Geolocating requests with Google Load Balancer for free
blog.doit-intl.com
blog.doit-intl.com
It uses your browser location to build the data, bootstrapped with Mechanical Turk workers around the world. It has one feedback loop, where if you use the JS library it will give you the users location if they deny browser location (if we have the data...) and if they do share location, then we update the database (but throw away the last part of their IP address).
There are two or three other loops where we could build more data (which you can get here https://www.open-geo-ip.com/data/download ).
I'm probably going to do a small kickstarter to pay for some cleanup and expansion work or just kill it if that fails to get funded. Any ideas appreciated on things to do with it.
Seriously? Did you help build BonziBuddy, too?
Well right now a) we most likely have no idea where an ip address is and b) even if we do, it's nearest-city accuracy.... which is exactly what everyone else does.
Denying browser location doesn't stop the app or website from using your ip address against some third party service to figure out where you are.
Just how like being uninvited from a party doesn't stop you from just showing up anyway (and trashing the bathroom for good measure).
I didn't state that it does. However, just because you can do something doesn't mean you should. Did it ever occur to you that if someone explicitly tells their browser that they don't want to be located that you should respect that?
I hope you are never critical of Facebook's or Google's privacy standards, because there's a full-length mirror with your name on it.
The lookup against what IP is in what city is published in numerous public databases that anyone can look up against in small doses at no cost, or at scale commercially.
This service shines a light on that, doing away with illusions of privacy and showing you where you potentially have none.
Comparing to Google and Facebook feels disingenuous. You can’t lookup any person in their DB and see their records. It’s not public precisely because they’re hoarding what (in aggregate) is legitimately private data.
It’s still an illusion of privacy mind, as all the recent fuss finally coming about demonstrates.
Also, this isn't about locating someone to their city. According to the blog post, it returns latitude and longitude pairs.
Yes, these may not be precise in some circumstances, but as detailed in many recent HN posts, Google has many many ways to narrow that down to a very close approximation of where you actually are. And it's only going to get better at it over time.
Should there be efforts to collect more information to make that public information more specific? Maybe. Can you actually delete already public information from the internet? Not really.
“Would you like to share what colour the sky is?”
You can choose not to. The webpage can still tell you. That information is public regardless whether you provide more specific information or not
The bottom line is that the user specifically requests not to be located, and this is a way to do exactly the opposite of what the user wants.
Being technically capable of doing something is not an excuse for violating trust.
Here's a web page that may help you wrap your brain around the concept: https://en.wikipedia.org/wiki/Ethics
Also, your argument is that because the user doesn't want it, it is unethical? I don't want to sit in traffic but that doesn't make traffic unethical.
Similarly, you accuse them of 'violating trust'. It's public knowledge that any IP address can be looked up. Just because you weren't aware of it doesn't mean your trust is violated. In the same way, just because you didn't know something was against the law doesn't make it not illegal.
I am for privacy, don't get my wrong, but your comments represent one of the biggest challenges with privacy right now: the assumptions of privacy and trust. It's hard to have rational and productive arguments about privacy when people get emotional about the inner workings of the system. If you don't agree with the system, work to change it, but don't blame others for what is, at the end of the day, just a feature of how it all works. Instead, try to understand the feature and think about how we can implement future systems with similar functionality but more privacy.
No, it's the equivalent of asking a woman in a bar if you can call her and when she says "no," you look up her number in the phone book and call her anyway.
I get what you’re saying and I see where you’re coming from, but to try and use this phone number analogy, it’s like telling someone what city/state they’re in based on their area code when they’ve opted to provide you no location information beyond their phone number.
The phone number itself contains location information. It’s not necessary accurate information as I could easily (and do) use a 212 number wherever I am I the USA, not just in New York.
Finally, we’ve had rulings about phone numbers and IP addresses. Phone numbers “belong” to the end user, not the operator, and move with the user if they want to. IP addresses “belong” to the carrier, and are non portable. In a number of cases, carriers actively provide city-level accuracy for where they’re using their IP space as it actively improves performance for end users.
It would be helpful if the home page demonstrated the passive geolocation results. The page asked for my browser location but didn't show the result.
btw the map zooming is very slow in my mobile browser for some reason.
I dealt with a ton of fraud a couple of jobs ago and being able to eliminate credit card transactions for people on Tor was huge in cutting down on charge backs from fake card use. The minFraud API was really beneficial as well.
Don't sell the offering short.
All Tor IPs specifically and publicly advertise the fact that they are an open proxy.
For the server seeing the incoming cc purchase requests, it's still majority fraud...
Code at https://github.com/runway7/blip
[1] https://support.cloudflare.com/hc/en-us/articles/200168236-W...
https://cloud.google.com/compute/docs/load-balancing/http/ba...
The load balancer expands variables to empty strings when it cannot determine their values, for example for geographic location variables when the IP address’s location is unknown, or for TLS parameters when TLS is not in use.
Geographic values (regions, subdivisions, and cities) are estimates based on the client’s IP address. From time to time, we update the data that provides these values in order to improve accuracy and to reflect geographic and political changes.
gcloud beta compute backend-services update app --custom-request-header 'X-Client-Geo-Location:{client_region},{client_region_subdivision},{client_city}' --custom-request-header 'X-Client-Geo-Region:{client_region_subdivision}' --custom-request-header 'X-Client-Geo-LatLong:{client_city_lat_long}' --custom-request-header 'X-Client-TLS-Version:{tls_version}' --custom-request-header 'X-Client-TLS-Chiper:{tls_cipher_suite}' --custom-request-header 'X-Client-Hostname:{tls_sni_hostname}' --custom-request-header 'X-Client-RTT:{client_rtt_msec}'
One feature that must be mentioned is that it allows you to cache content (could be anything: HTML, JPEG and more) for as little as 1 second! CloudFlare requires an enterprise plan and even then you cannot set a TTL lower than 30 seconds.
Also MaxMind does have completely free databases down to the city level, just with lower accuracy compared to their paid products: https://dev.maxmind.com/geoip/geoip2/geolite2/
Finally, the free version of MaxMind is great. Thanks for mentioning it.
If this is easy doable then that would be an easy migration route.
https://aws.amazon.com/about-aws/whats-new/2014/06/26/amazon...
Googles and maxmind features include city/lat/lng.