Live data from Hacker News

VPN location claims don't match real traffic exits

ipinfo.io

71–80 of 333 posts

Re: VPN location claims don't match real traffic exits

#71

Is there any real-life situation in which this matters, though? If you're picking a country so you can access a Netflix show that geolimits to that country, but Netflix is also using this same faulty list... then you still get to watch your show. If you're picking a country for latency reasons, you're still getting a real location "close enough". Plus latency is affected by tons of things such as VPN server saturatio…

> Is there any real-life situation in which this matters, though?

You’d be shocked at the number of people in regulated industries that thinks a VPN inherently makes them more secure. If you think your traffic exits in the US and it exits in Canada — or really anywhere that isn’t the US — that can cause problems with compliance, and possibly data domicile promises made to clients and regulators.

At minimum, not being able to rely on the provider that you are routing your client’s data through is a big deal.

Re: VPN location claims don't match real traffic exits

#72
post #22

This was a dumb study, and if they'd asked the VPN providers, I'm sure someone would tell them why. All the VPN providers I've used let you select the endpoint from a dropdown menu. I'm not using a VPN to make it appear I'm in Russia, I'm using it as one of many tools to help further my browsing privacy. My endpoint is one of 2 major cities that are close to me. Could I pick some random 3rd world country? Sure! That…

That may be your use case, but it by no means it's reflective of anyone else's. I live in a country that actively blocks and limits your connectivity to (ordinarily) public websites. Choosing an exit point that's in a different country is very relevant and important.

You are in the minority. Most folks that subscribe to VPNs are folks in the US, Canada, EU, and other "First World" countries. (I had a source a while back for something completely unrelated, however I didn't save it)

I'm not discounting you at ALL, I'm simply stating that the majority of traffic originate from these countries. Most of these folks just want to hide their IP address for various reasons. Privacy, Piracy, etc. Most don't care if it's in the next largest city, they just don't want it to appear to come from them.

Folks in countries like yours will likely pick endpoints to bypass the government. Folks up to nefarious stuff like cracking web sites, social media influencing, etc. will likely pick the target country more carefully. Anyone else? Whatever is the default.

I recognize this is a hard concept to understand for folks on this site, but the average joe signing up for a VPN doesn't even remotely understand what they are doing and why. They were pitched an idea as a way to solve privacy issues, block ads, etc. and they signed up for it. The software suggested a low latency link, and they went with the default.

The ads for a lot of VPN providers literally use scare tactics to sell the masses on the idea.

Re: VPN location claims don't match real traffic exits

#73
post #54

Interesting to learn you can identify the real country/area of origin using probe latency. Though could this be simulated? Like what if the VPN IP just added 100ms-300ms of latency to all of its outgoing traffic? Ideally vary the latency based on the requesting IP's location. And also just ignore typical probe requests like ICMP (ping). And ideally all the IPs near the end of the traceroute would do all this too. To…

It isn't just latency, but "triangulation".

  [IPinfo] pings an IP address from multiple servers across the world and identify the location of the IP address through a process called multilateration. Pinging an IP address from one server gives us one dimension of location information meaning that based on certain parameters the IP address could be in any place within a certain radius on the globe. Then as we ping that IP from our other servers, the location information becomes more precise. After enough pings, we have a very precise IP location information that almost reaches zip code level precision with a high degree of accuracy. Currently, we have more than 600 probe servers across the world and it is expanding.
u/reincoder, https://news.ycombinator.com/item?id=37507355

Re: VPN location claims don't match real traffic exits

#74
post #54

Interesting to learn you can identify the real country/area of origin using probe latency. Though could this be simulated? Like what if the VPN IP just added 100ms-300ms of latency to all of its outgoing traffic? Ideally vary the latency based on the requesting IP's location. And also just ignore typical probe requests like ICMP (ping). And ideally all the IPs near the end of the traceroute would do all this too. To…

with enough packets you can trilaterate an approximate locatuon. adding random jitter will just delay it a bit.

Re: VPN location claims don't match real traffic exits

#75

I tried to use ProtonVPN when I switched over to ProtonMail a year ago. But so much of the web does not work when you're on a VPN. For example even HackerNews has VPN restrictions. More and more sites know where VPN endpoints originate. How will VPNs prevent this in the future without them just become easy to block?

Same. If this is the situation then what is the use case for most "average" consumers?

Re: VPN location claims don't match real traffic exits

#76

I know multiple people who worked / working at Mullvad and they take their business, security and privacy _very_ seriously. Not surprised to see them shine here.

Windscribe and iVPN up there with Mullvad in TFA.

> Mullvad ... security and privacy _very_ seriously. Not surprised to see them shine here.

? TFA reflects on dishonest marketing on part of public VPN providers more than privacy / security.

That said, VPNs don't add much security, though, they are useful for geo unblocking content and (at some level) anti-censorship. In my experience, the mainstream public VPNs don't really match up to dedicated censorship-resistant networks run by Psiphon, Lantern, Tor (and possibly others).

Re: VPN location claims don't match real traffic exits

#77

I'm a big VPN user since I am the citizen of one country and the resident of another. Even for government services I have to use a VPN. I tried to access the bureau of statistics of my home country through my foreign residential IP and got 404s on all pages. Enabled VPN and everything magically started working. For watching the election result video stream I also had to VPN but at least that one gave me a clear messa…

Do you know anyone in that country who will let you stick an rPI behind their modem?

I have been thinking about it but it is tricky from a legal standpoint. What I'm trying to arrange next time I visit is to have a secondary line installed at my parents place that is in my name. So that when I pull heavy traffic from that line it doesn't impact them and I can't get them in trouble for posting a message that isn't government approved.

Re: VPN location claims don't match real traffic exits

#78
post #54

Interesting to learn you can identify the real country/area of origin using probe latency. Though could this be simulated? Like what if the VPN IP just added 100ms-300ms of latency to all of its outgoing traffic? Ideally vary the latency based on the requesting IP's location. And also just ignore typical probe requests like ICMP (ping). And ideally all the IPs near the end of the traceroute would do all this too. To…

If you ping it from UK and it ping >10ms then you know its there. And you are triangulating from multiple countries.

Re: VPN location claims don't match real traffic exits

#79

I know multiple people who worked / working at Mullvad and they take their business, security and privacy _very_ seriously. Not surprised to see them shine here.

Coincidentally, Mullvad, Windscribe and IVPN all worked when I was in China behind GFW, while more popular options did not.

Seems like there are VPNs, and then there are VPNs.

Re: VPN location claims don't match real traffic exits

#80

While exits matter to avoid countries with a nation-wide firewall, the geoip industry is a scourge. If an ISP wants to help their users avoid geoblocking via https://www.rfc-editor.org/rfc/rfc8805.html more power to them.

I hope they can use DNS for this instead like they do PTR entries
Post reply on HN