Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

271–280 of 333 posts

Re: VPN location claims don't match real traffic exits

#271
post #18

Earlier quoted context omitted.

With CGNAT becoming more widespread, formats like this might need expansion to include location data for ports. Ie. Port 10,000-20,000 are consumers in New york, port numbers 20000-30000 are in Boston, etc.

Sounds awful, though. Maybe we should get more widespread usage for IPv6 instead.

Surely IPv6 makes location spoofing harder, you're not identified by just location anymore but uniquely identified down to the device?

Re: VPN location claims don't match real traffic exits

#272

ProtonVPN clearly marks these “virtual locations” in their UIs as “smart routing”, so there really isn’t any deception here https://protonvpn.com/support/how-smart-routing-works

It's not marked in the Chrome extension UI.

Re: VPN location claims don't match real traffic exits

#273

Earlier quoted context omitted.

Yes. Let’s take an extreme example: you think you exit in Japan, but you’re actually exiting in China. This means your traffic will be analyzed and censored by China. The routers don’t care about where the provider says the IP comes from. If the packet travels through the router, it gets processed. So it very much matters if you do things that are legal in one country, but might not be in another. You know, one of th…

A more general case is for legal and SLAs. If a company uses one of these vpns to make sure their traffic only travels through a specific legal path, and then it's found that their traffic entered a different territory, there can be a lot of consequences. The case I can think of most accessible would be anything that streams copywriten video.

I've wondered about jurisdiction in copyright for a while -- if I access a USA website from a Swedish server, make a copy on that server, then stream it to a French location for viewing all the while being in UK. Where has any crime/infringement occurred; which courts have jurisdiction?

Anyone know of any caselaw addressing these issues.

Re: VPN location claims don't match real traffic exits

#274

I know multiple people who worked / working at Mullvad and they take their business, security and privacy _very_ seriously. Not surprised to see them shine here.

Has anyone else from Europe noticed how Mullvad's speeds and latency have becoming worse and worse during peak times in the recent months? I now have to change servers regularly, which was never the case ~2 years ago.

Re: VPN location claims don't match real traffic exits

#275
post #54

Interesting to learn you can identify the real country/area of origin using probe latency. Though could this be simulated? Like what if the VPN IP just added 100ms-300ms of latency to all of its outgoing traffic? Ideally vary the latency based on the requesting IP's location. And also just ignore typical probe requests like ICMP (ping). And ideally all the IPs near the end of the traceroute would do all this too. To…

There's quite a bit of effort in this space.

In my first job out of school, I did security work adjacent to fortune 50 banks and the (now defunct) startup I worked at partnered some folks working on Pindrop (https://www.pindrop.com/).

Their whole thing at the time was detecting when it was likely that a support call was coming from a region other than the one the customer was supposed to be in (read: fraudulent) by observing latency and noise on the line (the name is a play on "We're listening closely enough to hear a pin drop".)

Long story short, it's a lot more than just the latency that can clue someone in on the actual source location, and even if you introduce enough false signal to make it hard to identify where you actually are, it's easy to spot that and flag you as fake, even if it's hard to say exactly what the real source is.

Re: VPN location claims don't match real traffic exits

#276
post #54

Interesting to learn you can identify the real country/area of origin using probe latency. Though could this be simulated? Like what if the VPN IP just added 100ms-300ms of latency to all of its outgoing traffic? Ideally vary the latency based on the requesting IP's location. And also just ignore typical probe requests like ICMP (ping). And ideally all the IPs near the end of the traceroute would do all this too. To…

Ideally, there'd be a way to subtract lag. (A non-causal network switch? Would be big business...)

Re: VPN location claims don't match real traffic exits

#277
post #72

Earlier quoted context omitted.

That may be your use case, but it by no means it's reflective of anyone else's. I live in a country that actively blocks and limits your connectivity to (ordinarily) public websites. Choosing an exit point that's in a different country is very relevant and important.

You are in the minority. Most folks that subscribe to VPNs are folks in the US, Canada, EU, and other "First World" countries. (I had a source a while back for something completely unrelated, however I didn't save it) I'm not discounting you at ALL, I'm simply stating that the majority of traffic originate from these countries. Most of these folks just want to hide their IP address for various reasons. Privacy, Pirac…

> I recognize this is a hard concept to understand for folks on this site, but the average joe signing up for a VPN doesn't even remotely understand what they are doing and why.

So what? This article isn’t for them and this isn’t a major news site for the general public, it’s a site for people who want or need to know how things work.

Re: VPN location claims don't match real traffic exits

#278

Earlier quoted context omitted.

My bank app forces me to turn my VPN off. I’m not going to change my bank over that and I imagine most others do the same anyway or will eventually. I imagine many sites and services will just continue go “we’re gonna break this thing you need until you turn the vpn off.”

You can split tunnel most VPNs to let the bank through.

Not sure I can on an iPhone but yes on my desktop I’ve done that

Re: VPN location claims don't match real traffic exits

#279
post #261

Yeah happens to other “vpn” solutions like zero trust solutions like zscalar. Logs says the user in Buffalo, IP is in Toronto. Same for users on the southern border, us location and Mexican ip.

Zscaler enrages me with their use of the term "zero trust" in marketing, because due to their MitM-ing of TLS, they become a single-point-of-interception for all your organisation's traffic. "100%-trust" would better describe it for me, as you have to have 100% trust of Zscaler and anyone who has admin access to your organisation's Zscaler account.

Re: VPN location claims don't match real traffic exits

#280
This article fails to distinguish between false claims and true claims - VPN providers sometimes explicitly mark some locations as virtual, so there is no mismatch between the claim and the real exist as the title says, because the original claim was never "Bahamas is a physical exit"
Post reply on HN