15 ms·
VPN leaks users’ IPs via WebRTC
- cosmiccartel 9y agoJust want to point anyone looking to test their own VPN to https://ipleak.net/ https://ipleak.net/. That's been my go-to, and it seems more comprehensive than the linked service.
- tobltobs 9y agoOr try https://www.doileak.com https://www.doileak.com . (Shameless plug of of a project of mine)
- zaroth 9y agoNice project - but that name.... Sounds like a bad medical condition!
- degenerate 9y agoTo me it sounds like a LibGen/Sci-Hub type website, playing off the idea of leaking papers with DOI numbers: https://www.doi.org/ https://www.doi.org/
- progval 9y ago> WebRTC IP Leak: Your local IP: 10.41.41.2 . > Your browser supports WebRTC! Your real IP address is visible to every website you visit. > > Web Real-Time Communication (WebRTC) is enabled by default in Firefox, Opera and Google Chrome, and enables video chat, voice calling and P2P sharing from within your browser. > A neat trick, but it allows any website to instantly see your true IP address. The only way to avoid sharing your IP address this way is to disable WebRTC completely. Nope, that's not my "real" IP address
- userbinator 9y agoNope, that's not my "real" IP address Reminds me a bit of this old story: http://sirkan.iit.bme.hu/~kapolnai/fun/bitchecker.html http://sirkan.iit.bme.hu/~kapolnai/fun/bitchecker.html
- krylon 9y agoFWIW, the link did not work for me, but archive.org has a copy. It was hysterical!!! :)
- progval 9y ago> Timezone Difference: The time zone of your browser is while your request IP location timezone is Europe/Paris. Looks like there is a word missing.
- balupton 9y agoSeems my setup has me covered: https://www.doileak.com/?cb=liq1xtjsp37zvit5 https://www.doileak.com/?cb=liq1xtjsp37zvit5 Actual location is Kuala Lumpur, which was caught by the time zone... So need to look into fixing that. For those wondering, my setup is: ProtonVPN via the ProtonVPN Mac Beta (before I used Tunnelblick - which actually was more reliable - the ProtonVPN Mac Beta disconnects often) AdGuard Pro, with DNSCrypt using the Adguard Family servers: https://gist.github.com/balupton/48057270a67d70e2ac984fdfa475ad29 https://gist.github.com/balupton/48057270a67d70e2ac984fdfa47... Safari. With Camera, Microphone, Location, and Notifications all set as deny by default.
- jgalt212 9y agoFWIW, I show that Opera's free VPN does not leak the client's IP address. https://www.opera.com/computer/features/free-vpn https://www.opera.com/computer/features/free-vpn
- herbst 9y agoOperas VPN is not even a VPN tho. Check their phrasing they call it 'Web vpn' or something like this and already committed in the past that the naming scheme for their proxy was just a marketing trick. Written from Opera tho. So not saying it sucks :)
- cpeterso 9y agoYou can test WebRTC IP address (and media device id) leakage using https://browserleaks.com/webrtc https://browserleaks.com/webrtc. To disable WebRTC in Firefox, set the about:config prefs "media.peerconnection.enabled" and "media.navigator.enabled" to false.
- anfilt 9y agoMore like this: media.peerconnection.turn.disable = true media.peerconnection.use_document_iceservers = false media.peerconnection.video.enabled = false media.peerconnection.video.vp9_enabled = false media.peerconnection.video.h264_enabled = false media.peerconnection.identity.enabled = false media.peerconnection.identity.timeout = 1
- ta34662211 9y agoI need to find a way to automate the patching of Firefox's about:config when installing a new OS etc, quite a few telemetry/storage/WebRTC tweaks to date now. There is an extension [1] that'll at least disable the IP address gathering (it doesn't look to disable all of the above settings but may have a similar effect if browser.privacy.network.peerConnectionEnabled disables everything): [1] https://github.com/ChrisAntaki/disable-webrtc-firefox https://github.com/ChrisAntaki/disable-webrtc-firefox
- anfilt 9y agoThe simplest level would to add what settings you want to Prefs.js file. http://kb.mozillazine.org/Prefs.js_file http://kb.mozillazine.org/Prefs.js_file If you want the preferences locked the application level and not be overridden or be unchangeable at profile level. Mainly important if you are managing a lot systems. http://kb.mozillazine.org/Locking_preferences http://kb.mozillazine.org/Locking_preferences
- UnrealIncident 9y agoLook into vendor.js for patching about:config. I know Arch has one for sure in their package.
- bringtheaction 9y ago> To detect data from your torrent client we provide a magnet link to a fake file. The magnet contains an http url of a controlled by us tracker which archives the information coming from the torrent client. That’s pretty clever. Alternatively they could have a unique file of garbage and have some seeders for it and then when someone connects it would also be the same person. But the tracker solution is less work and probably almost entirely as good.
- deleted 9y ago[deleted]
- Digital-Citizen 9y agoAnd it needlessly requires Javascript to do things other services don't need Javascript to do. That's not a good plan. One's IP address should be detectable to at least some degree with data from the packets making the request for the webpage. Some of this is remedied with what appears to be duplicative information further down the page. DNS Address detection is done better by https://dnsleaktest.com/ https://dnsleaktest.com/. Geolocation detection is likely done by looking up what geolocation is paired with one's IP (and sometimes this data is wrong), so there's no real need for Javascript here either. It's not as if the requesting computer should supply this information, else it becomes even more easily spoofed. Some of this is remedied with what appears to be duplicative information further down the page. Torrent detection is also needlessly JS-driven, and done better at http://dev.cbcdn.com/ipmagnet/ http://dev.cbcdn.com/ipmagnet/. There are also some grammar errors confusing singular and plural in the text at the bottom of the page.
- zorkw4rg 9y agoClickbait? Its not "VPN providers" its "VPN provider software", I never even thought of using their software, most just give you the credentials for OpenVPN/IPSEC/PPTP or similar. Also if anonymity is of "real" concern you should never use a system that knows your real IP address in the first place. Instead create the vpn tunnel on a separate host system and run something like Tails in a VM (or better yet separate physical hardware).
- 3pt14159 9y agoThat tunnel won't help against real adversaries. Timing attacks and text content analysis will expose you. It's getting harder to be truly black online.
- bringtheaction 9y ago> text content analysis The solution to that is to use memes and bad grammar. I am not kidding. Keep your messages really brief and have a community of people that talk in a very similar fashion to one-another.
- pen2l 9y agoI think is how the birth of leetspeak came about, no? And why still a lot of "read me" files for pirated software use poor grammar. Another option is to use translation services, en->fr->ja->de->en. Reread message -- does it say what you mean? If yes, go for it! If not, modify as needed.
- kardos 9y agoSurely you mean an offline translation program, and not an online translation service like google's translator...
- solarkraft 9y agoOh, Google translate can mess up. There are also intentionally bad translators like https://lingojam.com/BadTranslator https://lingojam.com/BadTranslator
- ensignro2340 9y agoAnyone interested in setting up their own VPN should check out Algo: https://github.com/trailofbits/algo https://github.com/trailofbits/algo
- hyperpower 9y agoWhat's the advantage of this over OpenVPN?
- jakebasile 9y agoIt's natively supported by more operating systems. Namely, macOS and iOS. Also generates mobileprofile files that you can AirDrop to your device and have it set up in an instant.
- armitron 9y agoOn the flipside, it introduces monstrous dependency (strongSwan) written in memory unsafe C, is nowhere near as flexible as OpenVPN and is blocked by many networks since it can't operate over arbitrary ports and forces you to manage/own the server-end. 1) If I wanted to do that, I'd use OpenVPN rather than strongSwan. They're both written in C, but I get extra flexibility by using OpenVPN. Their "TLS is suspect" stance doesn't hold water in my view. 2) When I don't want to set up my own server, OpenVPN allows me to use or even chain lots of third party servers and create my own nested VPN topologies. Installing an OpenVPN client on my phone or tablet takes a few minutes. So, to summarize, Algo would be interesting if it didn't introduce dependency on memory unsafe code or minimized such dependency. But it doesn't. On the client, I do not see why I should trust Apple's IPSEC implementation (racoon?) more than OpenVPN client which is another point they tried to make. As it currently stands, it does not compare favorably to OpenVPN in any way.
- superkuh 9y agoOr reconsider the need for a VPN at all. By using a VPN you cut yourself off from participating as an equal citizen on the net. If it's just for browsing the web, irc, or the like it's much easier and better just to use a socks 5 proxy to a cheap VPS. I like shadowsocks-libev. But then again I don't use popular browsers that cram in fancy new features every week to expose new leaks and attack surfaces.
- deleted 9y ago[deleted]
- MaupitiBlue 9y agoGiven that its hard to figure out how they could be profitable, should we assume private internet access is a NSA honeypot?
- lima 9y agoBandwidth is cheap, massive overcommitment. Why wouldn't it be profitable?
- protonimitate 9y agoI don't understand this. Is profitability the only metric for if a service can be trusted or not? It's also not even mentioned in the article linked, not sure why you brought it up at all tbh.
- jaxn 9y agoProfitability (or the possibility of profitability) is absolutely a measure of whether something can be relied on. And if it can't possibly be profitable, then it means there is likely a non-obvious revenue stream or funding source, which means a ulterior motive. So yeah, if a service can't be profitable, it can't be trusted.
- OrganicMSG 9y agoA decent emergency medical response service is never profitable. It requires a vast amount of hospitals to ensure that there is one local enough to wherever you get ill or injured and they all have to be staffed by lots of different highly qualified specialists who are in as regular practice as possible. If you were going to require that they be profitable, there simply are not enough rich people for the doctors to work on in order to stay in good practice, or to pay for enough suitably equipped hospitals to ensure a short travel time in an emergency.
- CamTin 9y agoIn the US, we essentially do require that they all be profitable or else not exist at all. This is "solved" by just charging you (or your insurance company) tons of money if you actually need to use it. A medical emergency requiring an ER and an ambulance can easily cost as much or more than an ordinary person will earn in their whole lifetime.
- piracykills 9y agoWould enabling this uBlock option not be perfectly sufficient at preventing this attack? https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-leaking-local-IP-address https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-l...
- ryuuchin 9y agoIt should unless this is something new? I'm not sure why this is really news. We've known about this problem with WebRTC for quite some time now.
- voidsec 9y agoQuite funny, I've published this yesterday and went unnoticed until now, lol
- BlueGh0st 9y agoI was surprised it didn't tell me it was posted here before. I found the post and your comments on it over at /netsec. Really appreciate your work on this!
- en4bz 9y agoAnother thing to watch out for is leaking IPv6 connections. Depending on your configuration your VPN may not set the IPv6 default gateway.
- lovelearning 9y agoI don't use VPNs. For me, the more alarming information here is that SOCKS and Tor proxies are also leaking IP addresses. If a SOCKS proxy is configured in browser, isn't it the browser's responsibility to ensure all outgoing traffic - including WebRTC - goes via the proxy? Are these browser bugs? Update: Can confirm Firefox Quantum with SOCKS proxy leaks the address. Oh dear! Update 2: I didn't realize this is how WebRTC actually works. FF even has an entire page for tweaking this stuff https://wiki.mozilla.org/Media/WebRTC/Privacy https://wiki.mozilla.org/Media/WebRTC/Privacy. I hate it when features like these, which atleast in my case go mostly unused, have such critical weaknesses by design and it's not announced anywhere with a big red danger sign.
- confounded 9y ago> I didn't realize this is how WebRTC actually works. Yep. STUN is in the spec, and always has been. This has been a thing for years.
- scottlu2 9y agoSTUN is part of the story. The overall process is called Interactive Connectivity Establishment (ICE).
- confounded 9y agoTIL, thank you!
- blattimwind 9y agohttps://www.privacytools.io/#webrtc https://www.privacytools.io/#webrtc
- lovelearning 9y agoThank you for that site. Looks like I have to become more aware of browser internals.
- 9y ago
- jwilk 9y agoIt's 503 for me. Here's an archived copy: https://archive.is/XHX74 https://archive.is/XHX74
- aviv 9y agoThis has been known for a long long time, but keeps coming up in articles as a new finding.
- lovelearning 9y agoIf it's been known from a long time, then it's really unfortunate that nobody so far has bothered to contribute a fix to FF that changes its webrtc config flags correctly when a network proxy is configured.
- ryuuchin 9y agouBlock Origin has an option to do it[1]. [1] https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-leaking-local-IP-address https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-l...
- lovelearning 9y agoNever used it before but will do so now, Thank you!
- Thaxll 9y agoUse the VPN on your gateway / router, problem solved.
- smaili 9y agoComplete list of tested browsers and VPN providers: https://docs.google.com/spreadsheets/d/1Nm7mxfFvmdn-3Az-BtE5O0BIdbJiIAWUnkoAF_v_0ug/edit#gid=0 https://docs.google.com/spreadsheets/d/1Nm7mxfFvmdn-3Az-BtE5...
- fwdpropaganda 9y agoVPN isn't leaking anything, your browser is. A) Don't run javascript B) Config your firewall to block everything except connection to the VPN entry point.
- mtve 9y agojust for the record, "B" option is not helping here.
- smsm42 9y agoMy VPN provider is listed as "vulnerable" but testing with their test site does not show IP leak...
- voidsec 9y agoWhich one?
- CydeWeys 9y agoI don't have a need for this high level of security, but if I did, here's what I'd do: 1. Run VPN software on host. 2. Download a widely used, generic VM image. 3. Route VM's entire network connection through host's VPN. 4. Do whatever you need to do, in the VM only. 5. Reset VM to initial settings after each use. Am I missing anything?
- Froyoh 9y agoAhhh why is the scrolling messed up :/
- blunte 9y agoI did find a bit of irony that the page warning about VPNs leaking my IP was hijacking my scrolling.
- IronBacon 9y agoI think I've started reading suggestions to disable WebRTC at least a couple of years ago in regards to avoid VPN detection from Netflix, so I thought it was a common knowledge.
- LinuxBender 9y agoThis is a terminology problem. If you are using a VPN, a browser could not possibly leak your real IP, as all traffic would be encapsulated by the VPN. What is being described is actually a proxy.
- andoma 9y agoFWIW, Safari does not include your local IP address in the list of candidate addresses for WebRTC until you also authorize the page to access your camera.
- joering2 9y agoI'm suprised to see NordVPN is leaking. I see commercials everywhere all the time and its #1 or #2 on most VPN reviews websites. I was very tempted to switch, especially when they routers' Firmware is available for the newest/coolest routers out there; but kind of got used to ExpressVPN over the years, so went with them and their firmware for NETGEAR Nighthawk R7000 is very easy to use. Glad to see ExpressVPN is not leaking and I continue not to find any bad news about them (versus HideMyAss for example LOL)
- jlgaddis 9y ago> I see commercials everywhere all the time ... That's because of their marketing budget. > ... and its #1 or #2 on most VPN reviews websites. That's because of their affiliate programs.
- silent_comedy 9y agoNordVPN does not leak. Long time user. Simple test after acquiring free three day trial would be enough to clear any doubt, however people just love to speculate
- pasbesoin 9y agoOne reason I don't want my browser to become a fucking operating system. We already have Emacs for that. ;-)
- qwaitwhat 9y agoFWIW, various arbitrarily strung together components (your OS, DNS, VPN, Browser, WebRTC) are not going to guarantee anonymity. Simply because it is not their job. The only possible solution is a piece of software that guarantees end-to-end privacy by literally standing guard at each end (from the moment you connect to your network with your hardware MAC address exposed to the final moment when a web page is retrieved for you from your destiantion website). Shameless plug: my project proposes to do exactly this. https://qwaitwhat.github.io/ https://qwaitwhat.github.io/
- codedokode 9y agoIt seems that main purpose of WebRTC was disclosing user's IP addresses. By the way, did you know that Websocket can be used for port scanning [1]? I was surprised to find that Aliexpress code scans 127.0.0.1 (visitor's computer) for VNC, RDP and similar ports. [1] https://datatracker.ietf.org/meeting/96/materials/slides-96-saag-1/ https://datatracker.ietf.org/meeting/96/materials/slides-96-...
- dillondoyle 9y agoI think it's a bit crazy Chrome web tools/inspector doesn't show these connections easily. You can check out chrome://webrtc-internals but most people just look at the network tab which shows nothing...
- anfilt 9y agoFor firefox the following in about:config should do the trick. media.peerconnection.turn.disable = true media.peerconnection.use_document_iceservers = false media.peerconnection.video.enabled = false media.peerconnection.video.vp9_enabled = false media.peerconnection.video.h264_enabled = false media.peerconnection.identity.enabled = false media.peerconnection.identity.timeout = 1
- godzillabrennus 9y agoJust tested this with http://www.ExpressVPN.com http://www.ExpressVPN.com client on MacOS and it protected my IPv4 Public IP from being exposed but it does leak the local (NAT) IPv4 Private IP that I use on my internal network. Not good that it leaked anything but at least the public IP is hidden by their software.
- fuj 9y agoInstalling their chrome extension will hide all ips
- brink 9y agoLooks like this Chrome plugin allows you to turn on / off WebRTC and fixes the leak. https://chrome.google.com/webstore/detail/webrtc-control/fjkmabmdepjfammlpliljpnbhleegehm?hl=en https://chrome.google.com/webstore/detail/webrtc-control/fjk...
- _jomo 9y agoWhile this has long been known, I was never able to actually reproduce this and I'm not sure how it's technically even supposed to work. Assuming we're using IPv4, the default gateway is a VPN and the machine is behind a NAT: Any outside service (e.g. STUN server) would see the VPN's IP address. How would the browser even technically be able to know the public (i.e. the NAT's) IP address? However, the WebExtensions API allows tweaking this via the webRTCIPHandlingPolicy to only reveal the public "interface" IP address. FWIW, I'm always connected to a VPN and I have configured my macOS [0] and Android [1] firewalls to drop any connection other than the VPN's. 0: Wrote it down here: https://jomo.tv/security/pf-prevent-traffic-bypassing-vpn https://jomo.tv/security/pf-prevent-traffic-bypassing-vpn 1: Quite self-explaining: https://f-droid.org/packages/dev.ukanth.ufirewall/ https://f-droid.org/packages/dev.ukanth.ufirewall/
- yorby 9y agoMaybe the browser should not have access to your real IP when you are using a VPN? so it's the OS's fault?
- chime 9y agoIf you use computer/phone-based VPN, try https://www.dnsleaktest.com/ https://www.dnsleaktest.com/ or http://dnsleak.com/ http://dnsleak.com/ I have VPN on my home router with Tomato firmware. All of my devices pass this flawlessly.
- amenghra 9y agoI authored http://jsfiddle.net/alokmenghrajani/0qo4kq7x/ http://jsfiddle.net/alokmenghrajani/0qo4kq7x/ over 3 years ago...
- revanx_ 9y agothis is old news tho, I was aware of this for ages. If you check privacy websites thats one of the first thing they say, turn off webRTC in your browser.
- _o_ 9y agoHeh, this webrtc story is at least few years old and everyone privacy / security aware is blocking it. For testing webrtc and other leaks including fingerprinting rather use https://browserleaks.com/ https://browserleaks.com/ (and it is unable to capture any exposing data for my browsers on any of my devices)
- qwerty456127 9y agoBTW I think I would love a "VPN" (the term itself is misused massively, oftentimes it is just a proxy) accessed via WebRTC so it would be harder for the men in the middle to tell whether I am using a "VPN" or just calling somebody. Perhaps people in countries like China could make great use of such a thing too.
- yAnonymous 9y agoEvery browser should have settings to disable WebRTC and it should arguably be disabled by default. It can be very useful, but can also cause a lot of problems.
- mido22 9y agoPlease stop using clickbaity titles, first line that I saw in the post "I’ve tested seventy VPN providers and 16 of them leaks users’ IPs via WebRTC" So, more appropriate title would have been "23% of VPN providers leak user IP" :)