this post was submitted on 27 Dec 2024
33 points (92.3% liked)

Privacy

32173 readers
1056 users here now

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

Related communities

much thanks to @gary_host_laptop for the logo design :)

founded 5 years ago
MODERATORS
 

So, for privacy and security reasons, I use a VPN. This is normally Mullvad (with DAITA and quantum resistance enabled), but I have ProtonVPN, Windscribe, and Orbot handy in case something doesn't work.

However, lately I've noticed my connections being blocked. This is across three different ISPs: Sky, Virgin, and Wifinity. I have tried all three VPNs and Orbot, and I have tried several protocols (WireGuard, OpenVPN, IKEv2, Stealth, and of course SOCKS5) to no avail.

The logical solution would be to use a bridge in Orbot, but the button seems to have been removed. Also, by using Orbot, I will not be protected by my DNS.

I am currently using iOS, but my other machines run Linux and I will be getting a GrapheneOS phone in the near future.

Can anyone help?

top 17 comments
sorted by: hot top controversial new old
[–] [email protected] 35 points 3 days ago (1 children)

AFAIK the IPs used by VPN providers are getting flagged and blocked by certain sites in an attempt to force you off of the VPN so they can suck up your data. I'm sure there are other reasons too.

[–] [email protected] 3 points 2 days ago

yeah. and the can suck up whatever they want, I'll just go somewhere else. no website is unreplaceable

[–] [email protected] 2 points 2 days ago

If you are failing to connect to VPN, try changing the MTU to a lower setting like 1376 or something. Then connect using wireguard protocol.

[–] [email protected] 11 points 3 days ago (1 children)

Blocked?

As in VPN failing to connect?

Or the website you are attempting to visit giving you an error?

Btw, Proton VPN's latest version of the app has "Stealth" mode to attempt to bypass censorship, have you tried that?

The lastest version of Orbot has a line below "Start VPN" that says "Choose how to connect" tap that and choose a bridge.

Also, what country are you in, if you don't mind me asking? (I don't recognize the names of those ISPs)

[–] [email protected] 7 points 3 days ago

VPN failing to connect. Stealth mode didn't work, as described above. I'm in the UK.

Another user provided a working solution:

@hellfire103 I bet it's the DAITA on your Mullvad, choose MultiHop instead with Wireguard, quantum resist. and obfuscation . Then use a Linux set from boot SOCKS5 as you desire. I hope it helps.

However, alternative solutions would be appreciated.

[–] [email protected] 8 points 3 days ago

Other than DAITA, Quantum resistance may also be a problem. From experience, the key exchange needs near-perfect connection, otherwise it keeps failing.
This is further made into a problem by Android's private DNS handling. If it times out for long enough (seems like 10 seconds), then even after Mullvad finally connects, the DNS won't work.

[–] [email protected] 4 points 3 days ago

Orbot supports bridges, but not all of them. What's worse, the one type they lack is webtunnel, which would've likely helped (although, there's this fork). The option configure 'em was moved into the connection dialog.

[–] [email protected] 4 points 3 days ago

That sounds like it might be some sort of local issue with your configuration, but without more info we could only guess

[–] [email protected] 4 points 3 days ago

I am looking into obfuscation methods used in China now, like v2ray/VLESS/XRay. Maybe this would be the direction you'd want to go. I'd start with a good comparison article.

[–] [email protected] 3 points 3 days ago

Omg same. In my case I use random open servers with xray. Usually servers located in France and Germany are blocked, but servers with Chinese info on them still work (not located in china, just description and title contains Chinese).

[–] [email protected] 3 points 3 days ago (1 children)

Blocked as in sites reject traffic, or blocked as in can't connect to the VPN?

The former is on the far end and not uncommon. A lot of sites reject connections from known VPN endpoints because the same tunnels that provide privacy to you also provide privacy to attackers quit often. You just need to decide if the site is important enough to use without a cover.

If it's the latter, that would be a near end issue and would likely be your ISP or someone nearby that is looking to control your traffic.

[–] [email protected] 4 points 3 days ago

It's the latter. Damn Virgin!

Fortunately, another user provided a working solution:

@hellfire103 I bet it's the DAITA on your Mullvad, choose MultiHop instead with Wireguard, quantum resist. and obfuscation . Then use a Linux set from boot SOCKS5 as you desire. I hope it helps.

However, alternative solutions would be appreciated.

[–] [email protected] 1 points 3 days ago (1 children)

When you try to ping something on the internet do you know if the packets get dropped or rejected?

[–] [email protected] 1 points 3 days ago (1 children)

Normally dropped. Another kind user has provided a working solution, but please continue. The more solutions, the better!

[–] [email protected] 4 points 3 days ago (1 children)

Please let us know what solution you found?

[–] [email protected] 5 points 3 days ago (1 children)

@hellfire103 I bet it's the DAITA on your Mullvad, choose MultiHop instead with Wireguard, quantum resist. and obfuscation . Then use a Linux set from boot SOCKS5 as you desire. I hope it helps.

[–] [email protected] 3 points 3 days ago