Show HN: A New, Clean Geolocation API
ipdata.co
ipdata.co
Again :-( I just wonder if people will ever stop making assumptions about others given their IP address or hair colours and divide the Internet on these slippery grounds. The only legitimate and valid way to determine the client's location automatically is the browser or the OS geolocation API, and for the language it is the HTTP_ACCEPT_LANGUAGE header. The fact I have contacted your server from an IP address assigned to a Chinese ISP neither means I'm in China nor that I speak Chinese.
And it's sometimes the only information they have if the geolocation api doesn't give them anything.
Don't get me wrong. I totally agree that this thing is definitely not accurate(it thinks i'm 1300mi away) but it's good enough to get a general idea.
[1] made up number to get my point across
Indonesia -- 47%
Thailand -- 39%
Brazil -- 36%
Turkey -- 36%
UAE -- 36%
Viet Nam -- 35%
Saudi Arabia -- 34%
India -- 32%
Malaysia -- 32%
...
UK -- 14%
US -- 14%
https://wi-images.condecdn.net/image/3K6WrWwGrKN/crop/810Here is a better version of it: http://cdni.wired.co.uk/1920x1280/g_j/infopornhorizontal_1.j...
Wikipedia says that Indonesia has an internet penetration rate of 50%. It might be reasonable to assume that a low penetration rate means that a significant amount of the internet access is happening in a work place rather than in a residential place. If a significant amount of access is happening at a work place it might also be reasonable to assume that a lot of that access is happening over a VPN.
https://en.wikipedia.org/wiki/List_of_countries_by_number_of...
Many more people are using VPNs these days. It's still not a large percentage, to be sure, but people are indeed doing it. Hell, I'm on my company VPN right now, and this site mis-identified my location because our VPN is set up to route most addresses in AWS's address space through the VPN (and ipdata.co appears to be hosted on AWS).
Then you have stuff like people on planes (usually this is all routed through a single PoP somewhere), people on mobile data who are roaming internationally (often proxied through one of the home carrier's PoPs), etc.
I think using IP geolocation is a decent first-order approximation, and is useful if there are no other ways to get that information, but it must always be treated as unreliable.
Meanwhile, there is API to detect VPN, so that we can aware that the geolocation is good up to the server physical location.
It's such an extreme edge case that it doesn't really matter. (unless you are of course targeting that type of market).
In other words, IP address gives a general location in a huge number of cases.
I'm curious to know if other people noticed the same level of accuracy.
It’s funny... Google says this same thing publicly on their various webmaster blogs, but you know how Google Analytics determines your location? Your IP.
People who are using it for real-world-location and language detection are doing it wrong but being wrong on the internet is a common problem. :/
BI guys put in the feature request some years ago so they could make pretty maps (but ultimately take no actionable steps based on these), and call center were then taking these guesses as facts (think getting a call and having someone chummy ask "Hey, how's the weather in <city you don't live in>" in the wrong language...). What's worse is we then added some user-facing fields asking for the location information, and it was impossible to tell apart user-supplied info from the IP-derived info!
It took fighting with BA and BI, but we finally decided it was stupid and were able to simply remove it. (BI will have to "fix their maps" by doing their own assumptions, outside of the application)
I think the risk here is the assumption that the only devices where you may care about GeoLocation are ones that have this capability. There are cases where using the less precise GeoIP option is not only legitimate, but it's the only option you have. What about IoT or embedded systems where you may not have the capacity to determine the location?
You can't treat the data obtained from GeoIP databases as being absolutely precise. However, for most cases the data will be precise for most people's needs.
I'd be interested in hearing how you handle devices that don't have the APIs you mention.
Completely ignoring the aspect of VPNs (which is huge), I've also been fighting this mentality for the past few months trying to prove to Coinbase that I'm a US citizen with my US bank account (however I signed up from an IP in Croatia!), and being completely unable to do mundane tasks like browsing/editing my Google Photos photobooks since I wasn't on a USA IP.
Can we please, please, please stop tying IPs to location? It's obnoxious to have to set up proxies just to prove I am who (or where) I say I am.
I rest my case.
1. Your GO examples don't quite follow Go standard style "resp_body" instead of just "body", "resp", or "respBody"
2. Instead of "Error Codes" it should probably be "Status Codes" since the first "Error Code" is actually "200 OK"
Made the change.
However, I was just looking at your Python SDK: https://github.com/ipdata/python/blob/master/ipdata/ipdata.p...
What are you thinking. Never do this in a library. Also it looks a bit amaterish, as it's your only currently supported library I'd fix it up a bit - don't add .pyc/dist files to git, make it pep8, remove sys.exit() in a library (!!!) etc.
Pushed a new release: https://pypi.python.org/pypi/ipdata/2.6
- The Global infrastructure backing ipdata.co is pretty impressive, 4 data centers in the US, 1 in Canada, 2 in Europe and 1 each in Mumbai, Sydney and Seoul.
- We offer more datapoints, I tried to build this around the most common use cases for Geolocation, one of which is showing your users the right currency. This is something we provide, that is, the currency ISO code and symbol.
- I think our API is pretty darn fast :)
Your pros;
You offer more data formats, csv and xml whereas we only offer JSON.
You offer a pretty high free tier but I think there's definitely tonnes of people who derive a lot of value from ipdata :)
2) OK.
3) freegeoip is faster and locally hosted - no network latency
The entire thing runs as a one command docker instance - database updates are automatically managed
Someone else in the thread suggested Maxmind as an alternative. Their prices seem to be several times higher than yours. Can you double your prices? It seems really cheap. Too cheap?
Also, the location identified for me was off by 60 miles.
On your Documentation page you've used 8.8.8.8 as an example IP address. And 1.1.1.1, and 2.2.2.2... I'd rather see you use the IPv4 address blocks reserved for documentation by RFC 5737 [0]. That's what they're for! Unfortunately, they probably don't have any actual data associated with them so the examples would need to be fabricated...hmm.
And it looks like actually using one of those results in some output that does not conform to the format on your documentation page, so you'd best also add documentation about error handling.
Unfortunately it's never going to be spot on all the time.
Awesome points on the example ips and adding error handling documentation. Thanks for pointing me to rfc5737!
I'm adding the Error Code documentation right now.
Added a table with Error Codes and their accompanying messages.
Plans are kind of a pain because you have to have a sales process to get people to change. Mailchimp automatically upgrades/downgrades people between plans, which is a decent workaround, but still a little weird to customers.
I'm probably going to start work on incorporating this soon. Thanks for the input!
Having a web API is great for low- or mid-volume applications, but adding 10ms per user for an HTTPS call would still be like 1000x slower than hitting a local DB.
An API such as this exists would be a great choice where you need to modify content on the frontend. In which case you'd benefit from the availability of 10 endpoints around the world from which the API is available to provide the lowest latency to your users.
Having a geolocated IP API, while still serving and responding to requests from a single region is just lipstick on a pig.
Even if you're not hosting the country specific site in that region your user will still save time on making the call to our endpoint local to them.
Integrating maxmind is a bit of a pain and it’s a massive database. Not well suited to use cases like single purpose or ephemeral containers.
You’ll probably end up storing the maxmind db in a separate node on your local network, anyway. So you still have a latency issue (although lower, obviously). More importantly you now need to maintain an extra box per replicated cluster. It could make sense to outsource that management if the latency between your data center and ipdata is acceptable. Such low latency is easily achievable if ipdata has BGP anycast on servers in the same cloud region as your app.
I found Maxmind integration to be pretty straight-forward. They have APIs for most popular languages and most of the time, usage amounts to instantiating a reader object with the path to the database, then calling methods on that object with the IP in question. So, db.city(ip) returns all of the city information, etc.
Massive is a relative term I guess. But the databases are segmented, so you only take what you need and all the ones I've worked with have been tens of megabytes in size.
Nowadays these services are often heavily decoupled and therefore built to be as lightweight as possible. Think about small single purpose containers. Adding 100mb of memory requirements per instance could be quite expensive, depending which existing process is calling maxmind.
"Nowadays" people are wrong.
> Can I update my card details?
> Yes. Send an email to support@ipdata.co. Your request will be processed within 24hrs.
What is your process there? You're not asking people to send credit card information via email, right?
>Yes, send an email to support@ipdata.co requesting the change. You will receive a link from where you'll be able to securely update your details.
$ curl ipinfo.io/8.8.8.8
{
"ip": "8.8.8.8",
"hostname": "google-public-dns-a.google.com",
"city": "Mountain View",
"region": "California",
"country": "US",
"loc": "37.3860,-122.0840",
"org": "AS15169 Google LLC",
"postal": "94035",
"phone": "650"
}
It also started as a simple geolocation API when I first launched it over 3 years ago. Since then we've built many custom data sets and expanded to more products, including IP to company details, carrier detection, reverse IP hosting data and more. See https://ipinfo.io/products. We've been lucky enough to signup customers like Dell, Tesla, eBay, TripAdvisor, Plesk and others. Happy to chat and share notes at some point!I have a side project[0] that uses the geolocation api to post to Slack and seems to be pretty accurate, even on mobile. Maybe I'll try this as a fallback.
I'd say you can pretty much trust it up to the country level and greater region, more specific than that the results will not always be highly accurate.
1. Currency Data - The user's country's Currency ISO code and symbol are returned in the API output.
2. Phone Code Data - The user's country's Calling code is returned as well.
3. Global Footprint - Endpoints in 10 locations globally. 4 on both US coasts, 1 in Canada, 2 in Europe, 1 each in Mumbai, Seoul and Sydney. This ensures you get pretty low latencies wherever your app is hosted and wherever your end users are located.
4. Solid Infrastructure - The infrastructure backing Ipdata is pretty impressive, and built to scale to a substantial amount of traffic - in the hundreds of millions.
5. A free tier of 1500 requests daily (45 000/month) with no signup or credit card needed.
6. Examples in multiple languages on the Docs page at https://ipdata.co/docs.html, to make integrating with your site absolutely painless.
7. Regularly updated data - we check for changes daily and regularly update our data.
Coming soon; VPN/Proxy and Tor exit node data.
Neat. I'll make an updated express-geoip using this today or tomorrow.
`everyday` is an adjective, in this case you should use `every day` as two separate words.
Landing page said 1500 I think.
For the reference here you have one with description how they are generated: https://emojipedia.org/flag-for-united-states/
> Given an IP address, the system will return a probabilistic value (between a value of 0 and 1) of how likely the IP is a VPN / proxy / hosting / bad IP. A value of 1 means that IP is explicitly banned (a web host, VPN, or TOR node) by our dynamic lists.
We've been using it for a while and are pretty happy.
Disclaimer: I'm the founder of Shodan and identifying the type of connection is something we're often used for.
What Geo IP service would people suggest instead?
[edit] Aside from that, I personally would not do business with someone describing his own offer as "pretty generous", but that's just me.