“We are considering adding an extension to restrict the use of WebRTC”
bugzilla.mozilla.org
bugzilla.mozilla.org
If I were a conspiracy-minded person (I'm not), I'd have to wonder if this was some kind of corporate-driven attempt to suppress peer-to-peer networks. In fact, I do think this is being done in good faith (even though I strongly disagree), but other users will not be so understanding.
Edit: s/advertiser-driven/corporate-driven I think there are a lot of big companies, particularly social media, that have a huge vested interest in suppressing web-based peer-to-peer networks. Not claiming that's what's happening here, but the threat posed by WebRTC to those companies is very real. At present, a peer-to-peer Twitter would not be impossible to pull off technically with WebRTC, a DHT, and a modest number of STUN servers. The hard part is convincing users it's in their best interest to switch, but if that could be accomplished...
AFAIK, the conspiracy-minded people are claiming that this is a move by 'advertisers' to collect more user-identifying data.
1. https://www.reddit.com/r/netsec/comments/3dgwee/how_the_new_...
The distinction is both important, and blatantly obvious. Privacy control must remain with the one whose privacy is at stake.
That said, WebRTC from behind a VPN exposing your personal IP is a bit different. That's kind of like a light you installed rendering your curtains translucent. I'm not sure if it's the curtain's fault, or the light's, but it's certainly not what anyone had expected!
Given that OpenVPN somehow works in a way that doesn't expose your personal IP [1], I'd blame the VPN providers for saying that their VPN anonymizes web traffic when it actually doesn't.
As someone who works on sites implementing display advertising using these sorts of networks, I have nothing but contempt for the developers that are writing these JS. I've lost count of all the JS errors they cause (currently I see a lot of `Can't find variable: _body`), or just errant console.log messages (one on every browser scroll or resize was fun).
[1]: Edit: Amusingly I found a developer arguing for this WebRTC-punching, who says he's from White Ops (whiteops.com) working on anti-bot tools https://github.com/EFForg/privacybadgerchrome/issues/431#iss...
I am not a lawer. This is not legal advice.
> Although NYT shouldn't get off scott-free
Legals aside, ultimately you're (where 'you' == 'the company') responsible for what ends up on your website.
What I'm saying that this is more nuanced in practice. If you look at the JS console on some sites I work on at my company, you could come to the conclusion that we're bad developers because of all the JS errors you would see. Unfortuantly, they're made by others and we (developers) get little choice in the matter.
I have nothing but contempt for the companies that accept advertising from untrusted third parties who can offer no assurance as to the security or even the content of the code their platforms allow to run on client browsers. That doesn't even get into the tracking that the advertising platforms themselves have access to.
Host your advertising yourself and I let it through with very little exception. If it comes from another server, it's blocked.
Tons of document.write, loading dozens of more tags, everyone has their own copy of jquery, etc.
The industry just doesn't have any technical leadership in the governing bodies so there's no accountability or any expertise to check that the networks are built right.
However most networks go for the volume game so it just isn't that important to focus on JS performance. When you can spend time on jamming more expanding units and video into an ad that for the most part still works, that's better ROI than trying to optimize. Things are finally changing now with adblock and mobile usage but there are lots of long-tail shady networks who aren't legit with business practices in the first place (let alone dev) and the big companies just don't care because they're already big and engineering is a committee based process. Part of it is also the fact that there's no accountability in the industry, especially with tech.
I've been pushing for a technical certification process for ad networks (along with data/privacy handling) but it's a long road and won't happen anytime soon.
Using ad exchanges means that you always have ads available to make money from. When our ads team doesn't sell an ad directly, it'll go out to the ad exchange and get traded algorithmically.
If you're going to use display ads, you have little choice but to use an ad exchange, and no ad exchange is set up to not have content run from a third party - they simple haven't or don't care about the disadvantages that you or I see from running third party content. That industry just isn't as 'progressive' or modern.
Thankfully though, media and publishing companies (or at least the one I work at) are starting to become more away of the problems of relying on display advertising, and are starting to rely on them less and use other forms such as sponsorship deals or video ads[2]
[1]: Like this obnoxious wallpaper ad http://i.imgur.com/IPVAVwx.jpg although this is actually one of the better ones. [2]: A 'new' tech is 'server side ad insertion, where the video is inserted into the video stream on demand on the server. Pretty cool stuff https://www.brightcove.com/en/once
It's probably the worst of the worst in JS engineering sadly.
Then again between Ghostery and uBlock, I don't see most of it.
If the ad is a static image, use an <img> tag. If it's text, show the text. If it's a video, use <video>. If they want to run custom code, tell them to get lost.
Yeah, it's ultimately the ad networks' fault, but what did you expect?
(And yes, I know, this battle was lost in 1996 or thereabouts.)
You also have to factor in all the things ad servers are designed to do like control the number of impressions shown, track views, clicks, and interactions, as well as allow advertisers to rotate new creative in on-the-fly.
This way it's a little bit more than just dumping a random script into the body. However, I don't do much with ad serving so I'm not sure exactly what there is technically to curb the iFrame interacting with the parent site (apart from extra console.log statements)
And then they wonder why we run AdBlock.
The right way would be to route all the requests through Tor, not just those from the engine of the browser.
The problem is that there's a huge potential to deanonymize the user at an exit node because of all sorts of traffic other than web browsing. Do all of your chat programs encrypt everything? How about your email client? What about every daemon on your system that accesses the Internet?
At the very least, all of these can be used to fingerprint you.
WebRTC is a great example of why the user-agent turns out to be the right level to think about anonymity over Tor.
Regarding internal VPN IPs, I don't understand how this would help an attacker. If someone has broken into a VPN network and is in a position where they could make use of that data, then it's game over anyway. Otherwise, what do you want with an internal IP, besides fingerprinting?
By the way, fingerprinting no doubt is an issue, along with a dozen or so other JavaScript APIs that leak data. If you don't want to be fingerprinted, use something like NoScript. Advertisers can already uniquely identify you based on various other data leaked by JS, don't know why WebRTC has been singled out for this reason.
Your actual, ISP-assigned IP remains hidden to any site you visit.
In a time where sharing an MP3 can cost thousands of dollars, having a protocol that can share data like that without the users' consent is crazy.
It's probably a billion dollar business by now.
Estimates of 500,000 yearly C&Ds in Germany from 2011.
>http://www.wortfilter.de/news11Q1/news3945.html
C&D industry in Germany makes about 400 million a year.
Don't have numbers from other countries, but it's definitely a big business in Europe.
Swarm information is not enough as it doesn't prove that any data has been transfered.
http://arstechnica.com/tech-policy/2013/06/pirate-bay-data-s...
Earlier this week, Prenda faced a new and serious allegation: that it had actually put some pornography on BitTorrent itself, intending for it to be downloaded so that it could start a campaign of lawsuits and threat letters.
The Pirate Bay gave the data to TorrentFreak, which says that the IP address 75.72.88.156, which uploaded some porn files that Prenda has litigated over, "was previously used by someone with access to John Steele’s GoDaddy account."
http://arstechnica.com/tech-policy/2015/07/pirate-bay-founde...
http://arstechnica.com/tech-policy/2015/06/judge-finds-prend...
But then, I'm not completely insane. Laws often are.
Cases like the one I described could actually help by giving users plausible deniability, but that would just end with browser developers being pressured into disabling the feature.
One of the key features of twitter, the global reach of hashtags, would be impossible. Twitter relies very heavily on being centralised. Anyone claiming to build a decentralised twitter needs a very careful numbers-based argument as to what the bandwidth consumption of being a popular user or hashtag might be.
Ajax is one-way
If you want to prevent data from being sent to servers about you, you pretty much have to disable javascript completely though.
Web developers have been shown to be incapable of acting maturely (see http://blog.lmorchard.com/2015/07/22/the-verge-web-sucks/). They should be locked down until they can grow up.
The user can then choose to allow it for one time or to whitelist or blacklist the site.
It would force web developers to think much harder about feature detection and being non-intrusive about their usage. If someone gets nagged to enable webrtc just to read some news article it might actually cause some head scratching.
cross domain cookies, local storage, video/audio playback (at least in background tabs), ...
You could even make an argument for cross-domain javascript.
Sometimes it's insane what crap shows up in µMatrix. More requests going to 3rd party sites than the actual content that I want to look at.
Considering your emphasis, that's a bold claim. Simple to disprove with a single counter-example: Bittorrent does not communicate your internal IP to do its job
AFAIK, all major video chat applications use some variant of STUN, on which ICE is based, along with some proxying mechanism for users who truly can't connect directly to each other, which corresponds to the rest of ICE.
Note: this is a simplified explanation. Some details are glossed-over/wrong. But it will give you the basic idea. In order for someone to be able to talk to your machine they need to know your IP address. In general, this if fine because you can just tell people your IP address. However if you are on an internal LAN then you have the same external IP address as everybody else on the LAN. There needs to be a way to route packets to you.
A P2P application needs to have some way of telling the outside world, "If you want to send packets to me, this is how to do it". Of course, LANs are designed to stop people from being able to randomly send packets from outside the LAN to machines inside the LAN for obvious security reasons. So if you do this, then you are compromising the security of your LAN to a certain degree.
As I said, P2P apps need the ability to advertise how to connect to you or else you can only connect outwards. In other words, if it were a telephone, you could make outgoing calls, but couldn't receive incoming calls because nobody knows where you are. So when you start up Skype or Bittorrent, etc, it usually uses some tricks to figure out how people can contact you and advertises it.
The problem with WebRTC is not so much that it has this capability -- it needs it. The problem is that it is accessible remotely and doesn't ask for permission. You can go to a website that will jam some javascript at you that gets this information.
You can't even turn it off in the case that you don't want to use WebRTC. Requests to change the functionality to prompt the user (or at least have an option to prompt the user) when this functionality is used has been turned down. Not a lot of coherent reasoning has been given (as far as I can tell), but I imagine that the implementation is difficult and they don't think the majority of users will care.
I suppose as a middle-ground they have offered this plugin. I have my own strongly held beliefs on this topic (which may be evident from what I wrote), but hopefully this is neutral enough that you can understand the issue, do some reading and form your own opinion.
In Firefox, you can easily disable it:
1) Type 'about:config' in your address bar
2) Set 'media.peerconnection.enabled' value to 'false'. (The Default value is 'true')
That's an optimization, not a requirement.
IMHO it should be a configuration option, per-site, and off by default. WebRTC also isn't the only thing that applies to.
I have no idea what the W3C is thinking. I don't think even the W3C knows what its thinking. Its just being reactionary; trying to turn HTML5 into a "flash killer" and shoving feature after feature into the spec. I don't want to piss on progress, but I think privacy and security concerns get a backseat with W3C members, especially Google, whose very existence is dependent on finding information about users to sell to advertisers. Soon we'll need sandboxing and privacy apps to wrap our browsers in. I really hope Mozilla leads the way to pushing back on this recent mad push of thoughtless progress. A more moderate approach would be very much welcome and having more "off by default" options for easily abused features like P2P in the browser, which is what webrtc really is, makes sense.
Right now I had no idea what my browser is capable of. Can it silently turn on my camera and microphone? Probably. Can it make all sorts of crazy p2p connections to various servers/clients silently? Probably. Its all a little scary.
Article about browser feature creep, currently on frontpage: https://news.ycombinator.com/item?id=9961613
People do care about this stuff. Maybe not enough people, and maybe not the right people to do anything about it. But there are people right here on HN who do care about this stuff.
I normally rely on Hanlon's razor and assume this is the work of a bunch of short-sighted nerds that are only looking at the fun-and-shiny features. In light of stuff like BULLRUN and the methods described in PHK's amazing "Operation Orchestra"[1], I am forced to wonder who is pushing this crap - because someone is obviously trying to create a digital imprimatur[2].
[1] https://archive.fosdem.org/2014/schedule/event/nsa_operation...
To do this In Firefox:
1) Type 'about:config' in your address bar
2) Set 'media.peerconnection.enabled' value to 'false'. (The Default value is 'true')
Not just voice/video but text. That said, I'm not sure how useful the P2P aspects of text are, but being able to send files directly would be a nice ability.
uBlock is an adblocker, uMatrix has finely grained matrix controls for which http requests are even allowed to go through and requires tuning for most sites. I like having both :)
Though, I did test this on a college campus, so the network might just be leaking my internal ip, which ends up being my external ip also because of how they have the network setup. Which in hindsight is actually even scarier.
If you attack scenario is trying to circumvent authoritative governments, don't use a web browser with extra features or plugins like WebRTC turned on.
"Hiding a users 's true IP at all costs who are using a VPN" is not a reasonable design expectation for mainstream browsers. They are fixing bugs and adding features. This is an extreme edge case at best for them.
The vast majority of Chinese users who use VPNs aren't technologically savvy and just want to read the NYTimes or watch Netflix. Now any embedded ad or tracker can rat them out[1]. We shouldn't ask them to jump through 15 hoops or deal with the the slowness of Tor. A VPN offers a very good compromise of ease vs. security for casual users.
There are already forced opt-ins for accessing the microphones and cameras, this should probably be fully extended to require the user to opt-in when any WebRTC feature is used.
(VPN leakage is a valid concern though)
It would discourage reputable sites from abusing it, because users would start asking questions why a news site wants a p2p/videoconference connection.
Notifying the user after the fact sometimes works for things that are nuisances, but isn't good for privacy/security (imagine if your browser would execute unsandboxed JS and show you an icon each time it did it).
I suppose there might be a problem with IPv4 since there are so few IP addresses, so you'd still be vulnerable to targeted attacks, but it would solve the ad network problem.
Am I missing something or just underestimating the usefulness of hashing?
Plug-ins and extensions are, like, mostly non-existent entities, when released under circumstances without any actual demand for them. (compare/contrast: Java to AdBlock)
> But-but-but evil corporate overlords!
So what? They can do whatever they want on their core networks, so long as it doesn't bleed outside their edge.Sarcasm aside, what good can 192.168.1.4 possibly be to anyone?
(P2P encrypted video? Great. P2P systems in the browser driven by Javascript from any web page or ad network? Less great idea there.)
192.168.1.10
Based on this, you can probably guess the router is 192.168.1.1 and maybe even have a clue about the vendor based on the IP assigning patterns.
Then you can direct them to a page with an submitting POST <form> that makes modifications to their router settings. This is more like CSRF than XSS though.
192.168.1.1 192.168.0.1 192.168.2.1 192.168.10.1 192.168.100.1 10.0.0.1 172.30.0.1 172.30.1.1 172.30.1.1
Let's keep the big picture in mind here, people. Peer-to-peer networking is the web's big chance to weaken these huge personal data-scarfing companies. Please let's not kill it while it's just starting to grow.
With that said, now let me express an opinion (not a fact): for every technological innovation there are downsides and upsides, and it's up to people to decide if the greatness makes up for the (potential) problems. With cell phones for instance, most people accept potentially having their location disclosed to the accuracy cell towers and triangulation allow, because it's super damn convenient to be able to place and receive calls and text from just about anywhere. Of course, there's a minority that is not comfortable with this and refuses to use cell phones or takes extra precautions.
Similarly, people may be willing to accept the problems of WebRTC because its applications are enough to make up for the disadvantages. People who don't accept will find ways to not use it. If the majority of users ends up blocking it, we can conclude that people don't want a peer-to-peer web, but a more sensible conclusion will be that people were not OK with that particular implementation of peer-to-peer networking, and a different implementation is in order, or that at least patches to the current implementation are needed.
> Peer-to-peer networking is the web's big chance to weaken these huge personal data-scarfing companies.
I think that most likely, these data-scarfing companies (and other parties) will learn to use WebRTC (as it is now) for nefarious purposes, before it hurts a tiny bit of their bottom line. I bet it's much easier and there is much more immediate monetary support for developing the pieces necessary to track users with WebRTC, than to implement an actual peer-to-peer application with it.
IPv6 with its built in true end-to-end connectivity just called and wants to have a word with you, but you were stuck behind some inferior IPv4 NAT blockade.
IPV6 over POTS? How retro!
I won't even go into the debate of whether or not we want "the web" to be the support for the p2p network of the future.
> Peer-to-peer networking is the web's big chance to weaken these huge personal data-scarfing companies.
On the other hand, this particular problem is another ace in the hands of those huge personal data-scarfing companies.
Whether that's a good idea or not is certainly open to debate, but pretending that it's not happening isn't the answer.
It doesn't manage hardware or anything like that.
People use browsers as if they were an operating system. That does not make it one.
It's like calling a java virtual machine an operating system.
Looks like the Tor bundle disabled WebRTC about two years ago [1] [2]. I think a VPN user would expect the WebRTC connection to be routed via a VPN, as well, but I'm still figuring out how those work, exactly :)
0. PPTP exposes that you're on VPN and your computer's IP http://i.imgur.com/mKKfjj7.png, as does L2TP http://i.imgur.com/C68HvSN.png, while OpenVPN only exposes that you're (probably) on a VPN: http://i.imgur.com/IVQkwsd.png.
I also understand the proxy / vpn IP leaking issue. But since firefox is self reporting here, surely it would be possible to have a plugin to mask the actual IP or report garbage for those who have privacy concerns? It's overkill to disable or lobotomize the whole feature because of that one use case.