Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

221–230 of 333 posts

Re: VPN location claims don't match real traffic exits

#221
Back in 2022 I published a doc on how the egress IPs work at Cloudflare:

https://blog.cloudflare.com/cloudflare-servers-dont-own-ips-...

In summary, the location at which an IP egresses Cloudflare network has nothing to do with the geo-ip mapping of that IP. In some cases the decision on where to egress is optimised for "location closest to the user", but this is also not always true.

And then there is the Internet. Often some country (say Iran) egresses from a totally different place (like Frankfurt) due to geopolitics and just location of cables.

Re: VPN location claims don't match real traffic exits

#222

While exits matter to avoid countries with a nation-wide firewall, the geoip industry is a scourge. If an ISP wants to help their users avoid geoblocking via https://www.rfc-editor.org/rfc/rfc8805.html more power to them.

We (IPinfo) attended the IETF 3-day workshop on IP geolocation. Our presentation was about geofeed that can be viewed here: https://youtu.be/l8PR7VCmA3Q?si=dG-00UqljTopBquF&t=372 . It was a great session and we received a lot of questions. We attend different NOG conferences regularly. ISPs are incentivized to help us by providing good data. Although we are agnostic about adversarial geofeeds, ISPs themselves need to…

> ISPs are incentivized to help us by providing good data.

That's the entire problem in a nutshell. Good quality of service should not depend on every site I visit knowing my geographic location at the ZIP code or even street level (I've actually seen the latter occasionally).

I can somewhat understand the need for country-wide geoip blocking due to per-country distribution rights for media and whatnot, but when my bank does it, it just screams security theater to me.

Re: VPN location claims don't match real traffic exits

#223

While exits matter to avoid countries with a nation-wide firewall, the geoip industry is a scourge. If an ISP wants to help their users avoid geoblocking via https://www.rfc-editor.org/rfc/rfc8805.html more power to them.

With CGNAT becoming more widespread, formats like this might need expansion to include location data for ports. Ie. Port 10,000-20,000 are consumers in New york, port numbers 20000-30000 are in Boston, etc.

Why would any CG-NAT split their volume that way?

IPv4 addresses are not that scarce yet, and realistically any CG-NAT will have several IPv4 addresses per metro area, if only to allow for reasonable levels of geolocation (e.g. to not break the "pizza near me" search use case).

Re: VPN location claims don't match real traffic exits

#224

Another related but non-VPN story related to IP geolocation: Big techs (most notably Google) is using the location permission they have from the apps / websites on the user's phones / browsers to silently update their internal IP geolocation database instead of relying on external databases and claims of IP owners (geofeed etc). And this can be hyper-sensitive. I was traveling back home in China last year and was usi…

Some of our (IPinfo) services are hosted on GCP, and because our service is widely used (with 2 trillion requests processed in 2024) people sometimes say they cannot access our service. It is usually due to how Google's device-based IP geolocation is used. The user's IP address is often mistakenly identified as being located in a country where Google does not offer service.

I have seen a Europe-based cloud hosting provider's IP ranges located in countries where Google does not provide service. This is because these IP ranges are used as exit nodes by VPN users in that country.

Device-based IP geolocation is strange. We prefer IP geolocation based on the last node's IP geolocation. We hope to collaborate with Google, Azure, and other big tech on this if they reach out to us.

Re: VPN location claims don't match real traffic exits

#225
post #112

Earlier quoted context omitted.

Is this be cause they're paying the residential proxy owners some of it?

Most of the people whose devices and connections are being used as residential proxy exit nodes are not aware of it. They likely charge per GB because these residential connections are slow and limited compared to datacenter connections (doesn't help that they're often located in third world countries), and are often used for aggressive scraping, so charging a fixed monthly price would not be viable.

Probably safe to assume that yours is. Especially if a teenager is using your wifi.

Re: VPN location claims don't match real traffic exits

#226

While exits matter to avoid countries with a nation-wide firewall, the geoip industry is a scourge. If an ISP wants to help their users avoid geoblocking via https://www.rfc-editor.org/rfc/rfc8805.html more power to them.

Can really spot someone who has never had to deal with OFAC with a comment like this. Even if I don't necessarily agree with the concept, or who is actually being blocked, my business is dead in the water if I'm a) sent to prison or b) fined out of existence. Geographic IP information is one of our best tools to defend against those outcomes, and if anything it should be better.

On the other hand, GeoIP is arguably the reason you are in this situation in the first place, i.e., having to use it since it's there and everybody else is doing so as well.

Intentionally ambiguous regulations (in terms of how companies and individuals are expected to comply) backed by the existential threat of huge fines often lead to a race to the bottom in terms of false positives and collateral damage to non-sanctioned users.

Re: VPN location claims don't match real traffic exits

#227
post #123

Earlier quoted context omitted.

Apple, for better or worse, has been able to use their size to pressure sites into accepting connections from their Private Relay service. If VPN usage becomes the norm, sites will have to give in eventually.

It’s better than most VPNs, but the amount of Cloudflare challenges I get is really annoying. It’s a little weird because Apple has device attestation which is run via Cloudflare and Fastly. You’d think that would get you around the challenges, but that doesn’t seem to happen.

You should only get more challenges with VPN if the VPN users are abusing the websites. I actually get fewer CF challenges with NordVPN than without it.

Re: VPN location claims don't match real traffic exits

#228

Earlier quoted context omitted.

Apple, for better or worse, has been able to use their size to pressure sites into accepting connections from their Private Relay service. If VPN usage becomes the norm, sites will have to give in eventually.

My bank app forces me to turn my VPN off. I’m not going to change my bank over that and I imagine most others do the same anyway or will eventually. I imagine many sites and services will just continue go “we’re gonna break this thing you need until you turn the vpn off.”

You can split tunnel most VPNs to let the bank through.

Re: VPN location claims don't match real traffic exits

#229
post #118

Earlier quoted context omitted.

Check reddit.com/appeals some time after creating an account. If you are auto shadow banned, you can appeal.

Something like that happened to me, my 10+ year account and everything I've ever written just vanishing one morning. Even posts to a subreddit I moderate were repeatedly removed after every approval. No idea why, (the "wrong" public Wi-fi?) but my appeal was granted and nothing was fixed . Now I can't contact anyone, and the appeals page falsely claims that my account is in good standing and refuses to operate. When…

It happened to me too. I'm better off without Reddit, I decided.

Re: VPN location claims don't match real traffic exits

#230
post #165

Earlier quoted context omitted.

...then I'll just have to learn how to get stuff done with 512MB of RAM. (I'm sure that browsers like lynx still work just like they did in 2001, and that pine can still read mail. Shouldn't be a problem, right?)

links2 is still a work horse in 2025 for occasional debugging.

I know of links and have used it, but I don't think I've ever used links2.

Am I correct to assume that links2 is more of the same/better?

(Also: Your comment seems perfectly sane, but it was already marked as "flagged" by the time I saw it 18 minutes after it was submitted. I vouched for it.

But I wonder: Whose ruffles did you panty in order for your comments to land this way?)

Post reply on HN