Live data from Hacker News

Porn restrictions are leading to a VPN boom

popsci.com

291–300 of 316 posts

Re: Porn restrictions are leading to a VPN boom

#291
post #169

Earlier quoted context omitted.

Configuring 1.1.1.1 is a great option for people outside the US whose countries are unable to pressure Cloudflare for information. A better option for those of us in the US is to run our own DNS resolvers. My DNS resolver runs on a little PFSense box that also has DNS blocking and a ton of other features.

Let's be realistic. Porn, the subject of this discussion, is not illegal in the US; this is about age verification laws that apply to the website operators, who then self-block users from particular states. No one is going after Cloudflare for this information as there is no crime committed by the user. Given Cloudflare's logging policy ( https://developers.cloudflare.com/1.1.1.1/privacy/public-dns... ) and data disc…

Agreed Cloudflare is a decent company, but some of us would rather not leave crumbs to pick up if/when things change for the worse.

Re: Porn restrictions are leading to a VPN boom

#292
post #253

Earlier quoted context omitted.

> The absolute joy they had when I showed them how to set up 1.1.1.1 on their Android TV, phones, and laptops… so they could watch unrestricted gay porn in their heavily censored and state-controlled slice of the World Wide Web… I'd be very careful giving security advice to someone in that situation - in fact, I probably wouldn't do it, even though I am an experienced professional who knows more than most people in I…

No shit they can safely watch gay porn, it isn’t Russia/Iran

Well, by blocking it they're already well on the way there of course.

Blocking is step 1. Monitoring step 2. After that it starts getting into physical danger territory.

Re: Porn restrictions are leading to a VPN boom

#293

Earlier quoted context omitted.

You could say you were learning math: https://kotaku.com/on-pornhub-math-teacher-makes-his-mark-te... https://news.ycombinator.com/item?id=28934711

Yeah. An oppressive government will for sure take your excuse of “I was just learning math on PornHub”.

As if you will get a chance to explain in the dark hole they throw you in :(

Re: Porn restrictions are leading to a VPN boom

#294

Earlier quoted context omitted.

Reminds me of a... peculiarity in Turkey. Men are required to serve a mandatory term in the military, but are exempt if they're homosexual. However, to prevent this being used as a loophole to evade service, the men in question must prove that they're gay. This has resulted in the Turkish military having a very large collection of amateur gay porn.

Apparently it doesn't happen anymore. > The system has been undergoing change for the past few years: Lambda Istanbul's lawyer Fırat Söyle stated in 2012 that the rectal examinations, and the photographic evidence of anal intercourse have been dismissed as requirements when they gained worldwide and national media attention. — https://en.m.wikipedia.org/wiki/Pink_certificate But from when it did happen, it sounds...…

It's weird anyway. I know gay people that never do anal. That seems a weird "proof" despite it being completely out of line to expect that anyway.

Re: Porn restrictions are leading to a VPN boom

#295
post #126

Earlier quoted context omitted.

Maybe it's also a generational thing. In the 90s, I remember running my own squid proxy on a remote shared box somewhere, in order to circumvent "things." Granted, today, if it was just getting around general network restrictions via blacklist, then tethering is very convenient.

Ssh -D is quite handy

Tinyproxy also, when socks5 isn't supported

Re: Porn restrictions are leading to a VPN boom

#296

Earlier quoted context omitted.

I think you are smoking crack if you think Turkey has more freedom of speech than the UK.

Do you have any data to support your assertion or are you just making things up?

Start here: https://en.m.wikipedia.org/wiki/Censorship_in_Turkey

Re: Porn restrictions are leading to a VPN boom

#297

Earlier quoted context omitted.

> I don't think security professionals are lying. I think "security professional" is a meaningless descriptor like "thought leader" that one applies to themselves You don't believe that people who study security for a living might know more about it? Certainly software security experts should be given more credibility about software security than politicians should be given. I'm not sure I've ever run into the view b…

They're orthogonal issues because you can address one, the other, neither, or both totally independently. We can have very strict data protection laws and also have strict id checking for regulated industries. I'm well aware of RTA labels. I've pointed them out on similar threads. They're also not ideal (given that they're basically "yes/no" which will necessarily lead to arguments about what should be classified), b…

> They're orthogonal issues because you can address one [...] independently. We can have very strict data protection laws and also have strict id checking for regulated industries.

We can not have secure ID checking without data protection laws. They're not orthogonal. This is the same conversation that comes up every time the government tries to mandate secure backdoors into encryption. You can't massively expand usage of an insecure technology and when it's pointed out that the current technology is insecure say, "well that's a separate issue, we don't have to worry about that right now." It's not a separate issue, you're massively expanding a technology that is currently insecure, just own it.

> I'm well aware of RTA labels.

Then why did you claim that porn industries weren't doing anything? I mean, I'm trying to be charitable here, it would be very reasonable for you not to be aware of those efforts, most people aren't aware of them. But you're saying you were?

You're telling me that when you said:

> They should be proposing systems that they believe are reasonable to meet their obligation, but they are not. Instead, they've gone from at least requiring credit cards to... absolutely nothing.

You knew that this was false -- like literally just straight-up wrong? When you commented that porn industries had 30 years to propose government ID systems to avoid handling this data themselves and hadn't... you knew that porn industries had actually proposed and lobbied for government ID systems?

So why did you say otherwise?

> They're also not ideal (given that they're basically "yes/no"

Come on, this is obviously not an issue for you because if it was, you wouldn't be supporting the current bills, which all implement binary "yes/no" classifications. We could debate whether or not broad classifications that refuse to distinguish between types of porn are good or bad, but you are currently arguing in favor of a binary classification for the purposes of liability, so I don't think that discussion would be a good use of time. Obviously you're OK with binary classification for age-verification, so this is not a real objection.

> reddit and redgifs do not

It's not clear that Reddit is liable under all of the laws proposed. Reddit hasn't pulled out of any of these states or added ID checks. Your argument against the proposal of labeling is a site who's content isn't addressed under the proposed laws.

Also, if you don't like that Reddit doesn't currently use the unlegislated standard... legislate it. Pornhub isn't lobbying to block labeling laws. You can require Reddit to use a labeling standard.

> Also content can't be blocked at the router level if it's using TLS

My sibling in Christ, you proposed blocking sites and VPNs at the router level. This was your solution to foreign porn sites that aren't covered by these laws. Now suddenly that's not sufficient?

Regardless, we use per-page metadata all over the place on platforms like iOS and Android to enable functionality based on page contents -- from device support to PWA indicators. There is no reason why these platforms can't work those same indicators into content blocking tools. And the presence of headers on landing pages for sites like Pornhub can be used at the network level to block these sites entirely, which again... you proposed doing!

Blocking per-page content is just a bonus, the current bills don't address that concern. It's a mark of the superiority of labeling that it allows a level of granularity that current bills don't.

> Alcohol distributors don't seem to have a problem doing this.

I'll repeat, porn isn't always transactional and porn is rolled into normal political and social speech in a way that prevents making it purely transactional without limiting large categories of speech. It's not the same as alcohol.

Alcohol also isn't speech. Porn is.

> Generally the more I think about it, it does seem "reasonable" to just say businesses dealing in adult restricted materials are liable...

You're allowed to think it's reasonable. The problem is if you spread misinformation while defending that position. To summarize where this thread has gone, you've suggested:

- People shouldn't worry about data collection because the laws prevent it. This is false, many of the laws have limited liability and recourse for data collection, and most only target retention of ID information, not aggregate data collection about users' browsing habits. Additionally, none of the laws limit government collection of data.

- The laws are close enough to each other that they can be read interchangeably. This is false, although the laws are templates of each other they often differ on details, and the presence of a provision in one bill does not solve problems for other bills.

- Information does not need to be stored or collected to implement 3rd-party ID checks. This is false, there are no 3rd-party ID checking services that I'm aware of that do not collect and store information about users.

- Retention laws would solve the security problems. This is false and a misrepresentation of security professionals' criticism of the bills. Retention is one part of the security and privacy risk.

- Porn companies have not proposed any alternatives. This is false, they have -- both ID systems and labeling systems. What's wild about this one is that you're suggesting you knew that this was false when you said it, which is not something I would have suggested.

- Porn verification is identical to alcohol/gun verification. This is false, most porn consumption online is not via a transactional relationship.

----

Like I said, I don't care if you support the bills, that's fine. It's a free country, you can support whatever you want. Just don't spread misinformation while you're doing so.

Re: Porn restrictions are leading to a VPN boom

#298

Earlier quoted context omitted.

They're orthogonal issues because you can address one, the other, neither, or both totally independently. We can have very strict data protection laws and also have strict id checking for regulated industries. I'm well aware of RTA labels. I've pointed them out on similar threads. They're also not ideal (given that they're basically "yes/no" which will necessarily lead to arguments about what should be classified), b…

> They're orthogonal issues because you can address one [...] independently. We can have very strict data protection laws and also have strict id checking for regulated industries. We can not have secure ID checking without data protection laws. They're not orthogonal. This is the same conversation that comes up every time the government tries to mandate secure backdoors into encryption. You can't massively expand us…

You can of course have secure id checking without data protection laws: the companies doing the check can just not store information about the check, regardless of whether they are required to delete it. As long as they are not required to retain it, which I have not seen anywhere, they certainly can choose not to. Here though, the laws I've looked at all specify that they must not retain it. They could have higher penalties, but they already explicitly forbid it.

Like I said several times and have said in other similar threads, I'm inclined to think RTA headers are a "better" approach. Currently they're not consistently implemented on either end (e.g. Firefox doesn't support them, sites I mentioned don't send them), but it'd be a quick win to mandate that in commercial contexts, which would include Firefox.

But you don't have to look far to find people who think the filtering problem is entirely intractable (they're in this thread). I think it's worth trying the metadata approach more with commercial mandates to implement something along those lines. I can see why people could argue that's been tried enough (filters have existed for over 20 years, and access for children is still easy), and they need something more. It's not clear that they're even wrong, though I'd like to see us try still. But the more I consider it, it really doesn't seem like that big of a deal to just do ID checks. Presumably you'd do it once to establish an account that's above the age limit. Not the end of the world.

Maybe I'm wrong about these sites' lobbying efforts. Maybe most of them have been posting on their front page big banners asking people to tell their representatives to support mandatory metadata processing/filter enablement laws. I sort of doubt it, but it could be. I do know that some major sites (e.g. reddit) don't implement the metadata or any other controls.

It's not clear what the "percent of content" in these laws means, but when I looked at dumps last year, reddit looked to be ~40% porn by posts (obviously not if you consider comments to be content for counting). It is (or was, as of last year, if dumps are accurate) pretty close to being more porn than not. Certainly for a discussion about how porn sites behave, they are a major porn site with millions of users, and they do exactly nothing to turn away minors (in fact they obviously target them) or segregate the site.

I pointed out elsewhere that routers can block common VPN protocols (e.g. ipsec or wireguard). Of course they can do almost nothing to block something going over TLS:443, and soon they won't be able to do SNI sniffing either. So network filtering of sites is not possible anymore unless they stop using TLS.

Anyway, my point about worrying about data collection and retention is that people should worry about it to the same extent they do with eBay or some small shopify-based site. They should worry about it! But they shouldn't specifically worry about porn sites. And the laws here seem to all ban retention, which is good. Perhaps they could have higher penalties, but they do ban it. Generally e-commerce sites don't have retention regulations.

It's not clear to me how governments would get any records to retain, but sure they should disallow it.

3rd parties already store data that can be used for verification. I don't see KYC laws being undone anytime soon. There's no need to record any information about a verification occurring. I'm sure companies offering KYC services who are already used to operating in regulated environments can deal with not retaining submitted information.

I don't really understand your point about "transactional" relationships. If you have a business providing a service, they can follow relevant laws for their industry. If total wine decided to place an unmonitored "free beer" keg out front where children could get to it, they'd almost certainly end up in legal trouble.

Or perhaps a more direct analogy would be if you opened an adult theater with an automated ticket machine so no one checked who was coming in. Or a Redbox that took cash and rented adult movies with no checks. That business would never fly in person. Why is it different online?

Re: Porn restrictions are leading to a VPN boom

#299
post #70

Earlier quoted context omitted.

Only the DNS lookups. Not the content of what you’re viewing over https. Everything after domain name is encrypted

The DNS lookup are often enough. You can try to claim you were shopping for new shoes on pornhub.com, but not many people will buy it

or just claim ignorance. or the opposite and claim browser DNS prefetching when a blog spam comment linked to pornhub

Re: Porn restrictions are leading to a VPN boom

#300
post #290

Earlier quoted context omitted.

SNI header from TLS handshake is unencrypted so service providers (and Government's packet inspection engines) absolutely do see what website you are visiting https://en.wikipedia.org/wiki/Server_Name_Indication Server Name Indication payload is not encrypted, thus the hostname of the server the client tries to connect to is visible to a passive eavesdropper. This protocol weakness was exploited by security software…

But the SNI hostname will only include everything left of the TLD. So that is the TLD, the domain name, and the subdomain. It excludes the rest of the URL. If you have installed a root cert to allow the government to MITM, then there isn't really anything you can do...

SNI is enough to classify traffic for enforcement purposes.

dont forget that if certain SNI is detected, your ISP/government may try to force downgrade TLS or replace server-hello with their own cert - meaning you will need to install government certificate to browse certain websites and 99% of users will do that to get access

Post reply on HN