

People need to stop spreading this. It’s false and it’s dangerous because it presumes a basket of things that isn’t. It is incredibly easy to identify commercial VPNs meant for anonymity, skipping geo-blocks, torrenting, etc and separate them from those used for secure access to internal networks. For starters all traffic has an address. Those commercial VPN providers used easily and quickly identified servers for which off-the-shelf weekly/daily updated lists of IPs can be purchased from commercial companies. There are other things like traffic analysis but it’s frankly not necessary.
If the UK or the US wanted to block commercial VPNs entirely they could do so very easily. China and Russia have no interest in running no-logs VPNs for westerners to escape their censorship regimes and put in that kind of effort as the west has put into their own VPNs and solutions to enable “dissidents” (CIA provocateurs and liberals) to communicate. People single out China because they can’t block all VPNs, well the GFW designer said it isn’t meant to stop everyone just introduce friction so anyone who does so has to have gone against the current and hopefully knows their stuff. The technical means of doing so which the west has isn’t even getting into their control of the world financial system, they can seize bank accounts, arrest the people running these services, sanction and fine the hosting companies in the west for hosting them, deplatform them, etc. And the problem there is that the anti-west: China, Russia, etc are not interesting in hosting this stuff for westerners outside of western jurisdiction.













Yes. Certs can expire after whatever time the issuer wants to set for them. That could be six months or 20 years. Some infrastructure has limits on max and min lengths (more max than min usually) but not all and there are best practices as well.
More importantly the certs could have been five years old by the time this person got the TV for a total age of 8 years.