5 ms·
What happened if some government agency were to order both Obscura and Mullvad to log a certain user or certain activities? Wouldn't it be possible to combine t
by ortichic 2y ago
What happened if some government agency were to order both Obscura and Mullvad to log a certain user or certain activities? Wouldn't it be possible to combine those logs? If it isn't: would that change if Obscura was ordered to also use a separate Mullvad account for a specific user/IP?
- Nyr 2y agoGovernments do not even need any of the providers to comply, they can access global NetFlow data. This is conveniently not discussed by any commercial VPN provider.
- hypeatei 2y agoOkay, but this is a given if you don't run your own ISP. Your ISP can also see that you connect to Tor. Your data is still encrypted.
- Cyph0n 2y agoIt ultimately depends on your threat model. But assuming a state actor has access to NetFlow data, an attack could work like this: * State actor determines that an IP belonging to a VPN company had a session on example.com around t1-t2 * You -> VPN server at t1 * VPN server -> example.com at t1+latency * More traces from both sides until around t2 as you browse the site By correlating multiple samples, and accounting for latency between you and the VPN server and delay introduced by the VPN itself, they would be able to get decent confidence that it was you.
- Imustaskforhelp 2y agoBasically when you go at the point of state threat actors. Things get real spooky. The censorship , the what not. I feel sad that we have given governments such major accesses in the name of unification. We need more decentralization at the political level & economical level as well (like most money goes to your city , then state , then at the country , very nominal amount) Let city decide what it wants with major town hall discussions.
- culopatin 2y agoTown halls where only people with an agenda to push or retired and bored people show up?
- Imustaskforhelp 2y agoYou can change that much easier than changing something at the national level
- pinecamp 2y agoThanks for pointing this out. I wasn't aware of NetFlow. I don't use IVPN, but I found this writeup informative: https://www.ivpn.net/privacy-guides/isp-netflow-surveillance-and-vpn/ https://www.ivpn.net/privacy-guides/isp-netflow-surveillance...
- ortichic 2y agoHow would such an attack work?
- thrwaway1985882 2y agoThe threat actor most use to talk about this is a global passive adversary: a threat actor who can see all relevant traffic on the Internet but who can't decrypt or adjust the traffic. This adversary would have the ability to ingest massive amounts of data and metadata[0] it acquires from tier 1 ISPs all over the country[1] and the world[2]. They'll not see raw HTTP traffic because most everything of interest is encrypted, but can store and capture (time, srcip, srcport, dstip, dstport, bytes). From there, it's a statistical attack: user A sent 700 kilobytes to a VPN service at time t; at t+epsilon the VPN connected to bad site B and sent 700 kilobytes+epsilon packets. Capture enough packet flows that span the user, the VPN, and the bad site and you can build statistical confidence that user A is interacting with bad site B, even with the presence of a VPN. This could go other directions too. If bad site B is a Tor hidden site whose admin gets captured by the FBI and turns over access, they'll be unmasking in reverse – I got packets from Tor relay A, which relay sent packets at time-epsilon to it, (...), to the source. There's very little you can do to fight this kind of adversary. Adding hops and layers (VPN + VPN, Tor, Tor + VPN, etc.) can only make it harder. It's certainly an expensive attack both in terms of time consumption, storage, and it requires massive amounts of data, but if your threat model includes a global passive adversary, game over. [0] https://en.wikipedia.org/wiki/XKeyscore https://en.wikipedia.org/wiki/XKeyscore [1] https://en.wikipedia.org/wiki/Room_641A https://en.wikipedia.org/wiki/Room_641A [2] https://en.wikipedia.org/wiki/FVEY https://en.wikipedia.org/wiki/FVEY
- gosub100 2y agoCould they go to synchronous packet transfer and static payloads? - users only ever talk to nodes in 8kb chunks, and they TX/RX 12 packets per second. - nodes only talk to each other in 128kb chunks. Up to 8x / second, no lower than 1x/second
- thrwaway1985882 2y ago
- zikduruqe 2y agoHonestly, paying for a VPN is just purchasing slow internet speeds at a premium. https://www.youtube.com/watch?v=9_b8Z2kAFyY https://www.youtube.com/watch?v=9_b8Z2kAFyY Just use Tor.
- push0ret 2y agoCould you protect against NetFlow analysis by pushing a bunch of noise over the VPN tunnel at all times? I'd assume it would at least make the analysis significantly more challenging.
- thrwaway1985882 2y agoSome of the prior works in this paper[0] address noise in anonymity networks, but in general: you either add noise at the link level which malicious nodes can identify & ignore, or you add noise by injecting fake chaff packets that are dropped somewhere inside the network which are statistically identified when you look at packet density across the network. This might or might not extend to VPN nodes depending on your threat model - I'd personally assume every single node offered to me by a company in exchange for money is malicious if I was concerned about privacy. [0] https://www.cs.utexas.edu/~shmat/shmat_esorics06.pdf https://www.cs.utexas.edu/~shmat/shmat_esorics06.pdf