Even a VPN Can't Protect You From This Browser Security Flaw

Lifehacker Tech by 6 min read 107x views
Even a VPN Can't Protect You From This Browser Security Flaw

Share Post


A VPN conceals your IP location by routing your net traffic through a distant server, preventing anyone surveilling the network from tracking your online activity. Theoretically, that method no one have to be capable to acknowledge you whenever you nexus to a network and browse the internet, equal your ISP. 

In practice, though, there are plentifulness of gaps that hackers can exploit. A during back, Lifehacker covered browser fingerprinting, which uses hundreds of data points, akin your hardware specs, functioning scheme version, web browser, and GPU signature, to established a shade overview that follows you about equal whenever your VPN is enabled. There's another way cyberattackers can obstruct your data, and it involves exploiting a communication leak correct inner your browser. 

Major browsers akin Chrome, Firefox, and Edge have a characteristic called WebRTC that lets them bypass the encrypted Transmission Control Protocol (TCP) tunnel created by your VPN to established high-speed connections for demanding tasks akin video streaming, sound calls, and display sharing. This leaves your genuine IP location exposed throughout the transmission, offering plentifulness of period for attackers to grasp the identifying data you are trying to hide. 

Luckily, VPN providers are getting improved at preventing WebRTC leaks through additional safety features, but these protections frequently need to be configured manually in your VPN settings or, if your VPN does not recommendation WebRTC leak prevention, immediately in your web browser. I’ll display you how to set it up stage by step, so you don’t get blindsided by an unintended IP location leak. 

How WebRTC leaks bypass your VPN 

WebRTC safety toggle in Surfshark VPN
VPN providers are getting improved at addressing WebRTC leaks Credit: Surfshark

WebRTC is abbreviated for Web Real-Time Communication, a innovation that lets your browser discover the shortest path to nexus to another equipment for high-bandwidth data transfer. It establishes a straightforward peer-to-peer association alongside another equipment using your community IP address, improving your data transfer speeds during video and sound calls, live streaming, and display shares. 

Everybody on the net has likely been exposed to WebRTC connections at one item or another—for example, whenever you create a video call through Google Meet. Because the innovation requires your community IP location to established a faster connection, it bypasses your VPN’s default TCP encryption tunnel using a distinct communication protocol called User Datagram Protocol (UDP), which foregoes safety for speed. 

WebRTC connectivity is built into most contemporary web browsers, including Chrome and another Chromium-based browsers, Firefox, Edge, Opera, and equal Safari. It’s additionally enabled by default, which method that your VPN won’t conceal your IP location whenever you’re on a video gathering or livestream unless you obtain distinct steps to forestall unencrypted data transfers. 

IPLeaks browser leak test for WebRTC connections
Visit a website akin IPLeaks or BrowserLeaks to see if your web browser is encrypted during WebRTC connections Credit: IPLeaks

How to test for a WebRTC leak

You can test for WebRTC leaks by using particular online tools to run safety checks on your browser during the VPN is switched on. Here’s how to do it: 

  1. Enable your VPN using the provider’s app or browser extension. 

  2. Visit a website akin BrowserLeaks or IPLeaks on your preferred browser to test for leaks. 

  3. Check for the results in the “WebRTC Leak Test” division of the test report. Look at the outcome corresponding to the “Public IP Address” field. 

  4. If it says “No IP Leak,” you’re good. But if it says item akin “WebRTC IP doesn't equivalent your Remote IP,” or displays your genuine IP location location in that section, you’re exposed. 

How to disable WebRTC in your browser to forestall IP leaks

Many top VPN providers recommendation built-in WebRTC safety using network firewalls and slay switches that forestall IP leakage. However, if operating a leak test reveals that your association is exposed, your safest choice is to disable WebRTC connections at the browser flat (Chrome, Edge, Firefox, Opera, etc.). 

There’s a tradeoff here, since many platforms, including Google Meet and Discord on the web, necessitate WebRTC features to function properly. With that in mind, it’s improved to toggle it off during delicate browsing sessions and flip it rear on whenever you’re on a safe video call alongside person you know. 

Not all browser handles WebRTC the identical way either. For example, Firefox lets you disable the characteristic outright, during Safari puts in particular restrictions to forestall excess data leakage, and Chrome doesn’t recommendation any built-in toggle without a third-party plugin. Here’s how you can disable WebRTC in most famous web browsers: 

What do you think so far?

Disabling WebRTC in Firefox

Firefox is the lone important browser that lets you disable WebRTC outright, without any extensions.

  1. Type about:config into the location bar and obtain the hazard warning.

  2. Search for media.peerconnection.enabled.

  3. Double-click the admission to flip its value from true to false.

Keep in intellect that this breaks any location that depends on the WebRTC feature, including video calls on Google Meet or Discord. 

Disabling WebRTC in Chrome

Chrome doesn't recommendation a built-in WebRTC toggle, so you'll need a browser expansion built specifically to authority WebRTC handling, specified as the WebRTC Control expansion accessible on the Chrome Web Store.

  1. Install a reputable WebRTC-control expansion from the Chrome Web Store.

  2. Set its WebRTC IP handling guideline to “Disable non-proxied UDP.”

  3. Reload a leak-test leaf to verify your genuine IP location no longer shows up.

Be selective concerning which expansion you install—a tool meant to bounds WebRTC use has no lawful logic to petition admission to your browsing former or the contents of all leaf you visit.

Disabling WebRTC in Edge

Edge runs on the identical Chromium motor as Chrome, so the resolution current is the same: There’s no native off switch, but you can use a browser expansion from the Microsoft Edge Add-ons shop or the Chrome Web Store to disable WebRTC.

  1. Install a WebRTC-blocking expansion compatible alongside Edge.

  2. Configure it to disable non-proxied UDP or obstacle WebRTC outright, depending on what it supports.

  3. If you’re fine alongside leaving WebRTC enabled as lengthy as your IP location stays hidden, you can category edge://flags into your browser’s location bar and allow “Anonymize local IPs exposed by WebRTC” without installing an extension.

  4. Re-test alongside your VPN connected to verify the leak is closed.

Are WebRTC leaks really value worrying about?

It seems nearly all day that a new safety exposure makes the headlines, so you power be wondering if all this precaution is value the trouble. 

If you’d akin to prosecute my regulation of thumb, I would say that if you’re privacy-conscious adequate to use a VPN, you should additionally pay notice to your browser’s WebRTC handling and at smallest anonymize your IP for UDP connections, if not disable WebRTC outright. Keep in intellect that WebRTC stays enabled by default equal whenever your browser is in Incognito Mode and you’re using a VPN at the identical time, so additional precaution is value the attempt if you attention concerning the additional privacy. 

Other Article Lifehacker Tech
Close Right Ads
Close Left Ads