Over the past few years, we’ve seen a veritable avalanche of security breaches and data leaks, while Congress has passed laws demolishing what little regulation existed to control how ISPs gather and sell your data. This has led many people to look for third-party privacy solutions. Virtual private networks (VPNs) offer a solution to some of these issues by masking one’s browsing habits, but only if the VPNs are themselves secure. New security research suggests many of them aren’t.
VoidSec tested a total of 70 VPNs thus far and found that 16 of them leak data via this known WebRTC bug. He also set up a website you can use to test if your VPN leaks information, demo code you can run if you don’t want to submit your IP address to a web host, and a Google document where users can submit their own findings. In order to function, a VPN has to know both your real IP address and the public IP address it has assigned to you. WebRTC shouldn’t be allowed to query that information, but thanks to this bug, it can. This means the protocol can be used to unmask anyone using a VPN. VoidSec writes:
WebRTC allows requests to be made to STUN servers which return the “hidden” home IP-address as well as local network addresses for the system that is being used by the user.
The following VPNs leak IP addresses:
As for browser-level vulnerability, be advised that most browsers rely on WebRTC and enable it by default. BleepingComputer also notes that another recent investigation by TheBestVPN.com found that many prominent VPN providers also log critical user details, including VyprVPN, Anonymizer, HideMyAss, and HolaVPN. Different companies log different things, but personal details, IP addresses, connection timestamps, device types, payment information, and the various websites you visit are all logged by at least some of these companies. In short, don’t assume that just because you’re using a VPN your data is actually being kept private in any meaningful way.
New macOS Security Bug Unlocks App Store With Any Password
Apple's macOS High Sierra has a flaw in the latest version that allows admin users to bypass a locked app store by entering any password they like.
Researchers Found Another Major Security Flaw in Intel CPUs
Security researchers have found another flaw in Intel CPUs — this time related to Intel Active Management Technology. Once again, this flaw can be leveraged to take complete control of a system, regardless of any security measures the user might employ.
Lawmakers Urge AT&T to Cut Ties with Huawei, Citing National Security Concerns
It's been several years since the last dust-up, but US lawmakers and regulators are still sounding the alarm about any cooperation with Huawei.
Most Android Security Scares Are Bullshit
Many of the Android malware stories we see making the rounds end up amounting to nothing because of the way the platform operates these days. While Android malware is definitely out there, you usually don't need to panic.