpn on if that is OK with you. Big snooty brother can suck his own ovaries...
You are completely off target here.

1) VPNs are widely used by malicious actors. A lot of bad traffic comes from VPN IP addresses.
2) Cloudflare don't block anything without a rule that I set up, so don't blame them.
3) I've recently had hundreds of thousands of requests hitting the website from single IP addresses, putting a major strain on the site and resulting in occasional long load times. At times there are thousands of "guest" sessions, each taking up RAM and CPU time.

In those situations, I will sometimes block an IP address, or where there's multiple bad source IPs from one organisation I sometimes block an ASN which generally blocks the entire organisation. I try to avoid doing this to ISPs. VPNs often use the dodgier cloud providers to host their services, as reputable ones don't want to host them, and so they may get caught in the ban triggered by malicious actors using the same hosting company to launch attacks or data scrapes of the site.

By using a VPN you are throwing your outgoing internet traffic in a bucket with a whole bunch of other people wanting to send spam emails, hide their dodgy online activity, download torrents, or access region-locked content they aren't entitled to. You run the risk of suffering from the poor reputations of the VPNs IP addresses that result.

Unless you live in, say, Russia, where all sites using Cloudflare are now blocked, in which case you have no choice but to use a VPN to access the site.
 
The Russian government has implemented a effective block on Cloudflare,

https://blog.cloudflare.com/russian-internet-users-are-unable-to-access-the-open-internet/
I'm an ISP. It is not us. We face specific obligations due to our licensing. There are two primary requirements we must adhere to:

1) We have to filter URLs, domains, and IP addresses from the RKN blacklist. Failure to comply can lead to fines and the loss of the license.

2) We must purchase DPI hardware from a state-affiliated supplier. This equipment is installed on every internet access channel we manage, and we are required to hand control over it to a contractor associated with a state agency (RKN). The state refers to these DPI as ТСПУ (Технические Средства Противодействия Угрозам), which are purportedly designed to counter threats to Russian infrastructure. However, their current use primarily targets the bandwidth throttling to foreign services, aiming to encourage the adoption of locally-controlled alternatives. Because this DPI implementation falls under national security concerns, the state does not disclose its specific objectives or operations. No court approval is necessary for these actions. This lack of transparency allows state representatives to lie with a straight face to the public and the press regarding the true reasons behind the diminished performance of services like YouTube and Cloudflare. They always promote the use of local services instead, blaming foreign services for lacking compliance with local laws, proper technical support, and adequate resources.

The ISPs are unable to countermeasure this practice and even fail to provide their customers with a consistent explanation not contradicting the official position.
 
Last edited:
The explanation FOR VPN is that it prevents you being 'followed' and data collected for sale to marketing types. There has been a LOT of media coverage given to this over the last few years and while I get the big business model of ever increasing profits, driving them to ever more extreme methods, have had enough of them treating me as a possession without cost to them.

An analogy is the regal slug and their door to door advertising. Used to be you could opt out and that was that. Now they demand we re register every two years but, also demand that it will take six months to take proper effect.
The cost of recycling is enormous and the cost of general waste likewise which WE pay for in local taxation. So, we not only get harassed by advertisers, we also get to subsidise them too.

Yes, there is an argument that if you do no wrong there is no harm, like the surveillance camera's in just about every shopping centre or town centre.

Not sure there is an answer for everyone tbh but there needs to be transparency, apparently the norton vpn can be turned OFF for certain sites but the support feller I tried dealing with was as legible as trying to read a pot of tea leaves in Beijing while in a house in London, with the mark one and no assistance.

Perhaps this discussion had to be aired because I am now a little better informed as to why vpn are unpopular with sites although it has taken a long while to come out by sites closing to visits from vpn users.
 
Bring back the good old Firewalls of yesteryear that used to be bundled with security suites instead of VPNs you cannot get access to the BBC website on VPNs either so I must think that it is a common issue Foo Fighter.

Everyone that uses a reasonably up-to-date operating system and/or a home NAT router has at least one firewall. VPNs serve a different purpose. I always use one online.

Overscan: VPNs are widely used by malicious actors. A lot of bad traffic comes from VPN IP addresses.
What is the source of your information? It is news to me.

While I suppose that some bad actors might use VPNs, I can't really see what advantage this would give someone attacking a web site. The ISP and the VPN provider always know the bad actor's IP address (and usually his name, billing address, and credit card number at the very least). The VPN provider is going to be more than a little sensitive to any activity that congests its network (VPNs are by nature slower and more vulnerable to heavy traffic) or implicates its own business. Besides, there are better ways to mask an attack The simplest approach is probably to use someone else's computer and identity. For example, DDoS and ransomeware attacks are often run via "bot farms" of hacked, unsecured third-party computers. And I personally know of a case where a small group of corproate employees set up a clandestine child porn site using company servers (they were arrested and fired).

So if a server does face a risk from VPN users, I suspect that the risk is low. Reverse proxy service (Cloudflare's main offering) is known to present quite significant risks to both web sites and users. Yet it is widely used, presumably because benefits to the site appear to outweigh risks.

A VPN is simply a network that encrypts network traffic between its users and its servers. When a VPN user requests a URL outside the network, the server decrypts the user's request, requests and receives the site content from the undicated URL, encrypts the content, and then forwards the content to the user.

The VPN thus protects against common security threats like eavesdropping and man-in-the-middle attacks. This is why most corporate network security measures include VPNs, sometimes even when crossing from subnet to subnet. VPNs:

* encrypt data in transit, making eavesdropping and man-in-the-middle attacks difficult to practically impossible

* mask the user's IP address (and sometimes the hardware MAC ID), making it harder to identify the user or target the user's computer.

Identity theft and privacy issues have since made VPNs important for individual security as well, especially for those targeted by politically repressive regimes.

Given the above, I doubt that corporate publishers, Google, and Cloudfare resist or refuse connections from VPNs. I think that Foo Fighter is right: VPNs, like script-blocking, make monetizing our personal information harder.

At its inception, Google came up with the idea that identifying users, tracking their preferences, targeting them with advertising, and selling their information on to others was the only way to make money on the internet. This is not so (the Duck Duck Go search engine makes money on search with static, untargeted, content-based ads). But data-protection is almost non-existent in the US and Google has made lots of money. So almost all businesses and content providers now make mass data collection (rather than accuracy or usefullness) a core part of their business models.

Ivalue privacy. And violating it for marketing purposes--and, incrasingly, for political purposes--can cause serious problems, like mistaken identity, harassment, and identity theft. This is why:

* I use a NAT router that substitutes its own IP address and MAC ID for those of the computers on our network.

* I use a municipally owned internet provider that does not log user accesses.

* I use a VPN.

* I use a script blocker, NoScript, to disable script by default and allow only the scripts that I need to make content that I want available.

* I register only for sites from which I get enough value to make compromising on security worthwhile.
 
In order to distinguish users from bots, there are a few indicators you can use.

As a website you always know the ip address of the request. If that ip belongs to a commercial ISP then its probably a user. If it maps to a datacenter company, it could be a VPN endpoint or pretty much anything - a bot farm, an AI scraping data. VPN companies rarely publish the IP ranges they use because the likes of Netflix, BBC etc can then ban their users, and circumventing region restrictions is used to sell VPNs. So its hard to know if traffic is from legit VPNs or not, only that it comes from Digital Ocean daracenter for example.

VPNs try to hide your identity from websites, but then how is the website owner supposed to identify real people from bots and AIs?

I am not longer doing any IP based blocks. You only need to answer the Javascript prompt if you are not logged into the forum already. If you are signed in you should just get in without any action needed if you are on a normal computer.

On some devices you may sometimes still get a prompt if you share an IP with lots of other users.

It can't get easier than that really.
 
I always use a VPN from my home computer and have never had a problem getting in.
 
I've tried a VPN (Nord, Express) on my Windows PC several times so that I could get into BBC programming that isn't otherwise available here, but the download/upload speeds (ISP Spectrum) were drastically reduced. Never able to get that resolved, so I gave up on VPN.
 
I use F-Secure and never had issues up/down speed is always high, currently d738.43 u627.93 on and d904 u 913.16 off.

Regards,
 
Last edited:
I can sign in with a VPN from work and home (different ones), but I can't sign on from work at all without VPN.
 
For some reason forum did not open for me now without VPN use, despite not being in Roskomnadzor blacklist. Likely it intesected by IP with some previously blocked site.

(or maybe UK hoster decided to block Russian IP's in which case I'd like to complain about discrimination ;) )
 
Last edited:
Back
Top Bottom