Live data from Hacker News

PureVPN IPv6 Leak

anagogistis.com

21–30 of 93 posts

Re: PureVPN IPv6 Leak

#21
post #8

Earlier quoted context omitted.

Alternatively, disable ipv4. The same statement holds true.

Unfortunately this is not true, loads of cool techy stuff (Sentry, GitHub) etc still don't work properly on IPv6, less techy stuff really didn't care at all.

You can use nat64 to talk to legacy networks. Ipv6-only networks (with nat64 or 464xlat etc) are becoming increasingly popular. There is also this new concept called "ipv6-mostly network" that is getting rolled out: https://www.ietf.org/archive/id/draft-ietf-v6ops-6mops-02.ht...

Re: PureVPN IPv6 Leak

#24
post #6

I strongly suggest that you use something like Network Namespaces through Vopono[0] or Gluetun[1] if you use a commercial VPN for "privacy" or "security" aka torrenting and shitposting. Relying on these clients is always a gamble and if your software (Browser, Torrentclient, etc.) cannot know you public IP only the internal IP of the VPN you are also safe against some exploits and misconfigurations a desktop client w…

Wouldn't blocking IPv6 and using a kill-switch prevent leaking?

Block IPv4 as well and you're pretty solid.

Re: PureVPN IPv6 Leak

#25
post #15

Earlier quoted context omitted.

Everything is TLS-encrypted anyway these days, so the primary concern is metadata privacy. When it comes to that, I trust VPN providers about as much as ISPs (i.e. absolutely not).

VP.NET doesn't require any trust at all [1][2]. [1] https://vp.net/l/en-US/blog/Don%27t-Trust-Verify [2] I work for VP.NET and can answer any questions regarding the technology as well!

Interesting! But "no trust required" is a strong statement; don't I need to trust at least Intel? :)

Re: PureVPN IPv6 Leak

#26

What about NordVPN and ExpressVPN are those somewhat trustworthy?

Given their need to advertise with pretty much any YouTube channel willing to take their money, I'd be inclined to question the quality the likes of NordVPN and SurfShark.

Re: PureVPN IPv6 Leak

#27
Hi, I'm the author of the blog post and just wanted to say thanks for the discussion.

I agree that relying solely on desktop VPN clients (especially closed-source ones) is risky... The network namespaces approach is new to me, but it looks like a solid way to isolate traffic and avoid these kinds of leaks entirely. Thanks for the suggestions.

Re: PureVPN IPv6 Leak

#28

I donwt know any single VPN provider apart from Mullvad with proper v6 implementation.

Solid dev + OSS ecosystem + Flat rates I'm satisfied!

$5/month vs eg $2/month with a long running sub with e.g. PIA (Chinese owners) though... I wish mullvad provided long running subs with better prices then what they currently provide.

Re: PureVPN IPv6 Leak

#29
post #5

I strongly suggest that you use something like Network Namespaces through Vopono[0] or Gluetun[1] if you use a commercial VPN for "privacy" or "security" aka torrenting and shitposting. Relying on these clients is always a gamble and if your software (Browser, Torrentclient, etc.) cannot know you public IP only the internal IP of the VPN you are also safe against some exploits and misconfigurations a desktop client w…

I strongly suggest you disable ipv6, as nothing will break by disabling it but many things break with it enabled.

That's not really true anymore. I've used a connection with both IPv4 and 6 for the past two years. There's a number of times where my stuff magically works, whiles others have issues, because my traffic is mostly over IPv6. Not once have I had an issue because my setup is dual stacked.

Re: PureVPN IPv6 Leak

#30
post #11

Earlier quoted context omitted.

Alternatively, disable ipv4. The same statement holds true.

Lots of things will break if you disable ipv4, including my work provided zscaler windows laptop (and not break in the good way where it fails open when you block traffic to zscaler nodes on your router) Very little will break if you disable ipv6

A lot of stuff breaks when you run Zscaler.
Post reply on HN