5 ms·
And by "exactly that purpose" you mean preventing ad fraud [1], right? They weren't using WebRTC to put you in a "VPN user" advertising segment. 1. https://www
by anfedorov 11y ago
And by "exactly that purpose" you mean preventing ad fraud [1], right? They weren't using WebRTC to put you in a "VPN user" advertising segment.
1. https://www.reddit.com/r/netsec/comments/3dgwee/how_the_new_york_times_uses_webrtc_to_gather/ https://www.reddit.com/r/netsec/comments/3dgwee/how_the_new_...
- monstruoso 11y agoDoesn't matter. Privacy is not about right or wrong, it is about privacy.
- anfedorov 11y agoPrivacy is not an absolute to be maximized at all costs. Do you have blacked out windows, or do you concede that the practical day-to-day infringement of your privacy is so minuscule and so easily mitigated by window shades that it's not worth the trade-off?
- 1stop 11y agono, but I have windows with curtains on the inside. Not the outside. The distinction is both important, and blatantly obvious. Privacy control must remain with the one whose privacy is at stake.
- anfedorov 11y agoAnd sometimes you have these curtains open? But what about privacy? Do you agree that sometimes people being able to look into your living room is not a big deal, even if it decreases your privacy by some definition? Great, then you agree that maximizing privacy at all costs isn't your or people's tradeoff point. Same with WebRTC - your internal network's IP is not the kind of privacy most people care about, nor should they. That said, WebRTC from behind a VPN exposing your personal IP is a bit different. That's kind of like a light you installed rendering your curtains translucent. I'm not sure if it's the curtain's fault, or the light's, but it's certainly not what anyone had expected! Given that OpenVPN somehow works in a way that doesn't expose your personal IP [1], I'd blame the VPN providers for saying that their VPN anonymizes web traffic when it actually doesn't. 1. https://tlog.anfedorov.com/vpns-webrtc https://tlog.anfedorov.com/vpns-webrtc
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- anfedorov 11y ago> a random guy on the internet says something and you think it is true? Yes, if they identify themselves and their company and what they say aligns with my personal experience. > You don't have the foggiest idea what they are really doing with the data. All we know is that they are collecting the data without user's consent. You never have any absolute certainty what anyone does with your data - all you have are hypotheses and probabilities. Who are "they" and what do you think they are doing? If adtech companies cared whether you're behind a VPN, they would make or buy a list of IP's that are provide VPN services and match that list. That's a ton easier than implementing a STUN server that scales to handle traffic from every single person who views one of their ads.
- glass- 11y agoIt's not only about the VPN leak. WebRTC also leaks internal IP addresses which provide additional entropy that can be used for fingerprinting.
- anfedorov 11y agoEntropy that changes when your local IP does? That's worse than useless for ad targeting. Even if it were useful, I don't think there's much of a chance that adtech companies will build out STUN servers to handle the kind of traffic they do just track down the 0.001% of users who do not accept third-party cookies. Can you even do WebRTC from an iframe? Browser fingerprinting is absolute FUD. It makes no sense for advertisers, and it's pretty useless for anyone else, too. Every time I visit the EFF site that checks my fingerprint, it tells me I'm still unique. That's perfect anonymity! Revealing a user's personal IP when they're using a VPN is a real problem, though, where the computer isn't doing what an even an experienced user would expect.