Encryption – Eraser https://eraser.heidi.ie Secure Erase Files from Hard Drives Mon, 28 Sep 2020 10:09:19 +0000 en-US hourly 1 https://wordpress.org/?v=6.8.2 https://eraser.heidi.ie/wp-content/uploads/2019/07/cropped-eraser-avatar-32x32.png Encryption – Eraser https://eraser.heidi.ie 32 32 Brave Browser Tips and Tricks https://eraser.heidi.ie/brave-browser-tips-and-tricks/ Thu, 17 Sep 2020 12:50:37 +0000 https://eraser.heidi.ie/?p=1470

The popularity of the Brave browser has grown tremendously due to its emphasis on privacy and giving users more control over their activity. You’re no longer the product, as is the case with conventional browsers using trackers to sell information to marketers and profiting from your personal data. What’s more, by blocking trackers and using less memory during operation, it provides a faster browsing experience for users, be it on desktop or smartphones. Once you install it, here are ways how you can set it up to get the most out of the browser.

Getting things ready

As you shift your activities to the Brave browser, two things will be important to ensure that you have smooth operations going forward:

  • Setting Brave as your default browser

That way, whenever you’re opening links, going through your social sites, accessing your mail and other activities, you will remain protected by Brave’s security shields. To have it as your default browser, you will get this option under the settings menu. The easiest way is to simply launch the browser and click on the button prompting you to make it the default browser.

Brave Default
  • Importing your settings

Like moving into a new home and bringing your furniture with you, you’ll want to bring over your bookmarks, saved passwords, browsing history and cookies from your previous browser. The import window will enable you to select the specific browser data that you will want to bring to Brave.

You can import them right from the Welcome Tour after installing the browser. In case you skipped this bit, launch the browser and click on the horizontal lines that are at the upper right corner, select settings, and in the window that pops up, click on “Import bookmarks and settings”. 

Brave Settings

Select the browser that you want to get the data from, then click on “Import”

 

Personalising the browser

Next is tweaking the browser to suit your individual preferences. This is where aspects like selecting the colour schemes and extension tools for your browsing experience come in.  Here are a couple:

  • Enable Dark Mode

  1. Go to settings
  2. Click on the Appearance tab
  3. On the Brave Colours options, change from Light to Dark. 
Brave Dark Mode
Brave Dark Mode

If you already have dark mode for your OS, you can simply inherit this by clicking on “Same as Windows” option thus giving it the same appearance with the rest of the system, so that whenever you change the OS settings the browser will automatically adapt to it. 

  • Choosing a customised theme

You can get more customisable themes from Chrome Webstore.

Here, you can use any of the themes just as you would on Chrome. Select the preferred theme, then click on “Add to Brave”. For instance, let’s pick on Oceanic theme:

brave-customise-theme

This will be quick and straightforward, and it gives you the opportunity to pick from a wide assortment of themes to suit your particular taste.

Increase your privacy when browsing

  • Use DuckDuckGo as the default search engine

To take your privacy a notch higher, you can choose to set the default search engine to DuckDuckGo. This is because alternatives like Google will keep a record of the queries that you type into the search bar.  Brave itself shields you from intrusions like the cookies, ads, and pop-ups, but when you’re using Google and similar search engines your privacy may be compromised. Making the switch to DuckDuckGo will ensure that your searches aren’t tracked. This is also accessed from the Settings window as shown below.

Brave DuckDuckGo default

Select DuckDuckGo, and you’re good to go. 

  • Use Brave with Tor

Using Brave’s private window, DuckDuckGo and (The Onion Router) together will make it extremely difficult for your online activities to be tracked. The websites being visited will also find it hard to identify or track the IP addresses that access it when browsing with this mode. You can use the browser with Tor by selecting the option from the drop-down menu after clicking the three horizontal lines on the top right corner. 

Brave with Tor

Make money with Brave Ads

The browser also allows you to monetise the amount of time you spend online. That way, over the course of your normal browsing activities, you will get to rake in some cheddar. This is through the Brave rewards, which can be accessed by clicking that triangle that’s on the upper right section of the browser.

Brave Ads

From the ads section, you can set the frequency of the number of ads that you want. You get to choose between 1 – 5 ads per hour. Ads will pop up in a non-intrusive way as you carry on with your normal browsing. When you view the ad and click on it, it will direct you to the target site, and you earn BAT (Basic AttentionTokens) in the process.

Are you a publisher or content creator? Joining the Brave Rewards Creators program will enable you to earn BAT tokens through tips from visitors coming to your website or channel and viewing your content. You also earn when you refer new users to Brave.  

Reward your favourite sites

On the other end of the spectrum, you can support content creators using BAT. This is basically like tipping the content creators for a job well done. 

This is through the auto-contribute feature, that enables the sites to receive your contributions based on how much you use the sites. Brave also gives you the flexibility to set how the payments will be made.  Click on the section indicated below to access the settings.

brave-award-sites

The wallet that the browser creates for the BAT tokens can also be linked to Bitcoin and other digital assets. You can also purchase the BAT tokens from cryptocurrency exchanges, or get BAT from special promotions that are done by Brave. 

Sync desktop browser and mobile app

This enables you to sync your browser across your different devices. Access the sync option from the dropdown menu, and click on “Start a new Sync Chain” and select phone/tablet. It will provide you with a QR code that can be scanned.

Brave Sync Desktop Browser with Mobile

From your other device, access the sync settings on the Brave app, select “I have a Sync Code” and scan the QR on your desktop browser.

Brave Sync QR Codes

If you’re syncing to another desktop PC or laptop, select “Start a new Sync Chain” and pick computer. You will be provided with 24 unique words.  On the target computer, select “I have a Sync Code” and enter these words.

Note that the words are sensitive, and should be treated like a password. If anyone accesses them, they can compromise your synced data.

Block social media

Some sites have single-sign on for Google and Facebook. Brave has a feature that disables this, and also blocks the embedded posts from LinkedIn, Twitter etc. This is accessed from the Settings, and you get to toggle the options as you see fit. 

Brave Block Social Media

In addition to enhancing your privacy, it also helps you in saving on the costs that you spend on data, since you will not be downloading the extra content. Less power is also spent, saving your device’s battery life. Let’s get more into this with the next Brave browser tip.

 

Save more power

Disabling scripts on the sites you visit also comes in handy in reducing your device’s energy consumption. 

For instance, when browsing through BBC news site, you may simply want to read news articles and not waste data bundles or power on the numerous videos and similar content that will be loaded as a result of scripts. To block them, click on the Brave Shields icon and toggle on the Scripts Blocked option.

Brave save more power
]]>
VPN Kill Switch 101: What It Is, And How It Works https://eraser.heidi.ie/vpn-kill-switch-101-what-it-is-and-how-it-works/ Mon, 07 Sep 2020 11:41:31 +0000 https://eraser.heidi.ie/?p=1445

If you’re already using a VPN, it means you’re keen on your privacy. While getting a VPN is the first step in protecting your online identity and activities, there are unforeseen risks that lie ahead, and potentially lead to your identity being unmasked and online activity tracked. One of the major threats is the VPN connection dropping due to network issues, which can leave your IP address exposed. That’s where the VPN Kill Switch kicks in.

What Is A VPN Kill Switch?

It goes by different names. Some VPN providers call it the Internet Kill Switch. CyberGhost labels it ‘Connection Guard’. With ExpressVPN, it’s been called the ‘Network Lock Kill Switch’. They all function on the same principle.

Basically, the Kill Switch is a feature that will automatically shut down your internet connection immediately you’re disconnected from the VPN service. That way no data will be sent over the network until you enable the VPN. If the Kill Switch has been turned off, then the internet connection would still be used as normal even when you’ve not connected to the VPN. 

There are two general modes of how the Kill Switch operates:

  • You can have an Active Skill Switch that detects the moment you lose the connection to the VPN service, which sends the information to the device and stops it from connecting to other networks. 
  • On the other hand, a Passive Kill Switch doesn’t wait for information from the VPN server. Immediately it loses the signal from the VPN server, it will automatically stop your device from sending out traffic.

In a nutshell, with a Kill Switch activated: 

Lost VPN Connection = No Internet Connection 

Why Do You Need A VPN Kill Switch?

The moment your network connection drops, your device will default back to its assigned public IP address. All your activity from that point onwards can be traced back to you. What’s worse is that you may not know it has even happened. For instance, those who remain connected to the VPNs for a long time – like when downloading torrents, they may not be around the computer to notice the drop in connection, and the device with default to the public connection without you knowing it. 

As an extra security measure, the VPN Kill Switch ensures that there will be no chance of your IP getting accidentally exposed in case the security of the internet connection is compromised. Since hacking a VPN server is not feasible, hackers opt to use cookies, spyware and malware, waiting for the VPN connection to drop for them to attempt mounting an attack on the phone, computer or network. It may also be a surveillance issue, for those in authoritarian regimes where online activities are constantly being monitored, and you don’t want an IP leak putting you in Big Brother’s line of sight. 

Say you were in the middle of an online transaction, whistle-blowing, or browsing a geo-restricted website, and then your VPN connection drops – even without your interference. This exposes your IP address, thus location. The site will notice that you’re reaching it from an unpermitted zone, and lock you out. Whatever activity you were doing at that time, be it accessing documents, streaming some entertainment or educational material, or even downloading a media file,  it will instantly get halted. 

Mainstream VPN providers come with the Kill Switch feature, from ExpressVPN, CyberGhost and NordVPN, to Private Internet Access and IPVanish. The mode of operation may vary based on the particular advances and capacity of the provider, but the gist of it is the same. For the mentioned ones, the Kill Switch will kick in immediately there is an interference with your internet connection. 

Is The VPN Kill Switch Automatic?

This varies depending on the VPN provider. For instance, with ExpressVPN, the Kill Switch will be activated the moment you make a connection since it has been enabled by default.  For others like VyprVPN, you’ll need to access the settings of the application to activate it. 

For some of the VPN providers, you also get to tweak the Kill Switch settings, to select when you want the feature to kick in. For instance, VyprVPN allows you to toggle between two settlings: ‘Application Level’ – the  Kill Switch is activated when the internet connection is disrupted while you’re running the application; and ‘System Level’ – here the Kill Switch will be active as long as you’ve been logged into the VPN, even when you don’t have the application itself running. 

Why Would You Get Disconnected?

Disruptions to your internet connection can happen due to a myriad of reasons. Don’t fret, you don’t need to get into geek-mode and start worrying about them, as long as the VPN installation process was properly followed. You may need to tweak some of the settings to suit your particular situation though. For instance, when it comes to the selected VPN protocol with ExpressVPN, switching from UDP (default setting) to TCP protocol may result in better connection stability. 

A common issue is a weak signal from your ISP, or a congested network. This is bound to affect the stability of your connection to the VPN provider. This also includes situations when you’re accessing the internet through a Wi-Fi connection, where if it is unstable then it will definitely affect the performance of the VPN service. 

The antivirus, firewall or anti-spyware of your device may also be interfering with the operation of the VPN service. In this case, you should include the VPN connection and an exception in the settings of the particular antivirus or antimalware program, whitelisting it. 

Conclusion

You use a VPN to protect your online identity, preventing your IP address, personal information and internet traffic from being exposed.  The VPN Kill switch will reinforce your defence, ensuring that there will be zero possibility of a data leak from your device. This is more critical if you use a connection for long periods, since it makes you more prone to issues that come with VPN network reliability.

Need a VPN?

]]>
What Is VPN Obfuscation And How Does It Protect You? https://eraser.heidi.ie/what-is-vpn-obfuscation-and-how-does-it-protect-you/ Fri, 04 Sep 2020 13:18:48 +0000 https://eraser.heidi.ie/?p=1439

So you’ve got the core elements covered. You’ve set up the VPN connection, and your data is private and secure. Your internet traffic won’t be traced back to you, and the information sent over the VPN tunnel is encrypted. Your identity is safe. However, there’s just one ‘problem’. Your ISP and government have the tools needed to detect that you’re using a VPN. Sure, they can’t read the traffic itself and know what you’re accessing or sending over the internet, but it does put you on their watchlist. Governments keen on identifying VPN traffic want to gather intelligence on what persons in their territories are up to – and in authoritarian regimes they go further to ban VPNs altogether. For the ISPs, it usually comes down to issues related with copyrights. 

There are regions where VPN users are even fined. For instance, in China, you must register with the government before being permitted to use a VPN, and in Chongqing province, VPN users failing to meet the legal requirements are fined $2,210.  In Iran, it can land one in prison for up to a year, and the population is restricted to just a couple of government-approved VPNs. Turkey and Belarus regimes are strict on internet usage, and within the UAE and Oman one can only pick from the list of ‘approved’ VPNs. Russia actively cracks down on VPN providers, with Putin legislation banning VPNs already in effect

So, you don’t want Big Brother to know you’re using a VPN service. That’s where VPN obfuscation comes in. 

What Is VPN Obfuscation?

It’s basically masking your internet traffic so that it hides that you’re using a VPN, and instead shows that data from your device is ordinary internet traffic. It comes by different names, including ‘stealth VPN’ and “VPN obfuscation”. Some providers have their unique names for it, like “NoBorders mode” with Surfshark VPN and “Chameleon protocol” when using VyprVPN.

It doesn’t change your traffic, but rather masks it, obscuring it from anyone looking to pinpoint VPN traffic. That way you can continue transferring the encrypted data, but also circumvent blocks that have been placed for VPN traffic, making your internet usage indistinguishable from the rest of the general public.

How VPN Obfuscation Works

When connecting to the internet and exchanging data over networks, the protocols used have their distinctive signatures. Third parties analysing the data packets can detect the signature. 

For instance, the most common VPN protocol, OpenVPN, has its digital signature. When the third party is analysing your connection, be it a government body, hacker, or the ISP you’re using, methods like the deep packet inspection are used.

VPN obfuscation comes in to dupe those analysing the traffic into believing that you’re using normal data packets, while in actual sense the VPN is still transmitting the encrypted data packets over its secure tunnel. 

Different methods can be used when masking the traffic. The goal is generally to add an encryption layer that makes the VPN traffic look like regular traffic. These include: 

This is part of the Tor Project, which was developed due to Tor traffic being blocked in territories like China. It will obfuscate the Tor traffic, preventing it from being detected.

While Obfsproxy was primarily developed for being used with Tor, you can also use it with OpenVPN. The setup uses different pluggable transports to hide the OpenVPN traffic, which will vary based on the block that is to be circumvented. For instance, obfs4 is one of the pluggable transports used with OpenVPN traffic, where it scrambles the traffic and makes it essentially look like nothing meaningful. 

This is open-source software that routes the VPN traffic through a TLS/SSL tunnel. Anyone snooping on the data packets will think that it is regular HTTPS traffic, because the TLS/SSL is one of the encryptions that is used by HTTPS.

Here, the OpenVPN traffic is disguised using the simple XOR cipher, which replaces the values of the bits of data, that way the data packet inspection methods will not detect the OpenVPN signature. Speaking of which, malware developers have also taken advantage of this to prevent their malicious code from being detected. The simplicity of the cipher means that it doesn’t always offer much protection especially from authoritarian governments cracking down on VPN usage. 

Mainstream VPN providers also offer obfuscation features as part of their services. These include:

  • ExpressVPN, which is renowned for even bypassing restrictions in countries like China that have loads of blocks, and has over 2000 servers for its network.
  • NordVPN, that also enables you to bypass the VPN blocks including regional firewalls like the Great Firewall and circumventing all regional geo-restrictions. 
  • SurfShark, with its over 1000 servers spread across over 61 countries, and where you get to obfuscate your VPN traffic by using the “NoBorders” feature
  • PrivateVPN, where you’ll need to enable the “Stealth VPN” feature, after which no one will detect that you’re connected to a VPN. 
  • Hotspot Shield that features fast connection speeds and relays your traffic through the “Catapult Hydra” protocol to ensure that it is secure and discreet. 
  • VyprVPN, where the feature is available by switching to the Chameleon protocol, obfuscating 256-bit OpenVPN encrypted traffic then transmitting it using port 443.

How VPN Obfuscation Protects You

Here are the benefits of VPN obfuscation, and how it keeps you safe from prying eyes:

  1. Bypassing government censorship

For territories with heavy restrictions on internet usage – like China, Iran, Pakistan, Egypt and North Korea, VPNs are widely used. Here, the governments block traffic to specific sites, like the “Great Firewall” of China that prevents users from accessing and using sites like Twitter, Pinterest, Google, The New York Times, Facebook and WhatsApp. As such, people turn to VPNs, where the content of the traffic is encrypted. The VPN, in turn, routes its traffic through secondary servers, that way when one is inspecting it, the traffic would be seen to have been directed to the VPN server, and not the banned website. However, the government knows this. The regimes are well aware that its citizens are using VPNs to circumvent the blocks. So they put in measures to block the VPN traffic. 

Governments can block VPN traffic in different ways. For instance, if they know the VPN server, they’ll simply block the traffic that is directed to it. This is why VPN providers keep on changing servers. Port 1194 that is usually used by OpenVPN traffic, can also be blocked. Techniques like Deep Packet Inspection (DPI) can be used, where they’ll detect the OpenVPN signature, and block the traffic. With obfuscation, where the VPN traffic is disguised as ordinary internet traffic, one will be able to bypass these measures.

  1. Bypass network blocks

For those in commercial facilities, educational institutions, offices and the like, some of the network administrators may have put in place detection measures that will identify VPN traffic. With obfuscation, you can circumvent them, and proceed using the VPN as normal.

  1. Prevent your ISP from throttling your internet speed

ISPs have a tendency to throttle one’s internet speed, especially when they detect that you’re making downloads, streaming or accessing specific websites. Sure, with ordinary VPN usage, the ISP will no longer get to see your specific internet content, or the websites you’re visiting. However, they may know that you’re using a VPN service, and slow down your speed. 

Note that the encrypting/decrypting measures that come with using VPNs, plus routing the internet traffic through different servers, means that the traffic will be slower than normal internet connections. However, when the ISP is throttling VPN traffic indiscriminately, it will be much slower. VPN obfuscation helps in protecting you from this. 

  1. Extra layer of privacy

The VPN already protects your identity and maintains your privacy, and obfuscating the traffic takes this a step further. That way in addition to your data being encrypted and your IP hidden, your traffic will be indistinguishable from the rest of the population using the internet. 

NEED A VPN?

]]>
What Is Double VPN, And Should You Use It? https://eraser.heidi.ie/what-is-double-vpn-and-should-you-use-it/ Fri, 04 Sep 2020 11:48:47 +0000 https://eraser.heidi.ie/?p=1431

This security feature is available with a few VPN companies, and is usually included in the top-tier packages. What does it mean? Should you cough up some extra cheddar to get it? In this article, we will break down Double VPN, and explain what you get from the extra layer of protection.

Double VPN 101: How It Works

First, the basic VPN connection. When you connect to your VPN server it becomes the intermediary between your device and the internet, passing your data through a secure tunnel. The data to and from the internet is encrypted, that way third parties will not be able to decipher it. 

Device >>> VPN Server 01 >>> Internet

Here, outgoing data is encrypted on your device (the laptop, smartphone, tablet, etc), then sent to the VPN server, where it is decrypted and sent to the target website, online service or app. 

Incoming data reverses this – it is encrypted on the server, and decrypted on your device. 

With Double VPN, a second server is added to this path.

Device >>> VPN Server 01 >>> VPN Server 02 >>> Internet

This means that you get a second layer of encryption. The second server can even be in a different city or continent. 

With this path, there are two approaches:

  • This first is Nested Double VPN. Here, for outgoing data:
  1. It is encrypted on your device twice. 
  2. This data is sent to the first VPN server, which removes one layer of encryption. 
  3. The result is then sent to the second VPN server, where the other layer of encryption is removed.
  4. The fully decrypted data is then sent to the destination website. 

Incoming data follows the reverse process. Each server encrypts the data it receives, and your device decrypts both layers of encryption. 

  • For the second approach, the data is not encrypted/decrypted twice on the end user device. Instead, for the outgoing traffic: 
  1. The device applies a single layer of encryption to the data. 
  2. This layer is removed at the first VPN, and the data is taken through a second round of encryption
  3. The data is then sent to the second server for decryption. 

This means that the data passing through the tunnels will only have a single layer of encryption, and both servers will be able to view the unencrypted traffic. 

This second approach is less common, and nested Double VPNs are more popular given that they provide the most private and secure configuration. 

Can more servers be added to the chain? Yes. This is referred to as VPN server cascading or VPN server chaining, where you get to have triple, quadruple or even more VPN setups. At every subsequent server, the IP is changed, and the data gets decrypted and re-encrypted before being sent along.

Why All The Fuss?

Well, while encrypting data gives you anonymity, since your ISP or any other third-party snooping on the traffic will find it difficult to decrypt, scrambling already-encrypted data makes it twice as difficult, and not worth the time, energy or money it would take to do so. 

In addition, neither of the VPN servers themselves can see both the source and destination of the internet traffic at the same time. While the first VPN sees that the encrypted data is coming from your device, it cannot tell where the data is going past the second VPN, meaning it won’t know the destination website. On the other hand, while the second VPN will decrypt the data and send it to the destination site, it will only know that it came from the first server, and not the original device that sent it. This gives the user an extremely high level of anonymity, and secures the data. 

What’s more, issues that would result from normal VPN connections – like the occasional IP and DNS leaks, will not be a concern here. Even if there is a leak due to a disruption in connection with the server, and the third part gets to unscramble some bits of data, this would only direct them to the location of the first server, and you will still have the second server clocking your identity. If the security of one of the servers is compromised, then the data getting to the second server will still be encrypted, meaning that third parties will not be able to read it.

Who Gets To Benefit From Double VPN?

Anyone who really wants to protect their privacy and anonymity. These are the likes of whistle-blowers, political activists, and citizens in locations where there are high levels of internet censorship. For instance, there are counties with authoritarian regimes that are forceful, cracking down hard on online freedom of speech. The Double VPN enables you to ensure that the chances of your online activities being traced through your network connection are virtually non-existent. 

The Disadvantages Of Double VPN

All that encrypting and decrypting is bound to weigh on your internet speed. Watching live broadcasts and buffering movies can be slow and frustrating. Certainly, it also depends on the speed that you get from the ISP provider. So, if you opt for Double VPN, ensure that you have sufficient bandwidth to accommodate it. 

Next is the price. As mentioned, this security feature is usually included as one of the top-tier packages with the VPN provider. Providers may also choose to separate the security options within the package, allowing you to use the default VPN normally and switch to the Double VPN when the need for the extra security arises. 

NEED A VPN?

]]>
Tests to check your VPN is not leaking information https://eraser.heidi.ie/tests-to-check-your-vpn-is-not-leaking-information/ Fri, 21 Aug 2020 10:29:03 +0000 https://eraser.heidi.ie/?p=1402

Tests To Check How Secure Your VPN Is

One of the dirty little secrets of the VPN industry is that many of them leak. For instance, an analysis of VPN android apps shows that as much as 84% and 66% of them leak IPv6 and DNS traffic respectively, with 18% of them lacking encryption for their tunnelling technologies. These are the likes of not routing the IPv6 traffic through the required VPN tunnel making it easier for user monitoring, or failing to forward the DNS traffic through the tunnel, which allows the in-path observers to monitor the user’s DNS networking activity. 

The result? Users are not sufficiently protected from tracking and online surveillance. Risks are higher with the free VPNs, but there will be some premium VPNs that leak out your information. The security of the VPN is not dependent on whether you’re using free or paid software, mobile or PC versions, since they can have both intentional and unknown anomalies that result in the leaks. For example, the leakage can be due to a bug in the software, or the VPN provider has actually set up the software to collect and share data with third parties. 

How Private Is Your Connection?

With the VPN market growing – and predicted to exceed $35 billion by 2022, the popularity of the software is undeniable, but so are the security concerns. The traffic leaks can be attributed to actual design decisions – like skipping out on IPv6 support, or errors by the developers when making the routing parameter configurations of the VPN software. There are also abusive practices by the VPNs themselves, such incorporating JavaScript for user tracking and advertisement needs, to redirect e-commerce traffic to their affiliate partners. You end up with a situation where a majority of the VPN services marketing themselves as the optimal privacy solutions actually leak out your DNS requests and/or IP address all over the net. 

Are you truly protected? Here, we will look at VPN tests that you can carry out to determine if your identity and network activities are kept private and secure:

Quick and easy tests

  • DNS Leak Test

DNS – Domain Name System, is the technology allowing easy website access. To connect to the internet, the DNS server translates the address of a website like “www.heidi.ie” into a numerical IP address like 168.251.226.14. 

This DNS service is usually provided by your ISP, unless you indicate a particular DNS server that you want to connect to. In such a situation, your ISP (Internet Service Provider) will still know that you have connected to the different DNS server. What’s more, the ISP can log the results, which are clear test logs showing each website that you’ve visited. This data can then be sold off to third parties, like advertisers. 

Enter the VPN. Your actual IP address is replaced by one from the VPN server, thus preventing the connection from being traced back to you. Anyone monitoring the connection should, ideally, not see beyond the address that you’ve been assigned by the VPN, thus preventing the traffic from being identified with you. The DNS leak takes place when the translation request gets leaked out of the VPN tunnel, which exposes the location and IP address of your Internet Service Provider. This information can then be linked back to you, which includes exposing your browsing history. 

The DNS leak test comes in to ensure that your VPN software is performing its role of hiding your location, and not leaking the IP address out of the protected VPN tunnel. For this, simply run an IP check. A simple “What is my IP” search on Google will show you the result, which you then compare to the IP from your VPN. 

You can also use these checks: 

For a properly functioning VPN, it should show the private address assigned to you by the VPN. It should not show your actual IP address. Some DNS leak tests end up showing the IP address of the Internet Service Provider. While this still gives you a level of privacy, it shows that there is problem with this configuration of the VPN. 

For instance, on firing up a VPN and connecting to its Texas server, these were the results: 

Texas Server Map

This is the address that is provided to us by the VPN service, and the location is that of its server. We are actually a continent (and an ocean) away, meaning that there is no leakage – since the region itself is not even remotely close. 

If you notice that your VPN is leaking your DNS data, then you should switch to a different service provider, preferably one that operates its own DNS system which is fully encrypted. This will hide both your location and that of your ISP address. 

There are also those who choose to alter the operating system configurations manually, setting it to use a third-party DNS provider, such as the alternative DNS options provided by WikiLeaks. Remember that you still run the risk of these DNS providers keeping request logs, thus the emphasis on getting a VPN provider has been verified to be keeping no logs. 

  • IP Address Leak Test

This takes you a step further, to identify whether the VPN you’re using is leaking out your location and IP address. This test should be done when connecting to the internet, and reconnecting to it. Why? Because there are situations where your connection to the VPN is dropped, necessitating the software to reconnect with the internet, and in the process leaks out your IP address. This is where the “Kill Switch” feature of the VPN provider should kick in. Here, the VPN completely disconnects you from the internet. 

This is how you perform the test: From our initial test with our VPN provider, the resultant IP address was 155.94.250.98. So, we disconnect from the internet, and then reconnect. The VPN automatically reconnects to the server, and these are the results: 

Texas Server Map 2

The same result was obtained. Meaning that there was no leakage. Note that you should take the extra measure of ensuring that your VPN service has the “Kill Switch” feature in place. 

For the reconnection bit, the test has a couple of more steps:

  1. Establish the connection to the internet and to the VPN service.
  2. Open your browser and head to an IP address test page. You can use any of the tools mentioned above. Here’s the kicker: Open multiple tabs. Certainly, at this point, they are all showing the same address that has been assigned by the VPN. 
  3. Disconnect from the internet. Keep the VPN running
  4. Allow some time to pass. A couple of seconds should do. 
  5. Reconnect to the internet, and quickly refresh the open tabs while the VPN is in the process of establishing the connection. 
  6. Stop refreshing the tabs immediately the VPS has reconnected to the internet. 
  7. Check the results in each of the browser tabs. 

If there is an IP address leak during the reconnection, then you should notice your real IP address in one or even more of the tabs. In case you establish that there is a leak, you should activate the Kill Switch feature in the VPN app. If the leakage is still occurring when the feature is active, then you should switch to a different VPN provider. 

You can also set up firewall rules that will block all the non-VPN traffic. However, this is a manual process, and can be quite the hassle.

Sites like IPLEAK.NET give you an extended IP address test. Here, it looks at your Java, Flash, and DNS, ensuring that they don’t leak out your IP. It looks through all the sources that are in the browser being used, showing the IP that has been detected. 

  • WebRTC Leak test

While this is a common issue when discussing VPN services, the WebRTC leaks are actually a vulnerability with the web browsers being used. These are the likes of Chrome, Safari, Firefox, Microsoft Edge, Opera and Brave browsers, which essentially become the weak link in the chain. 

What is it? WebRTC – short for “Web Real-Time Communication”, allows P2P filesharing, voice and video chats within the browser. This technology enables real-time communication without requiring additional browser extensions. The leak occurs when your IP address is exposed through the chats and file-sharing sessions, which can occur even when the VPN is working as intended. 

You can use these tools to check for the WebRTC leaks:

To prevent the WebRTC leaks, disable the feature from the browser itself. For instance, with Firefox, type in “about:config” into the address bar. 

Firefox - About:Config

A warning will pop. Agree to it, and click “continue”. In the search box, proceed to type “media.peerconnection.enabled”. Toggle the preference to false, as shown below. 

Peer Connection

For Chrome and other Chromium-based browsers where WebRTC disabling is not possible, you can use add-ons or extensions, such as webrtc.org’s official extension for Chrome

Advanced Tests

These will be technical, and will require more proficiency to be properly executed. They will point out any leaks that may be happening with your VPN provider. These are the likes of Express VPN’s testing suite that is used for in-depth testing of leaks. You can get the open source tools from GitHub. They use these tools when testing their own VPN to ensure that it is leak-proof. To carry out the test, setting up the machines and identifying the leaks, use this quick start guide.

Closing Remarks

It is recommended that you run the VPN leak test even when using the premium service providers. If they are functioning as intended, then there shouldn’t be any leak detected, meaning that your connection is private and secure. 

NEED A VPN?

Check out the range

]]>
Excel Password Unlockers https://eraser.heidi.ie/excel-password-unlockers/ Thu, 02 Apr 2020 14:42:11 +0000 https://eraser.heidi.ie/?p=1242

Let’s take a look at some Excel Password Unlocker Software out there, most of them free! Note: some may impose file size restrictions, e.g. Password-Find does not support files larger than 10MB.

LostMyPass

SIMPLE TO USE: No need to install any software; you upload your file onto their website.
COST: Outlined below
FILE FORMATS: PDF, Ms. Word, Ms. Excel, Ms. PowerPoint, 7z, WinRAR, WinZip
RECOVER METHODS:
Weak Password Recovery: FREE
Weak password recovery is free and fast (a few minutes). It uses a dictionary of 3 million weak passwords. Chances of recovery are around 22%.
Strong Password Recovery: Pay on Success – current price $29
You only pay for a successful recovery. It can take up to 24 hours. It uses a dictionary of 20+ billion real passwords. The password is recovered successfully in more than half of cases; around 61%
Brute Force with a Mask: Price on request
Brute force attacks or brute force cracking are when all possible characters that exist are tried until it hits on a combination that works. 100% success rate if correct mask (set of characters) is given.
For example, if you can remember that your password consisted of 8 or 9 characters, perhaps starts with “444,” and the remaining characters are lowercase letters (English alphabet), then that makes the search process a lot easier.

Passcovery Suite

SIMPLE TO USE: Safe and regular Windows installation kits digitally signed by the company. All installation data remain on the computer and are not transmitted online.
COST: from 60USD per one Office-compatible module
FILE FORMATS: supports all versions of Microsoft Office/OpenOffice/LibreOffice, Adobe PDF, RAR/WinRAR, Zip/WinZip, TrueCrypt, Apple iOS backups, WPA/WPA
RECOVERY METHODS:
Instant removal of weak passwords of all Microsoft Office versions
Searching for Excel/Word 97 decryption key
Three standard password attacks: brute-force attack, mask attack, dictionary attack
Extended (positional) mask attack that enables generating passwords from charsets individually defined for each position in the password
Mutating and blending of dictionaries to increase efficiency of dictionary attack
GPU acceleration on AMD/NVIDIA graphics cards to enable dramatic increase of the speed of brute-force attack

AccessBack

SIMPLE TO USE: Online service that guarantees decryption of password-protected Excel/Word 97-2003 files. No third-party software
COST: from $5 per one Excel/Word document decrypted online
FILE FORMATS:  guaranteed decryption of doc/xls files with a short (40-bit) encryption key
RECOVER METHODS:
Rainbow tables for guaranteed decryption of Excel/Word 97 files

Password Online

SIMPLE TO USE: No need to install any software; you upload your file onto their website.
COST: 10 EUR – only payable if recovery is successful.
FILE FORMATS: doc, docx, xls, xlsx, ppt, mdb, pdf, rar, zip, 7zip, eoc etc.
RECOVERY METHODS:
Instant Password Recovery
For weak passwords.
Password Reset
Sometimes, it is possible to reset the password inside the actual file itself.
Dictionary Attack
This method uses a dictionary. Every word in the dictionary is tried. This method is usually faster than Brute Force Attack.
Brute Force Attack
This type of attack tries every possible character combination in a given set, in the hope of password recovery. This method is usually very successful, if the correct set of characters is given.
Variation in Password
This method uses the possibility of the password having been mistyped or a missing character.
Plain Text Password Attack
This method is used mostly with Zip files.

Password-Find

SIMPLE TO USE: No need to install any software; you simply upload your file onto their website.
COST: Payment is only upon successful recovery.
FILE FORMATS: It works with Ms. Excel, Ms. Word, Ms. PowerPoint files and VBA Projects.
SERVICE STATISTICS:
MS Office 97-2003 100%
MS Office 97-2003 CSP 81%
MS Office 2007-10 80%
MS Office 2013-19 78%
RECOVERY METHODS: They don’t seem to outline their recovery methods on their website.
]]>
Cryptocurrency – The Ultimate Knowledge Base https://eraser.heidi.ie/cryptocurrency-the-ultimate-knowledge-base/ Tue, 09 Jul 2019 18:43:50 +0000 https://eraser.heidi.ie/?p=1161 What is Cryptocurrency?

Cryptocurrency is a geeky, technical, and misunderstood term. However, significant organisations, banks, and companies are aware of their importance. In this day and time, it is difficult to find any organisation that has not invested time and money into Cryptocurrencies. Cryptocurrency is the digital currency of the future. It is decentralised and safe. However, there is more to Cryptocurrencies than just these basics.

How did cryptocurrency originate?

Cryptocurrency did not originate as a currency, but rather as a side product of another invention, the Peer to Peer Electronic Cash System. Satoshi Nakamoto, the inventor of Bitcoin, intended to save double spending by utilising a peer-to-peer network. This network has no central authority.

How does the peer-to-peer network work?

Realising digital cash means requiring a payment network with accounts, balances, and transaction details. The major problem faced here is that these networks have to prevent one entity from spending the same amount twice. A central server records all balances, thus preventing the entities from spending the same amount of money twice.

The peer-to-peer network built by Satoshi solved the centralisation of balances by making the system decentralised. In the peer-peer network, every peer needs to maintain a list of all transactions. All peers check if the future transactions taking place are valid or an attempt to double spend. If any peer disagrees, transactions are broken.

What exactly are Cryptocurrencies?

Cryptocurrencies are nothing but limited entries in a database that cannot be changed until and unless specific conditions are met.

The money in your bank account too is just an entry in the database. The entry can only be changed under specific conditions. If the condition of you physically owning the coins and notes is met, then the amount in your database is decreased. Hence, money is just a verified entry in databases. A central database handles transactions of your money.

Cryptocurrencies are similar to the money you own, except the fact that there is no central database to keep track of the Cryptocurrency you own. The database is accessed, shared, and maintained by all servers in the network. Cryptocurrency transactions are hence handled in a decentralised manner.

What is blockchain?

Blockchain is the technology used by Cryptocurrencies to keep a decentralised track of all transactions. A blockchain is essentially a list of records called blocks, linked using cryptography. Each block in the blockchain system consists of a cryptographic hash of the previous block, the transaction data, and a timestamp.

In essence, blockchain is resistant to modification of data. Once a block is verified, it is irreversible and permanent. The blockchain system does not have a central authority but is shared with an immutable ledger. Hence, everything built on the blockchain is transparent, and everyone involved is accountable for their actions.

Example bitcoin transaction using blockchain technology

Let us take a look an example bitcoin transaction:

1. Bitcoin Cryptocurrency comprises of a network of peers.
2. Each peer maintains a complete history of all the transactions and the balance of every account.
3. Let us assume a transaction where A gives X Bitcoin to B. A transaction file is created denoting this transaction and is signed by A’s private key. This is basic public key cryptography.
4. After the transaction file is signed, it is broadcasted in the network and sent from one peer to the other. This is basic p2p-technology.
5. The whole network immediately knows about the transaction.
6. The transaction has to be confirmed for the process to be complete. Confirmation is critical in Cryptocurrencies. As long as the transaction is unconfirmed, it can be forged and is incomplete.
7. Only miners confirm transactions. Anyone can be a miner. However, miners need to invest some work in their computers.
8. To confirm transactions, miners have to find the SHA 256 Hash that connects a new block with its predecessor.
9. After finding the solution, the miner builds a block and adds it to the blockchain. Doing so rewards the miner a specific number of Bitcoins.
10. Since the difficulty of finding the hash increases the amount of computer power invested by the miner, only a certain amount of Cryptocurrency token can be created at a given time. This ensures that forged transactions do not take place.

What are the revolutionary properties of cryptocurrencies?

What makes Cryptocurrencies revolutionary? Why are Cryptocurrencies in such hype these days? There are some properties of Cryptocurrencies that make them extremely reliable, secure, and different than other forms of money.

Cryptocurrencies are secured not by people, but by math. There are more chances of you being hit by lightning, than the chances of your Bitcoin address being compromised. Listed below are the transactional and monetary properties of Cryptocurrencies:

Fast and global
Cryptocurrency transactions are propagated instantly in the network and are confirmed fast. Since peers are located all around the world, Cryptocurrencies are also global.

Secure
Cryptocurrencies are locked by a public key cryptography system and are secured not by people but by maths. Big numbers and strong cryptography makes it impossible to break Cryptocurrency.

Irreversible
Once a transaction is confirmed, you cannot reverse it. It is important to understand that sending your funds accidentally to a hacker or scammer is also set to stone, and you cannot reverse the transaction.

Pseudonymous
It is not possible to connect Cryptocurrencies, which are random chains of characters, to real-world identities.

Permissionless
Using Cryptocurrency is permissionless. You can download the Cryptocurrency software for free, receive, and send Cryptocurrencies without asking for permission from any central authority.

Controlled supply
Cryptocurrency supplies are limited. The schedule written in the code limits the supply of tokens. The monetary supply of a Cryptocurrency in the future can be calculated in the present day and time.

No debt
The money in your bank account is created by debt. However, Cryptocurrencies do not represent debts but rather just represent themselves. Cryptocurrency is as solid as coins of gold.

Some well-known Cryptocurrencies include:

• Bitcoin
• Litecoin
• Ethereum
• Ripple
• NEO
• Waves
• Bither
• STK Token
• Mycelium Token
• NeverDie
• Insanity Coin
• ZCash
• Dash
• XRP
• Monero
• Bitcoin Cash

]]>
Router Security https://eraser.heidi.ie/router-security/ Fri, 11 Jan 2019 11:04:28 +0000 https://eraser.heidi.ie/?p=1128 There is no anti-virus software for routers. No matter how secure your mobile devices, desktop computers or other electronic devices might be, having an unsecured router still makes you susceptible to malicious attacks.

A router is an interface between the internet and all your computing devices. It can hence be thought of as an interpreter. If the interpreter itself is malicious, then one can only imagine the things that can go wrong.

Router Security is a less-talked-about topic but is as important as installing anti-virus software on your computer. A hacked router can let a malicious person:

• Hijack your DNS,
• Cause a denial of service attack,
• Download malicious copies of software,
• Spy on your activities,
• Slow down your internet connection,
• Hack files that are being transferred, and
• Ultimately access the computers connected via the LAN of the router.

There are many side effects of neglecting router security. It is hence crucial for every internet user to do the right thing by making router security an important concern and by applying whatever methods possible, to ensure privacy and online security.

Since it is now established that router security is essential for every internet user, let us go into the details of how you can ensure it.

Step 1: Picking the right Router

You cannot secure a router if it is not appropriately chosen. Picking the right kind of router is the first step you can take towards router security.

Most people tend to use the router provided by their Internet Service Provider (ISP). The only advantage of doing this is the fact that you can call your ISP for any issue that arises in your internet connection. The downsides to using it, however, are many:

• Devices shipped by ISPs are incompetent in their initial configuration and maintenance. A device installed with a default password is certainly not the right option for you
• Some ISPs can spy on your data for their own use or by co-operating with spy agencies and governments.
• Some ISPs do not allow you to update the firmware or change DNS servers of the router
• ISPs generally provide a single router; hence you will have no emergency backup in case of failures
• A common type of router, provided by an ISP to millions of customers is an easy target for malicious users

A consumer router is a better alternative to ISP provided routers but is still not the best option. The most secure option to choose is hence a commercial router meant for small businesses.

When choosing a router, think of the long-term benefits that you obtain by using it. While the upfront cost of the router might seem like a huge investment, it is still a better option than compromising your security.

A router can only get as secure as the features it offers. It is not recommended to buy used routers as the software might have been modified maliciously. When choosing the correct router, consider the inclusion of these security features:

WPS

WPS (Wi-Fi Protected Setup) is not as good as it sounds. It is easy to use and easy to bypass feature that allows malicious users to enter an eight-digit PIN to access the router. The PIN is printed on the router itself. Once someone gets access to your PIN, you can change the network password or network name, but the validity of the PIN still remains intact.

Therefore, anyone who gets access to the PIN printed at the base of your router can access your router forever.

If a router uses WPS, it is not good enough. Check if WPS can be turned off. Proceed only if WPS is absent or can be disabled in your router.

WPA2

WPA2 encryption is good. However, one must consider some other points when looking for a secure router. Keep the following points in mind:

• Verify if your router offers WPA2 exclusively and not the combination of WPA2 and WPA
• A router that uses AES or CCMP is also as secure as the one that uses WPA2 encryption
• Ensure that your router does not use TKIP
• Look out for routers that offer WPA2 Enterprise support. This usually means that the router allows every Wi-Fi user to set their own user id and password. A RADIUS server is required to handle these user ids/passwords. This option might be a high bar for most people, but it is the best encryption mechanism possible

Local administrative access

Another aspect of determining the security of a router is its local administrative access mechanisms. A secure router must:

• Limit access based on LAN IP address or by Mac Addresses
• Limit the number of logons and allow only a single computer to log into it at once
• Lockout after repeated failed login attempts
• Create audit logs for every login attempt
• Timeout and allow you to set a timeout period
• Restrict access based on the SSID
• Allow you to log out

Remote administrative access

Remote administrative access in your router should be off by default. A secure router must:

• Limit remote administrative access to HTTPS
• Allow you to change the port number
• Allow you to restrict access on the basis of the source IP address or source network
• Timeout the running session after a certain timeout time

Default passwords

Be wary of routers that employ default passwords. Default passwords can look random, but follow a specific formula to be created. Once someone understands this formula, the rest is easy.

Check if the router forces you to provide a new non-default password for logging into the router. Additionally, check if the router forces you to provide non-default passwords for each new Wi-Fi network. Choose the router only if the two conditions are met.

Wi-Fi

A secure router must allow the options to:

• Schedule turning off the Wi-Fi at night and turning it back on in the morning
• Use the Wi-Fi ON/OFF button

The bottom line is that the router should make it easier to disable a Wi-Fi connection when it is not required.

Monitoring Attached Devices

Another feature of a good router is the ability to monitor the devices connected to it. A good router:

• Lists all the attached devices
• Allows you to list both DHCP assigned devices and devices with static IPs
• Allows you to list devices by grouping it on the basis of the Wi-Fi network
• Allows you to monitor the bandwidth usage of each device

Firewall

A good router’s firewall should:

• Close all ports on the WAN/Internet side
• Allow you to create outgoing firewall rules

Listed below are other good to have features which can help you make the right choice.

Factory Reset
Look out for a router that allows you to factory reset it and erase all personal data from it.
Logging
A good router logs unsolicited incoming connections, failed login attempts, internet accesses and changes made to the configuration.
Firmware
Another parameter that can help you determine the right router for you is its ability to make firmware updates.
HNAP (Home Network Administration Protocol)
The HNAP has been the baseline for many router flaws. A secure router does not support HNAP.
Port Forwarding
Make sure that your router limits port forwarding by IP address. It is better if your router allows you to schedule port forwarding.
Router Admin Password
The router admin password should not be too short and must allow the maximum password length to be at least 17 characters. A router should also defend itself against brute force password guessing.

Step 2: Configuring the router securely

Once you select the right router of your choice, it is time to configure the router as securely as possible. The below mentioned short list of configuration tricks can do wonders for the security of your router:

  1. Change the default password of your router. Make sure that you do not use a dictionary word. Incorporate some numbers and special characters in your password. Also make sure that the password is not something as menial as the name of something you love, or the name of your hometown.
  2. Ensure that the encryption mechanism used is WPA2 with AES. The password of your Wi-Fi network should be at least 16 characters long. Again, make sure to set a password that is not easy to guess.
  3. Turn off UPnP (Universal Plug and Play). While UPnP was initially designed to be used on a LAN, some routers implement it on the Internet too. There have been security issues with routers in the past because of UPnP, hence turning it off is the best way to ensure that your router is secure.
  4. Choose a sensible SSID (Service Set Identifier). Using a default SSID makes it easier for malicious users to crack the WPA2 encryption. Choose a network name that does not give away your personal information.
  5. Turn off WPS. It is actually better to choose a router that does not support WPS at all. If it does have WPS encryption, make sure to run it off.
  6. Turn off Remote administration.
  7. Check for new firmware occasionally. If your router does not release new versions of firmware, it might be the right time to switch to a new router.
  8. Use a Guest Network. Use a password protected Guest Network for guests and also for IoT devices.
  9. Test your router. Use available online testers to test the port information of your router.

The steps mentioned above are just the basic things you can do to ensure that nobody accesses your router or installs malicious software in it. If you are actually a freak for security, there are a number of other methods that you can employ to make your home router a fortress that can guard the electronic devices that connect to the web through it. Choose and implement anything from the list below:

  1. Change the user id of the router. That is if your router lets you.
  2. Change the default DNS servers that your router provides you. ISP-assigned DNS servers are usually the worst when it comes to security. It is better to use the DNS of a company that specializes in it.
  3. Turn off unused features. This is a good way to reduce the attack surface. The features that are better turned off are remote administration, web access from WAN, Telnet, SNMP, NAT-PMP and Remote GUI.
  4. Change the router’s LAN IP address. It is better to change the subset of the LAN side as a whole. Doing this prevents router attacks.
  5. Lock down the access to the router from the LAN side.
  6. Turn off Ping reply. Test this implementation by having someone outside your network ping your public IP address.
  7. Block the ports used by Windows file sharing. It is also a good idea to prevent network printers from making outbound connections.
  8. Disable the analytics on your router. You would not want your router company spying on you, so it is better to turn off the analytics feature in your router’s firmware releases.
  9. Use a clean web browser session to administer routers with a web interface. Start the browser, work on the web interface of the router, and shut down the browser after you are done with the administrative activities. The better option would be to use a private browsing mode.
  10. Always backup your configurations. If you have to reset the router at some time, you can restore the last backed up state of the router.

Step 3: Ongoing care for the router

After initially configuring the router, it is also essential to monitor for your router configurations regularly. There are a number of methods that can be adopted to ensure that your router’s security has not been compromised.

  1. Updating the router
    Check if your router self-updates regularly or not. Check for the availability of new firmware updates every month. If your router has the self-updating feature, make sure that the system is actually working as expected and if the new updates are actually worth using. There can be major security loopholes in some security updates. It might be a good option to revert the updates in such cases.
  2. Rebooting the router
    When a router gets infected with malware, the infection is sometimes very difficult to get rid of. However, most infections are temporary and simply rebooting the router can help you get rid of the infection. Make sure that you reboot your router every week or every month, in order to remove such kind of malware on a regular basis.
  3. Checking the list of attached devices
    Every router has the functionality of displaying the attached devices. Make sure that you check this list now and then and validate the list against the number of devices that your network actually uses. Some routers also offer the capability of assigning names to these devices.
  4. Checking the status of DNS servers
    A common attack against routers is maliciously changing the DNS servers. It is hence important to continuously check and ensure that your DNS servers have not changed. You can configure a DNS server on your own computer. Doing this ignores the DNS configuration present in the router. This is especially useful when you use public Wi-Fi networks. However, some routers override the DNS configuration of the computer and force the computer/laptop to use its own configuration. Hence, it is important to know the kind of router you possess and periodically check the DNS server configuration of your devices.
  5. Checking the logs of the router
    If your router offers logging facilities, it is recommended that you continuously check the logs for unsolicited incoming connections, failed login attempts, internet accesses and changes made to the configuration.

All in all, router security is not limited to buying a good router and configuring it one-time. New router threats are emerging every day and are posing serious threats to personal privacy and security. It is essential to keep yourself updated with router flaws, and periodically check your router security parameters to avoid compromising your personal information.

]]>
Virtual Private Network (VPN) https://eraser.heidi.ie/virtual-private-network-vpn/ Mon, 07 Jan 2019 11:53:22 +0000 https://eraser.heidi.ie/?p=1114

If you access the internet, or if you are a technically savvy person, you might have heard the term VPN floating around a lot. What exactly is a VPN and how does it allow you to be secure over the internet? Read on to find out.

What is a VPN?

A Virtual Private Network is essentially a service that allows you to benefit from the management, functionality, and security of a private network despite connecting to the internet via a public network. In other words, a VPN service lets you access the web safely by hiding your online actions and routing your connection through a server. A VPN can also be thought of as a secure tunnel between two or more devices, thus allowing you to access the web anonymously.

How does a VPN work?

It is now established that a VPN network allows you to access the web securely. How exactly does a VPN work? This is what happens when you connect the web through a VPN:

  1. When connecting to the internet using a VPN service, you start the VPN client from your computer/device. Your VPN service provider provides this VPN client.
  2. The VPN client encrypts your data even before your Internet Service Provider or any interested party can access it.
  3. Your encrypted data reaches the VPN server and is routed to the online destination. Your online destination can be a bank website, a search engine, or a video sharing website.
  4. When the encrypted data and request reaches the destination, the online destination sees that the request/data is coming from a VPN Server. Your computer and your location, however, remains hidden from the online destination.

Hence, connecting to the web through a VPN has these benefits:

• Your data is encrypted even before it reaches your ISP.
• If someone does peek at the data you are sending, they can only see the encrypted information.
• The destination site sees that the VPN server is the origin of the request and not your computer.
• It becomes difficult to identify your computer, or what you are doing.

The web consists of several servers which are interconnected with each other and which share your data amongst each other to let you browse a page. This leaves your personal data out in the open. If you are just surfing a normal website, this mechanism does not harm you. However, if you are browsing your online banking website, your important work website or your business email, then the chances of your data being compromised are huge.

There is no mechanism to hide your location and details from the online destination when accessing the web without a VPN. Your data remains in the open, and the online destination, as well as any interested party, can view it with ease.

How secure is a VPN?

The benefits of surfing the internet through a VPN is outweighed by the questions on VPN security. VPN security is a topic that causes a lot of debate amongst IT professionals. The fact that no two services are identical adds up to the complexity of determining the security level of VPN services. Additional complexities are added upon by the fact that VPN services are driven by legal and policy limitations and the laws of the country where the VPN service is located. The VPN services provided by a company generally depends on the given factors:

Legal factors and Company strategy

VPN service providers are there to protect your data and secure your privacy when connecting to the web. It is, however, important to note that they too are governed by local laws of the country and their own company strategy. There might be cases when the company is ordered to share their records with the court. In other cases, there can be international agreements between two nations to share web activity details. Hence, the borderline of VPN security is ultimately governed by the VPN service that you use. In other words, a VPN is only as secure as the VPN provider itself.

VPN Protocols

Another factor governing VPN security is VPN Protocols. A VPN protocol determines how data transmission occurs over a VPN service. Some protocols are elaborated below:

• PPTP (Point-To-Point Tunneling Protocol)
This is the oldest protocol in use and is a part of the Windows operating system. It uses a TCP control channel to encapsulate point to point packets. However, this protocol falls back in terms of security. It is advisable to avoid a VPN service provider who offers this protocol.

• L2TP/ IPsec (Layer 2 Tunneling Protocol)
This protocol uses keys at each end of your data tunnel to establish a secure connection, but the execution is not very safe. This is another protocol to avoid as its security is debatable and has been questioned a lot.

• SSTP (Secure Socket Tunneling Protocol)
This protocol is also built by Microsoft and is established with SSL/TLS encryption. It works by employing symmetric-key cryptography, meaning that only the parties participating in the transfer can decode the data. Since SSL/TLS encryption is a de facto standard for web encryption in this age, SSTP is a very secure solution.

• OpenVPN
OpenVPN is the most versatile and the most secure protocol in this age and time. It is based on the SSL/TLS protocol and is an open source project which is being improved by hundreds of developers constantly. It secures the connection by using keys which are only known by the participating parties.

• IKEv2 (Internet Key Exchange, Version 2)
This is another protocol built by Microsoft and is an iteration of Microsoft’s previous protocols. It is hence more secure than the other protocols designed by Microsoft. It works by producing the same symmetric key for the communicating parties.

Generally, most VPN’s allow you to select the protocol service to use. The combination of OpenVPN and IKEv2 is the most secure way to use a VPN service.

Is VPN fully legal?

Yes. VPN is a legal service. However, the roles related to VPN services are murky and are different everywhere. Hence, there are different interpretations to as if VPN is a fully legal service or not.

VPNs are legalized in countries like the UK, US, Canada, and Western Europe. VPN services are not legalized in countries like Oman, Russia, UNA, China, Turkey, Iran, Iraq, North Korea, and Turkmenistan. What matters, in this case, is your physical location when using a VPN service.

Find the laws of your local government to know the legal rules related to a VPN service, before deciding to take it up.

Does VPN make you 100% anonymous?

A VPN does not make you 100% anonymous, but it does to some extent. The extent to which a VPN can offer anonymity is however impressive.

Without a VPN, your data is open and subjected to breaches. Your connection remains fully open, and any person with the right tools can peek into the data you are sending over. Having a VPN in the middle means creating a barrier between you and the destination, and encrypting your data. The extent of anonymity of a VPN service depends on the following:

• Logs
If the VPN service keeps logs, then the extent of anonymity is somewhat reduced.

• Jurisdiction
The jurisdiction of the location of the VPN service makes a huge difference to the anonymity of VPN. If a VPN service provider is forced to keep records, then the government might come asking questions that need answering.

• Encryption mechanism and protocol used
The anonymity of VPN also depends on the security of the protocol and the encryption mechanism used.

Make your choice wisely, depending on the extent of anonymity that you require. A VPN service that does not keep logs/records and uses a good encryption mechanism and protocol will work best in keeping you anonymous.

What are the VPN logging policies?

The logging policies of VPN services significantly determines the level of anonymity and privacy that you obtain from the service. Every VPN service has its own logging policy, and the extent of logs they keep depends on their company strategy and local government rules. The logs that a service provider may save include the:
• User activity
• Payment logs
• Connection/ disconnection timestamps
• Devices used
• IP addresses

Tying these details back to you would be difficult, but is doable if a company would deliberately want to trace you. The fewer logs that the service provider keeps, the better will it be for you.

Beware of VPN service providers who ensure anonymity in their sales materials but do not implement it in real. Read a VPN provider’s privacy policy carefully, to know the logging policies that they implement.

Is it okay to use free VPNs in comparison to paid VPNs?

A good VPN service requires a lot of money to run. Costs associated with data transfer, robust servers, employees and infrastructure, etc. causes a VPN service provider to invest a lot into their services. If a VPN service is offered for free, you can be sure of the fact that a lot of compromises have been made.

A free VPN earns money by either having a logging activity for their own reasons or by displaying a lot of advertisements. Free VPN services can also be selling your data to a third party.

The average cost of paid VPNs rounds about to as little as 3-5 dollars a month. Subscribing for a VPN service one to two years upfront can offer you even more discounted rates.

The bottom line of this discussion is the fact that VPN services cost very little but are a good investment when it comes to increased online privacy. Using free VPN services can be even more expensive than it initially seems.

Is VPN Safe for Torrenting?

Generally speaking, VPN services can be used for torrenting. However, it depends on the service you are using and the kind of things that you torrent.

Torrenting is a protocol used to transfer files over the internet. However, it does not define the types of files being transferred. Torrenting is perfectly legal if you have the rights to the data being transferred. Regardless of the VPN services you use, piracy, however, is illegal.

VPNs have their own policy regarding torrenting. Most VPN solutions allow torrenting. However, some VPN services might have their own logging policies for torrenting. Generally, a VPN that does not log your other activities will not keep logs for your torrenting activities. Hence, the use of VPN for torrenting depends on a VPN provider’s logging policy and the type of content you torrent.

Another aspect that determines if a VPN is good for torrenting is the download speed that the service offers. This information is difficult to obtain, so it’s good to read some reviews related to the torrenting download speed that a VPN service offers before you make a choice.

Can VPN be used to Watch Netflix/Hulu?

You can use VPN to watch Netflix/ Hulu, but it again depends on the VPN that you use.

Netflix is available in over 130 countries, but its shows are not distributed equally. Due to legal issues, TV stations have the right to Netflix’s own shows, and those shows might not be available in specific regions.

Netflix and Hulu block content based on location filters. If your country is banned, it essentially means that you will be banned.

However, this problem is solved when you use a VPN to watch Netflix/ Hulu. When using a VPN, you can select the server that you want to connect with. To watch a show on Netflix/ Hulu, you can easily select the server in the country where the show is available. Since Netflix/ Hulu will not be able to see your location, but the location of the VPN server, you can watch the content with ease. Hence, VPN’s can actually help you gain access to Netflix and Hulu content that you could not obtain otherwise.

Does VPN Work on Android/iOS?

Yes. A VPN service can work on Android/ IOS. Many VPN services let you download mobile apps for Android or IOS and set up a VPN connection easily.

However, do not be tempted with free VPN apps for Android and iOS. Research by the International Computer Science Institute and the University of California Berkeley states that amongst the 280 free Android apps that use Android VPN permissions, 75% use tracking libraries, 38% of those apps are malware and 84% of those apps leak the user’s traffic details.

Does VPN Work on SmartTV/Kodi?

Smart TVs and Kodi boxes also use internet connections and using VPNs can help you keep your streams private. To enable a VPN connection in your Smart TV/ Kodi box, you can configure it on the device, or configure it on the router itself.

Most quality VPNs offer the ability to configure your Smart TV with a VPN connection. The steps for configuration differs from VPN to VPN. To configure VPN on your router, refer to the section below.

How to Install VPN on a Router?

The best way to ensure that everything in your home goes through a VPN connection is to configure VPN on the router itself. With this, you will no longer have to install VPN in your individual mobile devices, TV, desktop, etc.

Make sure that your router is compatible with VPNs before you start the configuration. You can do this by checking the website of the manufacturer product on the router. The setup of VPN on a router differs from service to service. You will just have to fill up some standard forms and the process to configure VPNs on a router is pretty straightforward.

How to use the VPN & Tor Combination?

Tor is a service that routes traffic through a worldwide network of random nodes to conceal the user’s location and usage. Using a Tor hence makes it difficult to trace internet activity.

While Tor and VPN are different fundamentally, they can be used as a combination to ensure increased online privacy and security. Tor is 100% free, and there are no limitations when using the free version. To combine the advantages of Tor and VPN:

  1. Enable your VPN connection.
  2. Use the Tor browser to browse the internet.

The VPN connection and Tor web browser now run at the same time. This setup will be considerably slower than the standard VPN-only procedure of accessing the internet. However, the main advantage of this setup is that you get super privacy.

What are Kill Switches and IP Leaks?

Kill Switch

A kill switch automatically kills your internet connection if the safe, encrypted connection drops. A VPN with a kill switch is desirable as your device might attempt to access the internet with a normal connection if a connectivity issue arises in the VPN connection. Not having a kill switch can expose your data when your device switches from the VPN connection to the unprotected connection.

IP Leaks

IP Leaks can occur when your VPN connection fails to hide your IP when you browse the internet. Good VPN services have clever scripts that prevent IP leaks. However, sometimes the underlying issue is with your computer configuration, browser, extensions and the apps that you use. Hence, IP leaks are not entirely VPN problems.

Hence, a good VPN service has clever programming hacks to avoid IP leaks and has a kill switch mechanism that will keep you entirely secure.

When to use a VPN?

There are many advantages of using a VPN service:

• It allows you to access geo-blocked content by hiding your location.
• It hides your activity on the web.
• It encrypts the data you send over the internet.
• It helps you access any Wi-Fi through a protected connection.
• It makes you anonymous on the web.

In conclusion, a good, paid VPN is a good investment (at just 3-5$ a month) if privacy, anonymity, and security are important to you or your business.

When not to use a VPN?

There is no reason not to use a VPN service if online security and privacy are important to you. VPN is an additional layer of security over SSL protocols, antivirus programs, etc. There are not many downsides of using a VPN service as it is a cost-effective and efficient way to ensure online privacy and security. On the contrary, beware of using the so-called free VPN services.

NEED A VPN?

]]>
Smartphone Security – (Android/IOS) https://eraser.heidi.ie/smartphone-security-android-ios/ Mon, 07 Jan 2019 10:59:07 +0000 https://eraser.heidi.ie/?p=1097 Smartphone security is not a new concept in itself, but its scope is changing day by day. While smartphones were used as a mere means of communication in the past, they are being used to store everything from important work-related details to bank account information.

If a potential vulnerability causes your smartphone data to be compromised, then it might turn out to be a potential catastrophe. They say prevention is better than cure. There are many ways how your smartphone’s data might be hindered with, and a number of solutions for the same. If you use a smartphone, it is a smart idea to stay updated about the kinds of potential threats and the preventive measures against them.

Theft Proof your Mobile Data

Taking preventive measures to theft-proof your mobile data saves you much trouble later. Stop malware makers and phishers on their tracks by taking these preventive measures into account:

  1. Lock your mobile
    As simple as it sounds, locking your smartphone is one of the most basic things that you can do to ensure smartphone security. If your phone gets lost by any chance, a simple PIN lock can prevent someone from immediately doing any harm to your personal data. It gives you the time and the chance to block your credit card details or block access to other important data. Locking your data is as simple as setting a PIN code, pattern lock, password or Fingerprint lock.
    • Password
    A password is a strong, secure way to lock your phone. Passwords can be difficult to guess, and it can help ensure that your personal data remains personal. However, typing a password into your mobile phone several times a day can turn out to be cumbersome. Use passwords only when you need the highest level of security.
    • PIN
    A PIN code can turn out to be a simple alternative to a password. It can be shorter, easier to remember and easier to type in several times a day. Using a 4 digit pin is a good solution, as there are 10 thousand different combinations. Just make sure not to choose something obvious like 1234 or 4321.
    • Pattern Lock
    A pattern lock allows you to draw a pattern using a grid of nine dots. You can create a huge combination of patterns, and it is easier to enter multiple times throughout the day. However, patterns are only as secure as the kind of pattern you create. Another con of using a pattern lock is the fact that someone can easily remember your pattern by just looking over their shoulder. Hence, patterns are recommended only if you have nothing to worry about.
    • Fingerprint Sensor
    Not all smartphones have fingerprint sensors. However, all new models of smartphones being shipped nowadays have fingerprint sensors embedded in them. A fingerprint sensor is by far the most secure and fast means of unlocking your phone. The only problem is that not all smartphone have a proper placing of the fingerprint sensor. Fingerprint sensors are hence the most recommended means of locking your smartphone. Use a PIN code or password only as a backup.
  2. Add protection
    Use the security features that come in your Android/ iPhone devices. Apple device users can turn on the “Find My iPhone” feature in iCloud, which might come handy in locating a missing device and erasing important data using an activation lock feature.
  3. Set strong passwords
    Be it your social media account, or your banking login account, setting a strong password everywhere is mandatory. Your password should be a unique combination of letters, numbers and special characters and should be difficult to guess. Do not use the same password everywhere, and use a password manager to keep track of all your passwords. Setting strong passwords is another method to ensure smartphone security and prevent someone from tampering with your personal information.
  4. Use apps from the Google Play Store or the Apple Store
    Apple Store and the Google Play Store continuously remove fraudulent apps from the marketplace. Rarely, Google and Apple do fail at protecting the influx of fake apps that seep into the Google Store and Apple Store unknowingly. However, it can be said that the Google Play Store and Apple Store are safer than ever now and downloading apps from these stores are comparatively more secure than downloading bogus apps from unreliable third-party applications.
  5. Use device encryption
    Encrypt your Android smartphone/ iPhone to encrypt the data in your phone. Encryption differs greatly from a simple PIN or passcode. Even if a hacker gets in through the lock screen, your personal information is rendered useless/unreadable unless they have the encryption key. The downside to encrypting your mobile data is that it takes you longer to log in to your device. However, using device encryption takes security one step further and is usable when you have extremely vital data in your smartphone.
    If you are an IOS user, setting device encryption is as simple as setting up a passcode to lock your device. The option can be found under Settings > Passcode.
    If you are an Android user, note that the lock screen and device encryption are separate entities but related. You cannot encrypt your data without turning on the lock screen. To enable device encryption, plugin in your device, set a strong password and navigate to Settings > Security > Encrypt Device. Follow the on-screen instructions and complete the process. Once you encrypt your phone, you cannot turn it off without factory resetting your phone.
  6. Use a Virtual Private Network
    Use a mobile Virtual Private Network to ensure that the free Wi-Fi you use when you have that sip of coffee on the way to work does not come back to bite you. However, make sure that you do not use a free VPN service as they usually don’t work.
  7. Use an anti-virus software
    Use a suitable, paid, anti-virus software to prevent malware from attacking your smartphone data. Some smartphone security anti-virus software also offers the feature of phone tracking, which might not work as expected, but are good-to-have additions.
  8. Delete unused applications
    Constant security updates of apps make the apps secure. However, not all apps regularly release patches, hence stagnant and unused apps might turn out to be an open door for a possible attack. Delete unused apps to reduce the chances of an attacker entering your phone to obtain vital information.
  9. Turn off unused connections
    Turning off Bluetooth and Wi-Fi when not in use does not only save your battery life but can also prevent your smartphone from possible attacks. Open network connections can be used to attack you hence it is advisable to turn off all connections when not in use.

Mobile Threats and Scams

Mobile threats and scams have become a rampant problem as smartphones are in the hands of every average person in this era. There are some common types of fraud committed through mobile devices that one should be aware of:

  1. Phishing
    This is one of the easiest ways for scammers to steal personal data. You get a message, asking to enter your login information. This information is then used to make purchases through the app to which you revealed the information. The same login information can also be used to gain access to other apps that you use since a normal user has the same login credential across several applications.
  2. Vishing
    Vishing is much like phishing and is its telephone equivalent. It involves the act of calling unsuspecting users by appearing to be a legitimate business. Scammers then extract vital information by making the victim think that they will profit. For example, a scammer might call you by pretending to be your bank and asking you for your PIN, or call you as an IRS agent asking for your tax details.
  3. Fraudulent websites
    A smartphone has a smaller screen than that of a desktop computer. Hence, it is difficult to differentiate a fraudulent website from a real one in a smartphone than on a computer. The difference in the logo, quality, and display of the website is un-noticeable in a smaller screen. The use of phony websites and information tampering using fraudulent websites are thus more common on a smartphone.
  4. Subscription fraud
    Fraudulent users gain access to a person’s information and use it to sign up for an expensive subscription. This kind of fraud falls among the most common mobile fraud.
  5. Stolen devices
    If your smartphone gets stolen, fraudulent users can use the device to make purchases through apps.
  6. SMS Fraud
    This kind of fraud usually involves sending SMS on behalf of a user, without his/her knowledge. The SMS is sent to make a purchase, which the user is unaware of. The payments received by the purchase then benefits the fraudulent user.
  7. Phantom apps
    Fake apps of well-known companies can also prove to be a big scam that lures users to pay fraudsters unknowingly. For example, a phony version of Google Wallet was released in 2014, that tricked users to paying money for cheap cars.
  8. Drive-by downloads
    The malware installed into your phone without your consent is referred to as drive-by downloads. Visiting the wrong website can generally trigger these drive-by downloads to be installed in your mobile device and causing harm later.
  9. Viruses and Trojans
    Viruses and Trojans attack your mobile devices by attaching themselves to legitimate programs and later hijacking your smartphone system. Viruses and Trojans can also send premium, costly, text messages.
  10. Network spoofs
    Network spoofs are fake access points set up by hackers to look like Wi-Fi networks. They are set up in high traffic locations with names like “Free Wi-Fi” or “Coffeehouse Wi-Fi” to lure users into creating accounts to log in. Most people generally use the same login credentials to log in to several places. The same username and password obtained from this account are used to gain access to the duped user’s email and banking details.

How to spot Fake Android Apps?

One of the major mobile scam on trend nowadays are fake Android apps that act as masters of disguise and cause harm to your personal data. Copycat apps are released extensively on a daily basis. It is difficult to keep track of which app is genuine and which is not. It is hence important for every smartphone user to know how to spot fake android apps and ensure their smartphone security.

  1. Research
    Before you download an app, do some background research on the number of downloads and the number of reviews that the app has. In some cases, lesser reviews might be an indication of a developer just starting out. In other cases, it might be a scammer intent on tricking you into downloading their malicious app.
  2. Read reviews
    Short and vague reviews or very less number of reviews are often the sign of malicious apps. Some reviews can also give you an insight into the pain shared by other users who have been duped by the app.
  3. Notice details
    Notice the details like the images and design of the app. If they look unprofessional and shoddy, it is probably a fake Android app put together to dupe unknowing users.
  4. Watch out for clones
    Most malicious and fake apps are the clones of the more popular apps. Examine the name of the developer and read reviews carefully in order to differentiate between the original app and the fake one.
  5. Read the documentation
    Good developers usually push out some minor description of what the app does. Read the documentation carefully to figure out if the app has just been pushed out to lure customers, or if it has actually been created with care.

How Free are Free apps?

Everyone loves free stuff. However, everyone also knows that not many things are actually free. The internet is full of free things to offer. How free are free apps? Have you paused before downloading a free app? Do you ever pause to realize that when you download a free app, you give something in return, i.e., your personal information?

Why is your personal information important?

Information is a commodity. Facebook and Google offer free services but collect, sell and analyze user data on behalf of advertisers. The information we share for free is monetized in a big way. When using an app for free, you are giving away your valuable information in return.

Every time you download a free app, you generally share:

• Your browsing history
• Your SMS app
• Your contact list
• Access to your camera
• Access to manipulate your cookies

This data is analyzed and used to deduce the advertisement content of products that you are most likely to purchase.

How do free apps earn money by using your personal data?

Since it is established that free apps are not actually free and take up your personal information in return, read on to find out the ways how free apps earn money:

  1. Online games
    Applications like WeChat (a messaging app in China) earn money through their online games which require purchases to unlock special features.
  2. Advertisement
    Online advertising is a big business, and it is driven by the personal data that you share to a free app. Most free apps also earn money through advertising the products that you are most likely to purchase.
  3. In-app purchases
    Some applications allow the user the download the application for free, but require money to unlock special features.
  4. Add-on services
    Many free applications like LinkedIn earn by offering add-on services. They obtain revenue from providing a platform for these add-on services.

How to protect yourself from free apps?

A huge percentage of top free Android and iOS apps have found to pose some risk to the users. It is always safe to know ways to protect yourself from free apps and prevent your personal data from being used.

  1. Be careful of what you install
    You might be asked to grant various permissions of an app. However, when you are granting permission to a free app, make sure you review the permissions first. For example, if you download a calculator, it does not make sense for the calculator to access your photos, contacts and other mobile data. Sometimes, just some common sense can save your personal data from being monetized.
  2. Stay updated
    Install your mobile updates as soon as they are available. Updating can be a gruesome process and can hamper your activities, but the updates are usually packaged with security updates that are essential in ensuring safety against unauthorized access of data.
  3. Review your installed applications
    You might have at some point in time, given unnecessary permissions to some free apps that you have downloaded. Review the installed applications and the permissions provided to them from time to time. Changing and reviewing application permissions can prevent the misuse of your personal data.

Other Mobile Threats

There are a number of other less common, but equally threatening mobile threats that one should be aware of:

  1. Spyware
    A jealous co-worker or a nosy spouse might install a hidden, application into your smartphone to keep track of your whereabouts. This kind of application is known as spyware, and needless to state, you would not want to be tracked and have your privacy compromised.
  2. Broken cryptography
    Some apps that you download into your mobile might have crappy code including weak encryption mechanisms that any hacker break. Flaws in an app created in haste is common, and hacking such apps is easier in comparison.
  3. Improper session handling
    Improper session handling can let your personal data float free into the hands of scammers with ease. To ease the access mechanism of mobile devices, many apps use tokens. These tokens allow users to access the application multiple times without forcing them to re-authenticate themselves. For security, apps need to generate new tokens with each access attempt. Not doing so can leave the app exposed and vulnerable to attacks and impersonation.

A normal, tech-savvy person has access to a huge load of information on the types of smartphone threats and the ways to prevent them. However, few people take smartphone security seriously and implement methods to ensure the protection of their personal data. It is always advisable to ensure that your personal data remains truly personal by doing whatever needs to be done to keep scammers at bay.

]]>