Slashdot Mirror


A Flaw In Hotspot Shield Can Expose VPN Users, Locations (zdnet.com)

An anonymous reader quotes a report from ZDNet: A security researcher has found a way to identify users of Hotspot Shield, a popular free virtual private network service that promises its users anonymity and privacy. Hotspot Shield, developed by AnchorFree, has an estimated 500 million users around the world relying on its privacy service. By bouncing a user's internet and browsing traffic through its own encrypted pipes, the service makes it harder for others to identify individual users and eavesdrop on their browsing habits. But an information disclosure bug in the privacy service results in a leak of user data, such as which country the user is located, and the user's Wi-Fi network name, if connected. That information leak can be used to narrow down users and their location by correlating Wi-Fi network name with public and readily available data.

25 comments

  1. Yeah by Anonymous Coward · · Score: 0

    Ya get whatcha pay for.

    1. Re:Yeah by godel_56 · · Score: 1

      I have used Hotspot Shield a couple of times to get around simple geoblocking of articles on sites, but no one in their would use it for anything requiring serious security.

  2. Too Popular by Anonymous Coward · · Score: 0

    Hotspot Shield still exists? Everyone savvy enough has switched to a more obscure VPN already.

    1. Re:Too Popular by Anonymous Coward · · Score: 2, Funny

      Q: What's the preferred VPN for hipsters?

      A: It's pretty obscure, you've probably never heard of it.

  3. Other ways too by Anonymous Coward · · Score: 0

    Since the file on the local web server exists, couldn't you just use a JavaScript call to get the data and use it in a http post to send the data to the target site, rather than messing with dns rebinding?
    Granted it won't work if they block JavaScript, but is it a viable option?

  4. Re:That's nothing! by Anonymous Coward · · Score: 0

    Creimertard. Mod down.

  5. Generic WiFi Names by Anonymous Coward · · Score: 0

    What are best generic wifi names to try avoid giving away your location? We have language differences and therefore it depend on your country. Let us use numerals. 12345

    1. Re:Generic WiFi Names by Anonymous Coward · · Score: 0

      What are best generic wifi names to try avoid giving away your location? We have language differences and therefore it depend on your country. Let us use numerals. 12345

      Hey! Those numbers look suspiciously ARABIC!

    2. Re:Generic WiFi Names by Anonymous Coward · · Score: 0

      Netgear, D-Link, Starbucks

  6. Why worry? by Mister+Liberty · · Score: 1

    Isn't this just 'metadata'.

  7. More proof that VPN is just "security theater" by Anonymous Coward · · Score: 0

    ...and you can bet that VPN networks are being monitored and hacked.

  8. Re: That's nothing! by Anonymous Coward · · Score: 0

    The permissive TOS allows it, get over it fatso.

  9. You get what you pay for by Anonymous Coward · · Score: 0

    Only morons use a "free" VPN service and expect actual anonymity and privacy. Because, just like Google and Facebook, they make $$$$ out of collecting your data.

    1. Re:You get what you pay for by Anonymous Coward · · Score: 0

      But making a payment to a vpn service puts you under suspicion straight away.

  10. Come find me by Anonymous Coward · · Score: 0

    My SSID is "Linksys"

    1. Re:Come find me by Anonymous Coward · · Score: 0

      Based on population spread, you're likely in the Northern Hemisphere. If you are, and your SSID matches the router brand, I'd guess the United States, in a medium sized city. Maybe Salt Lake City or Boise.

  11. Depends on the VPN by Anonymous Coward · · Score: 0

    That's why finding out a VPN's verified track record and involvement in user rights' issues is important.

  12. Re: That's nothing! by Anonymous Coward · · Score: 0

    I'm just training the mods to come to the right decision every time: creimertard = down vote.

    Get use to it.

  13. Comment removed by account_deleted · · Score: 0

    Comment removed based on user account deletion

  14. Re: That's nothing! by Anonymous Coward · · Score: 0

    Creimertard. Mod down.

  15. Comment removed by account_deleted · · Score: 0

    Comment removed based on user account deletion

  16. Re: That's nothing! by Anonymous Coward · · Score: 0

    This meme is getting very old and was shit to start with. Just fuck off the lot of yez.

    - Everybody else on slashdot who's not obsessed with creimer

  17. Comment removed by account_deleted · · Score: 0

    Comment removed based on user account deletion