Earlier quoted context omitted.
>Please don't. Not just because of the false positives and false negatives, but because user privacy is actually a good thing. Like it or not, bad actors use VPNs as well, and for some businesses the adverse selection caused by VPNs basically makes banning VPNs a no-brainer (eg. due to fraud).
Do we still not have a foolproof fraud solution? Why not just force 3D-Secure (offloads liability to the bank) or ask additional questions/verification if needed? It seems like the problem isn't payment fraud or nefarious activity but "fraud" in the form of people not sharing as much personal data as spyware operators would like.
And guess what the bank will most likely be doing to mitigate that liability shift. It's heuristics all the way down.