Jump to content
Usr6

VPNs are Using Fake Server Locations

Recommended Posts

Posted

Do VPNs really have all the servers they claim in exotic locations all over the world?

In many cases, the answer is no.

The true location of some VPN servers may be entirely different. In other words, a server that is allegedly in Pakistan is actually in Singapore. Or a server that should be in Saudi Arabia is actually in Los Angeles, California. (Both are real examples from below.) This is known as spoofing the true location.

Why is this important?

First, the performance may suffer if the actual server is significantly further away. Second, it’s bad if you are trying to avoid certain countries (such as the UK or US) where the server may be located. Third, customers aren’t getting the true server locations they paid for. And finally, using fake server locations raises questions about the VPN’s honesty.

In this article we’ll take a deep dive into the topic of fake VPN server locations. The point here is not to attack any one VPN provider, but instead to provide honest information and real examples in order to clarify a confusing topic. We will cover four main points:

  • VPN server marketing claims
  • Fake server locations with ExpressVPN (11 are identified)
  • Fake server locations with PureVPN (5 are identified, but there are many more)
  • How to test and find the true location of VPN servers

But before we begin, you might be asking yourself, why do VPNs even use fake server locations?

The incentives are mainly financial. First, it saves lots of money. Using one server to fake numerous server locations will significantly reduce costs. (Dedicated premium servers are quite expensive.) Second, advertising numerous server locations in a variety of countries may appeal to more people, which will sell more VPN subscriptions.

Here’s how that works…

My, what a larger server network you have!

Most of the larger VPN providers boast of server networks spanning the entire world. This seems to be the trend – they are emphasizing quantity over quality.

Take Hidemyass for example and their server network claims:

hidemyass-servers If you think there are physical servers in 190+ countries, I have a bridge to sell you!

Upon closer examination of Hidemyass’s network, you find some very strange locations, such as North Korea, Zimbabwe, and even Somalia.

But reading further, it becomes clear that many of these locations are indeed fictitious.

Hidemyass refers to these fictitious server locations as “virtual locations” on their website. Unfortunately, I could not find a public server page listing all server URLs, so I could not test any of the locations. However, the Hidemyass chat representative I spoke with confirmed they use “virtual” locations, but could not tell me which locations were fake and which were real.

 

PureVPN is another provider that admits to using fake locations, which they refer to as “virtual servers” – similar to Hidemyass. (We will take a closer look at PureVPN below, with testing results for the servers that are not classified as virtual.)

ExpressVPN also boasts of a large server network. Unlike with PureVPN and Hidemyass, ExpressVPN does not admit to using fake locations anywhere on its website. The ExpressVPN chat representative I spoke with claimed that all server locations were real. (This was proven through testing to be false.)

expressvpn scam-2 Testing shows that many of ExpressVPN’s server locations are fake.

Just like with Hidemyass and PureVPN, testing results show that ExpressVPN is using fictitious server locations, which we will cover in detail below.

Testing VPN server locations

With free network-testing tools, you can quickly find the true location of a VPN server. This allows you to cross-check dubious server locations with a high degree of accuracy.

For every VPN server examined in this article, I used three different network-testing tools to verify the true location beyond any reasonable doubt:

  1. CA App Synthetic Monitor ping test (ping test from 90 different worldwide locations)
  2. CA App Synthetic Monitor traceroute (tests from various worldwide locations)
  3. Ping.pe (ping test from 24 different worldwide locations)

First, I used this ping test, which pings the VPN server from 90 different worldwide locations. This allows you to narrow down the location with basic triangulation. In general, the lower the time (ms), the closer the server is to a given location. Pretty simple and accurate.

Second, I ran traceroutes from various locations based on the results in the first test. This allows you to measure the distance along the network to the final VPN server. With ExpressVPN, for example, I could run a traceroute from Singapore and find that the VPN server is about 2 ms away, which means it is also located in Singapore.

Third, I used another ping test to again ping the VPN server from different worldwide locations. This tool also includes traceroutes for each location (MTR).

Note: When running traceroutes or ping tests, you may have some outlier test results due to different variables with the network and hops. That’s why I recommend running multiple tests with all three of the tools above. This way, you will be able to eliminate outlier results and further confirm the true server location.

With every fictitious server location found in this article, all three tools strongly suggested the exact same location. If there was any doubt, I did not label the server as “fake” below.

ExpressVPN server locations

As we saw above, ExpressVPN boasts a large number of servers on their website in some very interesting locations.

In the map below you can see many of their southeast Asia server locations in red boxes. These are all the locations that were determined to be fictitious after extensive testing, with the actual server being located in Singapore.

Expressvpn servers fake Every ExpressVPN server location in a red box was found to be fake after extensive testing.

ExpressVPN does not make any of their server URLs publicly available. So to obtain the server URL, you need to have an ExpressVPN account, then go into the member area and download the manual configuration files.

In total, I found 11 fake VPN server locations with ExpressVPN. Below I will show you the test results for one location (Pakistan). You can find the the other test results in the Appendix to this article.

ExpressVPN’s Pakistan server (Singapore)

URL: pakistan-ca-version-2.expressnetw.com

ExpressVPN scam

Test 1: Ping times from different worldwide locations reveals the server is much closer to Singapore than to Bangalore, India. If the server was truly in Pakistan, this would not make much sense.

expressvpn india

ExpressVPN-Singapore.png

At only 2 milliseconds ping (distance), this “Pakistan” server is without a doubt in Singapore. But to further prove the location, we can run a few more tests.

Test 2: Running a traceroute from Singapore to the “Pakistan” VPN server, we can once again verify that this server is in Singapore, at about 2 ms ping.

expressvpn pakistan

Looking at every hop in the traceroute gives you the full picture of the network path. This shows how much distance (time) is between the final VPN server and the traceroute location. At around 2 ms, this server is clearly in Singapore.

Just for fun, we will run one more test, even though it is already clear where the server is located.

Test 3: Here is another ping test using the website ping.pe.

Screen-Shot-2017-07-07-at-11.37.32-AM-2.

The Pakistan server location is undoubtedly fictitious (spoofed). The real location is in Singapore.

One other sign you see with ExpressVPN’s fake server locations is the second-to-last server IP address (before the final hop) when you run the traceroute is the same. With all the fake server locations in Asia you find this IP address before the final hop:

174.133.118.131

With a traceroute you can see that the final (spoofed) server is always very close to the IP address above. This is simply more evidence pointing to the obvious conclusion that Singapore is the true location of all these servers.

In addition to Pakistan, here are the other fictitious server locations found with ExpressVPN:

  1. Nepal
  2. Bangladesh
  3. Bhutan
  4. Myanmar
  5. Macau
  6. Laos
  7. Sri Lanka
  8. Indonesia
  9. Brunei
  10. Philippines

Note: there may be more fake locations, but I did not have time to test every server.

Update: Six days after publishing this article ExpressVPN has admitted to numerous fake locations on its website (mirror) – 29 fictitious locations in total. Just like PureVPN and Hidemyass, ExpressVPN refers to these as “virtual” server locations.

PureVPN server locations

PureVPN has quite a few fake server locations.

On the PureVPN server page you find that many of the servers begin with “vl” which seems to stand for “virtual location”. You find two different types of these prefixes: vleu (which probably stands for virtual location Europe) and vlus (which likely means virtual location US). Every “vl” location I tested was indeed fake (or “virtual” as they like to call it).

purevpn virtual servers

But I also found that many of their non-virtual locations are also fake, such as Aruba and Azerbaijan in the screenshot above.

Here is one example:

PureVPN’s Azerbaijan server (United Kingdom)

URL: az1-ovpn-udp.pointtoserver.com

purevpn fake servers

The ping test clearly shows this server location to be in the United Kingdom – in close proximity to Edinburgh.

purevpn fake servers azerbaijan

Furthermore, the ping times for Turkey (which is close to Azerbaijan) are much higher than the UK.

purevpn servers fake scam

The server location is already clear; it is located in the UK.

But to further verify the location beyond doubt, I ran a traceroute from Edinburgh, UK to the “Azerbaijan” server:

Purevpn servers azerbaijan

At around 2 milliseconds, this server is without a doubt in the United Kingdom, not Azerbaijan.

In addition to Azerbaijan, I also found four other fake “non-vl” server locations with PureVPN:

  • Aruba
  • Saudi Arabia
  • Bahrain
  • Yemen

Note: I did not spend much time testing PureVPN server locations because it was clear that many locations were fake. Consequently, I only chose five examples for this article.

How to find the real VPN server location

Determining the real location of a VPN server is quick and easy with the five steps below.

Step 1: Obtain the VPN server URL or IP address

You should be able to find the URL or IP address of the VPN server in the members area. You may need to download the VPN configuration file for the specific location, and then just open the file and get the URL for the server. Some VPNs openly provide this information on their server page.

vpn server test Here I downloaded the OpenVPN configuration file for the ExpressVPN Nepal server. After opening the file, I find the server URL near the top.

Now copy the URL of the VPN server for step 2.

Step 2: Ping the VPN server from different worldwide locations

Use this free tool from CA App Synthetic Monitor to ping the VPN server from about 90 different worldwide locations. Enter the VPN server URL (or IP address) from step 1 into the box and hit Start.

vpn server ping

It will take a few seconds for the ping results to show.

Step 3: Examine results to determine actual location

Now you can examine the results, looking for the lowest ping times to determine the closest server. You may want to have a map open to examine which server should have the lowest ping based on geographical distance.

vpn test servers From all of the testing locations, Bangalore, India should have the lowest ping due to its close proximity to Nepal.

But if you look at all the results, you may find that the exact location of the server is somewhere else.

vpn scam server Looks like we have a winner. This VPN server is located in Singapore – NOT Nepal.

At this point it is clear that the server location is in Singapore, and not Nepal (for this example). But just to verify these results, we will run some more tests.

Step 4: Run a few traceroute tests

You can further probe the exact location by running a traceroute test. This is simply a way to measure the time it takes for a packet of data to arrive at the server location, across the different hops in the network. There are different options for traceroute testing, such as the Looking Glass from Hurricane Electric.

My preferred method is to use this traceroute tool from CA App Synthetic Monitor and then select the location to run the traceroute from.

First, you can run the traceroute from a location that should be the closest to the server location. In this case, that would be New Delhi, which is the closest location I can find to Nepal. Just enter the VPN server URL and select your test location for the traceroute.

vpn server 4

Now we will run another traceroute, but this time from Singapore.

VPN-server-5.png We have a winner: Singapore.

It is now clear that this ExpressVPN Nepal server is located in Singapore. But you can also cross check with one more test.

Step 5: Run another ping test

Just like in step 2, Ping.pe will ping the VPN server from different worldwide locations, allowing you to narrow down the likely location. This tool will continuously ping the server and calculate the average time for every location. Furthermore, it will run traceroutes for every location, allowing you to further verify the location.

As before, simply enter the VPN server URL and hit Go. The ping results will continuously populate in the chart.

VPN-Server-7.png Once again, the results clearly show this server is in Singapore. No doubt about it.

Now we can see beyond all doubt, this VPN server is located in Singapore, not Nepal.

Controlling for variables

With every fake server location I found, all three tools strongly suggested the same location. Nonetheless, you may still get some outlier results due to different variables and hops in the network. To control for variables and easily eliminate these outliers, simply run multiple tests with all three tools. You should find the results to be very consistent, all pointing to the same location.

Conclusion on fake VPN server locations

Dishonesty is a growing problem with VPNs that more people are starting to recognize. From fake reviews to shady marketing tactics, false advertising, and various VPN scams, there’s a lot to watch out for.

Fake VPN servers are yet another issue to avoid. Unfortunately with all the deceptive marketing, it can be difficult to find the true facts.

Most VPNs emphasize the size of their server network rather than server quality. This quantity over quality trend is obvious with most of the larger VPN providers. On the opposite end of the spectrum are smaller VPN services that have fewer locations, but prioritize the quality of their server network, such as Perfect Privacy and VPN.ac.

Some VPN users may not care about fake servers. Nonetheless, fake VPN servers can be problematic if you:

  • are trying to avoid specific countries
  • are trying to optimize VPN performance (which may be affected by longer distances)
  • are trying to access restricted content (fake locations may still be blocked)
  • expect the server to be where the VPN says it is (honesty)

With the tools and information in this article, you can easily verify the location of any VPN server, which removes the guesswork completely.

Appendix (testing results)

ExpressVPN Nepal (Singapore)

URL: nepal-ca-version-2.expressnetw.com

expressvpn-nepal.png

And now running a traceroute to the “Nepal” server from Singapore:

expressvpn-nepal-server.png

This “Nepal” server is located in Singapore.

ExpressVPN Bhutan (Singapore)

URL: bhutan-ca-version-2.expressnetw.com

ExpressVPN-Bhutan-2.png

And now running a traceroute to the “Bhutan” server from Singapore:

Expressvpn-bhutan-server.png

Once again, ExpressVPN’s “Bhutan” server is located in Singapore.

ExpressVPN Sri Lanka (Singapore)

URL: srilanka-ca-version-2.expressnetw.com

Sri-Lank-Expressvpn.png

Here’s the traceroute to the “Sri Lanka” server from Singapore:

expressvpn-server-sri-lanka.png

The “Sri Lanka” server is actually in Singapore.

ExpressVPN Bangladesh (Singapore)

URL: bangladesh-ca-version-2.expressnetw.com

ExpressVPN-server-Bangladesh.png

Here’s the traceroute to the “Bangladesh” server from Singapore:

Bangladesh-expressvpn-2.png

It is easy to see that the “Bangladesh” server is located in Singapore, especially when you compare the locations using the ping test.

ExpressVPN Myanmar (Singapore)

URL: myanmar-ca-version-2.expressnetw.com

expressvpn-myanmar-server-2.png

Here’s the traceroute to the “Myanmar” server from Singapore:

expressvpn-server-myanmar.png

This VPN server is located in Singapore (also verified by the other tests).

ExpressVPN Laos (Singapore)

URL: laos-ca-version-2.expressnetw.com

ExpressVPN-laos-server.png

Here’s the traceroute to the “Laos” server from Singapore:

expressvpn-server-laos-fake-2.png

This server is also clearly in Singapore.

ExpressVPN Brunei (Singapore)

URL: brunei-ca-version-2.expressnetw.com

expressvpn brunei server fake

Here’s the traceroute to the “Brunei” server from Singapore:

Brunei expressvpn server

Once again, this is clearly in Singapore. But given the close geographic proximity of these locations, I also checked ping times from neighboring countries, such as Malaysia and Indonesia, which were all significantly higher than the ping time from Singapore. All tests pointed to the same conclusion: Singapore.

ExpressVPN Philippines (Singapore)

URL: ph-via-sing-ca-version-2.expressnetw.com

Unlike all of the other fictitious server locations, ExpressVPN appears to be admitting the true location with the configuration file name. Below you see that the config file is named “Philippines (via Singapore)” – which suggests the true location.

Philippines-expressvpn-server.png

Here’s the traceroute to the “Philippines” server from Singapore:

expressvpn fake server location

Just like with all the other traceroute tests, this location is also in Singapore.

ExpressVPN Macau (Singapore)

URL: macau-ca-version-2.expressnetw.com

expressvpn macau server false

This was another server location that was very easy to identify as fake using the ping test. Because Hong Kong and Macau are right next to each other, the closest ping result should have been with the Hong Kong server. But instead, Hong Kong’s ping time was about 32 milliseconds and Singapore’s ping time was again around 2 milliseconds.

Here is the traceroute to “Macau” from Singapore:

expressvpn macau fictitious server

Another fake server location, which is clearly in Singapore.

ExpressVPN Indonesia (Singapore)

URL: indonesia-ca-version-2.expressnetw.com

indonesia expressvpn server fake

The ping test with this location was another dead giveaway. The ping result from Jakarta, Indonesia was 198 milliseconds, and the ping result from Singapore was under 2 milliseconds. Again, case closed.

Here is the traceroute from Singapore:

expressvpn fake server location indonesia

Location: Singapore.

PureVPN Aruba (Los Angeles, USA)

URL: aw1-ovpn-udp.pointtoserver.com

purevpn server aruba

All tests show this server is located in Los Angeles, California (USA). Here is the traceroute from Los Angeles:

purevpn server aruba 2

Actual server location: Los Angeles, California

PureVPN Bahrain (Amsterdam, Netherlands)

URL: bh-ovpn-udp.pointtoserver.com

Bahrain purevpn server

Here is the traceroute from Amsterdam.

purevpn server bahrain

This “Bahrain” server is undoubtedly in Amsterdam.

PureVPN Saudi Arabia (Los Angeles, USA)

URL: sa1-ovpn-udp.pointtoserver.com

purevpn server saudi arabia

Now running the traceroute from Los Angeles, California:

purevpn saudi arabia

This “Saudi Arabia” server is in Los Angeles.

PureVPN Yemen (Frankfurt, Germany)

URL: ym1-ovpn-udp.pointtoserver.com

purevpn server yemen

Here’s the traceroute from Frankfurt:

purevpn server scam

PureVPN’s “Yeman” server is clearly in Frankfurt, Germany.


UPDATES

HideMyAss (November 2017) – As a response, HideMyAss has told us, “We have always been open and transparent about virtual server locations and believe that the concept is explained comprehensively both on our website and in our latest software client.”

However, when you examine their server locations page, it is still not clear exactly which locations are “virtual”.

ExpressVPN – ExpressVPN has fully updated their server locations page to explain exactly which servers are real and which are “virtual”. They have also removed all contradictory claims about “no logs” and clarified their exact policies. You can check out the details on the ExpressVPN website here.

PureVPN – We have not heard anything form PureVPN since this article was first published. However, we did recently learn that PureVPN has been providing connection logs to the FBI while still claiming to have a “zero log policy”.

 

Sursa:  https://restoreprivacy.com/vpn-server-locations/

  • Upvote 5

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...