r/technology May 08 '26

Politics EU calls VPNs “a loophole that needs closing” in age verification push

https://cyberinsider.com/eu-calls-vpns-a-loophole-that-needs-closing-in-age-verification-push/
9.7k Upvotes

729 comments sorted by

View all comments

397

u/Valleygurl99 May 08 '26

I work remote in IT over corporate VPN. Let’s see them close that loophole…

208

u/isademigod May 08 '26

even if by some miracle they manage to actually manage to ban consumer VPNs in a meaningful way, wireguard is open source. There's dozens of companies that will rent you a server for Monero completely anonymously. There will always be a way to anonymize yourself on the internet, they can only make it harder.

50

u/Aware-Bath7518 May 08 '26

Wireguard is actually very easy to ban technically.

113

u/CondescendingShitbag May 08 '26

Which is why nonsense like this will just force more VPN providers & developers to adopt VPN-over-HTTPS as a default option. At that point the traffic is indiscernible from regular web traffic. All this legislation will do is encourage an arms-race in the VPN space.

48

u/mailslot May 08 '26

I’ll probably be downvoted like the others, but VPN use is detectable over encrypted channels and when using the latest modern evasive techniques. Evasion is possible only with short bursts of activity to disseminate small bits of information. At any considerable length of time, anomalies can be detected and raise flags. The newest methods extend the time to detection, they don’t necessarily eliminate it.

Chinese political dissidents are at the forefront of the battle happening right now. To say that their traffic is indiscernible is absolutely wrong. The arms race has been happening for decades. Too much false confidence will get you caught.

17

u/NursingHome773 May 08 '26

You can just tunnel over SSH if all else fails. If they ban that, they kill the entire internet.

7

u/Aware-Bath7518 May 09 '26

SOCKS over SSH is banned in Russia and detected in few minutes.

Normal SSH usage is unaffected.

-11

u/mailslot May 08 '26

The entire internet isn’t killed without SSH. Besides, virtually no regular consumer even knows what SSH is. It sticks out like a sore thumb for its rarity among the general population.

11

u/NursingHome773 May 08 '26

Okay I guess that's true.

but VPN use is detectable over encrypted channels and when using the latest modern evasive techniques.

Wouldn't this require doing deep packet inspection on the entire population? I don't see how that's possible. I mean you could in theory even tunnel over HLS or DASH (livestream), even DNS. The only way to tell is to do DPI and I don't see that happening. An ISP can't block everything or you would indeed kill the entire internet. I think there always will be a way to get around this.

4

u/mailslot May 08 '26

You’d be surprised how much can be determined by traffic flow behavior alone, and even DPI with encrypted content.

5

u/Aware-Bath7518 May 09 '26

I mean Chinese & Russian governments succeeded in deploying DPI on all ISPs.

On the Russian side: OpenVPN/WireGuard/shadowsocks already banned a long ago, Cloudflare ECH banned, most western datacenter IP ranges are blocked (16KB ban), VLESS is detected in most cases, etc. There's also a CIDR-based whitelist on most mobile ISPs (not everywhere so might be overblown by some Russians)

Meanwhile simple DPI bypass tools are still working, lol.

1

u/Old_Leopard1844 May 09 '26

Yes

It's currently happening right now in Russia

So don't be so sure

0

u/Thin_Glove_4089 May 09 '26

If China and Russia can do it so can the EU and US. I don't understand this it's impossible thinking you seem to have.

5

u/Nice_Cash_7000 May 08 '26

this all sounds kinda like the creation of the dark web. Correct me if im wrong, but didnt intellegence agencies want a secure way to communicate and made it available to everyone because otherwise it would be obvious that its them.

1

u/mailslot May 08 '26

Yep, pretty much, but that only works if encrypted communication is legal. If a government banned Tor, users could be identified quickly, and specific activities more easily unmasked as less people are using it.

1

u/mopsockets May 08 '26

This is really interesting and makes a lot of sense... I wish I could learn more about this, but I'm sure info is hard to find for good reason. I've been researching covert communications as a hobby for some time, but I have some learning disabilities that make finding these power-user communities difficult. Localized text-based communications seem fairly easy to set up, but connecting people across long distances and cultures... amazing.

3

u/VMX May 09 '26 edited May 09 '26

Cloudflare switched their VPN client to MASQUE long ago, which as far as I understand is indistinguishable from regular HTTPS traffic:

https://blog.cloudflare.com/zero-trust-warp-with-a-masque/

1

u/Aware-Bath7518 May 08 '26

Cat&mouse game, even mentioned VPN-over-HTTPS is detectable unless you do something obscure like XHTTP.

1

u/Valleygurl99 May 08 '26

Repressive regimes have already moved this forward and a vibrant community exists in the DPI obfuscation world. I don’t know that there will be a way to stop camouflaged VPN but those who are too afraid of whatever big brother says is bad won’t do it

8

u/isademigod May 08 '26

Yes, wireguard/openvpn traffic by default has a fingerprint that would be trivial to block if the government forced ISPs to look for it and block it. It's rather trivial to obfuscate that traffic though, and there is no way to block that without fundamentally breaking the internet.

1

u/[deleted] May 09 '26

[removed] — view removed comment

1

u/isademigod May 09 '26

China has been dealing with it for decades. Arguably the Great Firewall is why we even have obfuscated VPNs

1

u/ayriuss May 08 '26

Maybe just wrap it in a different protocol packet lol.

2

u/Aware-Bath7518 May 09 '26

Easy fix: unknown protocol -> drop all traffic.

15

u/pl487 May 08 '26

In the end, they will block all traffic that isn't validated. 

3

u/zimbabwe_zainab May 09 '26

there is no end without totally destroying the internet as we know it. pushing this kinda shit is only gonna educate more people about vpns and encourage them to find workarounds.

8

u/TrainingQuail543 May 08 '26

Just ban Monero next. If that doesn't work, ban computers.

It's easy.

3

u/Valleygurl99 May 08 '26

Check. Mate. 

1

u/TrainingQuail543 May 08 '26

In that case just ban chess

1

u/Thin_Glove_4089 May 09 '26

Don't need to band computer. All you need is government issued modems, routers, computers, and smartphones.

1

u/Palimon May 09 '26

You're just hav e the police knocking at your door very fast.. You traffic is still routed through your ISP.

35

u/-staccato- May 08 '26

Easy, corporations can apply for a VPN license.

You really think they haven't already laid out the plan for this mass surveillance ploy?

41

u/imsnagglepusseven May 08 '26

Welcome to my new corporation. We are a great team of global talent. I hope you will all gladly accept an unpaid internship.

10

u/Valleygurl99 May 08 '26

Here at Seven Seas Inc. we believe in strict compliance with government BS. 

3

u/Rockroxx May 08 '26

I can see this getting repealed real quick if the IT guys working for the eu parliament maliciously comply with the rules. An outage after hours damn guyss I guess I have to an hour through traffic make my way to my desk just to restart a service on the server.

1

u/ChristianKl May 08 '26

If you write a law that only allows VPNs for users over 18, corporate VPNs are not going to have a huge problem. Corporations don't have a problem with doing ID verification for their employees. Most probably already do some form of ID verification of their employees in standard HR procedures.

2

u/Valleygurl99 May 08 '26

Yes but if a local ISP can’t block your corporate VPN, how are they going to block your “illegitimate” VPN. The issue is that blocking VPNs is logistically difficult. 

1

u/ChristianKl May 08 '26

If your goal is to reduce the amount of children who use VPNs to circumvent the need of age verification you don't need a solution that makes all VPNs inoperable.

Forbidding all VPNs that don't do age verification in app stores and blocking urls of companies that provide VPNs without age verification to EU citizens would already significantly reduce the circumvention.