Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

281–290 of 333 posts

Re: VPN location claims don't match real traffic exits

#281
post #185

Earlier quoted context omitted.

Google, Apple, and Meta (maybe others?) have the data to build a complete GeoIP dataset. None of them will share because there are only downsides to doing so. When FB was rolling out ipv6 in 2012, well meaning engineers proposed releasing a v6 only GeoIP db (at the time, the public dbs were shit). Not surprisingly, it was shot down.

We are always happy to work with large technology enterprises and streaming platforms, not necessarily to sell, but to share insights, data, and practical advice. We observe the entire internet through active measurements, and we are open to co-publishing research when it benefits the broader ecosystem. Google/GCP is top of mind for me due to a recent engineering ticket. Some of our own infrastructure is hosted on GC…

Do Cloudflare's floating egress IPs probe in a way where you can easily geolocate them?

https://blog.cloudflare.com/cloudflare-servers-dont-own-ips-...

Re: VPN location claims don't match real traffic exits

#282
post #240

Earlier quoted context omitted.

Google's GeoIP is rubbish for me. Often it's hundreds of kilometres off, and varies a lot even for a fixed IP.

As always with big corporations, if the experience is OK for 90% of people but absolutely sucks for 10% of people, then that's totally fine!

I can tell you how we approach enterprise partnerships: absolute accountability. If something is wrong with the data, it is not our customers' fault for trusting us, it is our fault. End users talk to us directly. And because the data is so good these days, we just have to present evidence, that's it.

We with multi-billion-dollar corporations, and for every product integration we maintain an active, visible presence in their user communities.

For example: https://community.cloudflare.com/search?q=ipinfo%20order%3Al...

Customer support teams are encouraged to build support pipelines that either route data-related questions directly to us or send users directly. We remove friction rather than hiding behind layers of enterprise support.

We make a deliberate "account manager for everyone" effort when introducing ourselves to a partner's user community. We engage with influential community members and MVP users and encourage them to contact us directly when issues arise. We also connect with the engineers who work hands-on with our data and make it clear that they have a direct line to our engineering team.

We actively and aggressively monitor social media for reports of issues related to our data within partner platforms and engage with users directly when something comes up.

To be honest, this is not difficult. Once or twice a month, we may need to present evidence to a user to explain our data decision.

This is not a paid add-on or a special clause in an enterprise contract. Our customers do not pay extra for this level of engagement.

Developers hold us in high regard. Maintaining that trust requires ongoing investment of time and resources. We fundamentally believe developers trust us because of the quality of the product and the lengths we go to provide clear, honest explanations when questions arise.

Re: VPN location claims don't match real traffic exits

#283

Earlier quoted context omitted.

A better metaphor would be that Tor and VPNs are like wearing a mask in public. It's obvious that you're trying to be anonymous, but you're still wearing a mask, so no one knows who you are. You may be denied entry to certain establishments, but some of the bouncers don't block all masks and if you're persistent with changing your mask (Tor or VPN exit node), there's a good chance you'll get in. CTRL+SHIFT+L works on…

To continue on the analogy, many people using a VPN wear a mask but they also keep the same unique combination of clothes that they were wearing a few minutes earlier without a mask.

Wearing a mask in public while wearing your unique style of clothing, BUT you may be able to exit your apartment building through the service entrance if your landlord is into spelunking and replaced the front door with a nutty putty cave imitation.

I cannot overstate how much of a pain it was to share 51Gbps of peering with 40M other homes and 60M mobile customers. Luckily they now have made generous upgrades, shoving an additional 15M to 20M customers through a whopping 371Gbps.

Unless of course the network your traffic is headed to has deep, widely open and sufficiently climatized pockets.

Re: VPN location claims don't match real traffic exits

#284
post #222

Earlier quoted context omitted.

> ISPs are incentivized to help us by providing good data. That's the entire problem in a nutshell. Good quality of service should not depend on every site I visit knowing my geographic location at the ZIP code or even street level (I've actually seen the latter occasionally). I can somewhat understand the need for country-wide geoip blocking due to per-country distribution rights for media and whatnot, but when my b…

That is an excellent point! That is why we have the IP to country level data available for free. As you have recognized the fact that country level data is good for security, we are willing to take a massive hit on potential revenue to allow everyone to use our country level data for free, even for commercial purposes. We literally built separate dedicated infrastructure that provides unlimited queries for our IP to…

> As you have recognized the fact that country level data is good for security [...]

That's the opposite of what I said. I think blocking entire countries is largely security theater. Bad actors will just use botnets or other residential proxies wherever needed, while legitimate users traveling abroad get locked out.

I can see it make sense for login-free distribution of media with limited regional rights (e.g., some public broadcasters offer their streams for free but are only allowed to do so domestically), or to provide a best guess for region-specific services (weather forecasts, shipping rate estimates etc.), although I'd also love to see that handled via the user agent instead, e.g. via granting coarse location access, to prevent false positives.

I also wouldn't mind it as much as one of many input signals into some risk calculation, e.g. for throttling password (but not passkey) attempts, to be overridden by login status, but outright bans are incredibly annoying, and unfortunately that's what I see many companies doing with GeoIP data.

Almost as annoying: Companies insisting on serving me a different language just because I traveled abroad, even though my "Accept-Language" header is right there.

Re: VPN location claims don't match real traffic exits

#285

Earlier quoted context omitted.

What is this AppleTV box running TS that you speak of? Sounds awesome.

Check out the instructions from Tailscale: https://tailscale.com/kb/1280/appletv

I wish there was a way to use the tailscale app to connect to my own vanilla WireGuard endpoint at home. I don’t want to use and pay for tailscale when I can run WireGuard myself. But there seems to be no good WireGuard app for tvOS (there is for iOS and macOS though) and if the TS app works as well as it says, I’m jealous I can’t use it with my setup.

(There’s another really shitty VPN app for tvOS that I tried, but it also costs money so screw that. It’s also buggy as hell and crashes all the time.)

I should add that my use case is the occasional trip where we take the Apple TV with us places and want to access my media library. Or being able to share my media library with extended family (setting their Apple TV up with a vpn to my house.) More complex things like travel routers can work, but are more hassle than I want, although I’m increasingly leaning towards taking the plunge there…

Re: VPN location claims don't match real traffic exits

#286

I'm a big VPN user since I am the citizen of one country and the resident of another. Even for government services I have to use a VPN. I tried to access the bureau of statistics of my home country through my foreign residential IP and got 404s on all pages. Enabled VPN and everything magically started working. For watching the election result video stream I also had to VPN but at least that one gave me a clear messa…

I built TunnelBuddy (tunnnelbuddy.net) just for this. I am the same: citizen of one country and resident of another. I have multiple friends and family where I am from. I get them to open tunnelbuddy (nobody needs to sign up), to share a one-off password (like TeamViewer) and I get to access the internet as if I was at their place. Underneath, it uses WebRTC (the same tech as Google Meet). It is free to use, I just b…

That's a cool tool.

FYI: There's a typo in the URL you posted, an extra `n` :)

Re: VPN location claims don't match real traffic exits

#287
post #118

Earlier quoted context omitted.

Check reddit.com/appeals some time after creating an account. If you are auto shadow banned, you can appeal.

Something like that happened to me, my 10+ year account and everything I've ever written just vanishing one morning. Even posts to a subreddit I moderate were repeatedly removed after every approval. No idea why, (the "wrong" public Wi-fi?) but my appeal was granted and nothing was fixed . Now I can't contact anyone, and the appeals page falsely claims that my account is in good standing and refuses to operate. When…

> So at this point, I only lurk occasionally, because I'm not going to go through that social hell again

I feel ya. Sad thing is, there really isn't anywhere else to go for niche interests, or really much any particular information. AI fallout has finally killed the struggling web and online community. I think, there isn't much left besides cutting losses, resetting your dopamine receptors and finding community in the real world and all...

Well, now that's gonna be a bit of a challenge living outside big cities, where you can't afford rent, of course. I guess, if meeting other people is out, you can still always watch brain rot TV, or strap in the amyl nitrite inhaler and goon away for the time between work shifts. Until things are worth remembering again. When those investment trillions finally paid off and humanity accelerates into the new age of blissful meaning.

Re: VPN location claims don't match real traffic exits

#288

ProtonVPN clearly marks these “virtual locations” in their UIs as “smart routing”, so there really isn’t any deception here https://protonvpn.com/support/how-smart-routing-works

That seems reasonable, but they seem to be suffering their own problem with UI and UX design by not making that inherently clearer. I was getting a bit disappointed about Proton based on this evaluation even though the only problem I’ve had is their really lacking client UI/UX. They should make that visualization clearer. I don’t know the answer, but maybe offering a toggle or expansion for virtualized servers, might…

Surfshark has many labeled as "Virtual" but doesn't really give a good explanation as to what this means.

Re: VPN location claims don't match real traffic exits

#289
post #172

Earlier quoted context omitted.

Lots of people already have Apple TVs and the Tailscale integration is pretty good and can serve as an always online exit node. So no new hardware required. Could even remotely walk a non-techie through the process without too much effort. personally, I've just upgraded my family's wifi to Ubiquiti and can then use Tailscale Wireguard running on the gateway as a proxy! (with their permission)

Is it that common outside the us? I know of exactly one family here in Germany having Apple TV.

The only folks using Apple TV in 2026 are like 60+ yrs old.

I've literally not seen one in anyone's home for probably 5+ years. And even then nobody used them.

Apple TV was one of those products that relatively few people bought but they were loud about buying it, so it seemed more popular than it was. Then other services like Roku($20) quickly replaced it.

I'm in the USA.

Re: VPN location claims don't match real traffic exits

#290
This is interesting because for some people, it would be a feature to be operating with, say, a US VPN tunnel that is “on paper” in the Bahamas. Better latency. For instance, the average person downloading Torrents.

Of course, for the most high-stakes stuff if you were worried about some kind of major state level actors or something, you want to keep a very tight control over where your actual traffic is physically transiting. So it seems only proper that they disclose these discrepancies to customers.

Even still, I suspect encryption and proper lack of logs provides sufficient cover for most people for most actually likely threats.

Post reply on HN