Live data from Hacker News

VPN leaks users’ IPs via WebRTC

voidsec.com

31–40 of 172 posts

Re: VPN leaks users’ IPs via WebRTC

#33

Clickbait? Its not "VPN providers" its "VPN provider software", I never even thought of using their software, most just give you the credentials for OpenVPN/IPSEC/PPTP or similar. Also if anonymity is of "real" concern you should never use a system that knows your real IP address in the first place. Instead create the vpn tunnel on a separate host system and run something like Tails in a VM (or better yet separate ph…

That tunnel won't help against real adversaries. Timing attacks and text content analysis will expose you. It's getting harder to be truly black online.

> text content analysis

The solution to that is to use memes and bad grammar. I am not kidding. Keep your messages really brief and have a community of people that talk in a very similar fashion to one-another.

Re: VPN leaks users’ IPs via WebRTC

#34

Just want to point anyone looking to test their own VPN to https://ipleak.net/ . That's been my go-to, and it seems more comprehensive than the linked service.

> To detect data from your torrent client we provide a magnet link to a fake file. The magnet contains an http url of a controlled by us tracker which archives the information coming from the torrent client.

That’s pretty clever. Alternatively they could have a unique file of garbage and have some seeders for it and then when someone connects it would also be the same person. But the tracker solution is less work and probably almost entirely as good.

Re: VPN leaks users’ IPs via WebRTC

#35

I don't use VPNs. For me, the more alarming information here is that SOCKS and Tor proxies are also leaking IP addresses. If a SOCKS proxy is configured in browser, isn't it the browser's responsibility to ensure all outgoing traffic - including WebRTC - goes via the proxy? Are these browser bugs? Update: Can confirm Firefox Quantum with SOCKS proxy leaks the address. Oh dear! Update 2: I didn't realize this is how W…

> I didn't realize this is how WebRTC actually works. Yep. STUN is in the spec, and always has been. This has been a thing for years.

STUN is part of the story. The overall process is called Interactive Connectivity Establishment (ICE).

Re: VPN leaks users’ IPs via WebRTC

#36

Earlier quoted context omitted.

That tunnel won't help against real adversaries. Timing attacks and text content analysis will expose you. It's getting harder to be truly black online.

> text content analysis The solution to that is to use memes and bad grammar. I am not kidding. Keep your messages really brief and have a community of people that talk in a very similar fashion to one-another.

I think is how the birth of leetspeak came about, no? And why still a lot of "read me" files for pirated software use poor grammar.

Another option is to use translation services, en->fr->ja->de->en. Reread message -- does it say what you mean? If yes, go for it! If not, modify as needed.

Re: VPN leaks users’ IPs via WebRTC

#37

Given that its hard to figure out how they could be profitable, should we assume private internet access is a NSA honeypot?

Seems very unlikely to me.

Both the founder (Andrew Lee) and the CEO (Ted Kim) are known in the industry, have made their views on encryption and authoritarianism pretty clear in interviews, articles, and even full-page ads in the NYT and WaPo to argue for broadband privacy[0] and encryption.

PIA also seems pretty profitable; they certainly have enough to contribute to various open source projects, join pro-net-neutrality lobbying efforts like Fight For the Future, saved the Linux Journal from death (considered an "extremist forum" by the NSA's XKeyScore), and pay to keep Freenode ticking over (they also do loads of glitzy events for the Korean-American community).

You could argue that all of this is an elaborate hoax of course, but you could do that with anything.

[0]: https://twitter.com/Hunckler/status/846204241731575808

Re: VPN leaks users’ IPs via WebRTC

#38
post #32

This has been known for a long long time, but keeps coming up in articles as a new finding.

If it's been known from a long time, then it's really unfortunate that nobody so far has bothered to contribute a fix to FF that changes its webrtc config flags correctly when a network proxy is configured.

Re: VPN leaks users’ IPs via WebRTC

#40

Given that its hard to figure out how they could be profitable, should we assume private internet access is a NSA honeypot?

I worked at a well-known civil rights advocacy nonprofit for a long time and Private Internet Access was one of our major supporters. The owner is a huge ally of Internet freedom and privacy - a very good person who is an activist in their own way and using their success to make a positive impact. So perhaps I'm biased (even though I'm not in nonprofit anymore), but I would put the chance of an NSA honeypot at close…

Krita’s 4.0 release was on here recently, which reminded me of this https://krita.org/en/item/krita-foundation-update/

PIA put up £20,000 to keep them going after a tax mixup dropped a large bill on the foundation.

Of course, it could conceivably all be government funded philanthropy to make them look like the good guys, but there’s no evidence to suggest that.

Post reply on HN