4 ms·
So the problem is that, e.g., DNS isn't also queried over a VPN, so the sites you're looking at will still be 100% visible to anyone watching your network strea
by SomeCallMeTim 10y ago
So the problem is that, e.g., DNS isn't also queried over a VPN, so the sites you're looking at will still be 100% visible to anyone watching your network stream?
Or is the problem just that they're using the wrong terminology?
- bwat48 10y agopeople are complaining about the terminology they're using, because it only effects Opera and not other applications, even though that was completely obvious from the start. They clarify it here: https://www.opera.com/blogs/news/2016/04/opera-doubling-server-capacity-vpn/ https://www.opera.com/blogs/news/2016/04/opera-doubling-serv... "Our VPN feature is still in development. We are currently working hard to implement support for proxying even more of the browser traffic, including WebRTC and plug-ins. Having this functionality built into the browser, instead of as an extension, allows us to catch more situations, such as certificate revocation checks made by the system. Yes, the VPN feature is free, and we do not plan to charge for it. Our VPN is something we call a browser VPN. Under the hood it works by routing all the browser traffic properly encrypted via our secure proxies in various parts of the world. It will not route the traffic from other applications – as a system wide VPN would do – it’s a browser VPN after all."
- davb 10y agoWhich is actually a really interesting idea. Network interface level VPNs are great in certain situations. For instance, when using untrusted WiFi networks I'll connect to my VPS VPN hosted in the US or my UK RasPI VPN. But when I want to circumvent a geo-block to watch some sports on Al Jazeera Sport (now BeIn Sport), I don't want all of my traffic going through the public VPN provider in Saudia Arabia. I don't really trust public VPN providers. Normally I'd run a dedicated local VM which I'd connect to a public VM just to watch geo-blocked streaming media. Proxies, though. Per-application proxies. Or even better - per tab/window/browser profile proxies. This would solve my problem more elegantly.
- delroth 10y agoOn Linux I configure a network namespace that routes everything through my VPN, and I run a separate Chrome profile within that namespace (or whatever else I want to run and route through the VPN). http://pastie.org/private/fzx7btxmvxbnftgkx31k8g http://pastie.org/private/fzx7btxmvxbnftgkx31k8g is what I use as openvpn up/down script. Feel free to study/reuse.
- betaby 10y agoYou create that namespace under root? What next? You run nsenter NNNN and su - $username -c chromium? It's still able to communicate with Xorg thereafter?
- delroth 10y agoIndeed, something like "sudo ip netns exec myvpn sudo -u delroth -- google-chrome-stable --user-data-dir=~/.config/myvpn-google-chrome"
- gz5 10y agoYes, and app-specific VPNs too. So a SaaS app with embedded VPN in order to achieve certain security, quality or visibility goals between user network and their first cloud hop. Each app VPN using a virtual IP?
- pt 10y agoI am actually working on build something similar. So, you could roll out an app-specific VPN like secure tunnel real easy. It is inspired by the work at Google IT called BeyondCorp [1]. The target market is companies whose employees require secure remote access to internal apps, but IT does not want to give a broad network access via VPN. So, marketing/sales like employees who simply want to access internal portals, etc. without the hassle of dialing into a VPN. [1] http://research.google.com/pubs/archive/43231.pdf http://research.google.com/pubs/archive/43231.pdf
- homero 10y ago
- betaby 10y agoYes, it's an https proxy. And DNS queries are not leaked. Again since it's a HTTPS proxy your traffic is hard to inspect/intercept/MITM. Earlier discussion https://news.ycombinator.com/item?id=11540389 https://news.ycombinator.com/item?id=11540389
- danielparks 10y ago> DNS queries are not leaked. I imagine that you mean the proxy takes care of resolving hosts. For example, requesting https://google.com https://google.com doesn't resolve google.com. on the client, rather it sends a request for https://google.com https://google.com to the proxy server and the proxy server resolves google.com. Attacking the DNS lookup for the proxy itself won't work because the attacker would need the SSL certificate for the proxy. Hopefully Opera has pinned that certificate (or better, its signer), which prevents a rogue CA attack.
- tyingq 10y agoIt does leak via WebRTC unless you install a 3rd party plugin and configure it a specific way.