Skip to content

webrtc bug seems to leak "private" mesh ip addresses when connecting via peoplesopen.net #25

Open
@jhpoelen

Description

@jhpoelen

Just came across an article that describes a leak of private ip addresses via WebRTC through a VPN tunnel. From https://www.bleepingcomputer.com/news/security/many-vpn-providers-leak-customers-ip-address-via-webrtc-bug/ :

"[...] Around 20% of today's top VPN solutions are leaking the customer's IP address via a WebRTC bug known since January 2015, and which apparently some VPN providers have never heard of. [...]"

A demo site (see also the article) at https://ip.voidsec.com helps to see whether you are exposed.

On Opera v 52.0.2871.30 on Ubuntu 16.04, it appears that my peoplesopen.net ssid only exposes the (new) exit node: 64.71.176.94 . However, when using Chrome v65.0.3325.181 , my private mesh ip was exposed (see attached screenshot).

A apparent workaround is to disable WebRTC in your browser or use a VPN on top of the peoplesopen connection. Or switch to another browser like Opera / Tor.

screenshot from 2018-03-28 12-31-36

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions