this post was submitted on 20 Nov 2023
499 points (97.9% liked)
MapPorn
3178 readers
1 users here now
Discover Cartographic Marvels and Navigate New Worlds!
Rules
- Be respectful and inclusive.
- No harassment, hate speech, or trolling.
- Engage in constructive discussions.
- Share relevant content.
- Follow guidelines and moderators' instructions.
- Use appropriate language and tone.
- Report violations.
- Foster a continuous learning environment.
founded 1 year ago
MODERATORS
you are viewing a single comment's thread
view the rest of the comments
view the rest of the comments
Thing is, a VPN isn't just some magic tool that lets you view location-restricted content and hides your IP address. It's a relatively basic networking concept.
Essentially, it allows you to connect two or more local networks, i.e. LANs, as if they were one big LAN.
In particular, that means no firewalls in the way, no weird NAT behaviour, no need to deal with public IP addresses and so on.
And it secures the whole communication with encryption + implements a form of authentication, so that you can leave the individual services within the VPN relatively unsecured (assuming you don't separately expose them outside the LAN/VPN).
Or more concretely, my dayjob uses a VPN for the whole home office thing. And I've used VPNs plenty times just as a networking tool in my software developer job. Prohibiting the entire concept of VPNs makes many software solutions impossible or annoying to build, and will cause folks to expose insecure services to the internet.
Please stop. VPN + TLS is essential. VPN does not mean you're automatically L2 bridged with a local segment. Changing source headers because your exit gateway is somewhere else does not hide IPs in any way. Many consumer level protocols have original source IPs in the payload.
I was talking about the networking concept of a VPN. If you use a VPN to connect into a foreign country, where you then make a web request from that remote LAN to some questionable webpages, you absolutely do want TLS for that connection. But that's separate from the VPN concept.
I don't know much about the consumer-grade services, but I have heard that lots of them are actually just proxies, not proper VPNs, which I guess, is what you're talking about. With a proper VPN, you initiate the web request, using an IP address in the range of the remote LAN that you're connected to. Therefore, fiddling with the headers is not necessary, in that case.
Ultimately, my point is that proper VPNs can do everything the consumer-grade stuff does, so for an effective ban, you would need to prohibit them, too, which is where lots of organizations/companies will be strongly opposed.
You're not understanding what I said. Or you're intentionally pretending to be at a junior level to misinterpret. I recommend picking up any edition of Computer Networks from Tanenbaum.
Why so hostile?
Because he's a self admitted crackhead, and they tend to be very emotional.
Are you interested in the answer or Internet points?