Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

They were using a VPN that was exiting in New York City and had never exited from Romania.


It does seem somewhat disingenuous to not mention the VPN usage in your first comment. Makes reasonable people wonder what other details you're leaving out, even if there are none.


I failed to make it clear by just mentioning spoofing in general, my apologies.


Are you sure the exit point was in NYC? VPN providers don't always put their servers in the same country that their IP claims to be from.

While I agree that it's unlikely that they would serve NY customers from Romania, you will definitely see weird results from Geolocation services when going through some VPN providers.


Wait, why were they using a vpn? Where were they physically at the time?


How did NYS figure out "Romania" (even if wrongly) and communicate that to your friend?

That's a bizarre capability for a system that is as incompetent as has been seen.


Browsers send tons of information to all sorts of in-page components. If the attacker is incompetent, it's not that difficult to narrow down their location.

I wonder if CDNs can be used as "standard candles" for in-page scripts to measure latencies to multiple known network locations and infer a position from there across multiple sessions with different exit points. How many exit-point/latency pairs would I need to figure out the actual origin of a request?




Consider applying for YC's Fall 2026 batch! Applications are open till July 27.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: