Live data from Hacker News

“We are considering adding an extension to restrict the use of WebRTC”

bugzilla.mozilla.org

71–80 of 159 posts

Re: “We are considering adding an extension to restrict the use of WebRTC”

#71
post #13

Earlier quoted context omitted.

So we're willing to destroy the web's big shot at peer-to-peer networking out of concern that this adds one more data point for fingerprinting, out of dozens? Let's keep the big picture in mind here, people. Peer-to-peer networking is the web's big chance to weaken these huge personal data-scarfing companies. Please let's not kill it while it's just starting to grow.

The web isn't peer to peer. Why would I want a web browser to do peer to peer? Its a web browser!

some people seem to mistake browsers for an operating system.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#72
post #62

Earlier quoted context omitted.

In many European countries they can. They set up honey pots, log everything and then send costly C&Ds to thousands of people. Courts usually believe their "proof", no matter how bad it is. It's probably a billion dollar business by now.

Citation please.

Nothing to do with WebRTC but it's (allegedly) a tactic that has been used by a US-based LLC known as Prenda via torrents:

http://arstechnica.com/tech-policy/2013/06/pirate-bay-data-s...

Earlier this week, Prenda faced a new and serious allegation: that it had actually put some pornography on BitTorrent itself, intending for it to be downloaded so that it could start a campaign of lawsuits and threat letters.

The Pirate Bay gave the data to TorrentFreak, which says that the IP address 75.72.88.156, which uploaded some porn files that Prenda has litigated over, "was previously used by someone with access to John Steele’s GoDaddy account."

http://arstechnica.com/tech-policy/2015/07/pirate-bay-founde...

Re: “We are considering adding an extension to restrict the use of WebRTC”

#73
post #57

What the fuck, this leaked your real IP behind VPN since January 2014 and this isn't fixed yet? This sure looks like a Heartbleed-tier high-priority security hole to me. How is this not bigger news?

They leak the internal IP assigned to you by a VPN, which is not the same IP as the one seen by the websites you browse, nor is it the same as the IP assigned to you by your ISP.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#74

Earlier quoted context omitted.

It is a technical requirement, because the protocol attempts to connect over the local network if both peers are under the same NAT. The local IP is shared so that the peers can attempt to make a local connection.

I'd assume that this is a rather rare usecase in the world wide web, so why is it not disabled by default?

No, it's not rare. This is something all peer-to-peer networks running over IPv4 must do. WebRTC video, audio, or data wouldn't work without this.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#75
post #57

What the fuck, this leaked your real IP behind VPN since January 2014 and this isn't fixed yet? This sure looks like a Heartbleed-tier high-priority security hole to me. How is this not bigger news?

Leaking a client IP address is not even near the same universe of severity as remotely obtaining a web servers private TLS key. Given the lack of perfect forward secrecy used by web servers at the time, Heartbleed was a "read any encrypted traffic sent by the server, ever" issue.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#76
post #66

Earlier quoted context omitted.

And by "exactly that purpose" you mean preventing ad fraud [1], right? They weren't using WebRTC to put you in a "VPN user" advertising segment. 1. https://www.reddit.com/r/netsec/comments/3dgwee/how_the_new_...

[deleted]

[deleted]

Re: “We are considering adding an extension to restrict the use of WebRTC”

#77
post #66

Earlier quoted context omitted.

And by "exactly that purpose" you mean preventing ad fraud [1], right? They weren't using WebRTC to put you in a "VPN user" advertising segment. 1. https://www.reddit.com/r/netsec/comments/3dgwee/how_the_new_...

[deleted]

> a random guy on the internet says something and you think it is true?

Yes, if they identify themselves and their company and what they say aligns with my personal experience.

> You don't have the foggiest idea what they are really doing with the data. All we know is that they are collecting the data without user's consent.

You never have any absolute certainty what anyone does with your data - all you have are hypotheses and probabilities. Who are "they" and what do you think they are doing?

If adtech companies cared whether you're behind a VPN, they would make or buy a list of IP's that are provide VPN services and match that list. That's a ton easier than implementing a STUN server that scales to handle traffic from every single person who views one of their ads.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#78
Does anyone else feel that there's something terribly odd going on when restricting something needs to be an extension?

IMHO it should be a configuration option, per-site, and off by default. WebRTC also isn't the only thing that applies to.

Re: “We are considering adding an extension to restrict the use of WebRTC”

#79

Earlier quoted context omitted.

And by "exactly that purpose" you mean preventing ad fraud [1], right? They weren't using WebRTC to put you in a "VPN user" advertising segment. 1. https://www.reddit.com/r/netsec/comments/3dgwee/how_the_new_...

Doesn't matter. Privacy is not about right or wrong, it is about privacy.

Privacy is not an absolute to be maximized at all costs. Do you have blacked out windows, or do you concede that the practical day-to-day infringement of your privacy is so minuscule and so easily mitigated by window shades that it's not worth the trade-off?

Re: “We are considering adding an extension to restrict the use of WebRTC”

#80
post #57

What the fuck, this leaked your real IP behind VPN since January 2014 and this isn't fixed yet? This sure looks like a Heartbleed-tier high-priority security hole to me. How is this not bigger news?

Approximately nobody outside the tech industry uses VPNs to hide their real IPs (the number of people using VPNs, period, is relatively tiny compared to the overall population of the internet); approximately everybody who uses the internet uses HTTPS.
Post reply on HN