4 ms·
VPN can be trivially defeated any number of ways. I was shocked when I first learned this ten fifteen years ago through a site that showed my internet provider
by bedobi 2y ago
VPN can be trivially defeated any number of ways. I was shocked when I first learned this ten fifteen years ago through a site that showed my internet provider and location despite being on a VPN. I forgot the name of the site.
A huge problem that doesn't even require defeating is, most OSs and VPN clients, if the connection is shaky, just reverts to the default connection. Even a single packet is enough for your VPN to be worth nothing. In Ubuntu, it required setting up elaborate firewall rules and activate them after you get a stable VPN connection to avoid this. (and even that doesn't protect you from DNS and other stuff being able to track you) (let alone cookies which reveal who you are etc etc)
- lxgr 2y agoWhat is a trivial way to reveal a VPN-using website visitor’s actual IP these days? Browsers have improved a lot over the last ten years. > A huge problem that doesn't even require defeating is, most OSs and VPN clients, if the connection is shaky, just reverts to the default connection. This is mostly a function of the VPN client, not the OS. Some clients will reinstate default routes pretty quickly when they lose connectivity, others are pretty sticky. At least Android even offers a specific “always-on VPN” option to prevent leaks like that.
- dinobones 2y agoAre there any router/cheap "bridge" devices that can sit between your router and the internet and force outbound communication to go through the VPN, as if it were your ISP?
- bedobi 2y agoapparently lots of folks use Raspberry Pi's for this, which has added benefit of PiHole filtering out of ads etc no personal experience but sounds nifty, maybe there are other options too
- Hikikomori 2y agoJust use iptables and only allow the vpn traffic. Or do the same with a small Linux box.
- bedobi 2y agoapparently lots of folks who do this still have problems that a lot of software that promises to do this actually only does it for ipv4, so ipv6 traffic still exposes them, lol
- _0ffh 2y agoIt's not unusual to get the recommendation to deactivate ipv6, which isn't hard (on Linux at least).
- mftrhu 2y agoPretty much any of the GL.iNet devices should be able to do that.
- GardenLetter27 2y agoOn Linux this is easy with a network namespace and nftables.
- wepple 2y agoThere have been a bunch of these, although if you’re really that concerned, you might as well go all in with tor A modern version of this: https://github.com/grugq/portal https://github.com/grugq/portal
- dpifke 2y agoYou do not want to mix your non-anonymous and anonymous traffic over the same Tor connection, especially if you don't control the bridge (first hop) to which you're connecting.
- whoomp12342 2y agois there reading on this matter?
- m463 2y agoCan just be location services - it uses known bluetooth devices and known wifi networks to deduce your location
- bedobi 2y agocan be but that wasn't what i was experiencing
- vardump 2y agoWhat leaks your location might just be a DNS request. Depends on the configuration. The site can include a completely unique DNS name as a part of a page. Something like "a5afbdeffe.attacker.com".