Popular VPN Providers Leak Users' Details, Finds Study

Advertisement
By Indo-Asian News Service | Updated: 30 June 2015 18:39 IST
Even the Virtual Private Networks (VPNs) - which people use in the hope of avoiding mass surveillance - leak information about the user, says a study.

VPNs are getting increasingly popular for individuals wanting to circumvent censorship, avoid mass surveillance or access geographically limited services like Netflix and BBC iPlayer.

Used by around 20 percent of European Internet users, they encrypt users' Internet communications, making it more difficult for people to monitor their activities.

Advertisement

"There are a variety of reasons why someone might want to hide their identity online and it's worrying that they might be vulnerable despite using a service that is specifically designed to protect them," said study co-author Gareth Tyson from Queen Mary University of London (QMUL).

However, the new study of 14 popular VPN providers found that 11 of them leaked information about the user because of a vulnerability known as 'IPv6 leakage'.

Advertisement

The leaked information ranged from the websites a user is accessing to the actual content of user communications, for example comments being posted on forums.

Interactions with websites running hypertext transfer protocol (HTTPS) encryption, which includes financial transactions, were not leaked. The leakage occurs because network operators are increasingly deploying a new version of the protocol used to run the Internet called Internet Protocol Version 6 (IPv6).

Advertisement

IPv6 replaces the previous IPv4, but many VPNs only protect users' IPv4 traffic. The researchers tested their ideas by choosing 14 of the most famous VPN providers and connecting various devices to a Wi-Fi access point which was designed to mimic the attacks hackers might use.

Researchers attempted two of the kinds of attacks that might be used to gather user data. One is 'passive monitoring', which means simply collecting the unencrypted information that passed through the access point.

Advertisement

The second is DNS hijacking, which is redirecting browsers to a controlled Web server by pretending to be commonly visited websites like Google and Facebook.

The study also examined the security of various mobile platforms when using VPNs and found that they were much more secure when using Apple's iOS, but were still vulnerable to leakage when using Google's Android.

"We're most concerned for those people trying to protect their browsing from oppressive regimes. They could be emboldened by their supposed anonymity while actually revealing all their data and online activity and exposing themselves to possible repercussions," Tyson said.

 

Get your daily dose of tech news, reviews, and insights, in under 80 characters on Gadgets 360 Turbo. Connect with fellow tech lovers on our Forum. Follow us on X, Facebook, WhatsApp, Threads and Google News for instant updates. Catch all the action on our YouTube channel.

Advertisement

Related Stories

Popular Mobile Brands
  1. Motorola Edge 70 Pro Arrives With a 6,500mAh Battery at This Price in India
  2. Elden Ring Movie Film Adaptation Release Date, Full Cast Revealed
  1. NASA’s Curiosity Rover Finds Crater Filled With Sand, Alters Drilling Plans
  2. Control Ultimate Edition Arrives on iPhone and iPad With Touch Controls, Universal Purchase
  3. Asus ExpertBook Ultra With Intel Core Ultra X7 Series 3 CPU Launched in India Alongside ExpertBook P3, ExpertBook P5 Series
  4. Boat Aavante Prime X Soundbar Launched in India With Dolby Atmos, Wireless Satellite Speakers: Price, Features
  5. Qualcomm CEO Reportedly Visits Samsung Foundry in Korea to Discuss Producing 2nm Chips
  6. Coinbase Announces USDC-INR Trading Services for Users in India
  7. Redmi K Pad 2 Launched With 8.8-Inch 3K Display, Dimensity 9500 Chip: Price, Specifications
  8. Suyodhana OTT Release Date: When and Where to Watch This Telugu Mystry Thriller Online?
  9. OnePlus Watch 4 Launch Appears Imminent as Listing Confirms Snapdragon W5 Chip, OxygenOS Watch 8
  10. Sennheiser CX 80U, Sennheiser HD 400U With USB Type-C Connectivity Launched in India: Price, Features
Download Our Apps
Available in Hindi
© Copyright Red Pixels Ventures Limited 2026. All rights reserved.