Make a stealth version of your VPN so that ISP or telcos that block VPNs should not be able to tell by packet analysis that VPN is in use

600 votes
Anonymous shared this idea


  • Anonymous commented  ·   ·  Flag as inappropriate

  • [Deleted User] commented  ·   ·  Flag as inappropriate

    @Bliss - sounds interesting, perhaps PM could educate users on the basic principles of how a similar PM solution could work (e.g., video clips 1-3 minutes in duration). I imagine there's only a certain level of detail that would/should be shared, otherwise that same detailed information could be the basis for new future efforts to block VPNs, once again (this could be a vicious cycle if an education campaign is not properly managed). The goal is to find a stealth version of VPN that endures.

  • Bliss commented  ·   ·  Flag as inappropriate

    VyprVPN offers Chameleon Protocol which can bypass the DPI (Deep Packet Analysis) used by ISPs and service providers.

    "VyprVPN's engineers have developed a remarkable new, proprietary VPN technology called Chameleon. Chameleon scrambles OpenVPN packet metadata to ensure it’s not recognizable via deep packet inspection (DPI), while still keeping it fast and lightweight. The Chameleon technology uses the unmodified OpenVPN 256-bit protocol for the underlying data encryption."

    It will be good to see if ProtonVPN can develop something similar without spending too much time and resources. I am sure it can be easily be achieved since VyprVPN has already done it...

  • Anonymous commented  ·   ·  Flag as inappropriate

    Search engines like Yahoo and others already block certain VPN-PROX service like TOR, try doing a Yahoo search using TOR and see what you get not to mention that i heard that when a ISP anywhere detects that you are using TOR it is reported to the F.B.I. & Police in other countries as well. Theres also the fact that the U.S. Government has been funding the TOR & Network for years now by certain Journalists who obtained the Smoking Gun Documents.

  • xmusic commented  ·   ·  Flag as inappropriate

    *add SSL VPN
    *add DnsCrypt proton + dnschain

    Internet censorship in Russia
    freedom houseAbout Freedom on the Net

  • lonestar007 commented  ·   ·  Flag as inappropriate

    Fantastic idea, but it might create a cost spike for PM. I would like to see a cost analysis on this. Comments from other users AND the PM staff will be important in this decision. Perhaps early-adopter rollout on paid service side is the only way this will work and still keep the mail flowing securely.

  • Ignacio Vicario commented  ·   ·  Flag as inappropriate

    This would be bery important for people who live in countries where Human Rights are not respected and rule of law does not exist, like China, Iran, Turkey, Saudi Arabia and many, many other countries. Journalists and Human Rights advocates do need that.

  • Markus Hochholdinger commented  ·   ·  Flag as inappropriate

    Content providers such as Amazon and HBO also can detect VPN use more and more. Having a reliable stealth VPN that isn‘t detectable by any of those would be a real USP in the VPN market right now.

  • Anonymous commented  ·   ·  Flag as inappropriate

    This would actually be rather sophisticated of them to do so.

    There are only handful of other VPN services in the world that have independently engineered something where encryption isn't compromised but deep packet inspection is actively prevented, so it would make ProtonVPN a member of that unique group if they did introduce something like this.

  • Loren commented  ·   ·  Flag as inappropriate

    This really should happen. It does not good using it if you get blocked for using it.

  • Chris A commented  ·   ·  Flag as inappropriate

    They can tell based on the TCP ports used, and the GRE tunnels created. It would be nice to get around this using encryption to the VPN server using different ports, and regularly changing server names if not IP addresses.

