Services used by hundreds of thousands of people in the UK to protect their identity on the web are vulnerable to leaks, according to researchers at QMUL and others.
Virtual Private Networks (VPNs) are legal and increasingly popular for individuals wanting to circumvent censorship, avoid mass surveillance or access geographically limited services like Netflix and BBC iPlayer. Used by around 20 per cent of European internet users they encrypt users’ internet communications, making it more difficult for people to monitor their activities.
The study of fourteen popular VPN providers found that eleven of them leaked information about the user because of a vulnerability known as ‘IPv6 leakage’. The leaked information ranged from the websites a user is accessing to the actual content of user communications, for example comments being posted on forums. Interactions with websites running HTTPS encryption, which includes financial transactions, were not leaked.
The leakage occurs because network operators are increasingly deploying a new version of the protocol used to run the Internet called IPv6. IPv6 replaces the previous IPv4, but many VPNs only protect user’s IPv4 traffic. The researchers tested their ideas by choosing fourteen of the most famous VPN providers and connecting various devices to a WiFi access point which was designed to mimic the attacks hackers might use.
Researchers attempted two of the kinds of attacks that might be used to gather user data – ‘passive monitoring’, simply collecting the unencrypted information that passed through the access point; and DNS hijacking, redirecting browsers to a controlled web server by pretending to be commonly visited websites like Google and Facebook.
The study also examined the security of various mobile platforms when using VPNs and found that they were much more secure when using Apple’s iOS, but were still vulnerable to leakage when using Google’s Android.
Dr Gareth Tyson, a lecturer from QMUL and co-author of the study, said:
“There are a variety of reasons why someone might want to hide their identity online and it’s worrying that they might be vulnerable despite using a service that is specifically designed to protect them.
You might find this VPN Guide of interest . . .
The Latest on: Internet anonymity
via Google News
The Latest on: Internet anonymity
- 10 Eeriest Internet-Centric Horror Movieson October 9, 2020 at 10:35 am
If you're reading this online, you're already doomed, but you can't say we didn't warn you with our list of the best internet horror movies.
- 'Offensive and despicable': Sask. Party condemns internet rumour millon October 8, 2020 at 5:26 pm
A cryptic website and Twitter account are spreading what politicians and party members insist is a baseless story that the Sask. Party wants to drop Scott Moe. A mysterious website masquerading as a ...
- How “Am I the Asshole?” Created a Medium Place on the Interneton October 7, 2020 at 3:30 am
The famous subreddit started as a forum for one man to ask about his workplace behavior. Seven years later, it’s become a place where millions of people discuss good, bad, and everything in between.
- Treat students arrested over protests leniently, disregard anonymous complaints against teachers, principals urge Hong Kong leader Carrie Lamon October 3, 2020 at 1:19 pm
Hong Kong students arrested over anti-government protests should be treated leniently to allow for social reconciliation, the city’s biggest association of secondary school principals has urged, while ...
- Cowards Are Blackmailing Young Women to Death on the Interneton October 2, 2020 at 2:50 pm
The most despicable corners of the internet house a byzantine network devoted to sharing screen-captured images of naked—and often underage—girls. And quite a few of these individuals get off on ...
- Researchers Adapt AI With Aim to Identify Anonymous Authorson October 2, 2020 at 2:37 pm
At Black Hat Asia, artificial intelligence and cybersecurity researchers use neural networks to attempt to identify authors, but accuracy is still wanting.
- How the coronavirus, the internet and tons of money unexpectedly fueled sports cards' biggest boomon October 2, 2020 at 4:00 am
A LeBron rookie card for $1.8 million? How about a Mike Trout one-of-one for $3.9 million? As records continue to fall, the nostalgic industry is swarming with mega-rich investors and high-volume ...
- Survey: Many feel their current internet is too slow and overpriced, yet few have upgradedon October 1, 2020 at 9:02 am
Three-quarters of respondents didn't know what internet speeds would be adequate for their household and the overwhelming majority have yet to upgrade their service.
- Someone started a brand called ‘Biden Beauty’—and the internet is perplexedon September 30, 2020 at 11:53 pm
Biden Beauty' is selling everything from makeup sponges to tote bags in an effort to send the former vice president back to the White House.
- Regulation of the internet doesn’t have to stifle free speech – in fact, it can encourage iton September 30, 2020 at 3:52 am
You would expect the CEO of Index on Censorship to oppose threats to free speech. Surely, though, that should mean being against all threats to free speech – yet in a recent article, “New ‘online harm ...
via Bing News