Popular VPN Providers Leak Users' Details, Finds Study

Advertisement
By Indo-Asian News Service | Updated: 30 June 2015 18:39 IST
Even the Virtual Private Networks (VPNs) - which people use in the hope of avoiding mass surveillance - leak information about the user, says a study.

VPNs are getting increasingly popular for individuals wanting to circumvent censorship, avoid mass surveillance or access geographically limited services like Netflix and BBC iPlayer.

Used by around 20 percent of European Internet users, they encrypt users' Internet communications, making it more difficult for people to monitor their activities.

"There are a variety of reasons why someone might want to hide their identity online and it's worrying that they might be vulnerable despite using a service that is specifically designed to protect them," said study co-author Gareth Tyson from Queen Mary University of London (QMUL).

Advertisement

However, the new study of 14 popular VPN providers found that 11 of them leaked information about the user because of a vulnerability known as 'IPv6 leakage'.

The leaked information ranged from the websites a user is accessing to the actual content of user communications, for example comments being posted on forums.

Interactions with websites running hypertext transfer protocol (HTTPS) encryption, which includes financial transactions, were not leaked. The leakage occurs because network operators are increasingly deploying a new version of the protocol used to run the Internet called Internet Protocol Version 6 (IPv6).

Advertisement

IPv6 replaces the previous IPv4, but many VPNs only protect users' IPv4 traffic. The researchers tested their ideas by choosing 14 of the most famous VPN providers and connecting various devices to a Wi-Fi access point which was designed to mimic the attacks hackers might use.

Researchers attempted two of the kinds of attacks that might be used to gather user data. One is 'passive monitoring', which means simply collecting the unencrypted information that passed through the access point.

Advertisement

The second is DNS hijacking, which is redirecting browsers to a controlled Web server by pretending to be commonly visited websites like Google and Facebook.

The study also examined the security of various mobile platforms when using VPNs and found that they were much more secure when using Apple's iOS, but were still vulnerable to leakage when using Google's Android.

Advertisement

"We're most concerned for those people trying to protect their browsing from oppressive regimes. They could be emboldened by their supposed anonymity while actually revealing all their data and online activity and exposing themselves to possible repercussions," Tyson said.

 

Catch the latest from the Consumer Electronics Show on Gadgets 360, at our CES 2026 hub.

Advertisement

Related Stories

Popular Mobile Brands
  1. Top Deals on Phones Under Rs. 50,000 During Amazon's Republic Day Sale
  2. Amazon Great Republic Day Sale: Top Deals on Smartwatches Under Rs. 10,000
  3. OnePlus 15T Launch Timeline, Chipset Details Leaked
  4. OpenAI Has Officially Confirmed Ads Are Coming to ChatGPT
  1. OpenAI to Begin Testing Ads in ChatGPT, Says Responses Will Not Be Influenced
  2. Gurram Paapi Reddy OTT Release: When, Where to Watch This Telugu Crime Comedy Thriller
  3. Hypothetical ‘Dark Stars’ Could Rewrite Early Cosmic History, Research Suggests
  4. Honor Magic 8 Pro Air Key Features Confirmed; Company Teases External Lens for Honor Magic 8 RSR Porsche Design
  5. Lava Blaze Duo 3 India Launch Date Announced; Colour Options Teased Ahead of Debut
  6. Resident Evil Requiem Gets New Leon Gameplay at Resident Evil Showcase
  7. After ChatGPT Translate, Google Releases Multiple Open-Source Translation Models
  8. Realme Buds Clip India Launch Timeline Confirmed: Expected Specifications, Features
  9. NASA's James Webb Space Telescope Might Have Spotted Hidden Supermassive Black Holes
  10. Tere Ishk Mein Reportedly Streams on OTT Soon: All You Need to Know About Dhanush and Kriti Sanon-Starrer
Gadgets 360 is available in
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.