Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

171–180 of 333 posts

Re: VPN location claims don't match real traffic exits

#171

Earlier quoted context omitted.

Coincidentally, Mullvad, Windscribe and IVPN all worked when I was in China behind GFW, while more popular options did not. Seems like there are VPNs, and then there are VPNs.

I'm a bit curious about how that works. I love Mullvad but routinely I find sites like Reddit completely block it. Even yesterday someone posted a Debian wiki link[0] and I was blocked. It's not all of them but Reddit is a big killer. So I thought China would block all of them (aren't they known?) Fwiw I'm not switching from mullvad [0] https://news.ycombinator.com/item?id=46252366

I use obscura—which routes through mullvad—and the reddit problem is very annoying.

I finally hit the point of searching for mirrors yesterday and turns out, they exist.[0]

It’s really only suitable for lurking or being able to view search results, but it has eased the pain a bit.

0: reddit-viewer.com

Re: VPN location claims don't match real traffic exits

#172

Earlier quoted context omitted.

Do you have friends or family in your home country that will run an AppleTV box with Tailscale for you as an exit node? I can't get into work from a non-US IP, but I can Tailscale back to my house and it works just fine. I even gave my in-laws (who live several states away) an AppleTV box running TS just to have another endpoint if for some reason the power goes out at my house while I'm gone (rare, but happens).

Why do you need an AppleTV box and Tailscale for that? Use any PC (even a Raspberry Pi or any cheap "thin client") with Wireguard and you remove Apple and Tailscale from the equation entirely while keeping your setup 100% self-hosted.

Lots of people already have Apple TVs and the Tailscale integration is pretty good and can serve as an always online exit node. So no new hardware required. Could even remotely walk a non-techie through the process without too much effort.

personally, I've just upgraded my family's wifi to Ubiquiti and can then use Tailscale Wireguard running on the gateway as a proxy! (with their permission)

Re: VPN location claims don't match real traffic exits

#173

I'm a co-founder at WonderProxy, we didn't make their list (we target people doing application testing, not consumer VPNs). We're in 100+ countries, and I'll stand by that claim. It's a huge pain in the neck. In our early years we had a lot of problems with suppliers claiming to be in Mexico or South America who were actually just in Texas. I almost flew to Peru with a rackmount server in my luggage after weeks of pr…

I work for IPinfo. I have raised a ticket internally, but I think we focused on consumer VPNs for this test.

For our ProbeNet, we are attempting to reach 150 countries (by ISO 3166's definition). We are at around 530 cities. Server management is not an easy task. We do not ship hardware, but operate using dedicated servers, so this reduces one layer of complexity.

To maintain the authenticity of our server locations, we utilize cross-pings and network traffic behavior detection. If any abnormality is detected, the server will be immediately disabled to prevent polluting our data. There will be a ticket to investigate what went wrong.

We pay for each (excluding 3 to 4 servers where the owner and the team really likes us and insists on sponsoring) server. Expansion is an active effort for us, as there are 70k ASNs and about 100 more countries where we do not have a server.

We hope to partner with more ASNs, particularly residential ISPs and IXPs. So, a lot of effort is put into active outreach through WhatsApp, emails, social media and phone calls. We use a number of different data-based techniques to identify "leads".

Re: VPN location claims don't match real traffic exits

#174
Never heard of Windscribe but their homepage has "Become American" as a feature.

> Are you sick of not having access to foreign oil? Do you love using advanced weapons to fuck up someone’s day? Obsessed with manipulating your financial records to make yourself look more successful than you are?

Got a chuckle out of me.

Re: VPN location claims don't match real traffic exits

#176

I use Mullvad through Tailscale’s exit‑node integration, and it’s awesome. They are the only provider I trust these days. To highlight virtual routing: it’s useful in scenarios where a country blocks VPNs but you still need an IP from that country to browse local websites. In such cases, virtual routing comes in handy. For example, when India required all VPN servers in the country to log user traffic, Proton moved i…

I work for IPinfo. I am not sure what routing tricks Proton uses. I have looked into the smart routing and stealth protocol related documentation. I am not sure if Proton does anything unique when it comes to IP location. I am not saying this officially, but I am just curious here.

Smart routing documentation: https://protonvpn.com/support/how-smart-routing-works

'Virtual' VPN server geolocation involves informing IP geolocation providers that their Singaporean servers are located in India. We looked into data and latency-based locations, but the industry at large uses self-reported location information for their data. So, if you use a service that uses IP geolocation provider (that is not us) they will just tell them that the Singaporean IP address is located in India, because that is the information they have and they do not have any other ways to verify it. But at the end of the day, the location information is coming from the VPN itself.

I could be wrong, and there could be technology and technique I am missing, so I am happy to learn. The blog is written by our founder who is accessible to the Proton team if they want to share their feedback with us.

Re: VPN location claims don't match real traffic exits

#177

Most of these providers are in fact open about the fact that these locations are “virtual”, so it’s misleading to say they don’t match where they claim to be. There is however an interesting question about how VPNs should be considered from a geolocation perspective. Should they record where the exit server is located, or the country claimed by the VPN (even if this is a “virtual” location)? In my view there is usefu…

I work for IPinfo, and I appreciate your comment.

Our product philosophy is centered on accuracy and reliability. We intentionally diverge from the broader IP geolocation industry's trust-based model. Instead of relying primarily on "aggregation and echo", we focus on evidence-backed geolocation.

Like others in the industry, we do ingest self-reported IP geolocation data, and we do that well. Given our scale and reputation, we receive a significant volume of feedback and guidance from network operators worldwide. We actively conduct outreach, and exchange ideas with ISPs, IXPs, and ASNs. We attend NOG events, participate in research conferences, and collaborate with academia. We have a community and launch hackathon events, which allow us to talk to all the stakeholders involved.

Where we differ is in who our core users are. Our primary user base operates at a critical scale, where compromises on data accuracy are simply not acceptable. For these users, IP geolocation cannot be a trust-based model. It must be backed by verifiable data and evidence.

We believe the broader internet ecosystem benefits from this approach. That belief is reflected in our decision to provide free data downloads, a free API with unlimited requests, and active collaboration with multiple platforms to make our data widely accessible. Our free datasets are licensed under CC-BY-SA 4.0, without an EULA, which makes integration, even for commercial use straightforward.

I appreciate you recognizing that our product philosophy is different. We are intentionally trying to differentiate ourselves from the industry at large, and it is encouraging to see competing services acknowledge that they are focused on a different model.

Re: VPN location claims don't match real traffic exits

#178

Earlier quoted context omitted.

Do you have friends or family in your home country that will run an AppleTV box with Tailscale for you as an exit node? I can't get into work from a non-US IP, but I can Tailscale back to my house and it works just fine. I even gave my in-laws (who live several states away) an AppleTV box running TS just to have another endpoint if for some reason the power goes out at my house while I'm gone (rare, but happens).

Why do you need an AppleTV box and Tailscale for that? Use any PC (even a Raspberry Pi or any cheap "thin client") with Wireguard and you remove Apple and Tailscale from the equation entirely while keeping your setup 100% self-hosted.

> Wireguard and remove Apple and Tailscale from the equation entirely

I agree you could send them a preconfigured pi, but can we stop pretending talescale is just wireguard - there is a lot of convenience in the NAT traversal that you otherwise need router config and/or a publically routable server to achieve.

Re: VPN location claims don't match real traffic exits

#179

Cool, even our privacy protection is fraught with scammers and liars.

I work for IPinfo.

No, the article does not make this conclusion at all! It was carefully written to highlight the nature of virtual locations of VPN exit nodes and does not make such conclusions.

The article is written by our founder, who is accessible to the VPN industry at large and is open to feedback and comments.

Re: VPN location claims don't match real traffic exits

#180

Earlier quoted context omitted.

Why do you need an AppleTV box and Tailscale for that? Use any PC (even a Raspberry Pi or any cheap "thin client") with Wireguard and you remove Apple and Tailscale from the equation entirely while keeping your setup 100% self-hosted.

> Wireguard and remove Apple and Tailscale from the equation entirely I agree you could send them a preconfigured pi, but can we stop pretending talescale is just wireguard - there is a lot of convenience in the NAT traversal that you otherwise need router config and/or a publically routable server to achieve.

> but can we stop pretending talescale is just wireguard

That's precisely the issue. It introduces additional centralized dependencies and closed source components.

Post reply on HN