u/Timely_Dealer_654

Europe wants to set actual security standards for VPNs

This is pretty interesting. Europe is working on a new common security standard specifically for VPN services. The idea is basically to move away from VPN companies just saying “we don't log your data” or “we use military-grade encryption” and actually have some common rules behind those claims.

The proposed standard covers things like no-logs policies, RAM-only servers, opt-in telemetry, better protection of user data, regular security testing and faster security updates.

It's not final yet, but it could eventually become part of how VPN providers demonstrate compliance with EU cybersecurity rules. I actually think this could be good for the industry. There are hundreds of VPNs making basically the same privacy claims, and it's pretty difficult for the average person to know which ones are actually trustworthy.

The big question is whether this will genuinely improve VPN security or just become another certification logo companies put on their websites.

reddit.com
u/Timely_Dealer_654 — 1 day ago

Proton VPN usage jumps 600% in Oman as TikTok reportedly becomes inaccessible

Looks like something weird is happening with TikTok in Oman. According to TechRadar, people across the country started reporting that TikTok was suddenly inaccessible, despite no official announcement of a ban.

At almost the exact same time, Proton VPN Free sign-ups in Oman exploded, peaking at around 600% above normal levels.

The spike reportedly started around August 13 and coincided with users complaining online that they could no longer access TikTok normally. It's another example of how quickly people turn to VPNs when access to a major platform suddenly disappears.

What I find interesting is the lack of transparency. If TikTok is actually being restricted, shouldn't users at least be told why? Anyone from Oman here? Is TikTok still blocked for you, and does it work normally when using a VPN?

reddit.com
u/Timely_Dealer_654 — 2 days ago

The EU is introducing new security rules for VPNs and honestly, this could be a good thing

The EU is getting ready to introduce stricter security requirements for VPN providers under its Cyber Resilience Act.

Basically, VPN companies operating in Europe will have to meet clearer standards around things like encryption, authentication, vulnerability management and secure software development.

What's interesting is that the VPN industry actually helped shape the standard, with companies like Proton VPN and NordVPN involved in the process.

And IMO, this isn't necessarily another "EU wants to regulate VPNs" story. There are a lot of random VPNs out there claiming to offer "military-grade encryption" and perfect privacy, while users have basically no idea what's happening behind the scenes. You're routing your entire internet connection through these companies, so having some minimum security requirements doesn't sound crazy.

The downside is that compliance costs could potentially make life harder for smaller VPN providers. But if this helps weed out some of the sketchy free VPNs and forces providers to actually back up their security claims, I'm all for it.

reddit.com
u/Timely_Dealer_654 — 3 days ago

France is now ordering VPNs and DNS providers to block pirate streaming sites

Looks like the fight against illegal sports streaming in France is moving way beyond just blocking websites.

Canal+ recently obtained 14 court orders ahead of the new Premier League and Champions League seasons. Free, Orange, SFR and Bouygues have been ordered to block dozens of domains linked to illegal streaming/IPTV.

But here's where it gets more interesting: the orders also target public DNS providers and VPN services, including Google DNS, Cloudflare, Quad9, DNS4EU, Proton VPN, CyberGhost and ExpressVPN. Google and Bing are also required to remove the targeted domains from French search results.

CyberGhost and ExpressVPN reportedly challenged the requests, but the court rejected their arguments. The reasoning is basically that even a neutral intermediary can play a role in allowing users to access illegal content.

And the blocklist isn't necessarily fixed. New domains can reportedly be added during the season after validation from Arcom, with measures potentially remaining in place until May/June 2027.

Obviously piracy is one thing, but forcing VPNs, DNS providers, ISPs AND search engines to participate in blocking raises a much bigger question IMO.

Feels like we're slowly moving from "block the pirate website" to "block every possible way of reaching it."

reddit.com
u/Timely_Dealer_654 — 6 days ago

Internet freedom in Central Asia is heading in the wrong direction

Just read an interesting piece about how different internet access can be across Central Asia depending on which side of a border you're on.

Turkmenistan is by far the craziest example. Researchers tested 15.5M domains and found 122,000+ intentionally blocked, while filtering rules accidentally made another 5.4M+ domains inaccessible. Apparently, working VPN access has even turned into a black market, with VPN keys reportedly selling for around $50/month. But it's not just Turkmenistan.

Kazakhstan has blocked independent news sites and dozens of circumvention/VPN services. Tajikistan has literally shut down internet access for months during periods of unrest. Uzbekistan still uses blocking and surveillance, while Kyrgyzstan remains relatively more open, although restrictions there have been increasing too.

What I find kinda crazy is how VPNs go from being a "nice privacy tool" in some countries to basically being someone's gateway to the normal internet in others. And then governments block the VPNs too... so it becomes this endless cat-and-mouse game.

reddit.com
u/Timely_Dealer_654 — 7 days ago

737 fake VPN extensions were found on Chrome

This is a pretty good reminder to stop downloading random “free VPN” extensions.

Researchers found 737 suspicious VPN/proxy extensions, including 274 pretending to be legit brands like Proton VPN, NordVPN, Surfshark and ExpressVPN.

So you think you're using a trusted VPN, but you're potentially sending your traffic through some random third party instead.

And these extensions had already reached 75,000+ installs. Free VPNs were already sketchy enough. Now apparently you also need to check if the VPN you downloaded is even the real one

Always download VPN apps/extensions from the provider's official website.

reddit.com
u/Timely_Dealer_654 — 8 days ago

Hackers are now using fake job interviews to trick people into installing malicious VPNs

According to The Hacker News, a Russian state-linked hacking group has been targeting IT professionals with fake job offers and interviews. And the scam is actually pretty convincing.

It starts normally: a “recruiter” contacts you about a job, moves the conversation to Telegram, and eventually organizes what looks like a legit Zoom interview.

Then comes the technical test. They ask the candidate to connect to the company's “corporate VPN.” First they provide a WireGuard configuration that conveniently doesn't work. Then the recruiter says something like “No worries, just install our VPN client instead.”

That's where you're screwed. The VPN, called SopraVPN, is actually a modified version of the legitimate open-source WireGuard client. Once installed, it can secretly execute commands on your computer and download additional malware.

The important detail: WireGuard itself wasn't hacked or compromised. The attackers simply took legitimate open-source software, modified it, and repackaged it as their own VPN.

Pretty clever social engineering when you think about it. Most people would probably be suspicious of a random .exe sent over Telegram, but a “corporate VPN” during a technical job interview? That sounds way more believable.

Would you have caught this, or would you have installed it?

reddit.com
u/Timely_Dealer_654 — 9 days ago

VPN use seems to be blowing up across Latin America

I knew VPNs were getting more popular globally, but I didn't realize how quickly they were growing in Latin America.

According to a recent LatinAmerican Post article, LATAM already represents around 8% of the global VPN market, and apparently almost 1 in 3 internet users in Brazil and Mexico regularly use a VPN.

And there have been some pretty wild spikes lately. When Argentina blocked 70+ domains linked to pirate streaming sites, VPN demand shot up and Proton VPN reportedly became the country's most downloaded free app. During the World Cup, demand for Brazilian IPs also got so crazy that Proton had to add 89 new servers in Brazil in just one week.

What's interesting though is that it doesn't seem to be only about getting around streaming restrictions anymore. More people are using VPNs because of privacy concerns, public Wi-Fi, remote work, online banking, tracking, censorship, etc.

With Brazil having roughly 185 million internet users and Mexico around 110 million, that's a pretty massive market if VPN adoption keeps going this way.

The only downside is that the boom also attracts a ton of sketchy "free VPN" apps that make money through ads, tracking or user data... which is pretty ironic when you're downloading the thing for privacy in the first place.

reddit.com
u/Timely_Dealer_654 — 10 days ago

EU study wants sports piracy blocked within 30 minutes, and apparently VPNs should become internet cops too

This is getting interesting. A new study commissioned by the European Parliament is recommending much faster blocking of illegal live sports streams, potentially within 30 minutes.

Fair enough, go after piracy. But the controversial part is who they want involved.

The proposal isn't just about ISPs or pirate streaming sites. It suggests extending obligations across the infrastructure chain, including VPN providers, DNS resolvers, CDNs and hosting providers.

And that's where I think we're heading into dangerous territory.

A VPN's job should be pretty simple: encrypt my traffic, protect my IP and give me a private connection to the internet. It shouldn't be deciding which websites I'm allowed to access because some external authority added an IP/domain to a rapidly updated blacklist. Especially when we've already seen how messy these blocking systems can get.

The report itself acknowledges the risk of overblocking, and TorrentFreak highlights what happened in Spain: research found more than 554,000 domains were blocked at least once during football-related blocking, with legitimate infrastructure/sites getting caught in the crossfire.

That's the problem with "just block the IP." One IP can host a ton of completely unrelated services. I'm obviously not arguing that VPNs should exist to facilitate piracy. But forcing privacy tools to become another layer of internet enforcement feels like a pretty bad precedent.

Today it's illegal football streams. What gets added to the mandatory blocking list tomorrow? IMO, VPNs should protect your connection, not police it.

reddit.com
u/Timely_Dealer_654 — 10 days ago

Australia banned social media for under-16s. 81% are still using it anyway

So Australia introduced one of the toughest social media laws in the world, basically banning under-16s from platforms like Instagram, TikTok, Snapchat, Facebook, etc.

Sounds effective on paper. Except… 81% of under-16s are apparently still using social media. Before the ban it was 86%. So after all that regulation, age verification and millions of accounts being blocked, usage dropped by… 5 percentage points.

And teenagers are doing exactly what everyone predicted: lying about their age, creating new accounts, using adults' accounts and, yep, using VPNs to bypass restrictions.

Platforms have already removed or restricted millions of accounts, but apparently that doesn't mean millions of actual kids disappeared from social media. One teenager can obviously have multiple accounts across multiple platforms.

There are some signs the ban is having some effect though. Snapchat usage among 13–15 year olds reportedly dropped around 40%, and some parents say their kids are spending more time offline. Still, the 81% number is pretty wild.

This is kinda the problem with trying to regulate the internet through age verification and blocking. Teenagers have spent their entire lives online. Give them a restriction and five minutes later they're googling how to get around it lol.

And Australia isn't alone anymore. France and several other countries are moving toward similar restrictions.

reddit.com
u/Timely_Dealer_654 — 11 days ago

Turbo VPN was literally leaking users’ real IPs… even after they “fixed” it

This one is kinda insane. TechRadar discovered that Turbo VPN’s Windows app was leaking users’ real IPv6 addresses. You know… the exact thing people install a VPN to prevent.

Turbo VPN released a fix. Problem solved? Nope.

TechRadar tested it again and the IP leak was still happening across every protocol they tested. They had to contact Turbo VPN AGAIN, provide more evidence, and only then did a second emergency update apparently fix the issue.

Sorry but how does a VPN company not catch this themselves?

We're not talking about some random UI bug or the app crashing. The product designed to hide your IP was exposing your IP. That's like buying a password manager that accidentally publishes your passwords.

And this is why I think the VPN industry deserves way more scrutiny. There are hundreds of VPNs screaming "MILITARY-GRADE ENCRYPTION" and "TOTAL PRIVACY" while the average user has absolutely no way of knowing whether the thing actually works.

Turbo VPN deserves some credit for eventually fixing it, but TechRadar shouldn't have to basically QA-test a privacy company's product for them.

Makes me wonder: how many VPNs are leaking user data right now and nobody has noticed yet?

Personally, if a VPN fails at literally its #1 job, I'm uninstalling it.

reddit.com
u/Timely_Dealer_654 — 12 days ago

It's not because you use a VPN that you can't get hacked too

We always hear “use a VPN to stay safe online.”

Cool. Except… what happens when the VPN itself has a security hole?

That’s basically what happened with a vulnerability affecting Check Point’s VPN/security gateways. Hackers were reportedly able to bypass authentication and get a VPN session without actually being properly authenticated. The flaw was even linked to ransomware attacks.

And honestly, this is a pretty good reminder that a VPN isn’t some magic shield.

For companies especially, a VPN can basically be the front door to their network. If that door has a broken lock and nobody fixes it, hackers don’t need some Hollywood-level hacking skills. They just walk in.

Same goes for browsers, backup servers, firewalls, etc. A lot of hacks aren't crazy sophisticated, someone simply found a known security hole that hadn't been patched yet.

So yeah, use a VPN. But keep your apps and devices updated too. “Security software” still needs security

reddit.com
u/Timely_Dealer_654 — 13 days ago

US Cyber Director says cybersecurity has too much red tape. Good news for VPNs?

The US National Cyber Director just said something I didn't expect to hear at Black Hat: cybersecurity companies are spending way too much time dealing with regulations instead of actually improving security.

The idea is to cut overlapping compliance requirements and let security companies focus on stopping real threats rather than ticking boxes.

For VPN providers, this could actually be a good thing. Less time and money spent on regulatory paperwork could mean more investment in things users actually care about: better infrastructure, faster servers, stronger encryption, independent audits, and new anti-censorship features.

That said, there's another side to it. Regulations can also force companies to meet minimum security standards, so if they're rolled back too much, it could make it easier for shady VPNs to cut corners while still marketing themselves as "secure."

Personally, I'd rather see fewer pointless compliance checklists and more transparency. Independent security audits, open-source clients, bug bounty programs, and clear no-logs policies tell me a lot more about a VPN than whether it passed another paperwork exercise.

What do you think, would less regulation make VPNs better, or would it just give bad providers more room to get away with sketchy practices?

reddit.com
u/Timely_Dealer_654 — 15 days ago

So now using a VPN makes you "suspicious"? Yeah... that's a dangerous road

Apparently lawmakers are pushing a bill that could force people using VPNs to verify their identity before accessing certain websites. Let that sink in for a second.

The whole point of using a VPN is to protect your privacy. Millions of normal people use one because they don't want advertisers, ISPs, random Wi-Fi networks, or websites tracking every click they make. Journalists use them. Activists use them. Regular people use them.

Now the logic seems to be: "Oh, you're using a privacy tool? Guess you've got something to hide". That's honestly insane.

It's the same energy as saying, "Why do you lock your front door if you're not doing anything illegal?" Privacy isn't suspicious. It's a basic right.

And let's be real, forcing everyone to upload IDs or face scans to access parts of the internet isn't protecting anyone. It's just creating another giant database full of sensitive personal information waiting to get hacked.

Criminals aren't going to stop being criminals because of age verification. They'll find workarounds like they always do. Meanwhile, law-abiding users lose anonymity and get treated like suspects just for using a VPN.

Feels like we're slowly normalizing the idea that privacy itself is suspicious... and that's a pretty slippery slope.

reddit.com
u/Timely_Dealer_654 — 16 days ago

Millions of people are trusting "VPNs" that are basically copy-paste apps. Why is Google allowing this?

People will spend hours comparing password managers or banking apps, then download the first VPN with 50M installs and a 4.8 stars rating without thinking twice. That's wild.

A VPN literally sits between you and the internet. It can see where you connect, your IP, your browsing metadata... and somehow people are handing that over to apps run by companies they've never even heard of.

Turns out the Play Store is packed with clone VPNs. Same app, different logo, different name, rinse and repeat. Some of these have millions of downloads despite having almost zero transparency about who's behind them.

The whole "free VPN" thing is even crazier. Servers aren't free. Bandwidth isn't free. Engineers aren't free. So if you're not paying for the product... how exactly are they paying the bills?

And before someone says, "Google wouldn't allow it if it was shady"... have you seen the Play Store? Fake apps make it through all the time.

At this point, download count means absolutely nothing. A VPN should earn your trust, not buy it with ads and fake credibility.

reddit.com
u/Timely_Dealer_654 — 16 days ago