ZenMate leaks your IP!

Discussion in 'privacy problems' started by flinchlock, Jan 24, 2014.

  1. flinchlock

    flinchlock Registered Member

    Joined:
    Jan 30, 2005
    Posts:
    554
    Location:
    Michigan
    ZenMate leaks your IP! FIXED, if you kill Flash.

    https://zenmate.io/faq#other-extensions
    go here ==> http://www.cloakfish.com/
    "ZenMate for Google Chrome™ 3.3"
    Installed: 1/24/2014 9:32 am
    Deleted: 1/24/2014 10:50 am

    Mike
     
    Last edited: Jan 24, 2014
  2. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,828
    Location:
    Last Breath Farm
    Not good.
     
  3. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,828
    Location:
    Last Breath Farm
    I emailed about this to a tech support person I have corresponded with at ZenGuard and just received this response...

    I read in ZM FAQs this entry:
     
  4. J_L

    J_L Registered Member

    Joined:
    Nov 6, 2009
    Posts:
    8,516
    When I tried it before, Google doesn't offer to change my domain like with other VPN. What is my IP search shows a different address though.
     
  5. flinchlock

    flinchlock Registered Member

    Joined:
    Jan 30, 2005
    Posts:
    554
    Location:
    Michigan
    OK, fixed. :D

    @Page42! :thumb:

    Their FAQ "SECURITY & PRIVACY" section has six items:
    How would a mere mortal know the 2nd item is only true if you also do the 6th item?

    How about having your ZenMate buddy include ALL the text in the 6th item IN the 2nd item?

    I am messing with ZenMate just to learn stuff... no REAL NEED.

    I would hate to be someone in a scary country and get thrown in prison for the rest of my life just because Adobe Flash!

    Mike
     
  6. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,828
    Location:
    Last Breath Farm
    Are you familiar with Stop Making Sense? That's what you should do! LOL!
    Joking aside, my thoughts exactly.
    I will email "my buddy" with your suggestion. It's a good one.
    Glad you brought this to everyone's attention, Mike. Bit of a drag to have to install another extension in order for ZM to do its job properly. But FlashControl does appear to have merit on its own, and I will keep it onboard for awhile. :thumb:

    PS - By the way, I don't know that ZM is tracking or logging your IP... just that it is allowing it to leak.
     
  7. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,828
    Location:
    Last Breath Farm
    FYI, I sent your quote to ZM tech support verbatim, and told them that I thought their FAQ should include a more concise warning, along the lines of...
    FlashPlayer will cause your real IP to be leaked even if you are using ZM.
     
  8. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    Just use a normal VPN, anything free is not worth using. I would never trust my privacy to something free.
     
  9. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,828
    Location:
    Last Breath Farm
    ZM is free to home users, but costs for businesses... like so many models.
    Don't know if I agree with your "never trust my privacy to something free" premise.
    Your privacy can be compromised just as easily and readily by a paid service, to my thinking.
    Do you have some suggestions for good VPNs? TY
     
  10. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    Mullvad/BolehVPN is what I suggest right now. What business would use ZenMate, like... seriously. Corporate business use their own servers and a small business would probably just look up reviews and use something else.
     
  11. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,828
    Location:
    Last Breath Farm
    It's ben said that one should never purchase a VPN account because transactions can be traced. This would be a benefit of a free account, I'm thinking.
    Thanks for the Mullvad/BolehVPN rec.
     
  12. taleblou

    taleblou Registered Member

    Joined:
    Jan 9, 2010
    Posts:
    1,166
    what about instead installing "flash control" extension, you not only block flash but all plugins per your request ( the same thing as flash control and more) from google chrome "content setting" choosing click to play option for plugins?

    I am using it now and all flashes are blocked until I click on them and run them manually. So my question is does this offer the same or better protection then flash control extension?

    P.S. I just read that "flash control" does not block youtube videos from loading since it uses HTML5. But the chrome plugin tweak I mention here even blocks youtube until I click for it to play. SO it works better then flash control maybe.
     
    Last edited: Jan 24, 2014
  13. flinchlock

    flinchlock Registered Member

    Joined:
    Jan 30, 2005
    Posts:
    554
    Location:
    Michigan
    Thanks! I agree, "better then flash control". :D

    At the http://www.cloakfish.com/ web site, I see the following when I click on "more details" using the built-in Chrome "click to play" or FlashControl.
    Hmm, hostname is probably bad?

    Mike
     
  14. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    If your in China or Iran who keep notes of programs that subjugate the state then yeah host name is bad. But if your in a neutral country its fine as long as the host name is not related to your computer/ISP.
     
  15. taleblou

    taleblou Registered Member

    Joined:
    Jan 9, 2010
    Posts:
    1,166
    So it seem no-more leaking of your ip and your private ip is protected. Thats good I think?

    here is mine with chrome click to play and zenmate together from cloakfish:

    Your IP is*46.19.138.138*, no proxy can be detected
    Your country is , (Unknown City)
    Your primary language is english

    So my real ip is hidden and secured.
     
  16. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,828
    Location:
    Last Breath Farm
    If you click on the 'more details' hyperlink directly beneath the line that says "Your primary language is english", you'll probably see the "Your hostname is us9.node.zenmate.io" that flinchlock is referring to.
     
  17. mirimir

    mirimir Registered Member

    Joined:
    Oct 1, 2011
    Posts:
    6,029
    Friends don't let friends rely on proxies for anonymity ;)
     
  18. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    lol, good advice.
     
  19. Page42

    Page42 Registered Member

    Joined:
    Jun 18, 2007
    Posts:
    5,828
    Location:
    Last Breath Farm
    And feel free to elaborate, friends. ;)
     
  20. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    VPN's protect you system wide, proxies only in the browser. Things like Flash&Java can connect through your system and around your browser proxy which leaks your real IP. Let alone many other downfalls like slower speeds, lag, latency and broken websites.
     
  21. taleblou

    taleblou Registered Member

    Joined:
    Jan 9, 2010
    Posts:
    1,166
    So it is zenmate I am using is at country that has no effect on me. It does not show my country and location.

    Heck even cloakfish can be not reliable or accurate. I tried it with my real ip and no proxy and it gave my location wrong. lol.
     
  22. taleblou

    taleblou Registered Member

    Joined:
    Jan 9, 2010
    Posts:
    1,166
    I did it again as you said clicking on further detail and no us9node.zenmate.io.

    this is what it said.
    Your IP is 81.17.28.58 , no proxy can be detected
    Your country is Russian Federation, (Unknown City)
    Your current IP does not have a reverse hostname
    Your primary language is english
    You followed a link from http://www.cloakfish.com/

    Again the country node is wrong. lmao. I am not using russian federation. Zenmate does not have russian location.

    It seems zenmate changes location constantly.

    When started browser, I had unknown country then came here and it says now russian federation with different ip and I guess if I go to another page it will change again.

    lmao. I guess this will confuse those who try to track.
     
  23. taleblou

    taleblou Registered Member

    Joined:
    Jan 9, 2010
    Posts:
    1,166
    Me think having linux mint with chrome with plugin on click to play and zenmate will be the best option as it will confuse the spies.
     
  24. Taliscicero

    Taliscicero Registered Member

    Joined:
    Feb 7, 2008
    Posts:
    1,439
    Guys, IP's can sometimes be misread, happens all the time. Wrong GEO ID and such on the wrong lists.
     
  25. taleblou

    taleblou Registered Member

    Joined:
    Jan 9, 2010
    Posts:
    1,166
    here is the funny thing. I tried it with geo ip loctator and the same ip that cloakfish said is from russia geo ip locator said is from IRAN near tehran. lmao..

    It seems I am everywhere. Something has happened?
     
Loading...