Show HN: A simple IP address API
ipinfo.io
ipinfo.io
Imagine you want to redirect users to the correct country page in your site. In this case you need to get access to the ip geolocation in real time. GA won't help you there.
http://www.maxmind.com/en/geolite_city_accuracy
It's less accurate than their commercial offering, but good enough in many cases. For ease of use, there's a nice C API (https://github.com/maxmind/geoip-api-c) and wrappers like pygeoip for Python.
http://www.maxmind.com/en/city http://nginx.org/en/docs/http/ngx_http_geoip_module.html
I use it for my bitcoin client: https://github.com/bit-c/bitc
Anyway, this 'quality' should be free anyway ;-)
Why not check both rather than just one?
ipinfo.io thinks I'm in Brisbane, which is slightly more accurate (although also less specific), although still about 25km out.
It gets my Location wrongish here on the Gold Coast, but not too far out. We have huge suburbs though, all of the GeoIP DB's seem to think im in the wrong suburb, despite having a static IP on Telstra cable.
So, I'm wondering, does ipinfo.io maintain their own database, or do they sub-license someone else's database? If they're maintaining their own, how good are they at keeping it valid and updated and what is the coverage like?
Ip address 200.7.52.1 is a good way to check these services. This should position to the island of Sint Maarten. A serious offering would know that. The free ones always set the position to Curacao. Just about 900 NM away...
I posted this for a friend: https://twitter.com/coderholic
He's the guy behind Lighbox.com which Facebook acquired, really awesome guy!
I guess he'll be wondering where all the sudden traffic is coming in from!
Usually though I just use http://www.moanmyip.com for the weirdness of it. Or pretty much any search engine includes that up top when you search for "ip address".
It provides response formats: xml, json, csv, newline separated, serialized php. And enforce a limit of 240 requests per minute (that's 14,400 per hour for the lazy).
Fun fact, if you're running tor (tor-0.2.4.17 as proxy not the browser) you'll see the tor exit node in "IP:" and your actual ip i "Real IP:", thanks to gdns' EDNS (https://gdns.re/edns-demo/)
https://trac.torproject.org/projects/tor/wiki/doc/Preventing...
I disagree, but have you said it is down to my inability to explain what the problem is, then I agree.
I'm aware of the DNS leaks, and obviously wasn't clear enough and failed to explain what the problem was.
The leak only happens when you run the tor proxy daemon, and your own browser with the appropriate proxy settings.
It's down to the way Firefox, uses the defined proxy for the initial DNS and HTTP requests, but then bypasses it when doing DNS lookups for JS within the initial page loaded.
It doesn't leak DNS lookups made by JS scripts if you use the tor version that includes a mod-Firefox browser.
Now, people /have/ been predicting some crazy run on IPv4 for some time now, I was pretty certain it was going to happen in 2011 and while a run is still quite possible, it hasn't happened yet, and there are a bunch of outstanding /8s that could very well be returned; the DoD has been returning blocks, and they still have a bunch more they could return. Based on my own previous expectation that runout was going to occur in 2011, I'd be surprised if we run out before 2015.
Now, if you are dealing with network admins and infrastructure types? IPv6 is very important. I give my customers an IPv6 address by default, and will give a /64 upon request. It's pretty important for the sort of people I have as customers.
You see, we're the ones who have to deal with this 'nat hell' - and make no mistake about it, it will be hellish.
However, from a business perspective? If you are going after business types? The internet is still entirely IPv4.
I wonder if there are any additional data sources that can just be bought wholesale and sold in pieces? Think of all the applications that needed very precise IP address data but couldn't afford the whole dataset. They can now exist!
I could also be wrong and this isn't at all the approach this service takes...
And presumably, therefore, issued under licenses that forbid you from starting a query service? I'm pretty sure most of these IP data providers will offer their own on-demand query services
Access to the data is restricted to employees and contractors of the license holder. With contractors, the license holder is liable should the contractors violate the terms of the agreement.
Data may not be stored in a way that is publicly accessible.
If you wanted to build a public server with that, you would have to use their per-usage API according to their FAQ: http://www.maxmind.com/en/faq#lookuptool
Also, I wonder if it handles X-Forwarded-For headers that contain multiple IP addresses, because there are multiple levels of proxying taking place.
Also. No IPv6? How boring.
$ curl ipinfo.io/10.0.0.1
{
"ip": "10.0.0.1",
"hostname": "No Hostname",
"loc": "",
"bogon": true
}"127.0.0.1 is a bogon or private IP address that should not appear on the Internet."
But then I learned that "bogon' is actually a word:
http://en.wikipedia.org/wiki/Bogon_filtering
And re-reading the sentence, I'm not sure what "bogon" would be a typo for anyway..."Vogon"? Anyway, good handling of an edge/nonsense case!
I'll probably be using this. Thanks!
At least it got the US part right.
JSONP support: http://ipinfo.io/?callback=test
Paid JSONP support: https://ipinfo.io/?callback=test
MYIP="`curl -s http://ipinfo.io/ip`"
http://myip.enix.org/REMOTE_ADDR is similar.Thanks.
It merely does legacy IP, so what's the point?
Why not just use Maxmind though?
I'll go ahead and file an issue with the github lib.
http://whatsmyresolver.stdlib.net/
curl -L http://whatsmyresolver.stdlib.net/resolver/
? It should be relatively easy to add (happy to explain how it works), and I'm personally longing to turn off my service!But surely.. that would either require (a) a massive IP space (i guess that works if the site is IPv6 only), or (b) assuming a pretty short time between dns lookup and http request, and hence possibly false results if the dns lookup is cached somewhere and the IP has since been reused
I'd love to know if there's a better way of implementing this.
FreeGeoIP thinks I'm in Edinburgh, which is only slightly better.
Ideally they should be on separate domains, at which point HSTS would be more suited.
* Courtesy of Wappalyzer
The code is written in coffeescript, and some key npm modules are:
- https://github.com/caolan/async
- https://github.com/brycebaril/node-tokenthrottle-redis
- https://github.com/rs/node-netmask
I was at one point using https://github.com/tjfontaine/node-dns for the hostname lookups, but it was significantly slower that the built in dns module, so I ended up wrapping that with my own timeout logic.