9 ms·
Chromium based browsers leak user local IP via WebRTC foundation attribute
- Semaphor 4y agoWhat’s the issue there? How is knowing the local IP a security issue? And FWIW, the local IP does not get leaked when using a VPN. (edit: Or rather, the VPN local IP gets leaked. Same question, no idea if that’s security relevant in some way?) edit: Thanks everyone, I completely forgot about fingerprinting.
- proszkinasenne2 4y agoIt's both security and privacy issue. Whonix wiki explains the latter in more detail https://www.whonix.org/wiki/Data_Collection_Techniques#:~:text=WebRTC%20local%20IP%20discovery https://www.whonix.org/wiki/Data_Collection_Techniques#:~:te...
- Semaphor 4y agoIf you use Chrome-exclusive links, please at least also link to the closest standard section [0] and preferably, mention the Chrome-linked text directly. That said, they don't say anything about security, I obviously forgot about fingerprinting, but still don’t see security issues? [0] https://www.whonix.org/wiki/Data_Collection_Techniques#Fingerprinting_Techniques https://www.whonix.org/wiki/Data_Collection_Techniques#Finge...
- Etheryte 4y agoLeaking any kind of data is yet another data point for fingerprinting. You only need a few to uniquely identify a user.
- scratcheee 4y agoI've yet to see a normally configured browser _not_ be uniquely identifiable many times over through fingerprinting. At some point it feels like trying to drain the ocean with a cup. Maybe we just need to accept that anyone who really wants to fingerprint you _can_ fingerprint you unless you use a specialist browser. At that point the solution is fairly obvious, make it legally difficult to use unique fingerprinting and move on (ie stuff like gdpr). People will still do it, but they'll have to balance it with not falling foul of the law and wont be able to abuse it too much. We wont stop real world facial recognition by all trying to make our faces more similar either, we have to accept it's generally possible to do, but discourage the actual doing of it rather than trying to make it impossible. (note in both cases, actually preventing it when you have a reason to is totally possible and valid, via specialist browser modes and physical masks respectively)
- Semaphor 4y agoI just tried a clean FF profile with resistFingerprinting enabled. No dice. Everything adds only very few bits of identifying information (unlike my main profile which is already almost unique thanks to the accept header (English, then German)) yet it still results in 17.75 bits which according to EFF is unique. I’m agreeing with you, though I wonder, is there any way to not be unique? What would you have to do? Use Windows with no extra fonts, Chrome in English, on a FullHD monitor with webgl/canvas/audio fingerprinting protection extensions?
- hdjjhhvvhga 4y agoI believe the only feasible way without bending over backwards is to use the Tor Browser. But privacy and security always come at a price.
- Semaphor 4y agoActually, resistFingerprinting + switching to the user-agent string tor uses gets me 99% of the way there. All that’s missing is the weird window size (vertical taskbar), if I could get that to report a default size, I’d actually be better than Tor (they have a bunch of responses slightly more unique than FF with resistFingerprinting). But it’s academic for me anyway, I have Accept-Language en-US,en;q=0.7,de-DE;q=0.3 which is close enough to unique that nothing else really matters.
- CommitSyn 4y ago> All that’s missing is the weird window size (vertical taskbar) TBB actually adds a border at the bottom of the browser so the reported size isn't the actual size. If you change the size of your browser window to the tor-reported size then it should work. Unless I'm misunderstanding and you mean something to do with the scrollbar?
- codedokode 4y agoI think a HTML-only browser without support for CSS and JS might help.
- megous 4y agoYeah. All that's needed is to leak link-local IPv6 address from a single interface. There's your unique commputer identifier, unless someone's using mac randomization.
- rollcat 4y ago> How is knowing the local IP a security issue? It's a privacy issue. You can use it to fingerprint a user, local IP will give you quite many bits of entropy. <https://coveryourtracks.eff.org/ https://coveryourtracks.eff.org/> Honestly I'm not even sure if I'm surprised, but it's 2022 and we've been having this problem basically since the day WebRTC was introduced. At this point, if you care about privacy, you should probably put it in the same bag as third-party cookies and just block it entirely.
- Semaphor 4y agoWell, the big non-adtech browser is not vulnerable, so there’s that.
- amenghra 4y agohttps://bugzilla.mozilla.org/show_bug.cgi?id=959893 https://bugzilla.mozilla.org/show_bug.cgi?id=959893 is a fun read... Firefox used to also leak the internal IP circa 2015.
- codedokode 4y agoYes it is interesting how developers race to push new features allowing deanonimization of VPN users and better fingerprinting. There is also WebGL whose main purpose is to provide user's videocard model to advertising companies and governemnt institutions.
- MomoXenosaga 4y agoIf memory serves Ublock origin does just that.
- Semaphor 4y agoNot anymore on Desktop: https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-leaking-local-IP-address https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-l...
- 4y ago
- tyingq 4y agoHave a look at this that scans your local network: http://samy.pl/webscan/ http://samy.pl/webscan/ I think some browser changes might have hobbled it a bit, but it was startling when I first tried it.
- Semaphor 4y agoA bit? The site claims it found a host on literally every single private IP that exists ;) And closing it nearly killed my FF (full freeze for ~10 seconds).
- iosjunkie 4y agoOTOH, using Mobile Safari, this site leaked my device’s IP as well as a number of connected devices on my internal network. Anyone know an easy fix for this?
- CommitSyn 4y agoIf so, I'd love to hear it. As far as I know all iOS browsers are forced to use the same rendering engine, and I suspect there's no way to modify that.
- Gualdrapo 4y agoI seem to recall Fallon (based on Chromium) has a feature which disables that.
- panny 4y agoYou appear to be correct. I just tried the test on Falkon and it failed. But since not many poeple use Falkon regularly... maybe that's a fingerprint all by itself.
- Semaphor 4y ago> But since not many poeple use Falkon regularly... maybe that's a fingerprint all by itself. You can check here: https://coveryourtracks.eff.org https://coveryourtracks.eff.org
- Scharkenberg 4y agoI am using Microsoft Edge and the test on the linked page times out without detecting anything. Perhaps it is because I've enabled the "Anonymize local IPs exposed by WebRTC" flag.
- plaguepilled 4y agoWhat does "Used 0 keys for lookups" mean?
- prettyStandard 4y agoFrom what I can tell it is taking the local IP it finds and then looking it up in a database. If it doesn't find any IPs then it reports used 0 keys for lookup. So in this case it means you're not vulnerable.
- jackewiehose 4y agoHow to disable WebRTC on Firefox Mobile? I have uBlock which prevents from leaking the local IP but I don't want WebRTC at all. Why did they take about:config from us?
- lelandfe 4y agoDamned if you do, damned if you don’t. Disabling WebRTC would make your Firefox instance extremely unique and thus easily fingerprinted.
- jackewiehose 4y agoYes, but as far as I understand, the fight against fingerprinting is lost anyway. Having WebRTC enabled can be dangerous for other reasons. You could be seeding a torrent unknowingly just by visiting a website. This can turn into a freaking disaster if you live in country like Germany. It's a shame that browsers don't ask you for WebRTC like they do with webcams.
- jackewiehose 4y agoWas I wrong about the torrent stuff or did the downvotes come from web-developers who want WebRTC to be always available by default?
- Dylan16807 4y agoWell for one a website can make you secretly upload copyrighted content with plain old javascript. And it's going to be hard to hold you liable for data uploads that someone else initiated and you didn't know about.
- jackewiehose 4y ago> Well for one a website can make you secretly upload copyrighted content with plain old javascript Only to a webserver and thanks to CORS not to any webserver. There is no benefit for a website doing that - unlike with sharing a torrent to other internet users. The problem with torrents is that they are actively watched by "Abmahnanwälte" (lawyers who make a living by suing copyright offenders). > And it's going to be hard to hold you liable for data uploads that someone else initiated and you didn't know about yeah good luck with that. All they see is your IP and then you can try to explain how this happened and how you are totally innocent.
- Eisenstein 4y agoThis can be disabled in Brave by turning "WebRTC IP handling policy" to "Disable non-Proxied UDP" in "settings - > Privacy and Security".
- RadixDLT 4y agoperfect
- x-complexity 4y ago> This can be disabled in Brave by turning "WebRTC IP handling policy" to "Disable non-Proxied UDP" Not advised if you want to use WebTorrent, since it relies on WebRTC. Setting it to "Default public interface only" still allows WebTorrent & WebRTC-reliant tools to be used, whilst still only broadcasting your public IP (which is already known anyway).
- proszkinasenne2 4y agoIn Chrome/Chromium there is a WebRTC Network Limiter [1] extension that let you set "Use only my default public IP address" policy and render the method I presented ineffective. [1] https://chrome.google.com/webstore/detail/webrtc-network-limiter/npeicpdbkakmehahjeeohfdhnlpdklia https://chrome.google.com/webstore/detail/webrtc-network-lim...
- p1mrx 4y agoGoogle abandoned that extension in 2016, which is why the last option (for disable_non_proxied_udp) is greyed out.
- jovial_cavalier 4y agoIt gets "leaked" to a web app that I'm choosing to connect to? Why do I care?
- bearjaws 4y agoYeah we don't need privacy, especially to third party extensions loaded by sites, we should just set our user agent to our full name, address and phone number.
- RuggedPineapple 4y agoI know you said this as a joke, but I think you underestimate the convenience draw of that. Already if I have to sign up for something on not-my-primary-computer I'm annoyed because I can't use the Chrome autofill to take care of entering my address/phone/credit card details. For a large number of people the privacy concerns take a definite backseat to seamless and quick experiences and there isn't anything wrong with making that value judgement.
- jovial_cavalier 4y agoYour full name is not the same as your local IP. Since your NAT subnet is almost always /24, there really are only 256 local IP addresses. Which one you happen to be using at the time is not really important. There are 10,000 other things about your browser that could be used to uniquely identify you. This is a feature of WebRTC that allows it to do what it does, not a bug. If you are worried about 3rd party web apps sniffing your local IP and somehow using that info against your interests, don't go on the internet.
- BeefWellington 4y agoIf it leaks local ipv6 there may not even be NAT involved. This would unmask the user on the other end of a VPN or Proxy, for example. While this generation is done only for IPv4 space someone with sufficient time, resources, and inclination (say a large Ad conglomerate) could similarly start generating these for IPv6 address spaces.
- ajross 4y agoThe root technical issue here seems to be that the IPv4 space is fundamentally pretty small and easy to search, the browser just uses a crc32 to obscure the local IP address, and you can write code to brute force it with a little sophistication. The security impact, as others are pointing out, is pretty minimal. Knowing a local IP address behind a NAT isn't "not" a privacy issue (e.g. I can see things like gaming anti-abuse using tricks like this to discriminate users who need to be blocked vs. normal players), but it's not much of one.
- xg15 4y agoMany comments on this thread are about the pros and cons of leaking the local IP in an ICE candidate entry. You can certainly discuss this, but in my understanding, that's not what this post is about at all. The issue is about leaking the local IP in the foundation which is supposed to be some sort of opaque UUID - the local IP isn't supported to be in there at all, whether you want LAN connections or not. Is this correct?
- Sean-Der 4y agoFoundation was designed to be a tie breaker. If multiple candidates are valid with the same type you could use the lower foundation. Foundation is specified in ICE RFC. Almost two decades before mDNS candidates were discussed! I doubt privacy of IPs was ever a consideration
- thesuperbigfrog 4y agoIf you are unfamiliar with WebRTC I recommend checking out "WebRTC for the Curious": https://webrtcforthecurious.com/ https://webrtcforthecurious.com/ WebRTC is designed to be secure, so a privacy leak is not good.
- kevincox 4y agoWebRTC is designed to support direct peer-to-peer connections so the privacy leak is required. Maybe it would have made more sense to make peer-to-peer opt-in explicit?
- Sean-Der 4y agoI liked that idea also. The concern was dialog fatigue. If a web site prompts permission to ‘gather local candidates’ most users are just going to hit OK. So this wouldn’t stop abusive uses of WebRTC as hoped.
- Sean-Der 4y agoGlad you liked it! Anyway we could make it better?
- Fnoord 4y agoWebRTC was already known to leak local IP. Which can be dangerous if you're behind a VPN. I use two browsers. One with WebRTC disabled (Firefox) and one with WebRTC enabled (Safari/Chromium). The former also runs a myriad of other addons which increase privacy. The latter I use to connect to PiKVM.
- kornhole 4y agoI also use similar browser isolation strategy. I use one browser for real-ID activity such as banks, domain registrars.. and avoid entering real creds in the private browser to keep an anonymous fingerprint. This is one of those gray areas though where I don't always want to share my IP over Jitsi.
- lxgr 4y ago> The former also runs a myriad of other addons which increase privacy. Unfortunately, the more custom your browser behavior gets, the more finger-print-able you are :/ And that's not even considering potentially harmful plugins (either inherently so, or via browser store account takeovers).
- whatismybrowser 4y agoIt used to be available to detect, but they changed it a long time ago. It made it easy to help someone find their local ip address, without having to click around in settings or the command line: https://www.whatismybrowser.com/detect/what-is-my-local-ip-address https://www.whatismybrowser.com/detect/what-is-my-local-ip-a... But I understand the fingerprinting/privacy concerns, so it's for the best that it's not available.
- saghul 4y agoHas this been reported to Chromium / WebRTC? At a quick glance I don't see it in the WebRTC bug tracker.
- matheusmoreira 4y agoI think uBlock Origin prevents that.
- crtasm 4y agosee Semaphor's comment above: https://news.ycombinator.com/item?id=33328486 https://news.ycombinator.com/item?id=33328486
- ck2 4y ago* https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-leaking-local-IP-address https://github.com/gorhill/uBlock/wiki/Prevent-WebRTC-from-l... * https://browserleaks.com/webrtc https://browserleaks.com/webrtc
- AtNightWeCode 4y agoWebRTC again. On the same page. There is no isolation between remote and local networks in browsers.
- sesm 4y agoIs user IP leaked to another peer if there is a media server (like Kurento) between peers? I’ve worked in 2 WebRTC-based projects and in both cases the connection was not actually P2P, but had some kind of media server in between, either to mux multi-user conferences or to re-encode the media to a format supported by the other peer.
- encryptluks2 4y agoI'm not getting a leak with Chromium, but that is probably because I have my policy set to `default_public_interface_only`. I believe this is by design as WebRTC notoriously leaks local IPs.