Live data from Hacker News

Passive TCP/IP Geo-Location

geoloc.foremski.pl

61–70 of 91 posts

Re: Passive TCP/IP Geo-Location

#61

Little Snitch[1] does a very good job of preventing this sort of attack. Even if they give names to the servers that make me think they're something I want to allow, the time I spend clicking the "Allow" button is well outside the margin of error of the latency measurements. I'm in NYC and the tool places me in Frankfort, Germany. +1 for Little Snitch. [1] https://www.obdev.at/products/littlesnitch/index.html

Yes, I use and love Little Snitch too, but don't you have a rule that says Browser = Allow all?

Nope.

It only took me a few days to work out whitelists/blacklists for the sites I use often, i.e. most citicards.com subdomains get an "allow" but cardoffer.citicards.com gets a "deny". On other sites I come across it's usually trivial to whitelist the domains that provide their functionality, and most adservers and tracking servers I've already blocked.

Given browsers are the main place I get tracked, putting an allow all for my browser seems to defeat the purpose.

That said, it was pretty annoying the first few days.

Re: Passive TCP/IP Geo-Location

#65

Earlier quoted context omitted.

Yes, I use and love Little Snitch too, but don't you have a rule that says Browser = Allow all?

Nope. It only took me a few days to work out whitelists/blacklists for the sites I use often, i.e. most citicards.com subdomains get an "allow" but cardoffer.citicards.com gets a "deny". On other sites I come across it's usually trivial to whitelist the domains that provide their functionality, and most adservers and tracking servers I've already blocked. Given browsers are the main place I get tracked, putting an al…

Nice tool, is there something similar (in terms of UX) for Linux?

For browser I usually use Noscript... Not the same because it only blocks JS files though.

Re: Passive TCP/IP Geo-Location

#67
post #2

> This website demonstrates IP address geo-location by passively measuring TCP/IP round-trip times of web requests made to a few servers spread around the world. I don't get how that could be called passive. This is making your browser issue requests or am I missing something?

I believe the author's point was you could determine the location by monitoring other applications and their network calls. That being said, I highly doubt there are many requests being made to Bangalore, India and this appears to require requests to a wide array of locations all over the world.

It requires precisely what services such as Cedexis provide.

You visit a website that uses one or more CDNs for its big resources, and uses Cedexis to choose CDN node. When you first visit, Cedexis instructs your browser to retrieve small resources from some/all CDN nodes. Based on timings and throughput, it then chooses a CDN node to use for big resources.

If Cedexis does its job well and obtains the right data for Cedexis' purposes, then the passive observer also gets optimally usable data.

Re: Passive TCP/IP Geo-Location

#69
this puts me in one of about 6 locations in the world each with an accuracy of several thousand kilometers. probably because i suffer from quite unpleasant packet loss. but not convinced it works.

Re: Passive TCP/IP Geo-Location

#70
post #44
post #40

Earlier quoted context omitted.

OK... I get that. But, where am I? http://tinypic.com/r/2ushgus/9

Western Europe I think? It's confusing, some of the circles are shaded inside and some outside. I think the idea is if the ping is high it covers the whole globe except a circle around the antipodes (shaded outside), and if the ping is low it only covers around the server (shaded inside).

Mmm, right. Close but not quite. I like the idea but I think the visualisation needs some work. Too many people seem to have a hard time making sense of it.
Post reply on HN