thigger 0 Posted ... Not sure how long this has been going on but I've noticed that I can now see the true IPs of people making incoming connections to my computer (nb for people worried by reading this - this /doesn't/ mean our IPs are being exposed to the outside world, only that in theory our ISP or another entity capable of monitoring our connection might be able to trick openvpn into responding to a forged packet as part of a correlation attack). Is this deliberate? I note that the potential correlation attack could be foiled (or at least reduced to a timing-only attack) if your server firewall dropped packets with the source address set to the VPN entry ip, so I wonder if the setup has changed to this instead? (tested with Draconis, Sirius, Omicron) thanks Quote Share this post Link to post
Staff 9972 Posted ... Not sure how long this has been going on but I've noticed that I can now see the true IPs of people making incoming connections to my computer (nb for people worried by reading this - this /doesn't/ mean our IPs are being exposed to the outside world, only that in theory our ISP or another entity capable of monitoring our connection might be able to trick openvpn into responding to a forged packet as part of a correlation attack).Is this deliberate? I note that the potential correlation attack could be foiled (or at least reduced to a timing-only attack) if your server firewall dropped packets with the source address set to the VPN entry ip, so I wonder if the setup has changed to this instead?(tested with Draconis, Sirius, Omicron)thanksHello!The rewriting was "excessive" because packets toward the entry-IP were dropped anyway even before.Practical consequences:- eMule KAD no more "firewalled" (+, meeting a widespread requirement from our customers)- two or more clients connected to the same Air server can't communicate with each other listening services (this is a + or a - according to different points of view).Timing attacks in theory can't be fully prevented on any low-latency network, but you can make the life of an adversary very, very hard if you use AirVPN over TOR.Kind regards Quote Share this post Link to post