I use ProtonVPN for everything, and I’ve started noticing more and more sites simply blocking me if I try to connect to them through ProtonVPN. As much as it sucks, I’ve more or less become acclimated to having to deal with an increased number of captchas while using a VPN; but I’m pretty angry about being blocked outright. There are at least two broad blocking tactics. First, some sites will say that my network traffic looks suspicious and/or that they simply block traffic from certain IP addresses. But second, and far more maddeningly, some sites tell me that my username and password combo are incorrect when I’m using a VPN. But I know this to be a blatant lie because (1) I use a password manager that auto-fills login forms with credentials that match the domain name, and (2) such sites accept my credentials when I visit them without the VPN connection.

What the hell can we do about this shit? Do I have to run my own VPN to avoid sharing an IP address with other people and thus getting blocked? I really don’t want to do that because I have neither the time nor expertise, and I like that connecting through a VPN provider makes my IP address much less significant. I’m aware that this is connected to the broader conversation about WEI and other methods for determining whether requests are legitimate or not, and I’m sure that businesses of all sizes are reeling from massive increases in bot and AI activity. But solutions that end up punishing legitimate users are not good or valid solutions.

40 points

far more maddeningly, some sites tell me that my username and password combo are incorrect when I’m using a VPN

permalink
report
reply
2 points

Tbf, the banks knows your information is correct and you’re using a vpn.

This is the banks way of saying " hey jackass turn off your VPN and come back…"

I suspect many people who run vpns full time, constantly forget to turn them off…

permalink
report
parent
reply
-7 points

At least they got that far.

There’s a good reason as a web server to block anonymizing VPNs. Turns out the bad guys use them too. Who knew.

permalink
report
parent
reply
27 points

That’s an inherent problem with shared connections.

The thing with sites telling you that your login is incorrect is also sometimes intentional, so people trying to brute-force logins won’t realize they’re getting blocked or just that their attempt was incorrect.

And yes, the only possibility is to try a different server that hasn’t been abused, or run your own.

permalink
report
reply
3 points

This is what 2FA is for

permalink
report
parent
reply
18 points

The real solution is to avoid these sites when possible

But this practice tells you what we all needed to know… They won’t serve u unless they can track you.

Vote with us feet cattle

permalink
report
reply
16 points

Proton VPN advised me to switch to a different server when one is blocked by a website. That usually works for me. I haven’t had the username and password problem though. I think the only sites I’ve had to turn my VPN off for were credit reference agencies.

permalink
report
reply
4 points
*
Deleted by creator
permalink
report
parent
reply
3 points

This has been working for me. Sometimes it’s just the country I randomly connected to and need to pick another random one.

permalink
report
parent
reply
16 points

We need laws that prevent companies from discriminating by how you look. Websites should only be able to deny customers based on how they act. A simple innocent GET from a user with a VPN IP should not be legally permissible reason to deny them.

permalink
report
reply
1 point

That thing where they claim the username/password combo is wrong?

That sounds like a really good idea if the site thinks the reason they’re a lot of different lock-on attemps from that one ip is because its a hacker with a list of stolen credentials.

Basically just tell them their list is fake and “go away and stop bothering our customers, please.”

permalink
report
parent
reply
1 point

I’ve had this exact scenario happen with my Amazon account. One the one hand its annoying, but on the other I don’t want them to make it easier for someone in another country to order stuff using my account and credit card.

permalink
report
parent
reply
0 points

Thats not a good idea because these systems false-positive all the time.

If my first login attempt has the correct username, correct password, and correct totp token, then I should always be let in. That’s literally how auth works.

permalink
report
parent
reply
3 points

Yes! 100% agree with this and your law proposal!

permalink
report
parent
reply
1 point

You’re right!

(Still think they might be doing just that, some of them.)

permalink
report
parent
reply

Privacy

!privacy@lemmy.ml

Create post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

Community stats

  • 6.6K

    Monthly active users

  • 2.9K

    Posts

  • 78K

    Comments