Re: [rtcweb] Please require user consent for data channels

Daniel Roesler <diafygi@gmail.com> Fri, 17 July 2015 19:20 UTC

Return-Path: <diafygi@gmail.com>
X-Original-To: rtcweb@ietfa.amsl.com
Delivered-To: rtcweb@ietfa.amsl.com
Received: from localhost (ietfa.amsl.com [127.0.0.1]) by ietfa.amsl.com (Postfix) with ESMTP id 55ECC1B2B7D for <rtcweb@ietfa.amsl.com>; Fri, 17 Jul 2015 12:20:32 -0700 (PDT)
X-Virus-Scanned: amavisd-new at amsl.com
X-Spam-Flag: NO
X-Spam-Score: -2
X-Spam-Level:
X-Spam-Status: No, score=-2 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, FREEMAIL_FROM=0.001, SPF_PASS=-0.001] autolearn=ham
Received: from mail.ietf.org ([4.31.198.44]) by localhost (ietfa.amsl.com [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id xz3g31yiIv2Q for <rtcweb@ietfa.amsl.com>; Fri, 17 Jul 2015 12:20:31 -0700 (PDT)
Received: from mail-qk0-x22b.google.com (mail-qk0-x22b.google.com [IPv6:2607:f8b0:400d:c09::22b]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by ietfa.amsl.com (Postfix) with ESMTPS id 21C931A908B for <rtcweb@ietf.org>; Fri, 17 Jul 2015 12:20:31 -0700 (PDT)
Received: by qkfc129 with SMTP id c129so32904352qkf.1 for <rtcweb@ietf.org>; Fri, 17 Jul 2015 12:20:30 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20120113; h=mime-version:in-reply-to:references:from:date:message-id:subject:to :cc:content-type; bh=cU7BX3xGOr3++TTJsc82lID6bUNFBrzILkVieKeU5Pg=; b=BeYFsBfxfJ8qiYeK62iUDezSAnNwxuLn2iKXoZSGBdIm99EMJ9Er4yhM1s1vTUfDyw pdWIKpZrvL4bTPfdXAlXVWCnIvCOssmIozluSthx2njSt8jAesvoOz0B6D01ltNxMq2w iZAUcdtMgZxoVZItaeLp0mUq26CQNeu6i5bcJ70FJFpIe8pAjonIf9cTFH5gi+sZ75Px FBoO8MpCefbSm5PwCq3Ty76eV2egNzCn82M1bfjYw1dQSlB4XSqt9yeoIgUEUz+UbPm6 Xd3ZSwMRVrcRF4qD5z+FTVZ/wPtxOsXJNwAmNNcP6hLRG939XBNbNOVZCqVJsITEc2Fk 5KXw==
X-Received: by 10.140.234.142 with SMTP id f136mr21773444qhc.16.1437160830440; Fri, 17 Jul 2015 12:20:30 -0700 (PDT)
MIME-Version: 1.0
Received: by 10.140.108.130 with HTTP; Fri, 17 Jul 2015 12:20:00 -0700 (PDT)
In-Reply-To: <55A95364.2070806@gmail.com>
References: <CA+65OspMD_PVjk0BXh7t4LtjmFDcDatoeNjFQOO_OVtC-Br+OA@mail.gmail.com> <CAOJ7v-0UBGtP0-atxP7X4OTj-H6Lost5o42aAS65mA6CEqcQsw@mail.gmail.com> <CA+65OsrhXHK+cRAFLCZFt+34vr8eRhj+CN3DgznUBfSwmWYggw@mail.gmail.com> <CAOJ7v-24VCW6kkn7LOLkqZzhYEU0r=nmd_F7Zns1rnyqKN6xAg@mail.gmail.com> <55A95364.2070806@gmail.com>
From: Daniel Roesler <diafygi@gmail.com>
Date: Fri, 17 Jul 2015 12:20:00 -0700
Message-ID: <CA+65OsoChhMT9jVznvTUNLZKNw85UED-Z5+QkYq4aVG8fL-4Yg@mail.gmail.com>
To: Sergio Garcia Murillo <sergio.garcia.murillo@gmail.com>
Content-Type: text/plain; charset="UTF-8"
Archived-At: <http://mailarchive.ietf.org/arch/msg/rtcweb/pMp6MSSEpUo1rMwBqr56GoEmjwk>
Cc: rtcweb@ietf.org
Subject: Re: [rtcweb] Please require user consent for data channels
X-BeenThere: rtcweb@ietf.org
X-Mailman-Version: 2.1.15
Precedence: list
List-Id: Real-Time Communication in WEB-browsers working group list <rtcweb.ietf.org>
List-Unsubscribe: <https://www.ietf.org/mailman/options/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=unsubscribe>
List-Archive: <https://mailarchive.ietf.org/arch/browse/rtcweb/>
List-Post: <mailto:rtcweb@ietf.org>
List-Help: <mailto:rtcweb-request@ietf.org?subject=help>
List-Subscribe: <https://www.ietf.org/mailman/listinfo/rtcweb>, <mailto:rtcweb-request@ietf.org?subject=subscribe>
X-List-Received-Date: Fri, 17 Jul 2015 19:20:32 -0000

On Fri, Jul 17, 2015 at 12:11 PM, Sergio Garcia Murillo
<sergio.garcia.murillo@gmail.com> wrote:
> If I have understood the looong thread correctly, the issue is that Chrome
> overrides the OS default route and sends the STUN requests via all available
> interfaces, therefore leaking the IP addresses on the process.

Firefox has the same behavior in OSX. So it might also be OSX not
really sending all the traffic through the VPN (like the setting
says).

Would love someone more competent than me to investigate in both OSX
and Windows. I'd be willing to fund VPN subscriptions for them to use
with their research (Private Internet Access supports L2TP, PPTP,
OpenVPN, SOCKS, and they have their own client, but other VPNs are
reported as having their own clients leak the IP, so I'm willing to
fund those, too).

Daniel