3 ms·
This works in theory, and shows you've made good research on the topic. I operate an IP anonymizer detection service and these are the gotchas I think you'd fin
by juros 19d ago
This works in theory, and shows you've made good research on the topic. I operate an IP anonymizer detection service and these are the gotchas I think you'd find in real life though:
- some browsers / extensions disable webRTC by default, and certain privacy configs use a proxy to reach out to STUN. These are not "weird" browsers: Safari, Firefox, Brave, Opera do it by default or through configs.
- naive RTT calculations will cause you lots of false positives. Just as an example, some devices on low battery do slow down their network stack, randomly causing bigger RTT on some network packets and triggering your TLS > RTT*3. We discovered it the hard way, and there are many more other corner cases.
- as an independent site operator, I'd find this harder to deploy than i.e. deploying a reverse proxy or using 3rd party service. Also you'd need to always show an interstitial screen where the webRTC checks happen, instead of running your detections on the fly as each request comes in.
If you're interested on the topic, let's chat by email and/or take a look at our demos:
- https://demo.truesign.ai/protected-form https://demo.truesign.ai/protected-form
- https://demo.truesign.ai/protected-content https://demo.truesign.ai/protected-content
- jwally 13d agoSuper cool! Thanks for replying / sharing. Obviously, this would be a SAAS -I wouldn't want webmaster at jocokfuel.com or whatever having to roll their own rust stun server and make TCP RTT measurements :-) Spun up a quick and dirty demo at https://proxy.kyc.red https://proxy.kyc.red More detailed description is in there. I just ran some proxied sessions through your demo - really impressive! FWIW, make the "BLOCKED" text bright red and bold - success/accepted green. Would love to chat more about what you're doing and how you're doing it. I'm justin at wolcott dot io :salute