6 ms·
I recently switched to whole-home VPN by routing everything except a few external services through a wireguard connection on pfSense. Have to say I'm pretty ha
by jmole 2y ago
I recently switched to whole-home VPN by routing everything except a few external services through a wireguard connection on pfSense.
Have to say I'm pretty happy with it compared to running a random VPN client on my computer. Funnily enough, the only thing I've been unable to access while behind VPN was downloading a windows ISO direct from microsoft to reset a laptop.
- freedomben 2y agoI tried this, but the CAPTCHAs make browsing nearly impossible and (I think) are what breaks many of the devices on my network, and when it's on the whole home network from the router, it's a lot harder to turn it off when I just need to get something done. I'll probably end up spinning up an exit node on Linode or something, but I tried that on certain machines and it had some significant performance implications (though I'm not geographically near a datacenter so it probably wouldn't be the same problem for most people).
- jsheard 2y agoI gave up on VPNing my whole network when it progressed past CAPTCHAs and into getting blocked outright. Hard CloudFlare errors with no challenge, or getting my connections null routed altogether. Life's too short for this shit I'm afraid.
- blueflow 2y agoWhat tf did you do to get your ranges blacklisted?
- jsheard 2y agoProbably the fact that I was using Mullvad, the flipside of their commitment to privacy is they can't really do anything about abuse coming from their IP ranges and they inevitably end up on blacklists. With the desktop client you can at least mash the reconnect button until you get an IP that works, but that's a hassle if you are running the tunnel somewhere else.
- mlv- 2y agoYou'll get more CAPTCHAs and other issues with other VPNs, too, their IP addresses are just too easy to identify. VPNs with residential IP addresses can be a different experience, but they're a bit pricey if you can't justify their use as a business expense.
- pogue 2y agoWhat are some paid VPNs with residential IP addresses? I've always wondered why they don't just mask them as looking like ones anyway.
- kccqzy 2y agoWell you made the conscious choice to make your own traffic indistinguishable from abuse traffic.
- jsheard 2y agoYeah I get it, I'm not blaming anyone for shitlisting those IP ranges given the circumstances. There is no way to ensure user privacy that doesn't also give bad actors the same privacy, and end up necessitating the assumption that anyone who goes out of their way to be private is a bad actor. This is why we can't have nice things.
- kccqzy 2y ago> There is no way to ensure user privacy that doesn't also give bad actors the same privacy I disagree. There are upcoming technologies that have the potential of making this a reality. Like Private Access Tokens (https://www.ietf.org/archive/id/draft-private-access-tokens-01.html https://www.ietf.org/archive/id/draft-private-access-tokens-...) and its successor protocols, the Privacy Pass suite of protocols (split over many documents https://www.ietf.org/archive/id/draft-ietf-privacypass-architecture-16.html https://www.ietf.org/archive/id/draft-ietf-privacypass-archi... https://www.ietf.org/archive/id/draft-ietf-privacypass-auth-scheme-15.html https://www.ietf.org/archive/id/draft-ietf-privacypass-auth-... https://www.ietf.org/archive/id/draft-ietf-privacypass-protocol-16.html https://www.ietf.org/archive/id/draft-ietf-privacypass-proto... https://www.ietf.org/archive/id/draft-ietf-privacypass-rate-limit-tokens-06.html https://www.ietf.org/archive/id/draft-ietf-privacypass-rate-...) and so on. These efforts are spearheaded by Apple, Google, Cloudflare and Fastly. Of course Apple has iCloud private relay so they have incentives to make such things work well with iCloud private relay. Google has Google One VPN too. It also has reCAPTCHA that's widely used to block abuse traffic. Cloudflare and Fastly of course are big CDNs. Imagine a world where visiting a website over a VPN, and these tokens clearly distinguish you from abuse traffic while preserving your privacy, so that Cloudflare has no reason to present you with a CAPTCHA and reCAPTCHA gives you that tick without forcing you to pick pictures of motorcycles. Watch this space. Very interesting developments here.
- autoexec 2y ago> I tried this, but the CAPTCHAs make browsing nearly impossible Not even on a VPN and I get them all the time. Duckduckgo demanded one from me just this morning. To their credit, you don't even need JS enabled for what they're using.
- cjk2 2y agoYou get them a lot if your ISP uses CGNAT. Mine I have a static IPv4 and I rarely if ever get them.
- BrandoElFollito 2y agoAre ISPs in your country providing CGNAT addresses to your router? (as opposed to public IPs) In France this is always a public IP (fixed it but, it depends) - at least for all four major ISPs
- AureliusMA 2y agoI’m in France and I get CGNAT.
- BrandoElFollito 2y agoFrom which ISP?
- dspillett 2y ago(UK here, things will vary from place to place) Long-established ISPs generally have real IPv4 addresses to give out, though they are not statically allocated. If your router is on 24/7 you tend to have the same address for a long time, but it isn't really static. Newer ISPs are more likely to be using CGNAT. True static IPv4 is available from some ISPs, particularly those that target small/medium businesses as much as (or instead of) residential users. On mobile you are pretty much guaranteed to be behind CGNAT, though I don't think anyone would expect to have anything remotely static in that circumstance anyway. I have static IPv4 at home (actually a /29 – I've had this account long enough that it wasn't difficult to get back then, and the ISP is more commercially targetted), and VPN to that when mobile. Probably makes me easier to track by stalkers not blocked by PiHole and other such provisions, but it does mean I don't often see CAPCHAs. My VPN use is for protecting myself from potentially bad local networks, rather than hiding my ID or falsifying my location (or where location matters, I'm pretending to be at home not some other place), which is a different set of priorities to many.