Heres how it works, and what you’re able to do about it.
Whats All This Now?
Is My Data At Risk?
Lets back up a bit.
Many people use VPNs specifically toget around those location restrictions.
Usually thats enough to convince a service youre in a supported country.
How Can I test whether My VPN Is Affected?
The flaw was documented by developerDaniel Roesleroverat GitHub.
This demo is an example implementation of that.
Go back toWhat Is My IP Addressand check your IP address again.
You should see a new address, one that corresponds with your VPN and the country you selected.
Visit RoselersWebRTC test pageand note the IP address displayed on the page.
If both tools show your VPNs IP address, then youre in the clear.
How Can I Protect Myself?
Safari and Internet Explorer dont, and thus arent affected (unless youve specifically enabled WebRTC.)
Either way, if the test above worked in your surfing app, youre affected.
Its overkill, but itll disable WebRTC in your online window.
Opera users can use this add on as well, youll just have tojump through some hoops first.
Firefox: You have two options.
Find and set the media.peerconnection.enabled setting to false.
We should note that disabling WebRTC may break some webapps and services.
Run your VPN at your router instead of on your rig directly.
There are a number of benefits to this approach.
There are caveats, though.
That process can be easy or complicated, depending on your router, and your VPN.
Many VPN service providers suggest you set up your VPN at the router level anyway.
sign on to your routers admin page, and check your security or connection options.
Once its enabled, all of your traffic will be encrypted.
If you dont see it, all isnt lost.
Check with your VPN provider and let them know what jot down of router you have.
They may have instructions to walk you through the process.
All of those custom firmwares will allow you to set up your VPN at the router level.
This vulnerability is serious, but on the bright side, its easily mitigated.
Trust, but verify, and take your privacy and security into your own hands.
Title photo made usingNemo.
Additional photos byJames Lee,Paul Joseph, andWalt Stoneburner.