Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

201–210 of 333 posts

Re: VPN location claims don't match real traffic exits

#201

I can't connect to this site because my adblocker doesn't like it. It seems to be on the bad-domain-list https://www.cromite.org/filters/badblock_lite.txt . Now is the question: is ipinfo.io on this list for a good reason?

I can not access https://www.cromite.org/

It redirects to a dead link hosted on aruba.it. I can investigate it.

Re: VPN location claims don't match real traffic exits

#202

Earlier quoted context omitted.

How do other providers avoid this issue? Do they keep changing IPs or is the traffic that comes out of Mullvad worse in quality somehow?

From my experience, PIA VPN and Proton VPN also get blocked everywhere, from Reddit to captchas on Google Search.

PIA it’s one of the least trustworthy VPNs, highly recommend getting a different one.

Re: VPN location claims don't match real traffic exits

#203
post #175

There was an article on HN not too long ago about how to get a North Korea / Antarctica VPS[1], so this isn't entirely surprising! [1] https://news.ycombinator.com/item?id=45922850

That was actually a great article. For us, that is like a crowdsourced bug hunting program. We actually got duped ourselves, and we appreciate the author.

We added additional features for location hint modeling and selection for IPv6 networks. There are a handful of open engineering tickets to understand more about the entire internet infrastructure of the country. Of course, hosting a probe server out there would be helpful.

https://ipinfo.io/countries/kp

We always appreciate feedback like that.

Re: VPN location claims don't match real traffic exits

#204

Earlier quoted context omitted.

I have been thinking about it but it is tricky from a legal standpoint. What I'm trying to arrange next time I visit is to have a secondary line installed at my parents place that is in my name. So that when I pull heavy traffic from that line it doesn't impact them and I can't get them in trouble for posting a message that isn't government approved.

Heavy traffic to access a bunch of gov websites? There's definitely more to your story then. I'd say, anything heavy and random, use the general VPN and the rest use an rpi at your parents' home.

Video. Live video

Re: VPN location claims don't match real traffic exits

#205

While exits matter to avoid countries with a nation-wide firewall, the geoip industry is a scourge. If an ISP wants to help their users avoid geoblocking via https://www.rfc-editor.org/rfc/rfc8805.html more power to them.

We (IPinfo) attended the IETF 3-day workshop on IP geolocation. Our presentation was about geofeed that can be viewed here: https://youtu.be/l8PR7VCmA3Q?si=dG-00UqljTopBquF&t=372.

It was a great session and we received a lot of questions. We attend different NOG conferences regularly. ISPs are incentivized to help us by providing good data. Although we are agnostic about adversarial geofeeds, ISPs themselves need to work with us to ensure good quality of service to their users.

We already do quite a lot of outreach, in fact, most network engineers in the ISP industry across the world are familiar with us. But if any ISP operator has any feedback for us, we are only an email (or even a social media comment) away.

Re: VPN location claims don't match real traffic exits

#206
post #54

Interesting to learn you can identify the real country/area of origin using probe latency. Though could this be simulated? Like what if the VPN IP just added 100ms-300ms of latency to all of its outgoing traffic? Ideally vary the latency based on the requesting IP's location. And also just ignore typical probe requests like ICMP (ping). And ideally all the IPs near the end of the traceroute would do all this too. To…

I work for IPinfo.

We also run traceroutes. Actually, we run a ton of active measurements from our ProbeNet. The amount of location data we process is staggering.

https://ipinfo.io/probenet

Latency is only one dimension of the data we process.

We are pinging IP addresses from 1,200+ servers from 530 cities, so if you add synthetic latency, chances are we can detect that. Then the latency-related location hints score will go down, and we will prioritize our dozens of other location hints we have.

But we do welcome to see if anyone can fool us in that way. We would love to investigate that!

Re: VPN location claims don't match real traffic exits

#207

I am not sure that I really understand what they did. I am also missing some major VPNs in the list. I currently use AirVPN but this has something to do with my use case and pricing. Why do you want to use a VPN? - Privacy - Anonymity (hint: don't!) - unblock geolocation - torrents - GFC The last point is the hardest. https://expatcircle.com/cms/privacy/vpn-services/

I work at IPinfo, thanks for your comment/feedback. We will be expanding this research to include more VPNs next year.

Re: VPN location claims don't match real traffic exits

#208
post #31

Contrasting take: RTT and a service providing black box knowledge is not equivalent to knowledge of the backbone. To assume traffic is always efficiently routed seems dubious when considering a global scale. The supporting infrastructure of telecom is likely shaped by volume/size of traffic and not shortest paths. I'll confess my evaluation here might be overlooking some details. I'm curious on others' thoughts on th…

We (I work for IPinfo) talk about latency because it is a thread that you can start from when exploring our full depth of data.

We are the internet data company and our ProbeNet only represents a fraction of our investment. Through our ProbeNet, we run ping, traceoute, and other active measurements. Even with traceroute we understand global network topology. There are dozens and dozens of hints of data.

We are tapping into every aspect on the internet data possible. We are modeling every piece of data that is out there, and through research, we are coming up with new sources of data. IP geolocation is only product for us. Our business is mapping internet network topology.

We are hoping to work with national telecoms, ISPs, IXPs, and RIRs to partner with them, guiding and advising them about data-driven internet infrastructure mapping.

Re: VPN location claims don't match real traffic exits

#209
post #194

Earlier quoted context omitted.

While using mullvad reddit doesn’t block access if you’re signed in. So, login without mullvad, turn it on after that and it should work.

The question is not "how do you make reddit work over mullvad". The question is "if reddit can block mullvad why can't China".

There's a corollary to that question: why would China choose not to block Mullvad? We know every large nation with a capable online force maintains a fleet of ORBs, so maybe they consider Mullvad more useful for them as a functioning system?

Some of their own contractors may well depend on Mullvad. Perhaps as long as the overall "civilian" volume and user count remains acceptably low, the cost-benefit estimate may well be in favour of letting it slip by. (And for the civilians that do use a working variant, subject their connections to fine-grained traffic analysis.)

Re: VPN location claims don't match real traffic exits

#210
post #172

Earlier quoted context omitted.

Why do you need an AppleTV box and Tailscale for that? Use any PC (even a Raspberry Pi or any cheap "thin client") with Wireguard and you remove Apple and Tailscale from the equation entirely while keeping your setup 100% self-hosted.

Lots of people already have Apple TVs and the Tailscale integration is pretty good and can serve as an always online exit node. So no new hardware required. Could even remotely walk a non-techie through the process without too much effort. personally, I've just upgraded my family's wifi to Ubiquiti and can then use Tailscale Wireguard running on the gateway as a proxy! (with their permission)

Is it that common outside the us? I know of exactly one family here in Germany having Apple TV.
Post reply on HN