Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

251–260 of 333 posts

Re: VPN location claims don't match real traffic exits

#251

Earlier quoted context omitted.

I can’t access Reddit on Mullvad via Tailscale

There are working end-points and they tend to be stable. If you find a Mullvad server which works with Reddit, you can configure a socks5 proxy for a Firefox container assigned to Reddit (or any domain). This way, Reddit will always use the connection of the working route and your general internet experience isn't affected otherwise. Eg. you can still switch around connections to find a working one for Youtube... Don…

This is a good shout. Thanks!

Re: VPN location claims don't match real traffic exits

#252

ProtonVPN clearly marks these “virtual locations” in their UIs as “smart routing”, so there really isn’t any deception here https://protonvpn.com/support/how-smart-routing-works

That seems reasonable, but they seem to be suffering their own problem with UI and UX design by not making that inherently clearer.

I was getting a bit disappointed about Proton based on this evaluation even though the only problem I’ve had is their really lacking client UI/UX. They should make that visualization clearer. I don’t know the answer, but maybe offering a toggle or expansion for virtualized servers, might be a step in the right direction.

The design issues seems to be a common challenge with proton. The VPN client functions, but it is really grating how basic it is. You can’t even sort, let alone filter servers by load, let alone performance; so you’re scrolling through hundreds of servers. You can’t add regions or even several servers to create a profile with a priority, you have to pick a single server, among hundreds if not thousands in some countries. Oh, and as you’re scrolling through hundreds of servers for a single country, it’s a view of something like 10 lines high.

It’s bonkers

Re: VPN location claims don't match real traffic exits

#253

I tried to use ProtonVPN when I switched over to ProtonMail a year ago. But so much of the web does not work when you're on a VPN. For example even HackerNews has VPN restrictions. More and more sites know where VPN endpoints originate. How will VPNs prevent this in the future without them just become easy to block?

Even worse is the Reddit approach, where leaving your VPN on will get your account shadow banned permanently. But you are not notified of that, so if you are wondering why nobody is replying to your comments, check in a private session if you can visit your profile page.

I wasn’t even aware of that, but it does not at all surprise me, since it fits right in with the trajectory Reddit has long been on; from freedom of information, to full spectrum thought control and digital psychological reprogramming dungeon.

Re: VPN location claims don't match real traffic exits

#254
As per report, 3 providers do not lie.

I searched VPN which payed in crypto and OSS friendly. Mullvad and IVPN were in list, and these also do not lie about exits.

IVPN bought me with very deep transparency into company and WRT support, on top of Linux and Android.

I get maximal longest sub in one payment.

Mullvad is under North EU jury, IPVN under Gibraltar(which is nor exactly UK). So decided offshore like place also more safe against VPN control attempts.

Searched for decentralized VPNs(like TOR, but you pay for speed and do not care onions) some time ago too, we are not there yet.

Re: VPN location claims don't match real traffic exits

#255
Extremely disappointed to see ProtonVPN in this list. Despite others claiming about their smart routing as being a disclaimer of sorts, I am still disappointed that it was never explicitly clear that our privacy was still at stake.

https://protonvpn.com/support/how-smart-routing-works

Re: VPN location claims don't match real traffic exits

#256
post #237
post #185

Earlier quoted context omitted.

Google, Apple, and Meta (maybe others?) have the data to build a complete GeoIP dataset. None of them will share because there are only downsides to doing so. When FB was rolling out ipv6 in 2012, well meaning engineers proposed releasing a v6 only GeoIP db (at the time, the public dbs were shit). Not surprisingly, it was shot down.

At my previous company we had a subscription to Spur Intelligence. It is like Palantir for IP address info, and probably the closest to what you are talking about. They recently added GeoIP to their data and in the bit of testing I was able to do before I left it was scary good . I also had an amusing chat with one of their engineers at a conference about how you can spoof IPInfo's location probes...

> how you can spoof IPInfo's location probes...

Interesting. I would love to know how this is possible. Like with Geofeed or something else?

Re: VPN location claims don't match real traffic exits

#257

Earlier quoted context omitted.

We are always happy to work with large technology enterprises and streaming platforms, not necessarily to sell, but to share insights, data, and practical advice. We observe the entire internet through active measurements, and we are open to co-publishing research when it benefits the broader ecosystem. Google/GCP is top of mind for me due to a recent engineering ticket. Some of our own infrastructure is hosted on GC…

> From what we understand, when a large number of users from a censored country use a specific VPN provider, Google's device-based signals can bias the geolocation of entire IP ranges toward that country. Yep, this is a known effect. How it seems to work is: Google uses Android phones as data harvesting probes. And when it sees that a lot of devices in a given IP range pick up on GPS data, Wi-Fi APs or cell tower IDs…

They have a correction form but I am not sure if it is super robust: https://support.google.com/websearch/workflow/9308722?hl=en

I talked to someone who bought a /24 from South America to be used in the United States for office use. I asked him to tell everyone to get on WiFi and keep Google Maps running. Apparently, that solved the issue.

Re: VPN location claims don't match real traffic exits

#258
post #243

Earlier quoted context omitted.

I work for IPinfo. I have raised a ticket internally, but I think we focused on consumer VPNs for this test. For our ProbeNet, we are attempting to reach 150 countries (by ISO 3166's definition). We are at around 530 cities. Server management is not an easy task. We do not ship hardware, but operate using dedicated servers, so this reduces one layer of complexity. To maintain the authenticity of our server locations,…

Could you use RIPE Atlas and its network of probes, at least to fill in areas where it's difficult to get your own probes? That way everyone benefits.

We are actually a sponsor of RIPE Atlas and have a bunch of credits.

But I am not sure if we use them extensively. I think, as we own and operate the ProbeNet, much of the data collection efforts can be done through that in a scalable manner.

Re: VPN location claims don't match real traffic exits

#259
post #219

Earlier quoted context omitted.

Doesn’t have to be an apple box either. A raspberry pi is what I’m using. I’m in the exact same situation, living in one country temporarily but citizen of another, and I have an exit point in my home country at my parents place on a raspberry pi. Basically any computer will work.

Android TV works great as well. I have it running on an old Chromecast that cost less than $50 new. While I still prefer running a plain Wireguard VPN if possible (i.e. when there's a publicly reachable UDP port), the really big advantage of Tailscale over other solutions is that it has great NAT traversal, so it's possible to run a routing node behind all kinds of nasty topologies (CG-NAT, double NAT, restrictive fi…

I have run into the firewall problems before. Even seen them that block authentication but -if already connected to the tailnet before joining the WiFi in question - will continue to pass data. OpenVPN would not connect and couldn’t handle the IP address switch.

At worst, I turn on phone hotspot, authenticate, then switch back to WiFi. A purely serendipitous discovery on my part, but a very welcome one.

Re: VPN location claims don't match real traffic exits

#260

Earlier quoted context omitted.

Can you buy those in US stores? I’ve been paying for Mullvad with Monero for years. Love it

Amazon, but that kind of defeats the point.

It doesn't defeat the point in my threat model. No one in the position to log my traffic knows who I am other than my source IP address (which is already enough to link it back to me anyway). So let's take Mullvad at their word that they don't log anything, what's the threat now?

Maybe Amazon are x-raying the card numbers before shipping them out to customers, but that would require Mullvad giving up the card number -> account number -> account number traffic logs. Not much of a threat there.

Maybe all amazon orders are funnelled somewhere and they correlate the fact I bought a VPN card with my home address, and then correlate my bandwidth into Mullvad IPs (gained from my ISP logs) with data leaving Mullvad but that's all very unlikely and very circumstantial.

I'm also not doing anything illegal so perhaps my threat model/level is lower than the 'average' VPN user.

Anyway, not to be a shill but honestly I am just completely won over with how Mullvad do business. I know that a VPN does not make you automatically 'private'/'anonymous' but just the way they do business makes me happy.

Post reply on HN