Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Colour me unsurprised. Disappointed though.

I'm glad I disabled WebRTC when I first discovered it could be used to expose local IP on a VPN.

These "extension" technologies should all be optional plugins. Preferably install on demand, but a simple, obvious way to disable would be acceptable. (ie more obvious than about:config)

Not a great deal can be done about font metrics other than my belief that websites shouldn't be able to ferret around my fonts to see what I have. Not like it's a critical need for any site.



What would anyone do with your internal network IP?

Having these features as optional plugins means they are basically impossible to count on having in the basic web platform, meaning you're going to fight a losing battle to gain adoption for any applications that need them.

And the open web platform is the only platform right now that is enabling developers to create cross-platform applications outside of the restrictions of walled-garden app stores.


Not just internal network IP, but also public IP. There were quite a few test sites popped up when the issue came to light.

> Having these features as optional plugins means they are basically impossible to count on having

Funny. Didn't seem to prevent flash, acrobat or others becoming extensively adopted. If I want browser video chat I can install WebRTC etc.

If the cost of having that universal platform is compromising everyone's privacy, on any site that wants to check, it's not a fair or acceptable trade.

Seems to me we have this ass backwards.


You know every site you ever go to sees your public IP, right?

Seems to me you're just being paranoid.


Not when connected to a VPN, they should see the vpn public IP. The issue was that WebRTC enabled snooping on ISP-provided IP whilst on a VPN.

See https://github.com/diafygi/webrtc-ips or https://www.purevpn.com/blog/disable-webrtc-in-chrome-and-fi...


With your internal IP I can guess the brand of your router, determine if you are a home user or on a corp network, guess how many other machines might be on your network.

I can also assume that your router lives at .1 or .254 or similar, and use your browser to pivot and brute force the password while you browse cat pictures.


If your VPN is configured correctly, your IP will not be exposed.


Not all of my devices make it possible to disable WebRTC, which makes defense in depth a necessity. Can you provide pointers to more information?


I don't experience webrtc leaks with Openvpn and this config: http://pastebin.com/raw/hiH1TZtS (I use IVPN, their client prevents webrtc leaks on windows by default, but had to manually configure openvpn on linux).

Of course, I keep webrtc disabled in Firefox anyway except when i need it, defense in depth like you said.


Neat, thanks.


> These "extension" technologies should all be optional plugins.

But then still whether you installed an extension would contribute a bit of information to your fingerprint.


True enough, though I suspect not installed would be the majority case. I guess it should ask like browsers ask before location check.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: