6 ms·
Can your probes be identified and blocked?
by voltagex_ 3y ago
Can your probes be identified and blocked?
- kube-system 3y agoiptables -A INPUT -p icmp -j DROP
- chaps 3y agoThis isn't helpful. The comment was specifically asking about the probes, not ICMP traffic.
- kube-system 3y agoAnybody can do this same thing, if you're worried about this, you probably don't want inbound ICMP.
- chaps 3y agoCool. Thanks. But let's say I do.
- kube-system 3y agoThen there's nothing you can do. If you respond to pings, then others can take note of the responses you send.
- chaps 3y agoYou're missing the point that the question is effectively asking for a list of hosts that they can block. Edit: they provided a method: https://news.ycombinator.com/item?id=37510063 https://news.ycombinator.com/item?id=37510063
- kube-system 3y agoI understand that was the initial question. I am saying that is a fools errand. Anyone with a few VPSes, a calculator, and a map can do this. It isn't just ipinfo.io doing this. There are a lot of ip geolocation services.
- sgjohnson 3y agoAnd if you don't respond to pings, a traceroute can still be used to find the hop before yours, which will almost certainly achieve the same result for geolocation purposes.
- eptyc1 3y agoIndeed. Openwrt for some reason defaults to reply to pings. I see the value of ICMP for servers, but I don't see the value for home ISP routers. I disabled ICMP reply on my home router.
- sambazi 3y ago> Openwrt for some reason defaults to reply to pings. it's a bit like greeting-back ppl on the street. not doing it will not make you invisible. it will break somebody's assumption of decency, but most ppl don't care either way.
- sgjohnson 3y ago> I disabled ICMP reply on my home router. Doesn't actually help at all because the BGP announced prefix of your IP can still be tracerouted. You won't be physically far from it. Say if your ISP announces 125.15.18.0/17 and you're in 125.15.29.145, a traceroute will still yield a pretty good approximation of where you're at. The last hop ping is really quite immaterial here.
- voltagex_ 3y agohttp://shouldiblockicmp.com/ http://shouldiblockicmp.com/ (But the guy running the probes is making a good counter argument)
- j16sdiz 3y agoThis breaks PMTU and is the source of many mystery download stalls
- jiveturkey 3y agoThis doesn't help. Even if you apply this at your router, you are locatable up to your ISP. Which is generally close enough. Maybe if you delay pings by some amount (20ms? 100ms?), or randomize the delay, you can do a lot better at masking location.
- reincoder 3y agoIt is just ping data. We ping an IP address, get the RTT, draw a radius on the globe, and say that the IP could be anywhere inside that radius. Then we do another ping and draw another radius, and at the cross-section of the two radii could be your IP address. Now, if we do it enough times, we can get an estimate of where the IP address is located. The data is not derived from the IP address itself, but rather from the process itself. And it's just a ping. Moreover, the majority of the IP addresses are not pingable. So, we rely on other in house statistical and scientific models to estimate the location. The probe infrastructure is extremely complicated and there are billions and billions of IP addresses, which is why we do not have a robust range filter mechanism. You can implement a dynamic ping blocking mechanism or use our data to find hosting ASNs and block ranges of those ASNs. You can download the database for free: https://ipinfo.io/developers/ip-to-country-asn-database https://ipinfo.io/developers/ip-to-country-asn-database