Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

321–330 of 333 posts

Re: VPN location claims don't match real traffic exits

#321

Earlier quoted context omitted.

> Wireguard and remove Apple and Tailscale from the equation entirely I agree you could send them a preconfigured pi, but can we stop pretending talescale is just wireguard - there is a lot of convenience in the NAT traversal that you otherwise need router config and/or a publically routable server to achieve.

> but can we stop pretending talescale is just wireguard That's precisely the issue. It introduces additional centralized dependencies and closed source components.

And you will introduce a centralised dependency by using wireguard too - at least one of the nodes needs to be accessible from the other(s).

Re: VPN location claims don't match real traffic exits

#322

I know multiple people who worked / working at Mullvad and they take their business, security and privacy _very_ seriously. Not surprised to see them shine here.

When they wrote that 3 providers were honest about all locations I have to admit my first thought was "Mullvad, and who would the other two be?" With their reputation and trackrecord they really can't do any shady tricks. Imagine if they weren't among the 3 honest providers? That would be HN frontpage news.

While I pay for Mullvad directly through my bank, their account number approach built a lot of trust for me. "Here's your number, use whatever to fund it. 5 euro a month, no sales."

Re: VPN location claims don't match real traffic exits

#323

Earlier quoted context omitted.

Amazon, but that kind of defeats the point.

It doesn't defeat the point in my threat model. No one in the position to log my traffic knows who I am other than my source IP address (which is already enough to link it back to me anyway). So let's take Mullvad at their word that they don't log anything, what's the threat now? Maybe Amazon are x-raying the card numbers before shipping them out to customers, but that would require Mullvad giving up the card number…

But then how is that more secure than just paying Mullvad directly? Either way, there's a record of "this person gave money to Mullvad".

Re: VPN location claims don't match real traffic exits

#324

Earlier quoted context omitted.

Amazon, but that kind of defeats the point.

Buy amazon gift card in cash, setup new account, ship scratch card to locker? (Idk if they’d let you do that). I think you can still mail them cash?

Can an Amazon account be made anonymously? (I've never tried).

Re: VPN location claims don't match real traffic exits

#325

Earlier quoted context omitted.

If you're doing latency-based probing, location spoofing is presumably possible to an extent by adding artificial delays and possibly spoofing ICMP "TTL expired" packets like https://github.com/blechschmidt/fakeroute

I am not sure whether this kind of IP spoofing will impact our accuracy because we will likely identify the noise and behavioral anomaly and discard the location hint derived from traceroute. We have tons of historical traceroute data patterns, and generic traceroute behaviors are likely modeled out internally. So, if you can spoof the traceroute to your IP address, our traceroute-based location hint scoring weight f…

Yeah, I doubt there are more than a couple of hosts on the entire internet serving fake traceroutes anyway. Even finding hosts that don't enforce BCP38 requires quite some effort these days.

Re: VPN location claims don't match real traffic exits

#326

Earlier quoted context omitted.

Depending on crypto, and even on public ledger ones, there are ways to on-ramp cash to a new cold wallet.

For payments, a cold wallet affects only its security, never its transparency. When you pay from it, you expose an IP.

if the on-ramp to the cold wallet was cash then what good is that transparency.

Re: VPN location claims don't match real traffic exits

#327

Earlier quoted context omitted.

Buy amazon gift card in cash, setup new account, ship scratch card to locker? (Idk if they’d let you do that). I think you can still mail them cash?

Can an Amazon account be made anonymously? (I've never tried).

I assume if all the inputs are anonymous you could? Like phone/email. Never tried either haha.

Re: VPN location claims don't match real traffic exits

#328

Earlier quoted context omitted.

For payments, a cold wallet affects only its security, never its transparency. When you pay from it, you expose an IP.

if the on-ramp to the cold wallet was cash then what good is that transparency.

One can cycle it through an encryption or obfuscation layer with a no-log crypto foreign VPN. The layer can be LTC MWEB / Monero / Bitcoin Mixer, etc.

Re: VPN location claims don't match real traffic exits

#329

Earlier quoted context omitted.

90% of end users, not 90% of your customers. If your product blocks 10% of end users because it provides wrong geolocation data to your customer, sucks to be them!

That is a great point! For us, it is 100% of end users not limited to our customers. If you are impacted by our data in any way, it is on us. We are accountable for that. https://community.ipinfo.io/t/wrong-geolocation-based-on-ip-... Our free database is licensed under "CC-BA-SA" (freely distributable but requires attribution) because of accountability. If you use our data as an enterprise or a free open-source proj…

How can somebody who is blocked from (looking at your homepage) Docker Hub or Microsoft know that the reason they are blocked is that you have wrong data on them? How would they know to ask you? If they ask Docker Hub or Microsoft, they'll get funnelled into the "well it works for 90% of people" funnel.

Also the reason most IP information companies don't do this is the obvious risk of false information. I am currently in Somalia via a remote connection via Germany. Actually I'm not, but if I emailed you and said I was, how would you know?

Re: VPN location claims don't match real traffic exits

#330
post #18

Earlier quoted context omitted.

Sounds awful, though. Maybe we should get more widespread usage for IPv6 instead.

Surely IPv6 makes location spoofing harder, you're not identified by just location anymore but uniquely identified down to the device?

This was solved in 2007 with Privacy Extensions.

It has been a non-existent problem for roughly 20 years now. Why do people still keep pulling out "uniquely identified down to the device" as an argument?

Windows, macOS and most Linux distros by default rotate SLAAC addresses every 24 hours.

Post reply on HN