Services used by hundreds of thousands of people in the UK to protect their identity on the web are vulnerable to leaks, according to researchers at QMUL and others.
Virtual Private Networks (VPNs) are legal and increasingly popular for individuals wanting to circumvent censorship, avoid mass surveillance or access geographically limited services like Netflix and BBC iPlayer. Used by around 20 per cent of European internet users they encrypt users’ internet communications, making it more difficult for people to monitor their activities.
The study of fourteen popular VPN providers found that eleven of them leaked information about the user because of a vulnerability known as ‘IPv6 leakage’. The leaked information ranged from the websites a user is accessing to the actual content of user communications, for example comments being posted on forums. Interactions with websites running HTTPS encryption, which includes financial transactions, were not leaked.
The leakage occurs because network operators are increasingly deploying a new version of the protocol used to run the Internet called IPv6. IPv6 replaces the previous IPv4, but many VPNs only protect user’s IPv4 traffic. The researchers tested their ideas by choosing fourteen of the most famous VPN providers and connecting various devices to a WiFi access point which was designed to mimic the attacks hackers might use.
Researchers attempted two of the kinds of attacks that might be used to gather user data – ‘passive monitoring’, simply collecting the unencrypted information that passed through the access point; and DNS hijacking, redirecting browsers to a controlled web server by pretending to be commonly visited websites like Google and Facebook.
The study also examined the security of various mobile platforms when using VPNs and found that they were much more secure when using Apple’s iOS, but were still vulnerable to leakage when using Google’s Android.
Dr Gareth Tyson, a lecturer from QMUL and co-author of the study, said:
“There are a variety of reasons why someone might want to hide their identity online and it’s worrying that they might be vulnerable despite using a service that is specifically designed to protect them.
Read more: Most internet anonymity software leaks users’ details
You might find this VPN Guide of interest . . .
The Latest on: Internet anonymity
[google_news title=”” keyword=”Internet anonymity” num_posts=”10″ blurb_length=”0″ show_thumb=”left”]
via Google News
The Latest on: Internet anonymity
- Mom Refuses to Get Daughter Gift for 13th Birthday -- Internet Turns on Her After Learning Full Detailson May 9, 2024 at 12:41 pm
A woman is seeking the internet's opinion to see if she's really the "worst mom ever" after she didn't get her daughter any gifts for her 13th birthday because she wanted to teach her a lesson.
- How the internet became a breeding ground for slutshamingon May 8, 2024 at 2:56 am
If the history of slutshaming has taught us anything, it’s that we have been condemning female sexuality and shaming anyone who doesn’t appear to fit sexual norms since long before the smartphone ...
- Mootness, anonymity to be weighed in Title IX suit against Loyolaon May 7, 2024 at 10:28 am
A former Loyola University student who alleged discrimination after being expelled for sexual misconduct can proceed with his suit.
- Best Proxy Service Provider Sites of 2024on May 7, 2024 at 10:24 am
While proxies don't provide complete anonymity, they do typically hide your IP address. When you connect to the internet through a proxy, it displays the proxy server's IP address instead of your own.
- Permanent Deletion of Transactions Enhances e-Rupee's Anonymity: Dason May 6, 2024 at 8:11 am
Governor Das emphasizes the potential for permanent transaction deletion to enhance the anonymity of India's e-rupee (CBDC), paralleling cash. The RBI aims to enable offline transferability and ...
- UNC to ban anonymous social media apps, prompting free speech concernson May 5, 2024 at 9:08 pm
The University of North Carolina System plans to ban anonymous social media apps across its 16 campuses, arguing the technology companies have a “reckless disregard” for students’ wellbeing. Other ...
- Grandmother Breaks Family's 'No Kissing' Rule, Causing Internet Outrageon May 1, 2024 at 10:56 am
The new grandmother's daughter-in-law slammed her "BS playing the victim tears" in a rage filled social media post A new mom has taken to the internet for advice after ... The story, posted to an ...
- Republican at fundraiser says ‘no complaints’ from distilleries despite anonymous poston May 1, 2024 at 4:45 am
N.C. Rep. Jason Saine, a Lincolnton Republican who serves on the ABC committee, told The N&O in a text on Monday that “I don’t respond to anonymous posts on the internet.” On Tuesday, Saine confirmed ...
- Unlocking the World Wide Web: Surfshark’s Journey to Secure and Accessible Interneton April 29, 2024 at 10:32 pm
In today’s digital age, where online privacy and accessibility are becoming increasingly important, virtual private networks (VPNs) have emerged as essential tools. Among the sea of VPN providers, ...
- Anonymous post describes ‘unruly’ NC lawmakers at distillery. Here’s what we know.on April 29, 2024 at 4:01 pm
A Reddit user claimed that North Carolina lawmakers were drunk and disruptive at a Kentucky distillery event. What we know so far.
via Bing News