Earlier quoted context omitted.
> Wireguard and remove Apple and Tailscale from the equation entirely I agree you could send them a preconfigured pi, but can we stop pretending talescale is just wireguard - there is a lot of convenience in the NAT traversal that you otherwise need router config and/or a publically routable server to achieve.
> but can we stop pretending talescale is just wireguard That's precisely the issue. It introduces additional centralized dependencies and closed source components.
VPN location claims don't match real traffic exits
321–330 of 333 posts
Re: VPN location claims don't match real traffic exits
#322I know multiple people who worked / working at Mullvad and they take their business, security and privacy _very_ seriously. Not surprised to see them shine here.
When they wrote that 3 providers were honest about all locations I have to admit my first thought was "Mullvad, and who would the other two be?" With their reputation and trackrecord they really can't do any shady tricks. Imagine if they weren't among the 3 honest providers? That would be HN frontpage news.
Re: VPN location claims don't match real traffic exits
#323Earlier quoted context omitted.
Amazon, but that kind of defeats the point.
It doesn't defeat the point in my threat model. No one in the position to log my traffic knows who I am other than my source IP address (which is already enough to link it back to me anyway). So let's take Mullvad at their word that they don't log anything, what's the threat now? Maybe Amazon are x-raying the card numbers before shipping them out to customers, but that would require Mullvad giving up the card number…
Re: VPN location claims don't match real traffic exits
#324Earlier quoted context omitted.
Amazon, but that kind of defeats the point.
Buy amazon gift card in cash, setup new account, ship scratch card to locker? (Idk if they’d let you do that). I think you can still mail them cash?
Re: VPN location claims don't match real traffic exits
#325Earlier quoted context omitted.
If you're doing latency-based probing, location spoofing is presumably possible to an extent by adding artificial delays and possibly spoofing ICMP "TTL expired" packets like https://github.com/blechschmidt/fakeroute
I am not sure whether this kind of IP spoofing will impact our accuracy because we will likely identify the noise and behavioral anomaly and discard the location hint derived from traceroute. We have tons of historical traceroute data patterns, and generic traceroute behaviors are likely modeled out internally. So, if you can spoof the traceroute to your IP address, our traceroute-based location hint scoring weight f…
Re: VPN location claims don't match real traffic exits
#326Earlier quoted context omitted.
Depending on crypto, and even on public ledger ones, there are ways to on-ramp cash to a new cold wallet.
For payments, a cold wallet affects only its security, never its transparency. When you pay from it, you expose an IP.
Re: VPN location claims don't match real traffic exits
#327Earlier quoted context omitted.
Buy amazon gift card in cash, setup new account, ship scratch card to locker? (Idk if they’d let you do that). I think you can still mail them cash?
Can an Amazon account be made anonymously? (I've never tried).
Re: VPN location claims don't match real traffic exits
#328Earlier quoted context omitted.
For payments, a cold wallet affects only its security, never its transparency. When you pay from it, you expose an IP.
if the on-ramp to the cold wallet was cash then what good is that transparency.
Re: VPN location claims don't match real traffic exits
#329Earlier quoted context omitted.
90% of end users, not 90% of your customers. If your product blocks 10% of end users because it provides wrong geolocation data to your customer, sucks to be them!
That is a great point! For us, it is 100% of end users not limited to our customers. If you are impacted by our data in any way, it is on us. We are accountable for that. https://community.ipinfo.io/t/wrong-geolocation-based-on-ip-... Our free database is licensed under "CC-BA-SA" (freely distributable but requires attribution) because of accountability. If you use our data as an enterprise or a free open-source proj…
Also the reason most IP information companies don't do this is the obvious risk of false information. I am currently in Somalia via a remote connection via Germany. Actually I'm not, but if I emailed you and said I was, how would you know?
Re: VPN location claims don't match real traffic exits
#330Earlier quoted context omitted.
Sounds awful, though. Maybe we should get more widespread usage for IPv6 instead.
Surely IPv6 makes location spoofing harder, you're not identified by just location anymore but uniquely identified down to the device?
It has been a non-existent problem for roughly 20 years now. Why do people still keep pulling out "uniquely identified down to the device" as an argument?
Windows, macOS and most Linux distros by default rotate SLAAC addresses every 24 hours.