8 ms·
Check Your IP Reputation Score
- fotad 4y agoSo OVH is 0 and Hetzner is 1, I suppose some ASN are worse than OVH/Hetzner, will they get negative scoe?
- togs 4y agoIf this could somehow be tied to credit score, it would really discourage piracy.
- funstuff007 4y agoyou've rediscovered the secret sauce to peer to peer credit models https://www.turnkey-lender.com/blog/data-enrichment-is-the-secret-sauce-in-digital-lending/ https://www.turnkey-lender.com/blog/data-enrichment-is-the-s...
- egberts1 4y agoTurnkey: “45 million Americans have no credit history.” Almost entirely children. There were 73 million children in the U.S. in 2019—22 percent of our nation's population.
- data_maan 4y agoIt would. It would also discourage free speech and a number of other good things.
- tuatoru 4y agoWhy are "tor", "vpn", "iCloud relay", and "datacenter" considered threats?
- diroussel 4y agoIf you wanted to send spam, or run an attack, you’d want to run your traffico via tor or a vpn to hide your home or office IP. Not sure why iCloud relay would be a problem.
- ender341341 4y agoisn't icloud relay just a vpn?
- ronsor 4y agoIt's an Apple VPN, which makes it special since you usually don't want to piss off Apple/iOS users with "anti-bot" crap.
- sneak 4y agoTied to a unique and expensive Apple hardware serial number. It's a reputation-certification VPN.
- diroussel 4y agoIt’s an HTTP proxy. Two layers of proxy. I was just assuming that paying iCloud users might be less likely to launch bot attacks. But on reflection I guess that is just bias.
- usr1106 4y agoThey are threats to those who think that geoblocking is a good thing.
- SyneRyder 4y agoI've just been running through my own website logs for the week, and the majority of hacking attacks (mostly attempts at stealing AWS & Git credentials, but also outright hacking, vulnerability scans, exploit attempts & brute forcing attempts) have all been via VPN, Tor exit nodes, and relays. Legit website users just never use VPN or Tor for anything. Datacenter is not necessarily a "threat", but if a datacenter is trying to post to your website comment form, it's certainly posting some kind of spam or SQL injection attempt, and it's not a message from a legitimate customer. (Datacenter is actually a highly effective flag for detecting spam.)
- data_maan 4y ago> Legit website users just never use VPN or Tor for anything. You are wrong. I use that and a minority of legit people also do. The problem with your type of thinking is that you are only thinking in terms of what the population majority is doing and how they are behaving - lumping the minority of privacy conscious user in with all kinds if malicious actors. Basically the type of thinking that leads to all kinds of discrimination, unfortunately.
- SyneRyder 4y agoNo, it is based on my web logs across my websites. I have never had a single purchase come through a VPN or Tor node. I have never had a legitimate customer or personal enquiry come through a VPN or Tor node. 100% of VPN and Tor access to my websites have all been hacking and spam attempts. I have spent the last few months fighting spam & hacking attempts in detail - primarily from a Russian & Chinese exploit botnet that seems to have spun up around Feb 2021. This is why I am so confident in my statement, because I have been logging and collecting data on the spam & hacking attacks, and analyzing my data daily. I've detected attacks via AVAST's VPN, Nord VPN, Fiber Grid, Tor exit nodes on Frantech, GleSys AB, Hidehost, Performive VPN, HideMyAss, PureVPN, and I just spent this afternoon tracing a particularly dumb bot that tried sending thousands of requests through StrongVPN, just alternating between 2 IP addresses. And that's just a subset of what I've been fighting against. For what it's worth, I only see the Tor exit nodes occasionally, VPNs are much more common. I used to think VPNs and Tor were a good thing (about a decade ago). My mind has been changed by looking at the quantitative data I have collected.
- GoblinSlayer 4y agoThe point about proxy detection explains it as abuse in the form of ban circumvention.
- deleted 4y ago[deleted]
- a-r-t 4y agoIs this ipinfo [0] repackaging their product? [0] https://ipinfo.io/ https://ipinfo.io/
- deleted 4y ago[deleted]
- anyfactor 4y agono. Source: I work for IPinfo. We don't do "IP Reputation Score". We provide the attributes/insights related to an IP address, the user makes the decision of how to use that information.
- p49k 4y agoI thought IPinfo was just sourced from Maxmind, am I wrong? Is there any way to know who are the original sources of info in this space and who are reselling?
- coderholic 4y agoAll of our datasets at IPinfo, including geolocation, are proprietary and created in house - we're not reselling any 3rd party data.
- data_maan 4y agoSeems a slightly better business model than the one from the OP. But it still comes somewhat close to a China-social-credit system for the internet.
- yalogin 4y agoI don’t understand what this is or what the reputation really is. The site talks about threat intelligence and other marketing phrases. I hope I didn’t just give my IP to the site to just add to their database to show to their investors or worse data mine me somehow.
- jonathan-kosgei 4y agoFor context, a few months ago we launched our Blocklists [0] feature which allows users to query 100+ blocklists and find all the ones where an IP address has been listed. Blocklists based threat detection is however limited since they cannot contain every possible bad IP which leads to a lot of false negatives. To fix this we created an IP Reputation scoring model [1] and currently provide 4 scores. - Trust Score - VPN Score - Proxy Score - Threat Score The Trust Score simply aggregates the other 3 scores and is a value from 0 - 100, with 100 being a very high reputation IP address. [0] https://docs.ipdata.co/docs/ip-reputation-scores https://docs.ipdata.co/docs/ip-reputation-scores [1] https://docs.ipdata.co/docs/ip-reputation-scores https://docs.ipdata.co/docs/ip-reputation-scores
- data_maan 4y agoWhat he is basically saying is that they are the gatekeepers of the internet now and will decide for you if you are trustworthy.
- rdtwo 4y agoIt matters because it changes the difficult of some hype drops for sneakers and stuff. That’s about it, also maybe how long the ip will last before it gets flagged as a bot
- deleted 4y ago[deleted]
- nuker 4y ago> Threats: iCloud Relay Seriously?
- lostlogin 4y agoFor me it says “error, not connected to internet”. Or just doesn’t run.
- jimmydorry 4y agoSame. It must have been HN hugged.
- bslqn 4y ago
- jonathan-kosgei 4y agoCould you try now and let me know if this persists?
- KronisLV 4y agoGot a trust score of 100 for an IP address that's assigned to me through Latvijas Mobilais Telefons (LMT). I guess that's perhaps one of the "benefits" of sitting behind CGNAT (from what I can tell), where nobody can host their own stuff and thus various sites (good or bad) hosted on residential connections and other interesting use cases aren't a thing. It still doesn't feel too good to need cloud VPSes that act as proxies just so I can expose some sites from my homelab (e.g. a Nextcloud instance of D&D session recordings and other game details), even though for whatever reason it's still cheaper than asking the ISP for static IP addresses (e.g. a ~5 euro/month VPS). That said, all of my VPS IP addresses (which I've had assigned to my servers for a few years) routinely scored 15-25 and landed in the "High risk" trust scores, even though they have 0 threats showing up. Guess running my own VPN to tunnel my connection through them might not be the best idea, if I wanted to do that in the future?
- jbotz 4y agoHumph. My home IP address which is shared by thousands of random people behind two layers of NAT, in Brazil, gets a score of "63, low risk". My mail server, on Linode in the US, which has had the same IP# for about 20 years and sends mail to GMail and Microsoft without problems (and only from a small group of people who never send spam) gets a score of "0, high risk". This is useless garbage, and dangerous to boot. The last thing we need is more arbitrary and unaccountable "reputation scores" being propagated by self-appointed and unqualified reputation judges.
- jonathan-kosgei 4y agoThis is actually proof that it works as intended. Our scores are made to be consumed by web applications. In that context it makes sense that a cloud IP that's used to send mail would be treated with suspicion if it's seen trying to make a purchase on an e-commerce site.
- data_maan 4y agoThe audacity you people are having of shoving unconsented scores down our throats! I hope you choke on your own scores when a future-AWS-using-your-scores will deny your servers acces, because you accidentally sent an email from that server that was actually supposed to be doing something else.
- mindslight 4y agoPlease stop making the world a worse place. Every online purchase I make comes from a datacenter IP with resistFingerprinting = true. I've got a good ISP that probably isn't selling surveillance about me, but websites themselves certainly abuse IP addresses (as you're doing here), and I see no reason to browse like some naive jamoke - datacenter IPs are easy to rotate, and fine-grained wireguard is already integrated into my setup. When web sites increase the amount of hassling (and make no mistake about it, garbage like this, CAPTCHAs, nonconsensual "SMS 2FA" etc are all just hassles to customers), I file support tickets about their broken website. If a website continues down the path of snake oil to the point of becoming unusable, I generally end up no longer being a customer.
- data_maan 4y agoThis company is providing a horrible anti-service! Random company website you are visiting: "We're sorry, we can't offer you access to our service today, as you IP score was below our required threshold. Please try again later and have a nice day."
- mid-kid 4y agoThis is the sort of thing the likes of cloudflare and google use to decide whether it shows you a captcha or not. I agree discrimimating on things like IP and User Agent and cookies as well as other things is undesireable, but I'm glad this site is at least transparent about it.
- jonathan-kosgei 4y agoNo, if your reputation is really bad you'll probably just be shown a captcha.
- TT-392 4y agoAnd then you complete the captcha, the page reloads, and you have to solve another captcha. Never actually getting to the site
- data_maan 4y agoNo, Cloudfare often just blocks you. And if it doesn't, do you think that is a better solution, solving a captcha every 5 minutes? Just try using Google from behind a serious VPN provider, see how that works for you. Also, what is your opinion on geoblock, do you think that is a good thing? It seems you are one of the company's representatives that has never in his life consistently used a VPN or Tor, so you don't even know to what kind of restricted internet your company's products are leading to.
- byyll 4y agoAlthough I am not a fan of cloudflare, cloudflare doesn't just block you. It's up to the administrator to choose what action he applies to what type of user. https://developers.cloudflare.com/firewall/cf-firewall-rules/actions/ https://developers.cloudflare.com/firewall/cf-firewall-rules...
- brushfoot 4y agoThis is what I get for a public IP used for some of my websites: Threats: 0 Trust score: 0 - High risk I'm confused why it's considered high risk if no threats were detected. Maybe unknown IPs are considered high risk until proven otherwise?
- jonathan-kosgei 4y ago"Threats" is based on static blocklists. "Trust Score" is generated by a model. So what this means is, "even though this IP hasn't been reported anywhere we still think it's high risk".
- Terretta 4y agoYou're rating massive swaths of Verizon FIOS home internet fiber with static IP addresses as zero threat, high risk.
- data_maan 4y agoWhat this means is: If a company website uses these scores, you will be blocked, even though you did nothing wrong.
- brushfoot 4y ago> "Trust Score" is generated by a model. Does a consumer have any insight into what the model does/doesn't like about an IP, or is it a black box? I'm wondering how they could contextualize a score for their use case, or how I as the IP owner know what to fix to raise the score.
- data_maan 4y agoIn all likelyhood it will be an (neural net?) AI, and then it's hard to get insight into why decisions were made. And even if they could explain it you, it might be spurious correlations that were picked up. There is a huge field of interpretable/fair AI and these types of questions arise in much more serious instances (e.g. where people in prison aren't given parole due an AI "assisted" decision). The state of the art seems to be that there are no easy answers as soon as you start questioning a decision by a modern AI system (or want introspection). You can only hope to not be part of the 5% of the cases where the decision is bad.
- exabrial 4y agoIs there a way to whitelist our corp vpns that happen to be cloud hosted? Happy to provide contact info and transparency if abuse were to occur.
- jonathan-kosgei 4y agoYes! Send me an email at my first name at ipdata.co.
- gigel82 4y agoLOL, doesn't work on Firefox: "You are not connected to the internet".
- diroussel 4y agoI did some testing on 35.214.66.222, it says this could be an attacker because it's on the wikimedia blocklist. But it's on the wikimedia blocklist because it's an IP block owned by google, and wikimedia doesn't want google creating accounts. That doesn't make a website server from this IP an attacker!