Live data from Hacker News

Mastercard and Visa Start Banning VPN Providers

torrentfreak.com

71–80 of 113 posts

Re: Mastercard and Visa Start Banning VPN Providers

#71
post #69

Earlier quoted context omitted.

Picture, for example, a card which has a small OLED display which displays an amount and a merchant name. You press a little button on the card, and an authorization is generated, cryptographically signed with an embedded key, and sent to the card reader (which also provides the power for the card). Such a reader can be built into laptops, keyboards, smartphones, available as small stand-alone USB devices, etc.. Web…

Well, I can see why they haven't implemented that - its a huge undertaking to build specialized hardware like that into so much varied equipment. For all intents and purposes rolling out a system like that is impossible.

I don't believe it is materially more difficult than the NFC rollout. In fact, I believe it would be far easier than NFC if the financial industry would actually get behind it enthusiastically.

I'm curious, what other undertakings do you think are impossible? WiFi? Bluetooth? GSM?

Re: Mastercard and Visa Start Banning VPN Providers

#72
post #56

Earlier quoted context omitted.

Bad luck, but this is only an anecdote, thus hardly any sort of evidence.

The problem is that the only people with data are the Credit Card companies and the VPN providers, and they both have dogs in this fight. We wouldn't believe the numbers they released, if they released numbers, which they probably won't... So we're left with anecdote and personal opinions to base our decisions on. There's plenty of opinion in this thread - a few anecdotes won't hurt.

fraudulent purchases -> chargebacks

Chargebacks are bad for the VPN company. They cost $15 each.

Even if they cost nothing, a high ratio of chargebacks is not in the best interest of the credit card companies, who are at the top of the value chain. So chargebacks are bad for anybody along the chain.

Re: Mastercard and Visa Start Banning VPN Providers

#73
post #57

Earlier quoted context omitted.

As a westerner working a tech job in China this is honestly a bad trend. How am I possibly going to live without access to Facebook?

Setup your own VPN.

Run squid on a VPS outside of China and use ssh port forwarding to access it. In my experience this works better than VPNs while in China, since the latter somewhat recently began to be targeted by the GFW.

Re: Mastercard and Visa Start Banning VPN Providers

#74

Earlier quoted context omitted.

This is the obvious answer for people with the technical skill to maintain a VPN server but what about everybody else?

Really, we've all been spoiled by credit cards. Checks, money orders, wire transfers, and even cash, all still work. And while I'm not aware of a properly turn-key solution for a VPN server, it should hardly be an epic undertaking to create one. Setting up a Linode account and running a StackScript is simple enough even for mostly-clueless people.

Using sshuttle[1] you don't even need to setup a VPN, just get a VPS and run a simple command on your client machine to connect.

[1] https://github.com/apenwarr/sshuttle

Re: Mastercard and Visa Start Banning VPN Providers

#75

Earlier quoted context omitted.

I suspect that most people who commit copyright infringement are not credit card thieves. However, I don't like drawing conclusions without evidence, and I don't think it should be considered naive to ask for evidence before making up one's mind. In fact, I'd consider it extremely foolish to do otherwise.

Well you did draw the conclusion that it was a "bold claim" without evidence... The phrase "bold claim" is usually reserved for cases where the claim seems unlikely.

I would say that any claim is bold if it is surprising or apparently important, and is not covered by multiple mainstream sources.

Examples are claims of majority (A majority of people are suffering from sickness A, B, or C), Or claims of superiority (My car is the fastest in the world).

Re: Mastercard and Visa Start Banning VPN Providers

#76

Keep in mind that this is about chargeback risk, not implementing some secret government policy. "Anonymizing VPNs" are a high risk service -- the people signing up for them are more often "bad guys" than tech professionals looking for privacy -- and they're signing up with stolen payment information. There are far more hackers, crackers, carders, "script kiddies", spammers and other people that need to hide their lo…

"the people signing up for them are more often "bad guys" than tech professionals looking for privacy"

I think this is always a bad argument to make. By that same logic they'd be banning all torrent sites, too, and a lot of other stuff, possibly even Bitcoin.

I think these VPN's should sue Mastercard and Visa, just like Wikileaks did, and won. They can't just decide "who is the bad guy" and ban them.

Re: Mastercard and Visa Start Banning VPN Providers

#77
VPN's are unique in providing translation from a dynamic IPv4, to multiple static IPv4. Since most ISP's won't give out enough static IPv4 addresses, if you want to run private servers at home then a VPN is more or less the only way.

Dynamic DNS can be used for a singular server, through how reliable depend on the TTL and how accepting other DNS resolvers are in accepting low TTL's (which in practice some aren't). However, if you are behind NAT, VPN is truly the only option for home servers.

Re: Mastercard and Visa Start Banning VPN Providers

#78
post #57

Earlier quoted context omitted.

Setup your own VPN.

This is the obvious answer for people with the technical skill to maintain a VPN server but what about everybody else?

You could always connect to a Lahana[1] node for emergency situations. It's not as quick as a normal VPN and you shouldn't run a torrent client through it, but it works.

[1] - http://lahana.dreamcats.org/

Re: Mastercard and Visa Start Banning VPN Providers

#79

Keep in mind that this is about chargeback risk, not implementing some secret government policy. "Anonymizing VPNs" are a high risk service -- the people signing up for them are more often "bad guys" than tech professionals looking for privacy -- and they're signing up with stolen payment information. There are far more hackers, crackers, carders, "script kiddies", spammers and other people that need to hide their lo…

As a westerner working a tech job in China this is honestly a bad trend. How am I possibly going to live without access to Facebook?

It's easy – all you need is a standard webserver (any VPS will do, check out Low End Box [1] or just use Digital Ocean [2]) and that's it. No need to install or maintain any kind of VPN or proxy software. Just use the following command to connect to your fresh server:

    ssh -D 8080 username@ipaddress
That will establish a local SOCKS proxy which you can configure your browser (or any other application that supports proxies) to use, with localhost as the address and 8080 as the port.

The biggest difference to a VPN is that you need to separately configure every application to use the local proxy – otherwise, everything sent over the local proxy is encrypted and securely transferred (thanks to the SSH protocol) just like with a VPN.

Of course, you can also install a VPN server if you want, but that's probably a bit more complicated.

[1]: http://www.lowendbox.com/ [2]: https://www.digitalocean.com/

Re: Mastercard and Visa Start Banning VPN Providers

#80
post #69

Earlier quoted context omitted.

Well, I can see why they haven't implemented that - its a huge undertaking to build specialized hardware like that into so much varied equipment. For all intents and purposes rolling out a system like that is impossible.

I don't believe it is materially more difficult than the NFC rollout. In fact, I believe it would be far easier than NFC if the financial industry would actually get behind it enthusiastically. I'm curious, what other undertakings do you think are impossible? WiFi? Bluetooth? GSM?

NFC isn't even close to completion, who knows when, if it ever will, get there. What you are missing is the massive infrastructure investment in retail terminals. There are millions of these things out there and they just work. The cost-benefit ratio of a scheme like yours just falls apart in the face of all that inertia.
Post reply on HN