Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6000959
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 23, 20262026-05-23T00:46:05+00:00 2026-05-23T00:46:05+00:00

How easy is it to hack or provide mis-information to a website via a

  • 0

How easy is it to hack or provide mis-information to a website via a GeoLocation API?

I have a need to have users post their position to my server, but I need to ensure that the data is not spoofed. Pin-Point accuracy is not required, but I need to know that the user was at least in the vicinity of where they claim to have been.

As long as I protect my service from being invoked arbitrarily (with user provided parameters) can I trust the lat/long given by the GPS systems in modern smartphones accessed through native apps? What about through HTML5?

My question is basically, are the built-in OS APIs secure in the sense that (assuming non-rooted phones) that the data coming back from the API is valid? If not, is there any way I can verify the data is at least reasonable?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-23T00:46:06+00:00Added an answer on May 23, 2026 at 12:46 am

    Are you expecting malice?

    As with any technology relying on the client, you have to trust the client. With rooted/jailbroken phones, theoretically the data can be manipulated on the phone. If location services are disabled, you might get placeholder data (though you should get an indication that geolocation is disabled). As far as I know, there is no reliable way to detect whether an iPhone has been jailbroken for sn app store app, much less a website.

    That aside, any system can be gamed, but providing false geo data on a stock, non-jailbroken iPhone would not be trivial; the same probably goes for Android.

    You could also do sanity checks by using an external, IP-based geolocation service (that could, again, be fooled, for instance by proxy servers).

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

An easy jQuery question. I have several identical forms ( except their name )
Another easy one hopefully. Let's say I have a collection like this: List<DateTime> allDates;
any easy to use utility/tool/profiler/benchmark that able to test what is the maximum users
I wrote a fast and easy hack to walk thru directories (in stepmania song
I have a Django application which allows different kinds of users: firms, administrators, external
I understand that it is easy to hack Mach-O executable, I just want simple
The Setup I have designed a very easy to use MVC wizard. The cherry
I have a classifieds website, and I am about to create a members login
Hi hopefully this will be an easy one. I need to implement the classic
Easy question this time. I'm trying to test whether or not a string does

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.