OpenVPN Is Open to VPN Fingerprinting
arxiv.org
arxiv.org
I think so! It looks slightly different than how I remember it but same elements in there, thanks for sharing it.
Looks like Mullvad is clear.
Also in case anyone was curious about the name and image, I haven't thought about this series in forever: https://en.wikipedia.org/wiki/W.I.T.C.H._(TV_series)
Not for me. It detected Mulvad
What governments use today for censorship and spying will tomorrow be a one-click solution for small businesses and script kiddies.
HEUR:Exploit.Script.Generic;Trojan;High;Heuristic Analysis;http://witch.valdikss.org.ru; Expert analysis
Pls be careful.
<img src="file://witch.valdikss.org.ru/a" width=0 height=0>
This is a part of the attempt that the site does to retrieve the NTLM hash of your Windows account password. See https://hackerone.com/reports/1054382 for more details.
this technique has been around for a very long time and is no way novel. applying it to OpenVPN traffic specifically isn't either.
OpenVPN traffic, even encrypted, can look unique enough somewhere in the 'stream' (to borrow the IDS/IPS term) to be reliably idenitfied.
I'm talking about the part of the connection outgoing from the VPN, not the incoming traffic to the VPN, to be clear. I know for example that China can do deep packet inspection and that there are a number of projects to attempt to thwart this technique. But you seem to be saying that the part after the VPN can be identified?
I'm talking about the part of the connection outgoing from the VPN
your understanding is correct—that the 'segment' between VPN server and final destination/employer's public-facing infrastucture is no longer traversing a VPN tunnel and therefore could not be fingerprinted as VPN traffic.if using a public VPN service provider, it would be identified, however (quite easily and at very low technical cost mind you), based on source address, as public VPN service provider netblocks are well-documented.
see, for example: https://github.com/X4BNet/lists_vpn (first search engine result for me querying "vpn ip list")
To address your direct question, whether or not a service can detect that you are reaching it with a VPN service in the middle, the answer is a soft maybe. There are several heuristic methods, but they will not be entirely reliable and using them will risk false positives. Most service operators probably wouldn't go beyond filtering of known VPN services, which is of course widely implemented.
One reliable method is active probing of the traffic source, which is sometimes done, but it comes with some hazards for the service operator and is often easy to defeat.
i.e. if one uses the tls-crypt option?
As I understand it, that encrypts the handshake protocol such that simple data value matching will not work, and one would have to either use length and/or timing matches.
https://www.usenix.org/conference/usenixsecurity23/presentat...
[0]https://blog.torproject.org/obfsproxy-next-step-censorship-a...
My question is how do they detect that I am using a VPN and is there any workaround to access their site when I continue using VPN?
You might be able to get around this by paying a provider like ProtonVPN extra for a static IP outside of the known range associated with ProtonVPN
If you want to avoid a Mitm from detecting that you are using a VPN your best bet is probably to use some kind of tunnel that looks like regular https traffic. which means it uses TLS either with TCP or QUIC on port 443.
the boilerplate of the corporate face insists its for your businesses and their connectivity, so you could argue that confidentiality doesnt really include clandestine or obfuscated traffic presence at all.
However, you could also argue for OpenVPN (and several others) that as a security tool they should at least consider Goguen and Meseguer type noninterference as a conformant operation model by reducing the awareness of the traffic.
Of course it's also meant for that.
I can't say this would be much more of a weekend project with spicy.