Live proxy and VPN detection
proxy.incolumitas.com
proxy.incolumitas.com
Empirically not.
> You can add Proxy and VPN detection to your own Website or App.
Please don't. Not just because of the false positives and false negatives, but because user privacy is actually a good thing.
Like it or not, bad actors use VPNs as well, and for some businesses the adverse selection caused by VPNs basically makes banning VPNs a no-brainer (eg. due to fraud).
Practically: The economics probably check out, but bear in mind that it's not one-sided; this will cost you legitimate users.
Death by a thousand anti-fraud cuts. In the end it's a perfect dystopia.
Should I be able to walk around stores wearing balaclavas? Sure, robbers wear balaclavas, but innocent people do too.
It makes sense to filter out bad actors, but relying on vpn usage as the only signal for untrustworthiness is unwise.
The optimal amount of fraud is non-zero.
Also in an age of CGNAT, state enforced ISP level tracking and blocking. Blocking at the IP level is just lazy. It's like blocking a person because they come from the same town as someone else.
But I guess blocking $$$ corporate visitors should be fine by you as well.
It seems like the problem isn't payment fraud or nefarious activity but "fraud" in the form of people not sharing as much personal data as spyware operators would like.
And guess what the bank will most likely be doing to mitigate that liability shift. It's heuristics all the way down.
“I make my users have an account to view my content I automatically scrape from paid sites by scanning for changes 10 times per second. I have unfiltered ads in every unused pixel to optimize efficiency. I also like the ads that look real because they get more clicks and pay more. But my users are using Adblock! They’re literally STEALING from me! When I added a paid content as a service plan to combat this theft, my daily active users dropped by 99%! That must be because they were all fraudulent bot accounts just racking up my bandwidth costs! And the others now just don’t want to pay me for my work! Literally STEALING!”
My connection is my concern and not yours. If bad actors use VPNs while exploiting your site's vulnerable processes, its your concern and not mine.
Using the us east test server:
Proxy Score: 10/100 - Very likely not a Proxy
VPN Score: 0/55 - Very likely not a VPN
Using german test server:
Proxy Score: 10/100 - Very likely not a Proxy
VPN Score: 30/55 - Very likely a VPN
The thing that changed between both tests was the flow latencies vs ping latencies check. Clicking on more info it said: "flow variance too large in relation to avg flow: 0.6937484181219945"
I guess it works kinda, but not very consistent.
But e.g. https://ipinfo.io/ reveals immediately that this IP is a VPN IP address.
Proxy Score: 55/100 - Very likely a Proxy VPN Score: 15/55 - Could be a VPN (But Unlikely) Client Score: no client threat
And ipinfo gives me:
privacy: Object, vpn: false, proxy: false, tor: false, relay: false, hosting: true, service: "",
Personally, I think there is a market for indicating whether an IP is good or bad and giving it a reputation score. However, as a company, we prefer not to do that and there is a good reason for it. There are two core caveats:
1. Ambiguity: Scores can often be ambiguous when determining whether an IP is an "anonymous IP". Having a boolean response for VPN, proxy, or Tor is a simpler solution and we prefer simplicity.
2. Accuracy: We prioritize accuracy and strive for complete coverage. Some "ip reputation" providers essentially just repackage threat feeds. We want to avoid getting involved for now.
Our policy is to be reliable and allow our customers to sell IP reputation and cybersecurity solutions using our data. If they wish to create reputation scores using our data, they are more than welcome to do so.
So tried several other VPNs that should be detected, none were
Perhaps using Firefox breaks this site?
If you run someone else's Javascript.
Yeah, there is lots someone can detect if you run their Javascript.
Proxy Score: 0/100 - Very likely not a Proxy
VPN Score: 0/55 - Very likely not a VPN
Proton VPN (paid tier): Proxy Score: 35/100 - Might be a Proxy
VPN Score: 10/55 - Could be a VPN (But Unlikely)
And then these jump to 95 and 25 when I switch my VPN to a far away continent.Interestingly, Google One VPN is also not detected. I suspect that's due to Google intentionally sharing that IP range with Google Fi.
Proxy Score: 45/100 - Likely a Proxy VPN Score: 15/55 - Could be a VPN (But Unlikely)
Service sure does assume a lot of things.
Shifting to overseas it detected a clock difference between my browser and the exit point. I was testing with chrome though so insecurities like that are to be expected.
> The most important proxy detection tests with the highest accuracy are:
> 1. Latency Test - latency - This test is extremely effective at detecting proxy connections. It works both for residential and datacenter proxies. The reason why this test is effective: It is very hard to spoof and fake the latency test effectively. Furthermore, this test captures the very essence of proxy connections.
> 2. TCP/IP Fingerprint Test - tcpip_fp - This test is also capable to detect both residential and datacenter proxy connections. Although it is possible to spoof the TCP/IP fingerprint of a proxy server, most commercial proxy providers don't do it.
> 3. Timezone Test - timezone - The timezone test detects both VPN and Proxy connections. Clients can prevent the leaking of their locale and timezone, so this test can be bypassed rather easily.
LOL - so the author has never been stuck on DSL or a WISP?
Edit: For that matter, I wonder how many cell connections fail the latency test
Of course this does not work for VPN services like PureVPN, OVPN, and SwissVPN that provide a real public IP address to the client (so both pings measure the latency to the client), or for VPNs that properly firewalled the external NAT IP so that it is not pingable and does not send TCP RST or ICMP Port Unreachable messages when probed. But PureVPN IP ranges are known, so it is detected that way.
All these signals will either be too weak and let through enough false negatives as to be essentially useless, or too strict and produce so many false positives that a significant portion of the legitimate users leave in frustration. Unless you are some oppressive regime cracking down on VPN usage, I truly don't see where this will be useful. I guess it's helpful to compile the list of modern methods for detection and fingerprinting, so VPN providers can mitigate them.
...which I'm actually fairly pleased about.
* Proxy Score: 45/100 - Likely a Proxy
* VPN Score: 10/55 - Could be a VPN (But Unlikely)