I use ProtonVPN for everything, and I’ve started noticing more and more sites simply blocking me if I try to connect to them through ProtonVPN. As much as it sucks, I’ve more or less become acclimated to having to deal with an increased number of captchas while using a VPN; but I’m pretty angry about being blocked outright. There are at least two broad blocking tactics. First, some sites will say that my network traffic looks suspicious and/or that they simply block traffic from certain IP addresses. But second, and far more maddeningly, some sites tell me that my username and password combo are incorrect when I’m using a VPN. But I know this to be a blatant lie because (1) I use a password manager that auto-fills login forms with credentials that match the domain name, and (2) such sites accept my credentials when I visit them without the VPN connection.

What the hell can we do about this shit? Do I have to run my own VPN to avoid sharing an IP address with other people and thus getting blocked? I really don’t want to do that because I have neither the time nor expertise, and I like that connecting through a VPN provider makes my IP address much less significant. I’m aware that this is connected to the broader conversation about WEI and other methods for determining whether requests are legitimate or not, and I’m sure that businesses of all sizes are reeling from massive increases in bot and AI activity. But solutions that end up punishing legitimate users are not good or valid solutions.

  • u/lukmly013 💾 (lemmy.sdf.org)@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    13
    ·
    11 months ago

    This is extra maddening with my banking app recently. I even set up split tunneling for it, but it still somehow figures out the VPN. The problem is, it doesn’t let me do ATM withdrawals nor generate one-time virtual cards. Ironically, it still let’s me view full details of my physical card…

    So just disconnect from VPN? Oh, not so fast. It remembers that VPN was used at some point, and I’ll have to deactivate the app and then reactivate it without ever connecting to VPN.
    Since I have to deactivate and reactivate it daily, immediately when needed, this has led me to decreasing the security by using virtual card reader for 2FA kept on same device as opposed to using physical one and keeping it at home as I used to before this BS.

    This is what I mean by the physical 2FA card reader:

    Yes, that’s the only thing at hand I had to cover the card number :)

    • privacybro@lemmy.ninja
      link
      fedilink
      English
      arrow-up
      1
      ·
      11 months ago

      Just make another user profile and dont put a vpn on it (assuming android)

      Also it still knows you’re using vpn because split tunnel still uses the VPN provider’s DNS server, so sounds like they are also checking who you DNS provider is.

      They sound like complete scumbags. Switch banks lol.