5 ms·
Time to use a VPN in your docker pipelines ;) Or run your systems outside of Spain. Or can this be avoided by using an alternate DNS?
by sigio 6mo ago
Time to use a VPN in your docker pipelines ;) Or run your systems outside of Spain.
Or can this be avoided by using an alternate DNS?
- darkwater 6mo agoThey are planning to also block VPN providers during football matches, see https://www.techradar.com/vpn/vpn-privacy-security/la-liga-wins-court-order-requiring-nordvpn-and-proton-vpn-to-block-illegal-football-streams-in-spain-but-vpn-firms-say-they-have-not-been-notified https://www.techradar.com/vpn/vpn-privacy-security/la-liga-w...
- prmoustache 6mo agoWhen talking about VPNs, it doesn't have to mean "third party VPN". You can host your own on any VPN service outside of Spain.
- darkwater 6mo agoYes, but that's not something many can do easily. Also already having to use a VPN is not the "right" solution. The right so solution is to beat some sense inside some politician's head, and force them to write and approve laws that don't let stupid (or conniving) judges pass orders like this one we are talking about.
- prmoustache 6mo agoI agree it is not the right solution. But anyone who is pulling docker images in a sunday afternoon while the rest of the country is glued to their screen to watch a football game or enjoying a sunny sunday outside having beers and tapas and what not should be capable of setting up wireguard.
- marginalia_nu 6mo agoGiven the context of the HN audience, it's probably something you can do.
- darkwater 6mo agoI wasn't strictly speaking about HNers. Using NordVPN and the likes is already done by slightly savvier users. Just look at where those products are advertised. Spinning up and provision a VPS to act as a VPN exit node in some other country raises the bar 10x or more.
- msh 6mo agoIt takes very light technical skills to deploy algo
- Mordisquitos 6mo agoThey are not "planning" to block VPNs. A technologically illiterate judge has ordered it, but there are no plans nor mechanisms to enforce it.
- chrismustcode 6mo agoIf they can block IPs of cloudflare what extra mechanisms would be needed to block VPN IPs?
- chmod775 6mo agoThe only viable way to even get most of them is to shut down internet access entirely. It's not a realistic solution, unlike blocking a few well known IP ranges belonging to a large corp like Cloudflare. And even if you managed to get them all beforehand, some VPN providers will adapt and keep some servers in reserve, putting them online just as you managed to block the previous ones. Getting around internet censorship is a large chunk of their business, and some are really good at it.
- echoangle 6mo agoYou don’t really need to block all, you just need to annoy the users enough that paying is easier. And I think there are enough games to use up the IP reserve pretty quickly and getting new ones every time is pretty annoying.
- chmod775 6mo agoI can provision a new VPS in about 5s of active work. I'd probably fully automate spinning up new servers and failing over because automatically detecting which got blocked is trivial. Bonus points if you use providers that let you attach multiple IPs to each VPS for cheap. Use some censorship resistant decentralized protocols to provide the next couple IPs to your client software and you're good. And then they still need to monitor hundreds of VPN providers for whether they have new IPs, which is not neccssarily as easy as just grabbing a list of them. Once they have some, they then need to forward them to the ISPs and ask for them to be blocked. Their process is significantly less friendly to automation. No country ever won this fight short of total shutdown/disconnects.
- ufocia 6mo ago"A _Sanish_ Court has ordered NordVPN and Proton VPN to block IPs transmitting illegal football streams" [emphasis added], that is inspain.
- skgsergio 6mo agoAlternate DNS doesn't help, they block at IP level. Yes, they block IPs belonging to CDNs (CF including R2, BunnyCDN, CDN77, Fastly, Alibaba, Akamai even)...
- littlecranky67 6mo agoIt is not a DNS based block, but on the IP level. Once I knew what caused the issue, I figured I use one of my Hetzner vServers as an exit node in tailscale. But come on, this can't be true. I wonder how many other people in IT wasted hours on issues and tickets to find out it is due to a football match taking place. Admittedly, chances are low, as football matches are usually outside of office hours.
- gred 6mo ago> run your systems outside of Spain So much for digital sovereignty :-)