Live data from Hacker News

Porn restrictions are leading to a VPN boom

popsci.com

221–230 of 316 posts

Re: Porn restrictions are leading to a VPN boom

#221

Earlier quoted context omitted.

> Good thing these laws specifically ban them from storing that information that they don't want to store. Well... companies. They don't ban government agencies from retaining that data if they get access to it. But ignore that and assume for a second that they do. The problem is that the laws kind of contradict themselves: "don't collect information that compromises privacy" and also "do this in a way that basically…

Why would they need to be auditable? That's not in any of the laws I've read, and in fact as you note, the law makes that impossible. If the law contradicts a requirement that you made up, and does not itself contain that requirement, then why would you presume that it has that requirement? There's literally no reason to have e.g. a knowledge based auth or signed id request hit disk. It doesn't need to be saved for a…

> If the law contradicts a requirement that you made up, and does not itself contain that requirement, then why would you presume that it has that requirement?

First off, always good to be clear that there are multiple laws here, even if many of them are templates of each other; there's not "the law". Secondly, this is hiding behind ambiguity in many of these laws' language; it's easy to claim that a law doesn't specifically require that companies retain information about their efforts, but I guarantee you in any court case about this, requests for that information would come up.

It is painfully naive to assume that any company would feel safe implementing a legally required system that does not provide them with any evidence to prove that their system works or has worked in the past. The ambiguity about what many of these bills mean when they call for a "reasonable method" of identity verification is exactly the kind of contradicting language that I'm talking about above. "We didn't ask you to do X, we just put you in a situation where not doing X would be extremely dangerous."

I would argue that a State going to a company and saying, "do something 'reasonable'" with no legal guarantee or precedent about what will and won't be reasonable, and then additionally adding restrictions that make it practically impossible for any existing ID verification system online that I'm aware of to fit that requirement -- I would argue that is tantamount to an attempt to ban porn. It's a system that can't really be safely complied with. Of course companies being able to provide documentation and evidence of their prior verifications is a practical requirement for them operating in that kind of environment.

> There's literally no reason to have e.g. a knowledge based auth or signed id request hit disk. It doesn't need to be saved for a "short time". It doesn't need to be saved on permanent storage at all.

I don't see any indication in the laws I've read that this would be sufficient; where are you getting this idea from? In fact (I'll remind you), Texas's law explicitly refers to digital identification as something that gets stored and accessed as proof of identity. The bill's own language does not support the idea that identification would be completely transient and instantaneous.

So it is completely reasonable for critics to question these requirements given that nothing in the law would prevent the government from making a case that completely transient identification is insufficient. And even if it was sufficient, from a purely technical perspective it is not clear to me how this magically transient identification would work. Information transmitted between parties gets stored, that's how this stuff works -- what ID verification system are you imagining that can happen instantaneously without referencing any stored information and without any information leaving RAM? I'm not aware of one.

> "Let's assume for a moment that the law says the opposite of what it actually says". But it doesn't.

What? Every single law I referenced requires the transmission of this data and explicitly suggests sharing it with 3rd-party verification services. That's not me reading into the laws, it's just fact.

> It's easy for the government to investigate whether you check IDs: open the site and see if you request ID information. Present fake info and see if you accept it.

What system for instant ID verification that does not rely on storing or accessing stored, indexed information about an identity works like this? How do you propose that sites detect fake info without referencing that info against stored identifying information? Because advocates for these laws keep on saying this is easy and then describing systems that as far as I can tell, do not exist.

-----

I'm accommodating a little bit of a rabbit hole above, but I do need to loop back around to the more relevant point:

> There's literally no reason to have e.g. a knowledge based auth or signed id request hit disk.

Regular, consistent transmission and collection of ID information online presents security risks that are unique to remote identity verification and that are not present in physical spaces like shops and stores. Even if there existed a system that allowed this verification to happen entirely in RAM, that would not address the security points that professionals have raised. And even that magical system would necessarily require storing that information in more places -- on user phones and browsers in an easily transmissible format. It would necessarily require users to become more comfortable sharing information online that they should not be comfortable sharing online.

I'll repeat the same point I made in my previous comment:

> Advocates of these bills ignore that security researchers have an issue with collection and transmission of sensitive data in addition to storage, and so advocates point to narrow, non-specific language about long-term retention as if that solves all of the issues. It doesn't.

Pointing to retention as the only security risk in these laws misrepresents the concerns of security professionals. Ambiguous language that is inadequately explained or elaborated on within bills and that (theoretically) addresses one part of security researchers' concerns is not sufficient to dismiss their overall concerns. Regular uploading and transmitting of ID information to 3rd-parties over the Internet is more dangerous than showing your ID in a liquor store; transmission of that data necessarily requires copying that data, putting it in the hands of multiple parties, verifying their trustworthiness, and interacting with extremely complicated systems that have larger attack surfaces than a cashier looking at your face.

It's just not accurate to act like they're the same.

Re: Porn restrictions are leading to a VPN boom

#222
post #203

Earlier quoted context omitted.

I doubt Texas will. How would they enforce it? And good chance the federal courts will rule it is pre-empted by federal law (the FCC). For historical (and arguably even political) reasons, federal courts give the states a bit more leeway when to adult content. But regulating general purpose content-neutral VPNs would really be stepping directly into the FCC’s domain, in a way which would directly impact interstate co…

Great Firewall of Texas. I could legit see them investing insane dollars on this project. I don't think this is federally illegal either

> The Congress shall have power to regulate Commerce with foreign Nations, and among the several States, and with the Indian Tribes.

Re: Porn restrictions are leading to a VPN boom

#223
post #20

Also it is extremely common in middle and high school to use VPNs to get around school network restrictions.

Back in my day, it was about obscure web proxies. I remember one that was called something like abelincolnfacts.com, which looked like a blog about Lincoln. But clicking an icon of his face in the top right revealed a web proxy interface to browse the web unfettered.

Bess can't go there.

Re: Porn restrictions are leading to a VPN boom

#224
post #20

Also it is extremely common in middle and high school to use VPNs to get around school network restrictions.

Back in my day, it was about obscure web proxies. I remember one that was called something like abelincolnfacts.com, which looked like a blog about Lincoln. But clicking an icon of his face in the top right revealed a web proxy interface to browse the web unfettered.

A super common one from my time is to use google translate’s web translation feature as a proxy since google translate is almost never blocked

Re: Porn restrictions are leading to a VPN boom

#225

Surely it's overkill to pay for a whole month of constant vpn use. You could cook something up that provides access for a short session aaand we've circled back to dialers.

A lot of VPN plans have a traffic limit instead although a free VPN with no traffic limit is really cheap tbh

Re: Porn restrictions are leading to a VPN boom

#226
post #203

Earlier quoted context omitted.

I doubt Texas will. How would they enforce it? And good chance the federal courts will rule it is pre-empted by federal law (the FCC). For historical (and arguably even political) reasons, federal courts give the states a bit more leeway when to adult content. But regulating general purpose content-neutral VPNs would really be stepping directly into the FCC’s domain, in a way which would directly impact interstate co…

Great Firewall of Texas. I could legit see them investing insane dollars on this project. I don't think this is federally illegal either

> I don't think this is federally illegal either

If the FCC wanted to overrule it, they could, and the Courts would likely be on the FCC's side. See https://crsreports.congress.gov/product/pdf/R/R46736

But I doubt it would ever get that far. It would be a huge burden on every large corporation operating in Texas, if interstate traffic had to go through some legally mandatory firewall or content filter. The Texas state legislature is generally pro-business, and if almost every major corporation in Texas would be lobbying them not to do something, I doubt they'll do it. And, in the very unlikely event the legislature ignored that lobbying and did it anyway, and the Governor didn't veto it – then those corporations would likely go straight to petitioning the FCC, and I think it is likely they'd succeed in convincing the FCC in overruling it.

Re: Porn restrictions are leading to a VPN boom

#227
post #202
post #57

Earlier quoted context omitted.

Tethering is idiot expensive in USA. Every provider will DPI and block it or throttle it. It's awful.

I've had a very cheap provider in the US for years that has unlimited tethering/hotspot, and unlimited everything else. I've "only" ever used it for as much as 1 or 2TB in a month, though -- which is a ton for most individuals. (And only occasionally. It Isn't my primary connection, but sometimes it is a very useful connection.) (They do attempt to throttle it, but that's been solvable for me with just a TTL hack on…

Did you mean 1 or 2 GB?

Re: Porn restrictions are leading to a VPN boom

#228
I have done some searches for age verifying services to plug into an adult site and not found anything that seemed reasonable (a few in Euroland and one that has contact for pricing, which means it's not affordable).

I am wondering how this can even be implemented with static html pages, I am guessing if a site was php there would be some session id kind of thing that could connect with a third party API..

If anyone wants to build some verify things I see a small side business brewing here, perhaps we should make a couple of things to implement,

even though I think these laws will be thrown out one they hit the supreme court, the tech could be used for other things like sales of age restricted things.

Re: Porn restrictions are leading to a VPN boom

#229
post #169

Earlier quoted context omitted.

Configuring 1.1.1.1 is a great option for people outside the US whose countries are unable to pressure Cloudflare for information. A better option for those of us in the US is to run our own DNS resolvers. My DNS resolver runs on a little PFSense box that also has DNS blocking and a ton of other features.

Let's be realistic. Porn, the subject of this discussion, is not illegal in the US; this is about age verification laws that apply to the website operators, who then self-block users from particular states. No one is going after Cloudflare for this information as there is no crime committed by the user. Given Cloudflare's logging policy ( https://developers.cloudflare.com/1.1.1.1/privacy/public-dns... ) and data disc…

I don't think this subthread is about the US, but just as a sidenote on the US, Project 2025 directly calls for porn to be made illegal and for attacking Internet providers and companies like Cloudflare that enable its access (https://static.project2025.org/2025_MandateForLeadership_FOR...):

> Pornography, manifested today in the omnipresent propagation of transgender ideology and sexualization of children, for instance, is not a political Gordian knot inextricably binding up disparate claims about free speech, property rights, sexual liberation, and child welfare. It has no claim to First Amendment protection. Its purveyors are child predators and misogynistic exploiters of women. Their product is as addictive as any illicit drug and as psychologically destructive as any crime. Pornography should be outlawed. The people who produce and distribute it should be imprisoned. Educators and public librarians who purvey it should be classed as registered sex offenders. And telecommunications and technology firms that facilitate its spread should be shuttered.

Even in a Conservative-majority court this kind of ban would likely be ruled unconstitutional very quickly, but we should be clear when talking about this kind of thing where it is that a substantial number of Conservative foundations would like to go (https://www.project2025.org/about/advisory-board/). There is a non-trivial Conservative movement to to ban porn.

Re: Porn restrictions are leading to a VPN boom

#230
post #219
post #208

Earlier quoted context omitted.

Unless your phone is rooted, TTL mangling happens on the hotspot-using client devices. Specific details depend on what that client device uses for an operating system, and this makes it impossible to neatly summarize. But it can be done fairly easily with things like OpenWRT or Mikrotik's RouterOS, or a regular stand-alone Linux box, and IIRC it's a simple one-liner on a Windows machine. Because it can't be easily su…

Ok that does seems more viable than mangling it on the average Android phone. Unless of course you're tethering another smartphone by sharing the wifi hotspot, which in my personal experience is a common use case.

Yeah, rootless smartphone-to-smartphone (or tablet) is a harder problem to solve without an intermediary device.

But! That intermediary device could be something like a Raspberry Pi Zero.

It isn't "low power" by the strictest definitions, but it is also not particularly expensive power-wise -- it can be powered with USB OTG from a smartphone from the past decade or so. And it is very small, which also counts.

It can obviously run a real Linux distro (or just parts of one), but can also run OpenWRT -- which by nature tends to tolerate intermittent power very well.

It's theoretical, but (again in theory): A Zero W running OpenWRT might be a relatively simple path for a portable hotspot abuser.

First, dump OpenWRT onto an SD card, plug it in an and get in there with a browser -- however that is done.

Second: Create an interface or two for getting hotspot data into it: Maybe one of them via wifi, and another via USB tethering from the connected phone.

Third: Test. At least the Pi itself should have Internet connectivity by this point.

Fourth: Set it up as a wifi access point (I think that chipset can do both at once in OpenWRT), and get NAT going.

Fifth: Utter the well-documented incantations for mangling TTL on all of the hotspot interfaces.

Sixth: Wrap it in nice 3M Super 33+ electrical tape for posterity and a minimum of protection for those tiny SMD parts.

Seventh: ???

Eighth: Profit!!! Or, better: Push the resulting SD card image to the usual places, with correct attribution and license compliance, so that others can benefit more-easily.

Seems doable. To use, just power it on/plug it in, and turn tethering/hotspot on with the donor phone. And then connect other phones to the WiFi AP provided by the Pi.

It'll eat phone batteries pretty quick, but it might last long enough to get someone else out of a jam. (It'll also work well on a portable power bank, and those are also cheap.)

Post reply on HN