Posted in

What Kind of Sensitive Data You Can Unwillingly Transfer to the Internet

An IP address is the most common identifier on the Internet. Its value may vary in different situations, but as a rule, there is a popular approach to frighten young and inexperienced members of numerous Anonymous groups through claims about disclosing their IP addresses. Such options as proxy servers, VPN, Tor, I2P can help hide your IP address. Each tool has its pros and cons. Even if you are already using the above hiding methods, though, bad things can happen and your data can become exposed to interested parties. Let’s see what might happen.

General

Profiling

Profiling occurs when most traffic goes to the Internet through one exit node, such as Tor. If this happens for a long time, then it is possible to relate this activity to a specific user. The exit node may not know your IP address, but it will know what you are doing.

Solution: Do not constantly use the same Tor relays. Regularly change exit nodes (VPN servers, proxy servers), or use the Whonix OSdistribution.

Man-in-the-middle attacks (MITM)

MITM attacks are aimed at listening and modifying traffic on the exit node, such as Tor or any proxy server. An interesting attack scenario can boil down to modifying the digital signatures, GPG or SSL fingerprints, or hash sums of downloaded files on the exit node.

Solution: Be careful when you receive warnings about the validity of certificates and security keys.

DNS leaks

DNS leaks occur when an installed application can send its DNS queries using the ISP’s DNS servers. This is often the case when people using a local proxy server (SOCKS 4, 5) try to send traffic to the Tor network coming from various applications that resolve DNS names bypassing Tor.

Solution: When working with a VPN, the most convenient option is to use static DNS servers of the VPN provider or, if you have a personal VPN server, use OpenDNS servers (208.67.222.222, 208.67.222.220) or Google DNS (8.8.8.8, 8.8.4.4). To prevent such leaks when using Tor, it is recommended to use the Tor Browser Bundle or, if you really need to send 3rd party application traffic to Tor, then the most secure and versatile option is using an Isolating Proxy that allows the traffic only through the SocksPort.

There are no DNS queries on the I2P network. When you are working with an outproxy, DNS queries are performed on the outproxy itself. When SOCKS proxy in Firefox is being used, DNS leaks will occur by default. In order to get rid of this, you need to type about:config in the address bar, and click I’ll be careful, I promise! Then, find the string called network.proxy.socks, double click it and change the value to true. Now that you are using SOCKS proxy, DNS requests will also go through SOCKS.

Deanonymizing activities when in an anonymous session

This may happen when, for example, a user initiates an anonymous session and visits his Facebook page to communicate with friends. His Internet Service Provider will not know what the user is doing. But the social network, despite the fact that it does not see the real IP address, knows for sure who has logged in.

Solution: Mind what you’re logging into when using VPNs, proxies, Tor.

Simultaneous connections via anonymous and open channels

In this case, for example, if a user visits a website and the Internet connection gets lost it will be easy for the website server owner to see two simultaneously completed connections (your anonymous and open sessions) and thus find your real IP address.

Solution: Do not allow simultaneous connections to any web service/site via anonymous and open channels.

Text authorship attribution

Security researchers created an application that compares the text written anonymously and another text available on the Internet which belongs to a known author. This app determines the authorship with a high degree of probability.

Solution: This topic has not been studied enough yet. Do not publish anything that can be associated with you personally.

MAC address

Your device MAC address becomes known to a Wi-Fi access point when you connect to it.

Solution: If you are worried that the Wi-Fi access point will remember the MAC address of your network interface, just change it beforehand.

Web Browsers

Cookies

Cookies are text files with certain values stored by the application (often a browser) for different purposes, for example, authentication. It often happens that the user first visits a website without using anonymization services and the browser saves cookies. Then, this user connects to the same website using an anonymous session.

This way, the server owner can match the cookies and identify the user. Moreover, there are so-called 3rd-party cookies. For example, after you view a banner ad on a 3rd-party website, the site owner will be able to track you on all websites where this banner is located.

Flash, Adobe, Java, etc.

These things are, essentially, separate applications that run on behalf of the user. They can bypass proxy settings and set their own long-lived cookies. In addition, they are full of vulnerabilities.

Browser fingerprinting

A browser provides the server with dozens of data categories, including the so-called user agent details. All of this can form a unique digital fingerprint of your browser. You can be found by this fingerprint even in an anonymous session. You can see here what kind of data your browser sends out.

Scripts

JavaScript, which is executed on the client side, can collect even more information for the server owner, including private data. Moreover, if the site you visit is prone to XSS, then the JavaScript located on it will help the attacker carry out a cyber attack with all the ensuing consequences.

Web beacons

Web beacons/bugs are invisible web page details used to monitor visits to the site. They can additionally harvest different types of data about you. Google’s web bugs are widespread throughout the web.


HTTP Referer

An HTTP referer is an HTTP header with which the website can determine where the traffic is coming from. In other words, if you have clicked on a link that sends the HTTP referer, then the site to which this link leads will be able to find out which particular site you came from.

Common solution: Configure each browser to block each of the entities described above that can leak sensitive data. Many comprehensive articles on this issue can be found here.

Applications

It is important to understand that many applications were initially designed not so much for ensuring anonymity, but rather for stable and effective work. Below is a list of some popular applications that can independently (in the background) transmit your private data to their owners.

  • Some BitTorrent clients ignore proxy settings and send traffic through open channels.
  • Windows Update sends dozens of data categories to its servers, including a unique 128-bit identifier (GUID). Windows Update is also vulnerable to MITM, and therefore, an exit node like Tor can be one more source of the attack.
  • License keys of paid applications or serial numbers of free ones can also be transferred to the Internet, for example, when activating or updating software, thus helping identify the user.
  • Windows Media Player can independently request information about the music or exchange service data.
  • Time zone data can be transmitted when you are using IRC chat via CTCP, Client-to-client protocol.
  • Windows OS report sent in case of an error also contains identification data.
  • Files‘ metadata may include important info: creation date, authorship, geotags, etc.

Common solution: Do not use any untrusted and unverified applications when in an anonymous session. Use special Linux distributives like Tails that cut off insecure apps, tools, and services.

David Balaban is a computer security researcher with over 15 years of experience in malware analysis and antivirus software evaluation. David runs the www.Privacy-PC.com project which presents expert opinions on the contemporary information security matters, including social engineering, penetration testing, threat intelligence, online privacy and white hat hacking. As part of his work at Privacy-PC, Mr. Balaban has interviewed such security celebrities as Dave Kennedy, Jay Jacobs and Robert David Steele to get firsthand perspectives on hot InfoSec issues. David has a strong malware troubleshooting background, with the recent focus on ransomware countermeasures.

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.