An IP address is the most common identifier on the Internet. Its value may vary in different situations, but as a rule, there is a popular approach to frighten young and inexperienced members of numerous Anonymous groups through claims about disclosing their IP addresses. Such options as proxy servers, VPN, Tor, I2P can help hide your IP address. Each tool has its pros and cons. Even if you are already using the above hiding methods, though, bad things can happen and your data can become exposed to interested parties. Let’s see what might happen.
General
Profiling
Profiling occurs when most traffic goes to the Internet through one exit node, such as Tor. If this happens for a long time, then it is possible to relate this activity to a specific user. The exit node may not know your IP address, but it will know what you are doing.
Solution: Do not constantly use the same Tor relays. Regularly change exit nodes (VPN servers, proxy servers), or use the Whonix OSdistribution.
Man-in-the-middle attacks (MITM)
MITM attacks are aimed at listening and modifying traffic on the exit node, such as Tor or any proxy server. An interesting attack scenario can boil down to modifying the digital signatures, GPG or SSL fingerprints, or hash sums of downloaded files on the exit node.
Solution: Be careful when you receive warnings about the validity of certificates and security keys.
DNS leaks
DNS leaks occur when an installed application can send its DNS queries using the ISP’s DNS servers. This is often the case when people using a local proxy server (SOCKS 4, 5) try to send traffic to the Tor network coming from various applications that resolve DNS names bypassing Tor.
Solution: When working with a VPN, the most convenient option is to use static DNS servers of the VPN provider or, if you have a personal VPN server, use OpenDNS servers (208.67.222.222, 208.67.222.220) or Google DNS (8.8.8.8, 8.8.4.4). To prevent such leaks when using Tor, it is recommended to use the Tor Browser Bundle or, if you really need to send 3rd party application traffic to Tor, then the most secure and versatile option is using an Isolating Proxy that allows the traffic only through the SocksPort.
There are no DNS queries on the I2P network. When you are working with an outproxy, DNS queries are performed on the outproxy itself. When SOCKS proxy in Firefox is being used, DNS leaks will occur by default. In order to get rid of this, you need to type about:config in the address bar, and click I’ll be careful, I promise! Then, find the string called network.proxy.socks, double click it and change the value to true. Now that you are using SOCKS proxy, DNS requests will also go through SOCKS.
Deanonymizing activities when in an anonymous session
This may happen when, for example, a user initiates an anonymous session and visits his Facebook page to communicate with friends. His Internet Service Provider will not know what the user is doing. But the social network, despite the fact that it does not see the real IP address, knows for sure who has logged in.
Solution: Mind what you’re logging into when using VPNs, proxies, Tor.
Simultaneous connections via anonymous and open channels
In this case, for example, if a user visits a website and the Internet connection gets lost it will be easy for the website server owner to see two simultaneously completed connections (your anonymous and open sessions) and thus find your real IP address.
Solution: Do not allow simultaneous connections to any web service/site via anonymous and open channels.
Text authorship attribution
Security researchers created an application that compares the text written anonymously and another text available on the Internet which belongs to a known author. This app determines the authorship with a high degree of probability.
Solution: This topic has not been studied enough yet. Do not publish anything that can be associated with you personally.
MAC address
Your device MAC address becomes known to a Wi-Fi access point when you connect to it.
Solution: If you are worried that the Wi-Fi access point will remember the MAC address of your network interface, just change it beforehand.
Web Browsers
Cookies
Cookies are text files with certain values stored by the application (often a browser) for different purposes, for example, authentication. It often happens that the user first visits a website without using anonymization services and the browser saves cookies. Then, this user connects to the same website using an anonymous session.
This way, the server owner can match the cookies and identify the user. Moreover, there are so-called 3rd-party cookies. For example, after you view a banner ad on a 3rd-party website, the site owner will be able to track you on all websites where this banner is located.
Flash, Adobe, Java, etc.
These things are, essentially, separate applications that run on behalf of the user. They can bypass proxy settings and set their own long-lived cookies. In addition, they are full of vulnerabilities.
Browser fingerprinting
A browser provides the server with dozens of data categories, including the so-called user agent details. All of this can form a unique digital fingerprint of your browser. You can be found by this fingerprint even in an anonymous session. You can see here what kind of data your browser sends out.
Scripts
JavaScript, which is executed on the client side, can collect even more information for the server owner, including private data. Moreover, if the site you visit is prone to XSS, then the JavaScript located on it will help the attacker carry out a cyber attack with all the ensuing consequences.
Web beacons
Web beacons/bugs are invisible web page details used to monitor visits to the site. They can additionally harvest different types of data about you. Google’s web bugs are widespread throughout the web.
HTTP Referer
An HTTP referer is an HTTP header with which the website can determine where the traffic is coming from. In other words, if you have clicked on a link that sends the HTTP referer, then the site to which this link leads will be able to find out which particular site you came from.
Common solution: Configure each browser to block each of the entities described above that can leak sensitive data. Many comprehensive articles on this issue can be found here.
Applications
It is important to understand that many applications were initially designed not so much for ensuring anonymity, but rather for stable and effective work. Below is a list of some popular applications that can independently (in the background) transmit your private data to their owners.
- Some BitTorrent clients ignore proxy settings and send traffic through open channels.
- Windows Update sends dozens of data categories to its servers, including a unique 128-bit identifier (GUID). Windows Update is also vulnerable to MITM, and therefore, an exit node like Tor can be one more source of the attack.
- License keys of paid applications or serial numbers of free ones can also be transferred to the Internet, for example, when activating or updating software, thus helping identify the user.
- Windows Media Player can independently request information about the music or exchange service data.
- Time zone data can be transmitted when you are using IRC chat via CTCP, Client-to-client protocol.
- Windows OS report sent in case of an error also contains identification data.
- Files‘ metadata may include important info: creation date, authorship, geotags, etc.
Common solution: Do not use any untrusted and unverified applications when in an anonymous session. Use special Linux distributives like Tails that cut off insecure apps, tools, and services.