PDA

View Full Version : Huge Security Flaw Makes VPNs Useless for BitTorrent



poutchiz
06-17-2010, 10:32 PM
Millions of BitTorrent users who have chosen to hide their identities through a VPN service may not be as anonymous as they would like to be. Due to a huge security flaw, those who use IPv6 in combination with a PPTP-based VPN such as Ipredator are broadcasting information linking to their real IP-address on BitTorrent.

As pressure from anti-piracy outfits on governments to implement stricter copyright laws increases, millions of file-sharers have decided to protect their privacy by going anonymous. In Sweden alone an estimated 500,000 Internet subscribers are hiding their identities. Many of these use PPTP-based VPNs such as The Pirate Bay’s Ipredator or Relakks.

Thus far, these services were believed to adequately hide a user’s IP-address from people they connect to in BitTorrent swarms, but this is not always the case. At the Telecomix (http://telecomix.org/) Cipher conference a security flaw was revealed that allows third parties to find the true IP-address of someone connected through a VPN.

The security risk is caused by a lethal combination of IPv6 and PPTP-based VPN services, which are very common. IPv6 is the Internet protocol that will succeed IPv4. The protocol is promoted by Windows 7 and Vista, among others, and most people are using it without even realizing it.

The technical details of the vulnerability, explained in this talk (http://bambuser.com/channel/telecomix/broadcast/832366), reveal that the true IP-address of users using IPv6 can be easily traced. Even worse, it seems that the Swedish Anti-piracy Bureau may already be using this flaw to gather data on ‘anonymous’ BitTorrent users.

The vulnerability is not limited to BitTorrent either. It can expose people who believe that they are hiding their real IP-address through nearly every connection.

In addition to this gaping hole in VPNs such as Ipredator and Relakks, the talk exposes several other weaknesses from a privacy point of view. Among other things, it is fairly easy to find MAC-addresses and computer names of people who use the same VPN.

The people who run Ipredator are aware of the issue, and TorrentFreak was informed that their users will be notified about the problem. Other VPNs using the same system may want to do the same. From our understanding of the issue, turning IPv6 off (http://www.google.com/search?&q=disable+ipv6) should alleviate the threat and make users fully anonymous again.


News made by Ernesto (http://torrentfreak.com/author/ernesto/), picked (untouched) from TF (http://torrentfreak.com/huge-security-flaw-makes-vpns-useless-for-bittorrent-100617/).

kssunbeam
06-17-2010, 11:24 PM
Well , that kinda suck.

I am sure there will be another solution but it sounds like a lot of damage had been done already :(

Is that something that effects seedbox users or just people using IP masking services?

poutchiz
06-18-2010, 12:02 AM
Is that something that effects seedbox users or just people using IP masking services?

Actually, seeboxes are much secure than such vpn services, as they are generally hosted far (if not in another country) from the user's residence + they usually include an internal anonymous/ security system...

But that doesn't mean what so ever that you're fully secure when using a seedbox. Actually, there is no fully secure system, as you might know, and probably will never be imo.

The networking system as it is built, records and archive every single step annd action made over the net. Thereby someone out there with some skills can always tracks your steps no matter how hard you try to hide them. But still the harder the better ! :wink:

kssunbeam
06-18-2010, 12:41 AM
LOL, do you know that saying? That to outrun a bear you dont have to be faster then a bear, just faster then the person running away next to you?

I know there isnt a way to be 100% secure. I wish there was anything that secure bit I do understand there isnt LOL.

For now, I think the best way you could to be secure those days is to use a seedbox and to avoid using public trackers, anything else and your IP is way too reachable.