3 ms·
I find the premise of the paper strange -- if the router is untrusted it can do many things, not just statistical traffic analysis at a high level (e.g. DNS/HTT
by dgl 2y ago
I find the premise of the paper strange -- if the router is untrusted it can do many things, not just statistical traffic analysis at a high level (e.g. DNS/HTTP may give away apps downloading a list of VPN endpoints).
In 2024 IPv6 isn't mentioned, even in the future work section. While privacy addressing is often used, the address is usually rotated infrequently in terms of tracking what a device is doing for a few hours, privacy addressing aims to stop tracking over days. A router can easily see the real MAC address in the neighbour table, but right now a client device using a VPN over IPv6 is potentially trackable even beyond the local router, which seems more interesting than their local only threat model.
I wonder if any VPN clients force renewing the IPv6 privacy address, combined with careful firewall rules to avoid leaking the device's other address(es)? I suspect many clients/people just disable IPv6 out of paranoia though.
- gruez 2y agoAFAIK most VPNs are ipv4 only and disable ipv6, so it's a non-issue.
- Workaccount2 2y agoWouldn't VPN's want to be ipv6 so they could constantly use unique IP's?
- gruez 2y agoWhy would they need unique IPs? They're already using NAT on ipv4 because they're sharing one server with tens/hundreds of users. Moreover, giving unique IPs per user might be better for networking purposes (ie. no need for NAT), but sucks from a product perspective, because it makes the users individually trackable. For a privacy product it makes little sense to do so.
- godelski 2y agoYou're probably often on an untrusted router. At least every time you're outside your house, and for many people even in their house. I don't get why just because an untrusted router can do many things that that means you can't talk about one of those things. Sure, there may even be more interesting things, but to who? And why should that stop a conversation about other things? How would you talk about those things in any detail if not one by one? I can neither speak, nor read, nor write in parallel.
- jiveturkey 2y agoof course an untrusted router can do many things, it's one reason you use a VPN at all. your provider's router is ... untrustworthy. i believe the point of the paper is that even if you use VPN, the router can detect that and classify you. VPN is illegal in some countries so this is relevant. let's avoid a "security must be absolute" mindset. like, thing A is not worth doing because thing B is still flawed. the paper seeks to address a specific thing A and things B,C,D are out of scope. in the paper abstract they specifically and only talk about the CPE router, which can identify LAN clients uniquely, but very similar thing applies to the upstream edge/border router. I believe (I only scanned it, didn't read it in detail) the paper focuses on the CPE router because the fingerprinting load is distributed and free in that case, and most often the provider owns the CPE anyway. so this is a reasonable place to focus on. however they've neglected netflow records (from provider owned upstream border/edge router) which can similarly be analyzed, offline at a leisurely pace, with arbitrary resources able to be thrown at it, and unlike a CPE firmware action cannot be detected. so i don't know how important the "router" part is. the ability to detect VPN itself isn't novel or even interesting, but i guess their claim is in presenting a traffic analysis that requires little sophistication and few resources, something lightweight enough that it can be run at the CPE.