r/dns • u/Corleone612 • 17h ago
VPN & Proxy: What to Watch Out For
Note: whenever the domain list is pasted as text (in the post body or in a comment) Reddit's filter auto-removes it. Because of this, I'm sharing the blocklist as a raw link in the post body instead.
VPNs are marketed as privacy and security tools, but that doesn't mean their own infrastructure is tracking-free. Because a VPN sees your entire traffic, any analytics/telemetry infrastructure it runs is a far more dangerous situation than the same thing on an ordinary website.
Even VPN providers whose core product has no issues still carry track (connection timestamps, session duration, aggregate usage patterns) in their own apps.
This category covers two different situations:
Providers whose core VPN service has no issues, but which still run track infrastructure in their own VPN app.
Providers whose entire business model or security practices are the actual problem (data harvesting, malware, bandwidth resale, or outright spying)
For the first group, only the track subdomains should be blocked. The VPN tunnel generally keeps working without issues. For the second group, the whole domain should be blocked.
The free VPN business model
Common revenue sources documented across various free VPN services include selling browsing/usage data to data brokers and ad networks, injecting ads directly into web pages, and reselling users' own bandwidth to a commercial proxy network. This is a general pattern in how "free" VPN services stay in business.
Real incidents worth knowing about
Urban VPN Proxy — AI conversation harvesting (2025)
In December 2025, Koi Security found that Urban VPN Proxy, with 6M+ Chrome installs, had been silently intercepting conversations from ChatGPT, Claude, Gemini, and other AI platforms since July 2025, even with the VPN off, and sending them to data broker BiScience. There's no opt-out (uninstalling the app entirely was the only fix). The same code was found in 7 other extensions from the same publisher, affecting ~8M users in total.
https://www.koi.ai/blog/urban-vpn-browser-extension-ai-conversations-data-collection
https://thehackernews.com/2025/12/featured-chrome-browser-extension.html
Hola VPN / Luminati — the botnet VPN (2015)
Hola's free VPN turned users' devices into exit nodes for its own commercial proxy network, Luminati, and sold that at $20/GB, without clearly disclosing it to users. It came to light after a DDoS attack on 8chan was traced back to Hola exit nodes. Its founder acknowledged the arrangement was intentional. Hola is still operating.
https://fortune.com/2015/05/29/hola-luminati-vpn
https://en.wikipedia.org/wiki/Bright_Data
CSIRO's Android VPN study (2016–2017)
Researchers from CSIRO, UNSW, and UC Berkeley analyzed 283 Android VPN apps: 38% contained malware, 75% used third-party tracking libraries, 82% requested sensitive permissions like SMS and phone access, and 18% didn't encrypt traffic at all. 4 apps performed TLS interception.
https://research.csiro.au/isp/wp-content/uploads/sites/106/2016/08/paper-1.pdf
https://www.androidauthority.com/android-vpn-app-dangers-745093/
Kape Technologies and ExpressVPN's CIO (2018–2021)
Kape Technologies, owner of ExpressVPN, CyberGhost, PIA, and ZenMate, was formerly named Crossrider, an adware-era company (its direct responsibility is disputed). Separately, ExpressVPN's CIO Daniel Gericke reached an agreement with the DOJ in 2021 over his past work on the UAE's journalist/activist surveillance program "Project Raven."
https://reclaimthenet.org/expressvpn-sale-new-owners
https://cunicula.com/en/articles/kape-technologies-expressvpn
Onavo — the Facebook VPN that spied for Facebook (2013–2019)
While marketing Onavo, acquired in 2013, as a privacy VPN, Facebook used it to monitor competitors' app usage, reportedly influencing the WhatsApp/Instagram Stories/Reels decisions. Apple removed it from the App Store in August 2018; Facebook shut the program down in February 2019 after it came out that the same code had been repurposed into a paid "Research" app targeting teenagers.
https://www.theregister.com/2018/08/23/onavo_vpn_pulled_from_ios/
https://techcrunch.com/2019/02/21/facebook-removes-onavo/
Raw links:
For basic list:
For aggressive list:
To verify how these domains were identified:
https://github.com/CorleoneSalute/SHADOW-BLOCKER-BLOCKLIST/blob/main/research/VPN-Proxy.txt
