I'm pleasantly surprised to see that the MaxMind folks are doing the "right thing" and relocating the default coordinates to the middle of bodies of water.
It'd also be nice if they returned (-inf, -inf) or something so people know it's not a "real" location, lest folks start looking for the house closest to the lake.
I would say the right thing would be to explicitly return a region rather than default coordinates at all. In the article it claims accuracy to about the ZIP code level, but when it's a default for the whole US, it's clearly not.
If the uncertainty can vary, you have to explicitly indicate it. If returning an irregularly shaped region is too hard, you can at least return a center and a radius.
...or is that what they were already doing, and the problem comes from people ignoring the radius? In that case, yeah, I guess they were doing what they could, and good on them I guess for moving the center to somewhere that won't cause problems when people ignore the radius. But it doesn't sound like that's what they were doing in the first place?
I wonder if it would be better for services to express uncertain coordinates as the min and max of latitude and longitude, rather than center and radius. The information conveyed is equivalent, but it would be a (small) barrier against lazy or clueless people ignoring the radius.
According to their API documentation[1] this is what they are doing: There is an "accuracy_radius" element being returned right next to latitude and longitude.
And according to the Internet Archive, this element existed already in 2015, so they do not seem to have added it in response to this article.
What they did seem to have added in response to this article, however (as it is new), is a more explicit warning for their customers:
"Latitude and Longitude are often near the center of population. These values are not precise and should not be used to identify a particular address or household."
To be honest, I think it is very hard for an API provider to ensure that their customers will use all the right disclaimers when providing their data onwards to their customers... I think the new approach with pointing the general coordinates into uninhabitated spaces and adding that warning seems probably the best they can do without completely changing their API design (which would make many customers very angry, I would guess).
Actually, what would be better, if the companies can't change their data to return an "area", would be for them to relocate these "default" values not to the middle of bodies of water (for the reason you mention, someone assuming the nearest "house" must be "it") but instead to find the lat/long of the nearest Police station and use that value.
That way, when random strangers show up, they won't cause trouble and could even file a proper report if they wished.
And when actual law enforcement arrives, with battering rams and all, they also won't cause undue stress, given that where they will have arrived is a Police station.
The story talks about the point used as the default location for "the US". How is the small town police station in Kansas going to be able to file a useful police report for the entire country?
Similarly, if the default location for the state of New York is the Oriskany Falls, NY police station, then how are they going to file a useful police report for something that happened in New York City?
I think the idea is that people are more likely to think for a second if they see that a police station is the supposed epicenter for a hotbed of criminal activity instead of just some random house.
Agreed. My comment asks why it's better to use a police station as the point rather than the chosen solution (mentioned at the top-level of this thread) of pointing to the middle of a large body of water.
The reasons given by the g'parent, for pointing to a police station, don't look like they would actually work in practice.
It would be especially slick to return (0, 0), which is a valid latitude/longitude pair but happens to be in the ocean off the west coast of Africa: It wouldn't crash naïve software, but it's obviously nowhere most people would consider going, even if they were ignorant enough to think there was an island there. (There isn't.)
If you got (0,0), how would you know which country the IP address is from? I think it makes perfect sense for a country's default location to be somewhere within that country.
(0,0) would only be a useful default if you knew the IP address is located somewhere on planet Earth, but not more than that. And at time of writing, the vast majority (all?) of IP addresses are located on Earth anyway, so it's not especially helpful.
i feel really sorry for these people. the idea that law enforcement and service providers are using ip based location for anything serious is absolutely incredible.
the location from ip address is a fallback for when you don't have anything better, and it is a fallback you take with the caveat of "could be completely wrong".
this was my opinion of it when i first discovered the concept over 10 years ago.
the victims should bring legal action imo and law enforcement should get its shit together and act competently at the very most basic of levels.
ip based geolocation is and never was reliable. the idea that you can get a search warrant based off of it is laughable and indicates gross incompetence, not just in one place, but at every stage that such a thing is knowingly used.
using things you don't understand to draw concrete conclusions is stupid. literally. its the very definition of the word 'misguided'.
I can think of a few issues which make that solution more murky.
Why put more work onto the local law enforcement, who now have to deal with people from well outside their jurisdiction?
There are currently people who go to point X to complain or threaten. In your model, some will arrive at point X to find out it's a law enforcement facility. Many fewer will try to go to X if it's in the middle of a body of water, because it's more obviously not a place where people live. Placing X in the water means less time is wasted on a wild goose chase.
There are corrupt law enforcement officers. Isn't there the chance that, say, the state police will come to investigate small-town Mayberry with a single sheriff and deputy?
Law enforcement facilities do move. Who is in charge of updating the coordinates when the sheriff's office moves a few blocks away and another business moves into the old facility?
> At its least precise, it can be mapped only to a country.
Even that isn't true. Plenty of corporations have all their IP addresses registered to their main office. In general the way these services work is that they ask the owner of the IP where they are and have no way to verify it at all. And of course there are always VPN services and proxy servers that will let you choose which country your IP address will read as being in. To say nothing of actually malicious parties that can break into a computer anywhere in the world and then make all of their traffic appear to have come from its IP address.
I've also seen the IP address entries for residential ISPs be off by more than a thousand miles simply because the ISP has customers in both places and assigned customers in one place IP addresses listed in the other place.
Geo IP can be useful for showing ads as long as you don't care that it's wrong some significant percentage of the time. Thinking it can be used to locate a bad actor is dangerous and absurd.
> 39°50′N 98°35′W. In digital maps, that number is an ugly one: 39.8333333,-98.585522. So back in 2002, when MaxMind was first choosing the default point on its digital map for the center of the U.S., it decided to clean up the measurements and go with a simpler, nearby latitude and longitude: 38°N 97°W or 38.0000,-97.0000.
If 39°50′N = 39.8333333, then how does 38°N = 38.0000?
And why wouldn't they round to 40 and -99 (or -98) ?
Yeah, the more I look at their rounding the less sense it makes.
OK, 39°50′N goes to 39.8333333. 50/60 is approximately 0.8333. Fine. But, 98°35′W should be -98.5833333, by the same rule they apparently just used, not 98.585522.
And I certainly don't see how 39.8333333 rounds to 38.0000 instead of 40.0000, or how -98.5833333 rounds to -97.0000 instead of -99.00000. It's like they rounded down and then subtracted 1.
The 50' (read as 50 minutes) means 50 60ths of a degree, so that part makes sense.
And not sure about the rounding, but 38N, 97W just "looks" more central looking at the map, so I'm guessing they just played around with the numbers for a few minutes to get it to look nice.
I've definitely done this, picking arbitrary points to place a marker on a map for, say, a big city, county or national park.
I think a lot of these reverse ip solutions return the center point of the zip code they have linked the ip to. For an estimation of location for marketing type purposes I think that works well. But when people assume that these databases really map to a physical address, this fails miserably as the article describes.
This shows the folly of using a meaningful value when there actually isn't one. Put a null in your database, or (better) structure your database so that if there isn't a value, there isn't a corresponding entry in your database, and a query for it returns the empty set.
When an API "default" can ruin the life of people, it's really sad that such "IP intelligence" was not thought right from the beginning to answer "can not be found".
Similar story [0] to a lesser degree is still horrible to the people it affects.
You hear this refrain so often it must be true. Comparing the "litigiousness" of countries is not easy due to different legal systems. One of the best metrics in my opinion is cases per capita. Germany and Sweden are at the top of the list. I think the U.S. comes in at 5th or 6th.
Where is the correction? I just grabbed the article from two different IPs and it says the same thing. Do you think that 600M is 10 orders of magnitude larger than 17M?
I'm pleasantly surprised to see that the MaxMind folks are doing the "right thing" and relocating the default coordinates to the middle of bodies of water.
It'd also be nice if they returned (-inf, -inf) or something so people know it's not a "real" location, lest folks start looking for the house closest to the lake.
I would say the right thing would be to explicitly return a region rather than default coordinates at all. In the article it claims accuracy to about the ZIP code level, but when it's a default for the whole US, it's clearly not.
If the uncertainty can vary, you have to explicitly indicate it. If returning an irregularly shaped region is too hard, you can at least return a center and a radius.
...or is that what they were already doing, and the problem comes from people ignoring the radius? In that case, yeah, I guess they were doing what they could, and good on them I guess for moving the center to somewhere that won't cause problems when people ignore the radius. But it doesn't sound like that's what they were doing in the first place?
I wonder if it would be better for services to express uncertain coordinates as the min and max of latitude and longitude, rather than center and radius. The information conveyed is equivalent, but it would be a (small) barrier against lazy or clueless people ignoring the radius.
According to their API documentation[1] this is what they are doing: There is an "accuracy_radius" element being returned right next to latitude and longitude.
And according to the Internet Archive, this element existed already in 2015, so they do not seem to have added it in response to this article.
What they did seem to have added in response to this article, however (as it is new), is a more explicit warning for their customers:
"Latitude and Longitude are often near the center of population. These values are not precise and should not be used to identify a particular address or household."
To be honest, I think it is very hard for an API provider to ensure that their customers will use all the right disclaimers when providing their data onwards to their customers... I think the new approach with pointing the general coordinates into uninhabitated spaces and adding that warning seems probably the best they can do without completely changing their API design (which would make many customers very angry, I would guess).
[1] http://dev.maxmind.com/geoip/geoip2/web-services/
Actually, what would be better, if the companies can't change their data to return an "area", would be for them to relocate these "default" values not to the middle of bodies of water (for the reason you mention, someone assuming the nearest "house" must be "it") but instead to find the lat/long of the nearest Police station and use that value.
That way, when random strangers show up, they won't cause trouble and could even file a proper report if they wished.
And when actual law enforcement arrives, with battering rams and all, they also won't cause undue stress, given that where they will have arrived is a Police station.
The story talks about the point used as the default location for "the US". How is the small town police station in Kansas going to be able to file a useful police report for the entire country?
Similarly, if the default location for the state of New York is the Oriskany Falls, NY police station, then how are they going to file a useful police report for something that happened in New York City?
I think the idea is that people are more likely to think for a second if they see that a police station is the supposed epicenter for a hotbed of criminal activity instead of just some random house.
Agreed. My comment asks why it's better to use a police station as the point rather than the chosen solution (mentioned at the top-level of this thread) of pointing to the middle of a large body of water.
The reasons given by the g'parent, for pointing to a police station, don't look like they would actually work in practice.
For the whole country it would make a certain amount of sense to use the address of the White House.
And a perfect way to feed the conspiracy nuts.
It would be especially slick to return (0, 0), which is a valid latitude/longitude pair but happens to be in the ocean off the west coast of Africa: It wouldn't crash naïve software, but it's obviously nowhere most people would consider going, even if they were ignorant enough to think there was an island there. (There isn't.)
If you got (0,0), how would you know which country the IP address is from? I think it makes perfect sense for a country's default location to be somewhere within that country.
(0,0) would only be a useful default if you knew the IP address is located somewhere on planet Earth, but not more than that. And at time of writing, the vast majority (all?) of IP addresses are located on Earth anyway, so it's not especially helpful.
> If you got (0,0), how would you know which country
You could read the "country" field that is returned together with the location.
How about making the default location for the U.S. be 38.8898,-77.009? Maybe that would get things fixed a bit quicker?
EDIT: added 'for the U.S.'
ADD: Here's a link to help: https://www.google.com/maps/place/38%C2%B053'23.3%22N+77%C2%...
Well now we'll be reading about people drowning in the lake searching for their lost iPhones in the nefarious villain's underwater lair.
i feel really sorry for these people. the idea that law enforcement and service providers are using ip based location for anything serious is absolutely incredible.
the location from ip address is a fallback for when you don't have anything better, and it is a fallback you take with the caveat of "could be completely wrong".
this was my opinion of it when i first discovered the concept over 10 years ago.
the victims should bring legal action imo and law enforcement should get its shit together and act competently at the very most basic of levels.
ip based geolocation is and never was reliable. the idea that you can get a search warrant based off of it is laughable and indicates gross incompetence, not just in one place, but at every stage that such a thing is knowingly used.
using things you don't understand to draw concrete conclusions is stupid. literally. its the very definition of the word 'misguided'.
Clearly the right thing to do is to have them map every single "default" IP to the nearest law enforcement facility rather than an individual address.
I can think of a few issues which make that solution more murky.
Why put more work onto the local law enforcement, who now have to deal with people from well outside their jurisdiction?
There are currently people who go to point X to complain or threaten. In your model, some will arrive at point X to find out it's a law enforcement facility. Many fewer will try to go to X if it's in the middle of a body of water, because it's more obviously not a place where people live. Placing X in the water means less time is wasted on a wild goose chase.
There are corrupt law enforcement officers. Isn't there the chance that, say, the state police will come to investigate small-town Mayberry with a single sheriff and deputy?
Law enforcement facilities do move. Who is in charge of updating the coordinates when the sheriff's office moves a few blocks away and another business moves into the old facility?
> At its least precise, it can be mapped only to a country.
Even that isn't true. Plenty of corporations have all their IP addresses registered to their main office. In general the way these services work is that they ask the owner of the IP where they are and have no way to verify it at all. And of course there are always VPN services and proxy servers that will let you choose which country your IP address will read as being in. To say nothing of actually malicious parties that can break into a computer anywhere in the world and then make all of their traffic appear to have come from its IP address.
I've also seen the IP address entries for residential ISPs be off by more than a thousand miles simply because the ISP has customers in both places and assigned customers in one place IP addresses listed in the other place.
Geo IP can be useful for showing ads as long as you don't care that it's wrong some significant percentage of the time. Thinking it can be used to locate a bad actor is dangerous and absurd.
Fun lesson on why judging others doesn't scale.
For Russian IP addresses default location is Moscow Kremlin. Why not make it The White House for the USA?
Just what we need: More conspiracy fuel for those everyday Americans who put complete confidence in default coordinates.
> 39°50′N 98°35′W. In digital maps, that number is an ugly one: 39.8333333,-98.585522. So back in 2002, when MaxMind was first choosing the default point on its digital map for the center of the U.S., it decided to clean up the measurements and go with a simpler, nearby latitude and longitude: 38°N 97°W or 38.0000,-97.0000.
If 39°50′N = 39.8333333, then how does 38°N = 38.0000?
And why wouldn't they round to 40 and -99 (or -98) ?
Yeah, the more I look at their rounding the less sense it makes.
OK, 39°50′N goes to 39.8333333. 50/60 is approximately 0.8333. Fine. But, 98°35′W should be -98.5833333, by the same rule they apparently just used, not 98.585522.
And I certainly don't see how 39.8333333 rounds to 38.0000 instead of 40.0000, or how -98.5833333 rounds to -97.0000 instead of -99.00000. It's like they rounded down and then subtracted 1.
The 50' (read as 50 minutes) means 50 60ths of a degree, so that part makes sense.
And not sure about the rounding, but 38N, 97W just "looks" more central looking at the map, so I'm guessing they just played around with the numbers for a few minutes to get it to look nice.
I've definitely done this, picking arbitrary points to place a marker on a map for, say, a big city, county or national park.
I think a lot of these reverse ip solutions return the center point of the zip code they have linked the ip to. For an estimation of location for marketing type purposes I think that works well. But when people assume that these databases really map to a physical address, this fails miserably as the article describes.
This shows the folly of using a meaningful value when there actually isn't one. Put a null in your database, or (better) structure your database so that if there isn't a value, there isn't a corresponding entry in your database, and a query for it returns the empty set.
When an API "default" can ruin the life of people, it's really sad that such "IP intelligence" was not thought right from the beginning to answer "can not be found".
Similar story [0] to a lesser degree is still horrible to the people it affects.
[0] https://gimletmedia.com/episode/53-in-the-desert/
This story takes place in the USA, one of the world's most litigous countries. Surely someone can be sued for this.
You hear this refrain so often it must be true. Comparing the "litigiousness" of countries is not easy due to different legal systems. One of the best metrics in my opinion is cases per capita. Germany and Sweden are at the top of the list. I think the U.S. comes in at 5th or 6th.
Am I missing something obvious? 600M is 10 orders of magnitude higher than 17M?
I bet the home in the #2 slot has 60M IPs associated with it. The author is just misusing the term.
That does not play well with my concept of orders of magnitude.
What is your concept?
http://public.wsu.edu/~brians/errors/orders.html
http://www2.pvc.maricopa.edu/tutor/chem/chem151/metric/magni...
https://en.m.wikipedia.org/wiki/Order_of_magnitude
Oh I just misread the sentence. Of course it should be one order of magnitude.
Looks like the author corrected the article.
Where is the correction? I just grabbed the article from two different IPs and it says the same thing. Do you think that 600M is 10 orders of magnitude larger than 17M?