Live data from Hacker News

Live proxy and VPN detection

proxy.incolumitas.com

71–76 of 76 posts

Re: Live proxy and VPN detection

#71
post #44

Earlier quoted context omitted.

The false positive rate is going to be insane. You mentioned roaming, but there are so many other scenarios where this could trigger - so, the user sits down at a starbucks and suddenly can't access the client's webpage, with some very confusing error about VPNs. Guess what, they are not going to fix their network, they are going to give up on going to that website. Without a plan how to measure/fix false positives,…

I don't see how Starbucks is going to trigger this. The NAT device is physically in the same building as the laptop, so the segment between the laptop and then NAT (which is what results in the difference in TCP/IP ping vs websocket ping) would be very short and undetectable.

Not every network is as simple as a router in front of a laptop. And some may treat websocket traffic differently. And do weird DNS stuff. Every time your basic assumptions are wrong, your client loses a user, and you don't even have a way to detect that.

All these signals will either be too weak and let through enough false negatives as to be essentially useless, or too strict and produce so many false positives that a significant portion of the legitimate users leave in frustration. Unless you are some oppressive regime cracking down on VPN usage, I truly don't see where this will be useful. I guess it's helpful to compile the list of modern methods for detection and fingerprinting, so VPN providers can mitigate them.

Re: Live proxy and VPN detection

#72
post #15

Earlier quoted context omitted.

>Please don't. Not just because of the false positives and false negatives, but because user privacy is actually a good thing. Like it or not, bad actors use VPNs as well, and for some businesses the adverse selection caused by VPNs basically makes banning VPNs a no-brainer (eg. due to fraud).

Ethically: Bad actors use a lot of things; that's a poor excuse for harming the innocent. Practically: The economics probably check out, but bear in mind that it's not one-sided; this will cost you legitimate users.

Oh, that gives me a good idea for a new website/slogan: bad actors use Toothpaste; lets ban Toothpaste!

Re: Live proxy and VPN detection

#73
post #10

ok but how does this work? i was expecting atleast a paragraph on HN to be honest

The documentation page linked to the demo page gives a good explanation on how this works ( https://proxy.incolumitas.com/integration_instructions.html ) > The most important proxy detection tests with the highest accuracy are: > 1. Latency Test - latency - This test is extremely effective at detecting proxy connections. It works both for residential and datacenter proxies. The reason why this test is effective: It i…

The latency test is garbage, on 4G it fails

Re: Live proxy and VPN detection

#74
post #15

Earlier quoted context omitted.

>Please don't. Not just because of the false positives and false negatives, but because user privacy is actually a good thing. Like it or not, bad actors use VPNs as well, and for some businesses the adverse selection caused by VPNs basically makes banning VPNs a no-brainer (eg. due to fraud).

Ethically: Bad actors use a lot of things; that's a poor excuse for harming the innocent. Practically: The economics probably check out, but bear in mind that it's not one-sided; this will cost you legitimate users.

I tried to pay for street parking a few days ago in Miami but the app wouldn't work at all. It turns out that ParkMobile just refuses to operate if your device is using a vpn and won't tell you the reason.

It makes sense to filter out bad actors, but relying on vpn usage as the only signal for untrustworthiness is unwise.

Re: Live proxy and VPN detection

#76

Earlier quoted context omitted.

If the cost of fraud this stops is more than the lost cost of legitimate users..

Enacting slavery is a great way to reduce costs and optimize productivity. Good idea?

I believe that would be illegal, sir
Post reply on HN