I know it isn’t specific to just Linux but I use Linux anyway so my question is,

Is there a way you could use a VPN without them knowing that? Or if they outlaw them is it really just game over?

If they made VPNs illegal I suppose stuff like TOR would follow except TOR is partly funded by the US state department and the US is one of my countries closest allies (one of the five eyes). So surely they wouldn’t shut down something the US funds directly… Would they?

I’ve read very very little about Gemini and other protocols like Gopher, would this be the way forward if they do this? And is that even remotely close to the security and potential anonymity you would receive from a VPN?

    • BD89 ( BD89@lemmy.sdf.org ) OP
      link
      fedilink
      arrow-up
      13
      ·
      11 months ago

      Can your ISP not tell you’re using a VPN?

      Would it not be easy for them to block access to VPNs if they outlaw them?

      What do you do then?

      I guess a better way to phrase the question is if they are outlawed how can I use one without my ISP knowing.

      If your ISP can tell you’re using a VPN then yes, making them illegal would prevent me from using them right?

        • Random Dent ( CrabAndBroom@lemmy.ml ) 
          link
          fedilink
          English
          arrow-up
          9
          ·
          11 months ago

          I can see the UK doing this, they love to implement ludicrously restrictive and impossible to enforce anti-privacy laws. My working theory is that they’re lobbied to implement them by IT consultancy firms, who then get hired to consult on, say, banning VPNs, take 10 years to investigate it at eye-watering cost to the public, then go “Yeah turns out you can’t ban VPNs, I don’t know what the previous government was thinking” and then use that money to lobby the new government to ban encryption or some other nonsense, then repeat.

          • Ŝan • 𐑖ƨɤ ( Sxan@piefed.zip ) 
            link
            fedilink
            English
            arrow-up
            4
            ·
            11 months ago

            Þe absolute best feature of beaurocracy is how inefficient it is. The Principia Discordia tells us:

            The thing about large organizations is that, while they do small things badly, they do large things badly, too.

      • Sometimes.

        They can keep a record of VPNs and monitor if you connect to their servers, or block that connection altogether.

        The problem with this is that new VPNs come and go all the time and active VPNs don’t always have static configurations. It would be impossible for them to reliably track all of them.

      • There is some nuance to what exactly is banned.

        I self host a vpn at my home that i use to connect to my home network on the go. This is a super common use-case and also cant be used to circumvent regional blocks.

        Work also uses a vpn to securely tunnel company hardware to our servers.

        A blanket ban on vpn software and technology would be ridiculously dumb. Almost as bad as blanket ban on encryption.

        If they make exceptions and only ban vpn with intention to hide and circumvent the law, then you only need some legal excuse if someone comes asking and its more a morality guideline then a criminal law.

        If they blanket ban “vpn technology” i would simply suggest ignoring it. Laws that stupid are too incompetent to take seriously. I recon its completely unenforceable.

        Either way you’re unlikely to be investigated unless the government already has a reason to investigate you. In which case you’re probably fucked no matter how secure your internet.

      • NedRyerson ( NedRyerson@lemmy.ml ) 
        link
        fedilink
        arrow-up
        2
        ·
        11 months ago

        Somewhat. They can certainly maintain a list of known IP addresses. Those IPs can be changed.

        When they change, you as a user need to be able to find the new addresses. Whatever mechanism you can use, your ISP can likely disrupt too. For instance, they can DNS block the API that returns the list of possible endpoints (as sometimes happens to Proton where I live).

        You can then counter by using private DNS. It’s a cat and mouse game.

  • brewery ( brewery@feddit.uk ) 
    link
    fedilink
    arrow-up
    19
    ·
    11 months ago

    I don’t know how any company I’ve worked for would operate, especially when headquartered in another country. They’ll just have to fire everyone in that country rather than compromise their security

      • hendrik ( hendrik@palaver.p3x.de ) 
        link
        fedilink
        English
        arrow-up
        1
        ·
        11 months ago

        I’ve heard they have government-approved VPN providers. And companies there use VPNs for their job. They’ll also do business on platforms which are blocked on the regular Chinese internet. Of course business is guided by the communist party so you might have someone keeping an eye on your company VPN (mis)use. People who went there told me they’re more lenient with foreigners. Your European/American company’s corporate VPN might work well, you might also experience connections being dropped and the Great Firewall messing with it. And there are some attempts at circumventing blockage, like TOR’s Snowflake, though all of this is a cat and mouse game, some (illegal) thing works for a while and then they shut it down and you’ll move to the next one. Though as a citizen of an oppressive regime you’d better think twice before engaging in a cat and mouse game with authorities.

  • hendrik ( hendrik@palaver.p3x.de ) 
    link
    fedilink
    English
    arrow-up
    14
    ·
    edit-2
    11 months ago

    It’d be a really bad situation. I mean we rely on VPNs and tunnels a lot. For half the people doing home-office, logging into the company’s VPN is the first thing in the morning. Field crew relies on them. That’s an additional layer of protection in the ATM of your bank…

    It’d wreck half the economy in the process. Or “they” need to outlaw specific things. Like private VPNs. And gather a list of private VPN providers and ban them via a great firewall. That’s possible. And would make life worse in a country. It’s possible to circumvent these measures. And it’s difficult to discern traffic and distinguish VPN traffic from other encrypted traffic so the country might want to implement some harsh measures as well. A police force knocking on people’s doors if they suspect them to evade law and demand they show their computer and smartphones.

    So in conclusion your best option is probably to move to a different place if you can afford to, once that becomes reality. (Edit: Maybe your best option is to protest this, do campaigns, call your representative and try to stop it. So we dont get into this situation in the fist place.)

  • DarkAri ( DarkAri@lemmy.blahaj.zone ) 
    link
    fedilink
    arrow-up
    13
    ·
    edit-2
    11 months ago

    You could buy a webserver outside the country and set up your own VPN software or something. I think there are forms that look like https.

    You should probably try to tell at least one person a week to never vote for those people again and try to resist your oppressive state in every way you can without getting yourself in trouble or hurt.

    Also try to do anything you can that they don’t want. If the powerful people in your country want something, try to oppose them. Don’t let them just shit on you and get away with it.

  • Kevin ( kmacmartin@lemmy.ca ) 
    link
    fedilink
    arrow-up
    11
    ·
    edit-2
    11 months ago

    You could rent a VPS in a neutral country and use ssh to create a SOCKS proxy to it, then use foxyproxy to add the proxy to firefox/librewolf/whatever and either allowlist certain sites you don’t want your country knowing about or denylist websites you don’t care if your country knows about (especially higher bandwidth sites that aren’t controversial like YouTube).

    At that point you’d have plenty of “real” traffic from the unproxied websites and any traffic the rest of your OS is using, and when you access the proxied sites you want to hide it’ll look like you’re using ssh and/or scp.

    You could also create a proxy server with a tor connection on the server and use ssh port forwarding to access it locally. The Mullvad browser + foxyproxy would probably be your best bet for using that since it’s basically tor browser without tor.

    EDIT: Additionally, if you wanted to proxy an application that doesn’t support SOCKS internally, you can configure proxychains with the proxy and then launch proxychains applicationname.

    • +1 ro this. The obfuscation tunnels traffic through the QUIC protocol used by https/3. Basically, it’s almost impossible to block QUIC without sabotaging the web. This is opposed to traditional VPN connections, which send encrypted (usually AES) packets over UDP, which is much easier to tell is a VPN.

  • communism ( communism@lemmy.ml ) 
    link
    fedilink
    arrow-up
    7
    ·
    11 months ago

    Most popular VPNs have some form of obfuscation options in their apps. But if you’re using e.g. raw Wireguard you won’t be able to use their obfuscation function.

    Btw technically they can’t really outlaw VPNs as a whole, only commercial/“privacy” VPNs. They couldn’t really tell if you’re e.g. using your friend’s PC as a VPN to access their LAN, since it’s a residential IP. Unless they’re looking for Wireguard packets, but that seems like an unlikely law since it’d piss off a lot of businesses that use VPNs to let their workers access the company intranet at home.

  • zippyEnjoyer ( zippyEnjoyer@lemmy.zip ) 
    link
    fedilink
    English
    arrow-up
    5
    ·
    11 months ago

    Until the “whitelist” principle is implemented for the network—you’re fine. You’ll be able to use stealth protocols, whose traffic is practically indistinguishable from regular HTTPS traffic to any website.

    You might ask:

    But won’t the internet censor notice that suspiciously large amounts of traffic are going to a single IP and block it?

    you’d be right, but only in the case where your server is configured incorrectly. nothing stops you from finding a hosting provider whose subnet contains YouTube caching servers and disguise your traffic as coming from there. then, to the censor, everything will look natural, since traffic is indeed going to YouTube.

    Once you have your own proxy server, you can create proxy chains to well-known services like Mullvad, IVPN, Proton, etc. Your intermediate server won’t see the traffic, so your privacy will be just as strong as when using these popular services directly—except with slightly higher ping.

    You might say: what if they introduce those very whitelists, allowing access only to IPs within your country of residence? Like in North Korea?

    I’ll answer: first, it’s unlikely to happen overnight, as it would be a fatal blow to the country’s economy. Second, even with whitelists, there are ways around them. In Russia, many people rent Russian CDNs (content delivery networks that reduce ping to services) and use them as an intermediate layer between a foreign server and themselves.

    Why can’t the censor block them? Because large companies use them—so blocking these CDNs would also break taxi services, banks, and many other services included in the whitelist.

    So it’s not that bad. The main thing is to have the will to fight for your rights, for your freedom. And methods, one way or another, will remain even under the strictest regimes :)