4 ms·
I wrote a non-root tethering app, so I might have a bit of tunnel vision. First, any good tethering app should be immune to a simple TTL check. The most likel
by kevko 15y ago
I wrote a non-root tethering app, so I might have a bit of tunnel vision.
First, any good tethering app should be immune to a simple TTL check. The most likely culprits are instead application traffic patterns. The following immediately come to mind:
- Browser user agents
- Automatic status checks under both OS X and Windows
- Application behavior:
* Netflix and Hulu on Android isn't supposed to happen.
* Browsers like Chrome are very aggressive and can open dozens of simultaneous TCP connections. DNS prefetching can also generate dozens of requests over UDP in a very short time window.
- zem 15y ago> First, any good tethering app should be immune to a simple TTL check. If the phone sets its TTL to 255, what can you do?
- kevko 15y agoThe goal is not to forward packets blindly like a NAT. You emulate the NAT's behavior by running a TCP state machine in user space and converting packets to regular Android SDK calls. This is what all of the non-root tethering apps likely do, because raw socket access is not allowed.
- zem 15y agoooh, i see. nice.
- Osiris 15y agoCan you avoid these issues by establishing an SSH or VPN tunnel through the 3G/4G connection?
- kevko 15y agoYep. Any non-root tethering app should just show the encrypted tunnel as a connection originating from the device itself. Just make sure that DNS requests don't leak when using an SSH tunnel. In fact, a simple port-forwarding app is all that's really necessary for most tunnel cases. All of this makes a $6-$8/mo SSH/VPN privacy service (e.g., cotse.net) rather intriguing.
- rasengan 15y agoMost properly configured VPN service providers will reroute any DNS request traffic to their private NS servers (e.g., privateinternetaccess.com). Another thing I'd like to mention is MPPE is not functioning in most Android builds, so don't rely on PPTP based VPNs on your phone - encryption won't work! Make sure your VPN service provider has IPSec/L2TP tunneling available. Obviously root users should opt for OpenVPN. (e.g., cyanogenmod 7+)