5 ms·
Do VPNs pay retail ISPs for exit points?
by andrewstuart 5mo ago
Do VPNs pay retail ISPs for exit points?
- TkTech 5mo agoNo, not usually. Few ISPs are willing to risk blacklisting. Just like scrapers (and a lot of VPNs are quietly using their custom VPN clients to sell your own IP [and data] to scrapers) it's mostly a "don't ask don't tell" situation for IP sourcing. You use a multitude of IP providers and if a scandal happens you just say "We didn't know!" and move on to the next. Almost always grey-market, very rarely through legitimate providers.
- r_lee 5mo agowhy is this downvoted? I'm not aware of a single ISP that would willingly let VPN providers use their ip blocks for their exit nodes
- deleted 5mo ago[deleted]
- tiffanyh 5mo agoI see DataPacket.com have VPN clients. Does anyone know if this is any issue for non-vpn users of datapacket.com? https://www.datapacket.com/case-study/nordvpn https://www.datapacket.com/case-study/nordvpn
- gruez 5mo ago>Does anyone know if this is any issue for non-vpn users of datapacket.com? Probably not that much worse than other VPS providers with trashed IP reputations, eg. digital ocean, vultr, ovh. If you're blocking bots, the first thing to block is any datacenter ip ranges, not just known VPN servers.
- dtech 5mo agoNot retail ISPs, but many extensions and free VPNs route VPN traffic through the connections of those who use them.
- joxdosba 5mo agoThis isn’t correct, the residential IPs are a completely separate and vastly more expensive product.
- giobox 5mo agoOne such extension, https://www.tuxlervpn.com/faq/ https://www.tuxlervpn.com/faq/: > Will other users of tuxlerVPN be able to connect using my IP address? "When you use our free residential VPN, you automatically agree to add your IP address into the community pool. This means that you are trading your own IP address in return for the ability to connect via the IP addresses of other users. You can opt out of this by purchasing our premium subscription; once you upgrade to the premium version, your IP address will be removed from our community pool."
- joxdosba 5mo agoIt says that, but doesn’t actually do it. Just like Hola/Luminati used to. You don’t want to route the non-paying traffic through slow and valuable residential connections you can sell, you’ll rent a few fast dedicated servers to do so. Residential proxies sell for around $1/GB, nobody is running a free or cheap VPN service on that. The idea is preposterous
- deleted 4mo ago[deleted]
- preinheimer 5mo agoI mean, most “residential proxy” providers are selling access to hacked devices, or sneaky plugins https://medium.com/@xianghangmi/resident-evil-understanding-residential-ip-proxy-as-a-dark-service-dea9010a0e29 https://medium.com/@xianghangmi/resident-evil-understanding-... Technical paper: https://ieeexplore.ieee.org/document/8835239 https://ieeexplore.ieee.org/document/8835239
- hnlmorg 5mo agoSome VPN providers don't even have exit nodes in the country they're claiming. Instead they'll have their IPs registered to the respective countries in GeoIP databases. This isn't a practice all VPN providers partake in. And from my own anecdotal experiences, Mullvad seem to be using services that are geo-located (I say this because I've tested latency between different endpoints in Mullvad). But it is something to be wary of with some of the less reputable providers.
- sammy2255 5mo agoMullvad doesnt do that, but "ExpressVPN" absolutely does
- preinheimer 5mo agoIPInfo did a report on this: https://ipinfo.io/blog/vpn-location-mismatch-report https://ipinfo.io/blog/vpn-location-mismatch-report From our side we noticed a VPN provider had a location we'd been trying to get, but had been unable to, so we started digging to find their provider. Long story short the server purportedly in some middle east country was actually 3ms away from our server in Berlin.
- joveian 5mo agoMullvad in particular has a page that lists the ISPs they use (in a few cases their own servers at a datacenter), although they don't list the datacenters (sometimes you can get this info from the ISPs). https://mullvad.net/en/servers https://mullvad.net/en/servers They also have a document that lists some of their practices around the servers, such as not using shared servers: https://mullvad.net/en/help/server-list https://mullvad.net/en/help/server-list I noticed that the website of one of the two providers they use near me was over a decade out of date :/. DAITA is Mullvad's anti-traffic analysis framework, without it a single hop can likely be easily deanonymized by logging by a single party (it isn't clear if multihop uses fixed packet sizes between their servers).