Jump to content

Google Publishes Chrome Fix For Serious VPN Security Hole


NelsonG

Recommended Posts

[img]https://torrentfreak.com/images/boxed.jpg[/img]As large numbers of Internet users wise up to seemingly endless online privacy issues, security products are increasingly being viewed as essential for even basic tasks such as web browsing.

In addition to regular anti-virus, firewall and ad-busting products, users wishing to go the extra mile often [url="https://torrentfreak.com/anonymous-vpn-service-provider-review-2015-150228/"]invest in a decent VPN service[/url] which allow them to hide their real IP addresses from the world. Well that’s the theory at least.

January this year [url="https://torrentfreak.com/huge-security-flaw-leaks-vpn-users-real-ip-addresses-150130/"]details[/url] of a serious vulnerability revealed that in certain situations third parties were able to discover the real IP addresses of Chrome and Firefox users even though they were connected to a VPN.

This wasn’t the fault of any VPN provider though. The problem was caused by features present in [url="http://www.webrtc.org/"]WebRTC[/url], an open-source project supported by Google, Mozilla and Opera.

By placing a few lines of code on a website and using a [url="http://en.wikipedia.org/wiki/STUN"]STUN server[/url] it became possible to reveal not only users’ true IP addresses, but also their local network address too.

While users were [url="https://torrentfreak.com/huge-security-flaw-leaks-vpn-users-real-ip-addresses-150130/"]immediately alerted[/url] to broad blocking techniques that could mitigate the problem, it’s taken many months for the first wave of ‘smart’ solutions to arrive.

Following on the heels of a Chrome fix [url="https://chrome.google.com/webstore/detail/webrtc-leak-prevent/eiadekoaikejlgdbkbdfeijglgfdalml?hl=en-US"]published by Rentamob[/url] earlier this month which protects against VPN leaks while leaving WebRTC enabled, Google has now thrown its hat into the ring.

Titled ‘[url="https://chrome.google.com/webstore/detail/webrtc-network-limiter/npeicpdbkakmehahjeeohfdhnlpdklia/related?hl=en-US"]WebRTC Network Limiter[/url]‘, the tiny Chrome extension (just 7.31KB) disables the WebRTC multiple-routes option in Chrome’s privacy settings while configuring WebRTC not to use certain IP addresses.

In addition to hiding local IP addresses that are normally inaccessible to the public Internet (such as 192.168.1.1), the extension also stops other public IP addresses being revealed.

“Any public IP addresses associated with network interfaces that are not used for web traffic (e.g. an ISP-provided address, when browsing through a VPN) [are hidden],” Google says.

“Once the extension is installed, WebRTC will only use public IP addresses associated with the interface used for web traffic, typically the same addresses that are already provided to sites in browser HTTP requests.”

While both the Google and Rentamob solutions provide more elegant responses to the problem than previously available, both admit to having issues.

“Some WebRTC functions, like VOIP, may be affected by the multiple routes disabled setting. This is unavoidable,” Rentamob explains.

Google details similar problems, including issues directly linked to funneling traffic through a VPN.

“This extension may affect the performance of applications that use WebRTC for audio/video or real-time data communication. Because it limits the potential network paths, WebRTC may pick a path that results in significantly longer delay or lower quality (e.g. through a VPN). We are attempting to determine how common this is,” the company concludes.

After applying the blocks and fixes detailed above, Chrome users can check for IP address leaks by using sites including [url="https://ipleak.net/"]IPLeak[/url] and [url="https://www.browserleaks.com/webrtc"]BrowserLeaks[/url].

Source: [url="https://torrentfreak.com"]TorrentFreak[/url], for the latest info on copyright, file-sharing, [url="http://torrentfreak.com/top-popular-torrent-sites-2015-150104/"]torrent sites[/url] and the [url="http://torrentfreak.com/anonymous-vpn-service-provider-review-2015-150228/"]best VPN services[/url].

[url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=cslF86an6J8:EfEillZIU4g:yIl2AUoC8zA"][img]http://feeds.feedburner.com/~ff/Torrentfreak?d=yIl2AUoC8zA[/img]</img>[/url] [url="http://feed.torrentfreak.com/~ff/Torrentfreak?a=cslF86an6J8:EfEillZIU4g:D7DqB2pKExk"][img]http://feeds.feedburner.com/~ff/Torrentfreak?i=cslF86an6J8:EfEillZIU4g:D7DqB2pKExk[/img]</img>[/url][img]http://feeds.feedburner.com/~r/Torrentfreak/~4/cslF86an6J8[/img]

[url=http://feed.torrentfreak.com/~r/Torrentfreak/~3/cslF86an6J8/]View the full article[/url]

Link to comment
Share on other sites

Please sign in to comment

You will be able to leave a comment after signing in



Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Our picks

    • Wait, Burning Man is going online-only? What does that even look like?
      You could have been forgiven for missing the announcement that actual physical Burning Man has been canceled for this year, if not next. Firstly, the nonprofit Burning Man organization, known affectionately to insiders as the Borg, posted it after 5 p.m. PT Friday. That, even in the COVID-19 era, is the traditional time to push out news when you don't want much media attention. 
      But secondly, you may have missed its cancellation because the Borg is being careful not to use the C-word. The announcement was neutrally titled "The Burning Man Multiverse in 2020." Even as it offers refunds to early ticket buyers, considers layoffs and other belt-tightening measures, and can't even commit to a physical event in 2021, the Borg is making lemonade by focusing on an online-only version of Black Rock City this coming August.    Read more...
      More about Burning Man, Tech, Web Culture, and Live EventsView the full article
      • 0 replies
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
    • Post in What Are You Listening To?
      Post in What Are You Listening To?
×
×
  • Create New...