Hacker News new | past | comments | ask | show | jobs | submit login

What benign reason could there possibly be that isn't better based on IP addresses rather than domains.



When this kind of VPN clients do split traffic based on domains, they do it with some tricks, either via DNS or capturing traffic on the browser, or similar things.

But for doing split VPN with IP addresses they need to create an IP route in the VPN client. If you just have a couple IPs, it's fine, but if you have a couple hundred targets, you're gonna break some guys Windows or Mac machine sending that huge routing table.

Also, there are targets that change IP addresses. For example, AWS Elastic Load Balancers change IP addresses sometimes (if nothing have changed in the last years, haven't deployed ELBs in a while...).




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: