Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

191–200 of 333 posts

Re: VPN location claims don't match real traffic exits

#191
post #185

Earlier quoted context omitted.

I work for IPinfo. I have raised a ticket internally, but I think we focused on consumer VPNs for this test. For our ProbeNet, we are attempting to reach 150 countries (by ISO 3166's definition). We are at around 530 cities. Server management is not an easy task. We do not ship hardware, but operate using dedicated servers, so this reduces one layer of complexity. To maintain the authenticity of our server locations,…

Google, Apple, and Meta (maybe others?) have the data to build a complete GeoIP dataset. None of them will share because there are only downsides to doing so. When FB was rolling out ipv6 in 2012, well meaning engineers proposed releasing a v6 only GeoIP db (at the time, the public dbs were shit). Not surprisingly, it was shot down.

We are always happy to work with large technology enterprises and streaming platforms, not necessarily to sell, but to share insights, data, and practical advice. We observe the entire internet through active measurements, and we are open to co-publishing research when it benefits the broader ecosystem.

Google/GCP is top of mind for me due to a recent engineering ticket. Some of our own infrastructure is hosted on GCP, and Google’s device-based IP geolocation model causes issues for internet users, particularly for IPv6 services.

From what we understand, when a large number of users from a censored country use a specific VPN provider, Google's device-based signals can bias the geolocation of entire IP ranges toward that country. This has direct consequences for accessibility to GCP-hosted services. We have seen cases where providers with German-based data centers were suddenly geolocated to a random country with strict internet censorship policies, purely due to device-based inference rather than network reality. Our focus is firmly on the geolocation of exit-node IPs, backed by network evidence.

https://community.ipinfo.io/t/getting-403-forbidden-when-acc...

We are actively looking to connect with someone at Google/GCP, Azure/Microsoft and others who would be willing to speak with us, or directly with our founder.

Our community consistently asks us to partner more deeply with enterprises because we are in constant contact with end users and network operators. To be honest, we do not even get many questions or issues. We are partners with a large CDN company, and I get one message about a month, which usually involves sharing evidence data and not fixing something.

From a large-scale organization's perspective, IP geolocation should not be treated as an internal project. It is a service. Delivering it properly requires the full range of engineering, sales, support, and personnel available around the clock to engage with users, evaluate evidence, and continuously incorporate feedback.

Re: VPN location claims don't match real traffic exits

#192

Earlier quoted context omitted.

I work for IPinfo. No, the article does not make this conclusion at all! It was carefully written to highlight the nature of virtual locations of VPN exit nodes and does not make such conclusions. The article is written by our founder, who is accessible to the VPN industry at large and is open to feedback and comments.

> I work for IPinfo Ngl, I never knew that those IP location tools are actual companies with full time employees. I always assumed they were just made by some random guy in an afternoon by wrapping maxmind API. Interesting to hear that that's not the case (at least for ipinfo; maybe some of the consumer-oriented IP lookup websites are like that)

Our headcount is approximately 70 right now. Most of engineering consists of data engineers, researchers, and data scientists because data is our product. Then we have infrastructure engineering, software engineering, integration engineering, support engineering, solutions architects, mobile application engineering, UX/UI designers, website engineering, API engineering (separate from the website because of the volume of traffic we receive), a full commercial team with partnerships and sales, finance/accounting, legal and a marketing team. I think I am still forgetting some people. We also work closely with consultants who are foundational to the internet as a whole. We have an open hiring policy for the right talent.

During our offsite, we had to rent out a small ship (ferry?) to host everyone: https://x.com/coderholic/status/1975333382604398702/photo/4

More than a decade ago, when IPinfo launched, a lot of community interaction was done by our founder. Now, you have me in a full-time role talking to people. My role is literally called Developer Relations.

We are not just a IP geolocation company; we are an internet data company. IP geolocation and VPN detection are only products to us; the team and goal are actually quite huge.

Re: VPN location claims don't match real traffic exits

#193
post #54

Interesting to learn you can identify the real country/area of origin using probe latency. Though could this be simulated? Like what if the VPN IP just added 100ms-300ms of latency to all of its outgoing traffic? Ideally vary the latency based on the requesting IP's location. And also just ignore typical probe requests like ICMP (ping). And ideally all the IPs near the end of the traceroute would do all this too. To…

This can fool someone from one location and only in one way (if you are near Somalia and expect a 10ms latency, a virtual VPN can't reduce latency to simulate been in Somalia). So it have to be dynamic to fool multiple locations to stay probable.

But anyway, *you can't fool the last-hop latency* (unless you control it, but you can control all of it), and basically it impossible to fool that.

Re: VPN location claims don't match real traffic exits

#194

Earlier quoted context omitted.

Coincidentally, Mullvad, Windscribe and IVPN all worked when I was in China behind GFW, while more popular options did not. Seems like there are VPNs, and then there are VPNs.

I'm a bit curious about how that works. I love Mullvad but routinely I find sites like Reddit completely block it. Even yesterday someone posted a Debian wiki link[0] and I was blocked. It's not all of them but Reddit is a big killer. So I thought China would block all of them (aren't they known?) Fwiw I'm not switching from mullvad [0] https://news.ycombinator.com/item?id=46252366

While using mullvad reddit doesn’t block access if you’re signed in.

So, login without mullvad, turn it on after that and it should work.

Re: VPN location claims don't match real traffic exits

#195

Earlier quoted context omitted.

I'm a bit curious about how that works. I love Mullvad but routinely I find sites like Reddit completely block it. Even yesterday someone posted a Debian wiki link[0] and I was blocked. It's not all of them but Reddit is a big killer. So I thought China would block all of them (aren't they known?) Fwiw I'm not switching from mullvad [0] https://news.ycombinator.com/item?id=46252366

How do other providers avoid this issue? Do they keep changing IPs or is the traffic that comes out of Mullvad worse in quality somehow?

From my experience, PIA VPN and Proton VPN also get blocked everywhere, from Reddit to captchas on Google Search.

Re: VPN location claims don't match real traffic exits

#196

I'm a big VPN user since I am the citizen of one country and the resident of another. Even for government services I have to use a VPN. I tried to access the bureau of statistics of my home country through my foreign residential IP and got 404s on all pages. Enabled VPN and everything magically started working. For watching the election result video stream I also had to VPN but at least that one gave me a clear messa…

> I would easily pay €30 a month for a VPN in my home country that uses a residential IP and isn't noticeable. I am aware that those exist, but 99% of them are shady. For residential IPs you can't even pay per month like normal VPNs, normally they charge per GB, usually over $2 usd per GB.

Prices are more in the 0.30$-0.45$ range if you know where to go, from my experience.

Re: VPN location claims don't match real traffic exits

#197

I tried to use ProtonVPN when I switched over to ProtonMail a year ago. But so much of the web does not work when you're on a VPN. For example even HackerNews has VPN restrictions. More and more sites know where VPN endpoints originate. How will VPNs prevent this in the future without them just become easy to block?

I wonder if using the wifi at a data center has the same broken browsing experience as using a VPN

From a datacenter IP, if the IP address is not shared with other users, you still get blocked from sites like Reddit, but you don't get most annoying captchas (for example on Google).

Re: VPN location claims don't match real traffic exits

#198
post #140

I seriously don't quite understand the point of using a VPN that doesn't offer you clean residential IPs somehow (and I don't really know good VPN like that). Most services where I really want to use VPN are well aware of VPN IP blocks and just won't allow any of these famous VPNs (that I am aware of, at least). And services that don't care if it's my real IP or not… well, usually I don't really care about exposing t…

You can pay for a static residential IP on Windscribe, but it's quite expensive.

Re: VPN location claims don't match real traffic exits

#199

Oh wow, I had no idea that “virtual location” is even a thing. Imo it should not, I don’t even see a use case for that, it just seems like straight-up lying about the traffic exit location. Glad to see the provider I occasionally use, Mullvad, passed the test.

Many providers in the list, such as PIA, warn the user when a virtual location is chosen. The point is to get a wider range of countries. Most websites, such as YouTube and Netflix, are fooled by the virtual locations, so it works!

Re: VPN location claims don't match real traffic exits

#200
post #194

Earlier quoted context omitted.

I'm a bit curious about how that works. I love Mullvad but routinely I find sites like Reddit completely block it. Even yesterday someone posted a Debian wiki link[0] and I was blocked. It's not all of them but Reddit is a big killer. So I thought China would block all of them (aren't they known?) Fwiw I'm not switching from mullvad [0] https://news.ycombinator.com/item?id=46252366

While using mullvad reddit doesn’t block access if you’re signed in. So, login without mullvad, turn it on after that and it should work.

The question is not "how do you make reddit work over mullvad".

The question is "if reddit can block mullvad why can't China".

Post reply on HN