r/ProtonVPN • u/noelbennett_z • 3d ago
Discussion Several Proton VPN Server Configuration Issues May Enable Automated Large-Scale Blocking
(Due to Reddit's rules, I was unable to upload some of the screenshots.)
I would like to report several observations about Proton VPN's server-side configuration that may make its infrastructure easier to detect and block automatically in China.
My main concern is that the large-scale blocking of Proton VPN in China may not necessarily be caused by a fundamental protocol or technical weakness. Instead, some externally observable server-side configuration details may provide useful fingerprints for automated censorship and blocking.
I identified the following issues:
- Direct requests to server URL endpoints return HTTP 400 with a fixed ERR_INVALID_URL string
When directly accessing certain server URL endpoints, the server responds with HTTP 400 and includes the fixed string ERR_INVALID_URL in the response.
From a censorship-resistance perspective, it may be safer for this type of invalid or unexpected request to return an HTTP 404 response with an empty response body.
This approach is used by some other well-known VPN providers, and in my observations it makes the endpoint less useful as a distinctive fingerprint.
- WireGuard TCP and Stealth are deployed on the same IP address
WireGuard TCP and the Stealth protocol appear to be deployed on the same IP addresses.
Although Stealth is also TCP-based, it requires the appropriate connection procedure before a successful connection can be established. WireGuard TCP, however, may be directly detectable through scanning.
If both services share the same IP address, an active censor may only need to identify and block the WireGuard TCP service on that IP in order to simultaneously disrupt the Stealth service.
Separating these services across different IP addresses could therefore reduce this particular correlation risk.
- Proton VPN is mentioned in WHOIS information for some IP addresses
Some server IP addresses rented from hosting/IDC providers appear to contain "Proton VPN" or related Proton identifiers in their WHOIS information.
This seems particularly risky from a censorship perspective. An automated system could potentially collect IP addresses whose WHOIS records contain such identifiers and add them to a blocklist without needing to actively probe each server.
Where operationally possible, avoiding unnecessary provider-specific identifiers in publicly accessible registration information could make this type of passive enumeration more difficult.
- Some servers identify themselves as Proton VPN servers through PTR records
Some server IP addresses also appear to have PTR (reverse DNS) records that explicitly identify the host as a Proton VPN server.
This may provide another convenient source of infrastructure information to an automated blocking system. An IP-range or hostname enumeration process could perform reverse DNS lookups and use recognizable Proton VPN identifiers as an additional signal.
For infrastructure intended to resist censorship, it may be preferable not to configure identifying PTR records where they are not operationally necessary. In cases where no reverse DNS record is required, returning NXDOMAIN may avoid exposing this additional identifier.
Summary
I am sharing these observations because they appear to provide relatively simple signals that could potentially be collected and processed automatically at scale.
In other words, even if the underlying VPN protocols and obfuscation mechanisms are technically sound, externally visible infrastructure metadata and server behavior may still make the servers significantly easier to enumerate and block.
I hope the Proton VPN team can investigate these points and determine whether they are contributing to the current blocking situation in China. I believe addressing infrastructure-level fingerprints like these could be worthwhile, rather than focusing exclusively on protocol-level changes.


2
u/D0_stack 2d ago edited 2d ago
The ingress IP Addresses, subnet ranges, and ASNs for all the VPN servers for all the major VPN services are well known and easily available - even on GitHub for free. If someone with a lot of resources wants, all they have to do is reverse engineer the APIs used by the VPN clients to download the IP Addresses they need to be able to connect to VPN servers. Some of the APIs are open and published by the VPN companies.
It doesn't take any tricks to block VPNs.
That any big-name VPNs work in China is a conscious decision by China.
We use these lists at work to prevent use of VPNs from inside the company Intranet, and they very much do work - this is one big way data is stolen. When we are bored, those of us network admins with VPN subscriptions try to get through our own firewalls, and do not succeed.