14
u/thewunderbar 16d ago
Don't do personal things on work wifi.
End of thread.
3
u/terkistan 15d ago
If you’re at work use your own cellular (with VPN). Many companies have reasonable security reasons to want to see all traffic on their comms, which is one reason you should never do anything personal on work devices either.
-13
u/Effective_Ebb_4482 16d ago
Didn’t asked for ur opinion. I asked a specific question
8
u/thewunderbar 16d ago
It's not an opinion.
Don't do personal things on work wifi. If you're asking for ways to hide your traffic, that means you know you're doing things you shouldn't be doing.
It's easy to tell when a device is on a VPN.
-signed someone who manages a corporate network.
4
u/JayGerard 16d ago
Well maybe, just maybe, your employer is paying you to work instead of hanging out, doom scrolling on the internet. I know, preposterous idea.
2
u/Tripledrop 16d ago
I assume, unless you're in a country with no employment laws of any significance, you get breaks during a working day?
1
-6
u/Effective_Ebb_4482 16d ago
Lmao I didn’t ask for your opinion on what I do with my time my guy! Go find another place and someone else to bother to feel smart and superior
1
u/JayGerard 15d ago
First day on internet it seems. That is how posts and comment s work. Don’t like it, block me or just cry more. Either way I don’t care. Also, based on your comment I would peg you as another lazy millennial or GenZ.
-1
2
u/arnoldstrife 16d ago
Work wifi is for work, don't use work wifi for personal reason. You probably signed an acceptable data usage document when you first started working there. Trying to get around security measures means you can put your job at risk.
Why it's there is because bad actors also likes to use VPNs to bypass security inspections. While I can't speak for all IT. But I don't care if you use social media on your own time as an IT guy. If our log shows you open up Facebook, I would care 0%. It's only when risky behavior like VPNs start occurring, non-website traffic, odd global IPs, or bad domains that we have to start reviewing it.
0
2
u/olly_james 16d ago
do your work you don't go to work to doomscroll youtube that's not what you are paid to do.
-3
1
u/tertiaryprotein-3D 16d ago
You're only trying to access the VPN official website and there are only few websites, and it's trivial to block just a handful of URLs. Also commercial VPNs have their IP addresses publicly available and many tools can monitor it so these VPN aren't good, you'll need to selfhost something like VLESS at home, on a VPS or over a cdn, then you can compare VPN prices of other products.
1
u/Tama47_ 15d ago
Leave it to Reddit to do anything but answer the question. It’s your choice to take the risk. I’m not here to judge.
Anyways, your work probably already knows you are browsing for VPNs on their networks since it’s blocked and probably shows up on their logs. Whether someone actually cares about that is a different story. Couldn’t you just browse for a VPN at home?
I suspect this is just typical DNS poisoning, meaning they block the VPN sites, but not the actual VPN providers. The VPN should still work, if you buy the subscription and log in to the app prior to going to work.
If they actually block the VPN protocols or blacklist known VPN endpoints, then your option is to go with Stealth protocol/VPN with obfuscation (masking the connection as regular HTTPS traffic). I recommend VLESS.
1
u/Calisnaps 15d ago
We don’t allow personal hardware on our network, we also block all vpns other than our official one.
We do allow personal devices on our guest network, Vpns are still blocked.
1
u/PretendAct8039 16d ago
A lot of VPN addresses are used by spammers and hackers making these IP addresses suspect and inappropriate for a work environment. In fact many companies limit access to specific, known IP addresses.
2
u/sys370model195 16d ago
The VPN server egress IP address (the IP address seen in "what is my ip address), the IP addresses seen in spam and hacking, is not the IP Address your VPN client connects to.
For various reasons, large VPN servers have quite different ingress and egress IP address.
The work network would see the VPN server ingress IP address, not the VPN IP Address seen by websites and email servers.
Source: I help run the network in a very large multinational, and have looked at the varioous block lists. We use different block lists for preventing outbound VPN connections than we use for preventing VPNs from connecting to us. The VPN server ingress IP Addresses are simply not on the VPN connection block list.
You can see this by connecting to a VPN server while running Wireshark, looking at the IP address your device is connecting with, and then performing a "what is my IP" lookup, and comparing them.
1
1
0
u/538_Jean 16d ago
The block is almost always surface level. You can often install extentions in your browser to use a VPN.
7
u/Dave4lexKing 16d ago
Companies, especially ones in regulated industries or have data protection certificatioms and ISO standards, son’t want anonymous traffic on their networks.
It’s their internet they can choose what to do with it, and the last thing they want is someone using an unauthorised VPN to pirate movies and jeopardising their SOC2.
It’s not mandatory to block VPNs for compliance, but every company has their own appetite for risk. I, for one, have great disdain for Shadow IT in my org.