How feasible would it be for the host under measurement to introduce additional artificial latency to ping responses, varying based on source IP, in order to spoof its measured location?
Not-impossible, but it would be a whole lot simpler to just not respond to pings in the first place.
Courtesy of Xfinity and Charter overprovisioning most neighborhood’s circuits, we already have that today for a significant subset of U.S. Internet users due to the resulting Bufferbloat (up to 2500ms on a 1000/30 connection!)
Totally feasible but a bit like all these situations - it’s not happening in practice.
>varying based on source IP,
Aha, that's what you would think, but what if I fake the source of the IP used to do the geolocation ping instead!
Totally feasible.
You could do even cooler tricks, like https://github.com/blechschmidt/fakeroute
Pointless? Almost certainly.