6 ms·
There are plenty of VPN and proxy detection services, either as a service (API) or downloadable database, which are surprisingly comprehensive. Disclaimer: I’ve
by tallytarik 10mo ago
There are plenty of VPN and proxy detection services, either as a service (API) or downloadable database, which are surprisingly comprehensive. Disclaimer: I’ve run one since 2017. Years on, our primary data source is literally holding dozens of subscriptions to every commercial provider we can find, and enumerating the exit node IP addresses they use.
There are also other methods, like using zmap/zgrab to probe for servers that respond to VPN software handshakes, which can in theory be run against the entire IP space. (this also highlights non-commercial VPNs which are not generally the target of our detection, so we use this sparingly)
It will never cover every VPN or proxy in existence, but it gets pretty close.
- rdsubhas 10mo agoInteresting. I assumed all VPNs switched to IPv6 by now, making detection much harder.
- tux3 10mo agoMany websites including Soundcloud are still only accessible through IPv4, so this is moot, even if VPNs support IPv6 it's enough to block their V4 exit nodes for Soundcloud.
- bombcar 10mo agoIPv6 isn't magically unrouteable, it just routes much larger blocks of "end IP addresses." You just track and block /24 or /16 as necessary.
- deleted 10mo ago[deleted]
- tallytarik 10mo agoMuch of the internet still does not support IPv6, so most providers will give you an IPv4 address. In fact only a few providers even support IPv6 at all. Even with IPv6 it's not a huge problem. With a few samples we can know that a provider is operating in a given /64 or /48 or even /32 space, and can assign a confidence level that the range is used for VPNs.
- deleted 10mo ago[deleted]
- addandsubtract 10mo agoTangent: if you hold access to all VPN providers, have you thought about also releasing benchmarks for them? I would be interested in knowing which ones offer the best bandwidth / peering (ping).
- acka 10mo ago> Years on, our primary data source is literally holding dozens of subscriptions to every commercial provider we can find, and enumerating the exit node IP addresses they use. Assuming your VPN identification service operates commercially, I trust that you are in full compliance with all contractual agreements and Terms of Service for the services you utilize. Many of these agreements specifically prohibit commercial use, which could encompass the harvesting of exit node IP addresses and the subsequent sale of such information.
- infecto 10mo agoTOS are pretty meaningless in cases like this. It amounts to getting rejected as a customer and your account canceled.
- itintheory 10mo agoI think ToS violations can also run afoul of CFAA.
- infecto 10mo agoThose are pretty old cases that I think the courts have moved away from and even in those cases it was a TOS violation and explicit c&d that the company ignored.
- qingcharles 10mo agoI don't think they can any longer, I think there is case law on this. Illinois law makes it a misdemeanor to violate web site ToS, though. And felony for the second time IIRC. Other states probably also.
- fourside 10mo agoMaybe the tables could be turned and we can build a service with dozens of subscriptions to every VPN detection service and report them for ToS violations ;)
- MangoToupe 10mo ago
- ranger_danger 10mo agoThis will also cause problems with anyone that happens to (even accidentally/unknowingly) use apps that integrate services from companies such as BrightData/Luminati/HolaVPN/etc. where they sell idle time on your device/connection to their VPN/proxy customers. The legitimate end-user will then no longer be able to use e.g. SoundCloud.
- blibble 10mo agoI fail to see the problem if people that allow their internet connection used by scammers/AI crawlers are banned from every service
- majorchord 10mo ago> unknowingly Often times random shovelware apps will have these proxy SDKs embedded in them, and the only mention of it being part of the software is buried in some long ToS that nobody reads.
- kstrauser 10mo agoI’m with you on this one. Some of my projects are flooded with sus traffic from Brazil. I don’t believe there are a million eager Brazilian hackers targeting me in particular. It’s pretty clear from analysis that they’re all residential hosts running proxies, knowingly or otherwise. The more concise word for this is “botnet”. Computers participating in one should be quarantined until they stop.
- GoblinSlayer 10mo agoYou might want to learn how internets work today: https://en.wikipedia.org/wiki/Network_address_translation https://en.wikipedia.org/wiki/Network_address_translation
- Dylan16807 10mo agoSort of valid today. But the more sites that require a residential VPN for normal use, the less legitimate that argument becomes.
- 0xdeadbeefbabe 10mo ago> which are surprisingly comprehensive How does the buyer even know what the precision and recall rates might be?
- recursive 10mo agoProbably contrary to the stealth aspect.
- m00dy 10mo agowho's buying your service ?
- cons0le 10mo agoSounds like snitching as a service
- vb-8448 10mo agojust out of curiosity: if i'm located in spain and i setup an ec2 or digital ocean instance in germany and use it as a socks proxy over ssh, do you will detect me?
- dizhn 10mo agoThat's a hosting service IP block. Some sites block them already. Netflix for instance.
- tallytarik 10mo agoIt won’t end up in our proxy detection database, but we track hosting provider ranges separately: https://www.iplocate.io/data/hosting-providers/ https://www.iplocate.io/data/hosting-providers/
- deleted 10mo ago[deleted]
- kube-system 10mo agoIt is even easier to block hosting providers. They typically publish official lists. Here's the full list for both of those providers: https://ip-ranges.amazonaws.com/ip-ranges.json https://ip-ranges.amazonaws.com/ip-ranges.json https://digitalocean.com/geo/google.csv https://digitalocean.com/geo/google.csv (And even if they don't publish them, you can just look up the ranges owned by any autonomous network with the appropriate registry.)