Automatically translated.View original post

Several free VPN apps on Android are unsafe.

Several free VPN apps on Android are unsafe to use.

According to a report by The Hacker News website, it cited research presentations from three research teams including the University of Michigan, the University of New Mexico, and the IIT Delhi Institute at the NDSS Security Conference in February. The research discussed the use of the MVPNalyzer tool, a tool for monitoring, analyzing, studying mobile phone versions of VPN applications. The tool was developed by VPNalyzer, a tool for analyzing desktop versions of VPN applications. Interestingly, the free VPN applications available for download on the official app stores of Android users like Google Play Store are more than 281. The apps have many vulnerabilities that can affect the security and privacy of users, and worryingly, they have more than 2.4 billion downloads from users around the world. The major vulnerabilities are as follows:

The first and most important vulnerability, Tunnel Hijacking.

In reviewing VPN applications, the group found that five apps on the Google Play Store downloaded the Configuration file, which is a file to command the app to contact the designated server down like an unencrypted file. If the hacker is on the same network, it can intervene to overwrite the value to replace the user's contact with the VPN provider's server. It turns out to be a contact with the hacker's server. 5 applications with the server name the application contacted for use are as follows:

BambooVPN: Turbo Fast VPN (free.vpn.unblog.proxy.bamboovpn)

VPN Pro (com.nebulatech.voocvpnpro)

Free VPN (com.appoxide.freevpn)

Hexa VPN (com.secure vpn.proxy)

101 VPN (com.shwe.vpn101)

The second vulnerability, data leakage (Leak).

Investigating security, the research team found that out of 29 applications, 24 were leaked in DNS traffic, leaking information about what websites users were accessing to the outside world. These applications had 360 million downloads, of which 6 were leaked to the outside world, and 4 were used without encryption.

In a separate review from the above review, more than 169 app providers were detected to have made no attempt to disguise the traffic of Disguisse, making it easy for government sensor agencies to detect and block its use and creating risks for users.

The third vulnerability, tracking behavior.

People tend to use VPNs for privacy, such as avoiding being tracked, but these free VPNs track user behavior. Over 76 applications send the advertiser an Advertisement ID that matches user behavior.

In addition, more than 80% of the 246 free VPN applications have been sent to advertisers, including mobile phone models, screen sizes, and operating system versions. Moreover, one application has been found to send Exact Location to advertisers, so that many providers violate user privacy.

The fourth vulnerability. Very weak elements (setup).

The research team also found many other concerns on free VPN applications, such as: over 89% of all applications have a single layer of authentication, such as password usage or Certificate use, rather than both at the same time. Not only that, about 1 in 5 of all applications use obsolete encryption systems, use Blowfish cipher encryption, and triple DES, making them easy to penetrate. These two encryption methods have security vulnerabilities for hackers to access. Yeah, like CVE-2016-6329 and CVE-2016-2183.

# Trending # lemon 8 diary # vpn # Android # freedomhack

2 days agoEdited to

... Read moreจากประสบการณ์การใช้งาน VPN บนระบบ Android ผมได้สังเกตเห็นว่าหลายคนเลือกใช้แอป VPN ฟรีโดยไม่รู้ถึงความเสี่ยงที่ซ่อนอยู่เบื้องหลังงานวิจัยล่าสุดจากทีมวิจัย 3 สถาบัน ซึ่งแสดงให้เห็นถึงช่องโหว่ในการใช้งาน VPN ฟรีหลายแอปที่มีผลกระทบอย่างมากต่อความเป็นส่วนตัวและความปลอดภัยของผู้ใช้งาน หนึ่งในช่องโหว่ที่น่ากลัวคือการเข้าสวมรอยอุโมงค์ (Tunnel Hijacking) ซึ่งเกิดจากการที่แอปบางตัวดาวน์โหลดไฟล์การตั้งค่าที่ไม่ถูกเข้ารหัส ทำให้แฮกเกอร์ในเครือข่ายเดียวกันสามารถแทรกแซงและเปลี่ยนเส้นทางข้อมูลจากเซิร์ฟเวอร์ VPN ไปยังเซิร์ฟเวอร์ที่แฮกเกอร์ควบคุมแทน ส่งผลให้ข้อมูลทั้งหมดของเราเสี่ยงถูกขโมยและสอดแนมได้ง่าย นอกจากนี้ การรั่วไหลของข้อมูล (Leak) ยังเป็นอีกประเด็นที่น่ากังวล เพราะข้อมูลการเข้าชมเว็บไซต์ผ่าน DNS ถูกเปิดเผยออกไป ทำให้ความเป็นส่วนตัวที่คาดหวังจากการใช้ VPN ถูกทำลายลง ผู้ใช้จำนวนมากไม่รู้ว่าแอป VPN ที่เลือกใช้อาจไม่ได้เข้ารหัสข้อมูลเสียด้วยซ้ำ การติดตามพฤติกรรมผู้ใช้งานก็ยังเป็นปัญหาใหญ่ ผู้ให้บริการ VPN ฟรีเกินกว่าครึ่งทำการส่งข้อมูลตัวระบุผู้ใช้ และข้อมูลอุปกรณ์ให้กับผู้โฆษณา ซึ่งเป็นการละเมิดความเป็นส่วนตัวอย่างมาก เดินทางที่ใช้ VPN เพื่อหนีการถูกติดตามกลับกลายเป็นถูกติดตามแบบละเอียดแทน สุดท้าย ยังมีความอ่อนแอในระบบยืนยันตัวตนและการเข้ารหัสที่ล้าสมัย ซึ่งเปิดโอกาสให้แฮกเกอร์เจาะเข้าสู่ระบบได้ง่าย การใช้มาตรการความปลอดภัยสองชั้นและอัลกอริธึมการเข้ารหัสที่ทันสมัยจึงเป็นสิ่งจำเป็นอย่างยิ่งสำหรับการปกป้องข้อมูลของผู้ใช้งาน จากสิ่งที่ผมเรียนรู้ แนะนำให้ผู้ที่ต้องการใช้ VPN ควรศึกษาข้อมูลผู้ให้บริการให้ดี เลือกใช้แอปที่มีรีวิวดี ได้รับการตรวจสอบความปลอดภัย และไม่ให้บริการฟรีอย่างสมบูรณ์แบบโดยแลกกับข้อมูลส่วนตัว รวมถึงไม่ควรเปิดเผยข้อมูลสำคัญหรือทำธุรกรรมที่มีความเสี่ยงผ่านแอป VPN ที่ไม่เชื่อถือ เพื่อปกป้องความปลอดภัยในโลกออนไลน์ได้อย่างแท้จริง