Kansas couple sues IP mapping firm for turning their life into a “digital hell”
arstechnica.com
arstechnica.com
Why are people expecting the output of an IP mapping database to be precise enough to send law enforcement to that physical location? From what I could gather from the article, law enforcement (and others) are treating it as if it was as exact as a reverse phone number lookup, while in reality there's no way a global IP mapping database can get much more precise than "around that city" (unless perhaps if the IP address is in a datacenter).
That is, even without it being a "default location", sending people to the GPS coordinates obtained from an IP mapping database is nonsense.
A GeoIP lookup can fail, and that error should be propagated through to whoever is using it - instead of returning a default value.
Good thing that is exactly what it does.
I actually spent a couple of weeks not so long ago trying to get data on accuracy benchmarks from tech firms in China. Initially they didn't even understand the question - they just used a standard database provided by someone else which is treated as Gospel.
So I'm not too surprised non tech people like police make this mistake.
The everyday layperson doesn't understand technology as well as we'd like them to. A common analogy is comparing an IP address to a mailing address or phone number for computers. For most purposes, this analogy is good enough. When we start trying to pinpoint people for crimes, the analogy is no longer perfect.
While it is a common analogy, is not "good enough" because it is incorrect, inaccurate, and has lead to a host of problems far removed from this current GeoIP issue.
RIAA/MPAA is one of the worst offenders at attempting to equate an IP address to a Physical Address/person for the purpose of civil and legal liability. I believe they are the ones that cemented this very very flawed and incorrect analogy in to the minds of the less technical minded persons
Case in point: the RIAA/MPAA. They took the analogy and ran with it just as you said. That's not the fault of the analogy or the people who first used it.
[1] I saw an apartment community in a less desirable part of town that advertised free Wi-Fi for the entire community.
[2] Qatar
Ignoring the default location issue.
Imagine I'm a police officer and I don't know that MaxMind returns a default location. I then take an IP pop it into my tool and it gives me a lat/long. I take that transpose it on a map and see that to my surprise there's a single home or address at that location (these folks live on a 600 acre ranch). If I'm an investigator and all I have to work with is an IP, even knowing that MaxMind isn't perfect wouldn't it still be worth it to take a trip out to that point to investigate?
BTW Just for giggles this is the map if you use the returned coordinates
https://www.google.com/maps/place/38°00'00.0"N+97°00'00.0"W/...
If you don't want this happening, you're going to need a police department that doesn't fire cops whenever the become smart enough to understand what an 'IP address' is.
Most homes in the USA do not have static IPs. So this approach to mapping would not work.
I've seen my exact address filled in on a pizza site I had never before visited.
There's an interesting note in the Fusion article[1], where it mentions "[the farm] is a two-hour drive from the exact geographical center of the United States".
> As any geography nerd knows, the precise center of the United States is in northern Kansas, near the Nebraska border. Technically, the latitudinal and longitudinal coordinates of the center spot are 39°50′N 98°35′W.
> In digital maps, that number is an ugly one: 39.8333333,-98.585522
> So MaxMind decided to clean up the measurements and go with a simpler, nearby latitude and longitude: 38.0000,-97.0000.
I wonder whether that decision - to choose a location, rather than use the precise centroid of the area - will cost MaxMind the case.
[1] http://fusion.net/story/287592/internet-mapping-glitch-kansa...
And, the problem with returning Null or 0,0 is that it implies there is no information available. There is still value in having a default location of the country of an IP is known, but the location is not. If you work with MaxMind a lot, you know that 38,-97 is a US IP with unknown location.
Amusingly, that would actually lead many agencies to a closer proximity of the scammers they're searching for.
I wonder how many geocaches are hidden in that patch? (Hmm... had to register to geocaching.com to find out; apparently just one at the exact spot and then a couple nearby.)
This doesn't make any sense. Why does it need to return a place in the middle of the US when the location is unknown?
This is what it should return: "location is unknown" and absolutely NOT a pair of geographical coordinates
SIZE The diameter of a sphere enclosing the described entity, in
centimeters, expressed as a pair of four-bit unsigned integers,
each ranging from zero to nine, with the most significant four bits
representing the base and the second number representing the power of
ten by which to multiply the base. This allows sizes from 0e0 (<1cm) to
9e9 (90,000km) to be expressed. This representation was chosen such that
the hexadecimal representation can be read by eye; 0x15 = 1e5. Four-bit
values greater than 9 are undefined, as are values with a base of zero
and a non-zero exponent.
HORIZ PRE The horizontal precision of the data, in centimeters,
expressed using the same representation as SIZE. This is
the diameter of the horizontal "circle of error", rather
than a "plus or minus" value. (This was chosen to match
the interpretation of SIZE; to get a "plus or minus" value,
divide by 2.)
...so, for a point "somewhere" in the united states, I'd reckon that SIZE=1·10⁰m (1 times 10^0=1m) and HORIZ (and VERT) PRE set to 5·10⁶m (5 times 10^6=5000km) would be a sane choice.(measuring on google maps, the united states seem to measure about 4500km from east- to west-coast)
That is the stupidest data format I have ever heard of...
I'd imagine it's the same as finding the geographic location of a street - often a point on the middle of the street is picked.
Not saying that this couldn't have been handled better though.
This makes it much easier for downstream application developers to filter out "Invalid" addresses, and simply eyeballing them on a map makes it clear what the "Invalid" value is.
Recognizing how your data will be used, and taking some precaution to ensure that it doesn't result in scenarios described in the article is quite often fairly straightforward. (As evidences - The article itself made it clear that when they don't know the actual location, they have changed the long/lat to return a value in the middle of a lake to avoid this sort of problem in the future).
"Just send the drones to bomb the centroid of city X" doesn't seem so smart
Or they should have a giant disclaimer on their results saying that their information is subject to errors and it should not be used for legal/law-enforcement purposes
To map a specific IP to a specific physical location you want to arrest someone at, you'd have to actually go to the ISP (with a subpoena) and ask them what customer that IP was allocated to at a specific time, then look up that customer's address. They know that, right?
That said, after reading again and again how ridiculous desicions like these lead to these disproportionate real-world effects, I can't help but laugh at the sheer absurdity of it all. "Digital hell", indeed.
I guess they could just not give lat/long when unknown, but still state country, state, county, etc. if they're known.
http://dev.maxmind.com/geoip/geoip2/web-services/#location
It is up to the Developer to do sanity checks on the Accuracy for their type of application.
in some instances just knowing it came from the US or some other country is accurate enough.
To claim they should simply not return any data if they do not have an accuracy level to your arbitrary standards would make the service useless
IMO Max Mind is not the problem here, people taking the data and using it as if it is accurate to 1in is the problem.
Geo-location data on IP address has NEVER EVER been that accurate, NEVER. The fact the law Enforcement, Consumers and others use this data as the sole data point then act on that data is the problem, not that Max Mind Returned a Lat Lon to the center of the US
Ideally they'd offer version of the service that gives a probability 'heat map', but in reality 99% of users would use a simplified version with an app configured threshold for what constitutes useful info for that app, and also how to convert a heat map to a single point (since that what most people seem to want) or a very localised region (e.g. within 100 meters or so).
In reality the simplified version would be provided as a service with a default threshold, anything under the threshold would not report a position, but could still report a country ISO code and perhaps state, county as optional extras. These are workable compromises to the ideal of everyone consuming a heat map in a sensible way (IMO).
that is not "ideal" at all, one of the first uses of this data was for real time CC fraud Detection, giving a computer processing CC info a graphical "heat map" is less than useless. Most geolocation API data is consumed by computers that use it for many things, not presented to the user directly.
>In reality the simplified version would be provided as a service with a default threshold, anything under the threshold would not report a position, but could still report a country ISO code and perhaps state, county as optional extras.
It appears you believe this data is only for Human Consumption. If an API is designed to return LAT and LON and Accuracy, then that is what is should return, not an ISO country code. I get you believe no API should be designed this way, but I as a developer that consumes these services prefer it that way, makes it easier to write against
I as a developer am asking for Max Mind to give me Lat Lon and Accuracy, not a ISO Country Code or Heatmap
> It appears you believe this data is only for Human Consumption.
Most human's I've encountered don't refer to countries by their ISO code... most.
I wonder if it would be feasible to set it to one of the small islands map makers include to identify copyright infringements. Or, have a known fake territory where any 'dead' values can to be parked, such as the above.
If they can not tell me what room in my home I am located should they simply return "the moon" as my location?
Different Services use this data for different reasons, some times simply knowing what nation the IP is from is enough, but you believe they should return "the moon" if all they can determine it is came from with in the US?
This sounds like the setup for a cop-v-cop shoot-em-up movie.
[1] http://fusion.net/story/287592/internet-mapping-glitch-kansa...
[2] http://fusion.net/story/290772/ip-mapping-maxmind-new-us-def...
How do you design your API so that it is as difficult as possible for your clients to misinterpret?
The "always return a center & accuracy" API is very simple and elegant, but with the benefit of hindsight, you can assume that a significant fraction of your users are just going to ignore that accuracy number and treat the center as precise. As was pointed out elsewhere in this thread, the default point isn't the only problem -- any town, city, or state will generate similar problems.
One option would be to return a richer result type: (COUNTRY, "United States") (CITY, "Portland, OR, USA") (REGION, latlng-a, latlng-b) (POINT, latlng, accuracy)
Now it becomes more difficult for a client to pretend most of those are precise points.
The best API is sometimes not the one that is easiest to use but most difficult to misuse.
I would hate to see a world where services are responsible for generating and clients are responsible for parsing data in an overly convoluted and cumbersome format, just to minimize the risk of irresponsible clients misinterpreting it.
> go with a simpler 38.0000,-97.0000.
Wait a minute, that's a weird rounding. Even if it's ill-advised, why did he chose that rather than 40,-99?
The other one being false negative (like an alarm not detecting trepassing).
False positive are called artefacts, but people want to believe so much in the infallibility of IT that they use detection system as if the result were error prone.
Hence what I call the Oracle syndrome: genuinely scientific person relying on an inaccurate system by nature as an exact system. Then they scale up system an what is anecdotal occurence becomes a serious concern with accumulation.
Non conformity with expectations are not handled anymore, they are disdained and measurement systems (hence that can fail) are used as exact systems.
It is like death penalty: should we care about the innocent people that will pay a dear price from wrongfully giving too much trust in non perfect systems knowing there is a tendency to make it hard to contest the decision because it would attack the trust we have in the system?
a) Maxmind shouldn't be returning a location like this for "Anywhere in the USA". It should either be 0,0 for unknown or something totally obvious like the Washington Monument in WA DC.
b) The fact that clueless/ignorant law enforcement is blithely trusting and USING this spurious data. Someday a person is going to get SWATTed and shot dead over this sort of thing.
[1] http://fusion.net/story/214995/find-my-phone-apps-lead-to-wr...
I don't work in LE at all but if I was, and I was getting sent to the same damn house every other week for everything from drug trafficking to sex slavery I'd start raising an eyebrow whenever dispatch tried to have me go there again.
I suppose they really can't just not go because of the gravity of most of those calls, but you'd think at least the stolen cellphone/car could wait until the morning.
> “That poor woman has been harassed for years,” Butler County Sheriff Kelly Herzet told me by phone. Herzet said that his department’s job has become to protect the Taylor house from other law enforcement agencies.
[1] http://fusion.net/story/287592/internet-mapping-glitch-kansa...
Previous Discussion: https://news.ycombinator.com/item?id=6470600