Surfshark VPN : Award-winning VPN service

jasonX

Bardzo aktywny
Dołączył
23 Październik 2015
Posty
239
Reakcje/Polubienia
1242

What is AitM? Understanding Adversary-in-the-Middle attacks




fk1Q6qH.png



In an AitM (Adversary-in-the-Middle) attack, a bad actor inserts themselves between you and a website, intercepting and manipulating the interaction. It’s a modern variant of an MitM (Man-in-the-Middle) attack, but it isn’t any less dangerous. That’s why it helps to understand everything from how AitM attacks work to their warning signs. Mr. Jon Sidor of Surfshark shares us info to further understand "Adversary-in-the-Middle" attacks. Read on below.


How AitM attacks work??

In an AitM attack, a malicious actor positions themselves between you and a website or service, intercepting and relaying your data in real time. This allows them to steal, modify, or manipulate sensitive data like login credentials, 2FA (Two-factor Authentication) codes, session tokens, payment details, and page content.

The mechanics of Adversary-in-the-Middle attacks?
Normally, your device communicates directly with a legitimate server when you’re using a website or app. Your device sends a request, the server processes it, and a secure session is established. From there, your device keeps interacting with the server as you browse pages, make payments, and perform other actions.

An AitM attack interrupts this direct connection by placing the attacker in the middle. They relay messages between you and the server, secretly capturing sensitive information as it travels from one side to another.


XnGOOUQ.png



Five-step infographic titled How AitM attacks work, showing how an attacker intercepts and exploits user data.
Here’s a step-by-step breakdown of the attack process:


  • 1. Attacker sets up a proxy

    The attacker sets up a malicious proxy that sits between you and the website, often using tactics such as phishing pages or fake Wi-Fi networks.

    2. User initiates a normal session

    You access a website as you normally would by plugging in a URL or clicking a login link. From your end, everything looks legitimate, but your connection is already being routed through the attacker’s proxy.

    3. Attacker forwards your request to the server

    Acting like a live relay, the attacker forwards your request to the legitimate server. The server sees it as a request coming directly from you.

    4.Server responds through the attacker

    The server processes the request and sends a response. This can be login results, authentication data, messages, or payment information. Since the response goes through the attacker, they get a first look at everything being exchanged.

    5. Attacker can alter or exploit data
    While the session is active, the attacker can also steal or modify what’s sent and received. They may:

    - Steal usernames and passwords;
    - Capture 2FA codes in real time;
    - Hijack session tokens to access accounts without reauthentication;
    - Change payment amounts or recipient details;
    - Inject malicious scripts or modify page content.

Common targets of AitM attacks?
Most AitM attacks are fairly opportunistic. That said, high-value services, platforms, and systems are more frequently in the crosshairs than others.

Here are some of them:

  • Corporate credentials and authentication: they act as the entry point, providing access to the organization’s internal systems, databases, and emails;
  • Cloud services and SaaS accounts: platforms like Microsoft 365 and Google Workspace hold sensitive data (such as confidential documents and customer records) and are often used to access other connected tools and services;
  • Banking and financial accounts: these are prime targets for obvious reasons — they offer direct access to money and allow attackers to view balances, move funds, or carry out fraudulent transactions;
  • MFA (Multi-factor Authentication) systems: MFA isn’t the final target itself, but many systems act like a barrier that attackers try to get past to reach the account they protect.


What is AitM phishing?

AitM phishing is a
Zaloguj lub Zarejestruj się aby zobaczyć!
where the attacker gets between you and the actual website you’re using. They relay your login process in real time and capture the session token issued after authentication. With the token acting like a temporary pass, they can take over your active session and access your account without re-entering login details or verification codes.

Understanding AitM phishing techniques?
In AitM phishing campaigns, a
Zaloguj lub Zarejestruj się aby zobaczyć!
sits between you and the website you’re trying to access. Rather than simply cloning a login page like traditional phishing attacks, the attacker uses this proxy server as an intermediary — passing data back and forth between you and the legitimate website.

When you enter your login details on what looks like a genuine page, the attacker forwards them to the actual service. Whatever the site sends back also goes through the attacker before it reaches you.

Once you log in, the real site creates a session cookie that confirms you’re authenticated.

How AitM phishing attacks bypass MFA?
The session cookie is how AitM phishing attacks typically bypass MFA. Instead of trying to break or guess the second factor, the attacker simply lets the login process play out while they focus on real-time credential harvesting in the background.

When you enter your username, password, and even your MFA code, they immediately forward those details to the legitimate site. If everything checks out and the login is successful, the real site issues a session token or cookie to confirm that you’re authenticated.

Since the attacker intercepts everything, they can grab the token as it’s sent back. That token signals that MFA has already been completed, and whoever has it can access the account without needing to log in or verify again. From there, the attacker just uses the token to get straight into your account.

Types of AitM phishing attacks
AitM phishing attacks usually share the same goal: hijacking your login session in real time. What’s different is how different AitM attacks operate. Let’s run through some of the most common types of AitM attacks.

Email-based AitM phishing
Email is a popular entry point for AitM phishing attacks since it’s regularly used for logins, password resets, and account notifications. This is why attackers often send malicious emails that lead you to a fake login page.

Typically, they impersonate trusted organizations such as big tech companies, banks, or even government agencies. They also mimic branding, language, and domain names so the email looks familiar and routine, making it easier for you to lower your guard.

To help you flag these emails before you interact with them, consider using tools like
Zaloguj lub Zarejestruj się aby zobaczyć!
.

SMS and social engineering AitM attacks
With global smartphone users expected to hit 6.1 billion in 2029, attackers are increasingly targeting mobile-based communication channels in AitM phishing attacks.

These include:

  • Smishing (SMS phishing): you get a text about missed deliveries, account issues, or security alerts, with a link that leads to a fake login page;
  • Vishing (voice phishing): someone calls pretending to be your bank or tech support and walks you through the steps to log in via a link they provide;
  • Quishing (QR code phishing): instead of a link, you’re pushed to scan a QR code that opens a fake login page in your browser.

Browser-based AitM attacks
Some AitM attackers target the browser level, where your active sessions are especially vulnerable:

  • Malicious browser extensions: disguised as helpful add-ons, these extensions access active sessions and grab authentication data like session tokens;
  • DNS (Domain Name System) spoofing: even if you enter the correct address, the attacker manipulates DNS results to reroute your traffic to a fake site;
  • SSL stripping: by downgrading encrypted HTTPS connections to unencrypted HTTP, the attacker makes your session data visible.


Real-world examples of AitM attacks
AitM may give the impression that it’s a new threat with little real-world impact so far, but there have already been plenty of reported cases.

Notable AitM attack cases
Let’s take a look at some high-profile cases that show AitM in action.

Attack on Microsoft 365 accounts

In 2022,
Zaloguj lub Zarejestruj się aby zobaczyć!
targeting over 10,000 Microsoft 365 compromised accounts. Victims received phishing emails that led to a fake page that proxy-redirected to the Azure Active Directory sign-in page. Attackers then captured credentials and session cookies, used them to access inboxes, and carried out payment fraud.

Attacks against banking and financial services

Zaloguj lub Zarejestruj się aby zobaczyć!
targeting people in the financial sector in 2023. These attacks started from a compromised trusted vendor and escalated into a series of AitM and BEC (Business Email Compromise) campaigns that affected multiple organizations.

Attack involving SOHO routers

An
Zaloguj lub Zarejestruj się aby zobaczyć!
— a Russia-linked threat actor — used compromised SOHO (Small Office/Home Office) routers and DNS hijacking to sit between victims and Microsoft services. It hit sectors like government, IT, energy, and telecommunications and impacted over 200 organizations and 5,000 consumer devices.

Attack statistics and trends
AitM has quickly become one of the biggest headaches in cybersecurity:


How to detect AitM attacks
AitM attacks might be trickier to spot than traditional phishing, but they aren’t invincible. The key is to stay vigilant and watch for common red flags.

Warning signs of AitM phishing
Some AitM phishing signs are more visible than others. These are the ones you’re most likely to notice:

  • Suspicious URL patternsTechnical indicators of AitM activity: in URL phishing, links may appear legitimate at first glance, but a closer look often reveals misspellings, odd subdomains, and other inconsistencies;
  • Certificate warnings: browser security alerts like Your connection is not private or Certificate not trusted can pop up when your connection is being intercepted or isn’t secure;
  • Unusual login requests: if you’re repeatedly asked to sign in or re-enter credentials within the same session, it can indicate session interception.


Technical indicators of AitM activity
Other signs of AitM attacks are harder to identify, especially when the clues appear mostly behind the scenes. In these cases, check system or account behavior:

  • Network traffic: you might notice unusual activity like repeated authentication requests or delays during login as your traffic gets routed through an intermediary;
  • Session behavior: strange activity patterns like sudden location jumps, repeated silent re-authentication, or sessions appearing active from multiple locations at once often suggest session interception;
  • Authentication logs: multiple login attempts, sign-ins from new locations, or mismatched IP (Internet Protocol) and device details can all point to AitM activity.


Attack disruption: preventing AitM phishing attacks
For strong protection against AitM phishing attacks, you need a multi-layered defense that combines user, organizational, and technical safeguards.

User-level protection strategies
In AitM phishing attempts, attackers often count on users trusting and breezing through logins. Here’s how you can make it that much harder for them to succeed:

  • Security awareness training helps you pick up on AitM tricks and patterns so you’re less likely to fall for or interact with them;
  • URL verification best practices reduce the risk of logging into fake login pages by encouraging you to always check the full domain;
  • Password managers only autofill when the domain is an exact match and cut out manual typing so AitM pages can’t capture what you enter;
  • Hardware security keys only work on the right sites and require a physical action for verification, which blocks AitM phishing sites from completing authentication.

Organizational defense measures
Disrupting AitM attacks at scale often takes more than just individual effort. This is where organization-wide protections come in:

  • Phishing-resistant MFA replaces easy-to-intercept login codes with cryptographic authentication tied to the real site;
  • Conditional access policies filter login requests based on device, location, and even behavior patterns to block or challenge suspicious sign-in attempts;
  • Email security gateways screen and check your messages, blocking phishing emails that lead to proxy login pages;
  • ZTA (Zero Trust Architecture) treats every access request as untrusted and verifies them continuously, limiting what AitM attackers can do with a hijacked session;
  • B2B cybersecurity suites like Surfshark for teams disrupt AitM attacks by combining VPN (Virtual Private Network) protection with real-time threat detection. Beyond a standard encrypted tunnel, these solutions can also include security alerts that notify admins if credentials have been leaked and antivirus software that prevents the installation of malicious proxies often used in AitM interceptions.


Technical controls against AitM
In addition to user and organizational measures, technical safeguards help to round out protection against AitM attacks:

  • Certificate pinning locks an app or service to a trusted digital certificate so it rejects fake certificates used in AitM attacks;
  • Token binding ties your login session to your device so attackers can’t reuse your stolen session cookie elsewhere;
  • Continuous authentication keeps verifying you throughout the session and blocks access if something appears off;
  • Behavioral analytics track how you normally behave and flag or block activity if it doesn’t match your usual pattern.


AitM vs. traditional phishing: key differences
AitM and traditional phishing attacks are often lumped together, but there are actually some significant differences between the two. Knowing how to tell them apart can help you better protect yourself.

Here’s a quick recap of how they differ:


y3HIWNu.png



The future of AitM attacks
AitM attacks are evolving quickly as attackers refine their techniques and find more gaps in security. In response, defenses are adapting just as fast to keep pace.

Emerging AitM attack vectors
AitM attacks are becoming more sophisticated as attackers look for new ways to scale, automate, and deliver their campaigns more effectively.

Here are some new AitM methods and trends to watch:

  • AI-powered AitM automation: attackers are starting to use AI (Artificial Intelligence) to scale and refine attacks, from generating convincing phishing pages to adapting in real time;
  • Mobile-specific AitM threats: as everything shifts to mobile, attackers are increasingly going after compromised users through in-app browsers, smishing, and mobile sign-in processes;
  • Cloud service vulnerabilities: as more logins move to the cloud, attackers often exploit weak or misconfigured login processes, session management, and identity verification.

Evolution of defense technologies
Security tools and measures are also stepping up their game as AitM attacks become more sophisticated.

These are some main ones to know:

  • Passwordless authentication — like hardware security keys — removes passwords entirely, so there’s nothing for attackers to steal or reuse;
  • Biometric verification advances make logins more reliable, using fingerprint or face recognition that’s harder to fake;
  • FIDO2 and WebAuthn (Web Authentication) standards replace passwords with a pair of cryptographic keys that verify identity without exposing credentials, minimizing AitM interception or reuse.


Conclusion: protecting against AitM threats
Considering how dynamic AitM attacks can be, there’s no one quick fix that can stop them for good. Instead, you can minimize the risk by combining smarter habits with layered defenses.

Start by getting familiar with common AitM tactics and always checking the full domain before you log in. You can also use a password manager to reduce manual credential entry. For stronger protection, switch from traditional MFA to phishing-resistant authentication methods.


Zaloguj lub Zarejestruj się aby zobaczyć!


Data and info derived / lifted from Surfshark with permission



Supplemental Information:

Zaloguj lub Zarejestruj się aby zobaczyć!


Zaloguj lub Zarejestruj się aby zobaczyć!


Zaloguj lub Zarejestruj się aby zobaczyć!
 

jasonX

Bardzo aktywny
Dołączył
23 Październik 2015
Posty
239
Reakcje/Polubienia
1242

Does Alexa spy on you?




dC4C4up.png


Alexa doesn’t spy on you. But if you want to be precise, the answer is a little more nuanced than a simple yes or no. After all, Alexa is built to listen for and process voice commands, which means it can sometimes pick up more than it should.

Mr. Jon Sidor of Surfshark shares how Alexa actually works, which privacy concerns are worth your attention, and what you can do to protect yourself. Read on below.

What is Amazon Alexa?

Amazon Alexa is a cloud-based voice assistant developed by Amazon. It’s built into thousands of products, from Amazon’s own devices like the Echo Dot and Fire TV to third-party apps, wearables, appliances, and even cars.

Depending on the device, you can use Alexa to:

  • Make calls;
  • Play music;
  • Set reminders;
  • Manage to-do lists;
  • Check traffic updates;
  • Answer everyday questions;
  • Control connected smart home devices like lights, security cameras, and thermostats.


How does Alexa work? Most interactions follow these basic steps:

  • You say the wake word to activate the device.
  • Alexa records your request and sends it to Amazon’s cloud servers.
  • Amazon’s systems process your request and find the right response or action.
  • The result is sent back to your device.
  • Alexa then delivers the answer or executes the task.

Is Alexa always listening?

Yes, Alexa is always listening, but not quite in the way many people imagine.

Alexa-enabled devices like the Echo keep their microphones on because they’re designed to listen for a wake word — usually “Alexa,” though you can change it. This is known as keyword spotting or wake word detection.

This is also where most of the confusion starts. Some people hear that Alexa is “always listening” and assume it means Alexa spies on you. In reality, Alexa is always listening for its wake word, which is very different. Though the microphone is always on, it’s not actively recording or sending everything you say.

Alexa is designed to only collect audio data like your search terms, shopping requests, and voice history — not everything it hears.


Lk8JvTA.png



Alexa collects: search terms, shopping history, voice recordings, device usage information, personal details, location data
That said, mistakes can and do happen. Sometimes sounds from your TV or your conversation with a friend might sound similar enough to accidentally trigger the device. This isn’t exclusive to Alexa either — other voice assistants like Siri, Google Assistant, and Samsung Bixby can experience similar false activations.

And when that happens, it can further muddle things and make it feel like Alexa is listening more than it actually is.

Does Alexa record conversations?

Alexa doesn’t record or store everything you say throughout the day. Instead, it only captures what you say after it detects your wake word.

Most of these recordings come from instances when you’re actively interacting with Alexa, like when you ask a question or give a command. In some cases, though, it may also record short audio clips unintentionally if Alexa is triggered by mistake.

Whether intentional or accidental, Alexa still sends the snippet to Amazon’s cloud servers for processing. Once the processing is done, these recordings are stored in the cloud and linked to your Amazon account.

That said, you still have some control over the recordings. You can review or delete them at any time, decide how long Amazon keeps them, or turn off voice history storage altogether if you prefer.

Can the Echo Dot be used by hackers to spy on you?

It’s unlikely for hackers to use an Echo Dot to spy on you, though it’s not completely impossible.

While smart speakers like the Echo Dot can be targeted in some situations, you can’t just flip a switch and turn it into a spy device. In reality, attacks like this usually require very specific conditions, such as physical access to your device, access to the same Wi-Fi network, or an already-hijacked Amazon account.

This actually came up at the
Zaloguj lub Zarejestruj się aby zobaczyć!
. Here, researchers showed how a modified Amazon Echo could exploit a weakness in how Echo devices communicated over the same Wi-Fi network and potentially take control of nearby speakers. In theory, this could turn them into hidden listening devices.

However, the researchers also highlighted a major catch: the attack required a physically altered device and access to the same network, making it highly complex and impractical for most attackers. Amazon has since patched the vulnerability.

What actually happens when you use Alexa

While Alexa isn’t designed to spy on you, there are still a few privacy risks you should be aware of before you start using it.

Amazon shares a lot of Alexa data with third parties

According to Amazon, it doesn’t sell customers’ personal data, but it does share certain Alexa data with third parties.

These can include:

  • Service providers that help run Amazon’s systems, such as cloud infrastructure providers or technical support teams;
  • Integrated service partners that connect their services to Alexa, like music streaming platforms, smart home device manufacturers, and navigation apps;
  • Developers behind Alexa skills— the apps that extend Alexa’s functionality — such as food delivery services, ride-hailing apps, or smart home systems.

This means parts of your Alexa activity may be processed outside Amazon, and you may not always have full visibility or control over where it’s sent or how it’s stored. What gets shared also depends on how you use Alexa. Since Alexa is used for everything from smart home control to everyday requests, it can reveal patterns about your routines, interests, and household activity.


Amazon might not delete your data when it says it does


Amazon lets you review and delete your data. You can also choose to automatically delete your voice recordings, text transcripts, and typed Alexa requests after a certain period of time, or stop saving voice recordings entirely.

But an official
Zaloguj lub Zarejestruj się aby zobaczyć!
reveals that deleting your data doesn’t always mean it’s removed from all of Amazon’s systems.

According to the complaint, Amazon repeatedly told Alexa users they could delete voice recordings and geolocation data. However, Amazon allegedly retained this data for years and used it to train Alexa’s algorithms. Amazon later
Zaloguj lub Zarejestruj się aby zobaczyć!
to settle the case.

Today, while you can now manually delete voice recordings through the Alexa app,
Zaloguj lub Zarejestruj się aby zobaczyć!
still states:

“We may still retain other records of your Alexa interactions, such as attachments you shared with Alexa, information you provided through your interactions, records of actions Alexa took in response to your requests, records of products you searched for, and other information related to your requests.”

Amazon employees may listen to your voice recordings

A
Zaloguj lub Zarejestruj się aby zobaczyć!
revealed that Amazon had thousands of employees and contractors listening to, reviewing, and transcribing samples of Alexa voice recordings to help improve the system. Some of those recordings might have even picked up unintended or sensitive background audio.

The same report also noted that reviewers sometimes used internal chat rooms to share files and help make sense of unclear audio. In some cases, people working on the transcription may have had access to additional information linked to the recording, including location data.

Following the report, Amazon introduced the option to opt out of saving your voice recordings. Nevertheless, as of March 2025,
Zaloguj lub Zarejestruj się aby zobaczyć!
to Amazon’s servers by default, even if you have chosen not to store the recordings long-term.

Accidental activations and misinterpretation

In theory, Alexa should only record after hearing its wake words. However, false activations do happen, as they do with other voice assistants.

Here are a few examples of Alexa misfiring or misinterpreting:

  • A
    Zaloguj lub Zarejestruj się aby zobaczyć!
    accused Amazon of secretly recording conversations after Alexa devices allegedly misinterpreted words and activated accidentally, even when users didn’t intentionally say the wake word;
  • Researchers from Ruhr-Universität Bochum and the Max Planck Institute for Security and Privacy found that
    Zaloguj lub Zarejestruj się aby zobaczyć!
    ;
  • A
    Zaloguj lub Zarejestruj się aby zobaczyć!
    found that smart speakers, including the Amazon Echo Dot, could accidentally activate and start recording as many as 19 times per day.


How to stop Alexa from unnecessary listening

You don’t necessarily need to ditch Alexa over privacy worries. Instead, with a few simple changes, you can minimize unnecessary listening and manage your data better. This is how you do it:


mpdJwFF.png


Mute the microphone when you’re not using Alexa

The first and most straightforward step is to mute the microphone.

If you’re using an Echo device, every model has a physical button that turns the microphone off completely. Once it’s switched off, Alexa no longer listens for the wake word. This also means you don’t have to worry about the device capturing anything in the background when you’re not using it.

Remove existing voice history

Clearing your voice history helps you control what Alexa keeps about you. It limits the amount of stored recordings linked to your account, including older interactions you may have forgotten about.

Here’s how:

1. Go to
Zaloguj lub Zarejestruj się aby zobaczyć!
in your browser.
2. Select Review Alexa History.
3. Use the drop-down menu to choose a date range, or filter by device or profile.
4. Select the recordings you want to delete, or choose Delete all history.
5. Select Delete to confirm.

Limit voice recording storage

Once you’ve cleaned up what Alexa has already stored about you, the next step is to tweak your settings so it doesn’t save new recordings, or only keeps them for a short time.

This is how you do it:

1. Go to
Zaloguj lub Zarejestruj się aby zobaczyć!
in your browser.
2. Scroll down to Manage Your Alexa Data and select it.
3. Select Choose how long to save.
4. Select Don’t retain.

You can also delete recordings using voice commands, such as “Alexa, delete what I just said” or “Alexa, delete everything I said today.” All you need to do is switch on the Enable deletion by voice toggle.

Opt out of training Alexa

The rule of thumb is simple: the less of your data that’s out there, the better. That’s why it’s also a good idea to stop your voice recordings from being used to help train Alexa.

Here’s how:

1. Go to
Zaloguj lub Zarejestruj się aby zobaczyć!
in your browser.
2. Scroll down to Help improve Alexa.
3. Toggle off the Use of voice recordings button.
4. Select TURN OFF.

Review connected Alexa skills

Managing Amazon’s settings is only part of the picture. To really close the gap, you also need to review third-party skills connected to Alexa. If you’re not using a particular skill, turn it off to minimize unnecessary access to your data.

Here’s how:

Go to
Zaloguj lub Zarejestruj się aby zobaczyć!
in your browser.
Select Manage Skill Permissions and Ad Preferences.
Review the skills you’ve enabled and turn off any you no longer use.

Pro tip: A trusted VPN (Virtual Private Network) like Surfshark VPN can add an extra layer of privacy. It masks your IP (Internet Protocol) address, making it harder for third parties to link your Alexa activity to your location or home network.
Zaloguj lub Zarejestruj się aby zobaczyć!
on your router to help protect all devices connected to your Alexa setup.

Should you be worried about Alexa spying on you?

You don’t necessarily need to worry about Alexa spying on you, as it isn’t built to listen in on your private conversations or actively monitor you. That said, as with any voice assistant, there are still some privacy risks to keep in mind.

However, rather than avoiding it entirely, it simply means using Alexa more consciously. Review your voice history and adjust your privacy settings. For added protection, you can use Surfshark VPN to make it harder for third parties to trace your Alexa activity back to you or your location.

Zaloguj lub Zarejestruj się aby zobaczyć!


Data and info derived / lifted from Surfshark with permission



Supplemental Information:

Zaloguj lub Zarejestruj się aby zobaczyć!


Zaloguj lub Zarejestruj się aby zobaczyć!


Zaloguj lub Zarejestruj się aby zobaczyć!


Zaloguj lub Zarejestruj się aby zobaczyć!


Zaloguj lub Zarejestruj się aby zobaczyć!
 

jasonX

Bardzo aktywny
Dołączył
23 Październik 2015
Posty
239
Reakcje/Polubienia
1242

Dausos now connects more reliably on strict networks




qGcrn9M.png



Dausos, Surfshark's proprietary VPN protocol, just received a significant upgrade. If you’ve been connecting from a school, university, or corporate network — this update is for you.









What changed
Our latest upgrade is focused on one thing: making sure Dausos connects reliably on restricted networks.

Highly managed networks — the kind you’ll find in academic institutions and corporate environments — use strict firewall configurations that may block or interfere with VPN connections. Previously, some users on these networks ran into connectivity issues with Dausos. This update fixes that.

“We want as many people as possible to experience the power of Dausos, which is why continuous improvement is our priority. Responding directly to user feedback, this update fixes the connectivity issues some experienced in certain network environments,” says Karolis Kaciulis, Leading System Engineer at Surfshark.

Why this matters
Whether you’re a student trying to access content on campus Wi-Fi or an employee on a tightly managed corporate network, this update directly addresses one of the biggest friction points for Dausos users.

Dausos was built for everyday users, and everyday users connect from all kinds of networks — not just open, unrestricted ones. Making sure the protocol holds up across all of them, including the ones that give other VPNs a hard time, is exactly what this update delivers.

A reminder of what Dausos brings to the table
If you haven’t tried Dausos yet, here’s why it’s worth trying:

  • Up to 30% faster speeds. Powered by AEGIS-256X2 encryption optimized for modern hardware, delivering better protocol-to-server speed;
  • Full post-quantum security. A hybrid ML-KEM×X25519 key exchange and ML-DSA self-signed root certificate system protect your connection against both today’s threats and tomorrow’s;
  • Your own dedicated tunnel. Unlike traditional VPN protocols, Dausos isolates each user’s data into its own private digital tunnel — your traffic stays separate from everyone else’s;
  • Advanced security by default. Post-compromise security ensures compromised keys can’t leak future session data, and port randomization obscures your connection path.


Dausos keeps improving
Dausos was built for VPN users, and that doesn’t stop with the initial release. Updates like this one are how we make sure it stays that way. If you haven’t tried Dausos yet, now’s a good time.

Zaloguj lub Zarejestruj się aby zobaczyć!


Data and info derived / lifted from Surfshark with permission
 

jasonX

Bardzo aktywny
Dołączył
23 Październik 2015
Posty
239
Reakcje/Polubienia
1242

What is a stealth VPN, and how does it work?




W3BXspp.png



A stealth VPN uses obfuscation techniques to disguise VPN traffic as ordinary HTTPS traffic. While a regular VPN encrypts your internet traffic, a stealth VPN goes one step further and hides the fact that you’re using a VPN at all. Stealth VPNs are especially useful on restrictive networks or in countries where governments, ISPs (Internet Service Providers), or network administrators actively block VPN connections.

Mr. Jon Sidor of Surfshark shares us this article which explores what a stealth VPN is and how stealth VPN protocols work. Taking the top stealth VPN strengths and limitations into account, it also covers when using stealth mode makes sense — and when it doesn’t. Read on below.

What is a stealth VPN?

A stealth VPN is a VPN (
Zaloguj lub Zarejestruj się aby zobaczyć!
) that disguises your VPN connection so it doesn’t look like VPN traffic to outside observers. It can be a standalone tool or a specific feature within a VPN service.

The “stealth” part refers to obfuscation: the process of altering VPN data packets so they resemble normal web traffic rather than encrypted VPN traffic.

Here’s the key difference between a regular VPN and a stealth VPN:

  • A regular VPN encrypts your traffic and routes it through a VPN server. Your data is protected, but the connection is recognizable as a VPN connection. Anyone inspecting your traffic — your ISP, firewall, or network admin — can tell you’re using a VPN, even if they can’t see what you’re doing;
  • A stealth VPN does everything a regular VPN does, but it also masks the VPN connection itself. Your encrypted traffic looks like normal HTTPS traffic, the same kind of encrypted connection your browser uses when you visit a secure website.

Why are some VPNs blocked or detected?

VPN connections leave digital fingerprints. Even though VPN data is encrypted, the way it’s packaged and transmitted differs from normal web traffic. Network monitoring tools can spot these differences using the following methods.

Deep packet inspection

DPI (Deep Packet Inspection) is the most common and effective way to detect VPN usage.
It works by analyzing the structure of data packets, including where they’re going and how they’re formatted.

Standard VPN protocols like WireGuard, OpenVPN, and IKEv2 each have recognizable packet signatures. DPI systems can identify these signatures and flag — or block — VPN traffic in real time. Governments in countries that restrict access to certain websites or services invest heavily in DPI technology to block VPNs at the network level.

Port blocking

Many VPN protocols use specific ports by default. For example, OpenVPN typically uses UDP port 1194.

A network administrator can simply block traffic on that port to successfully block VPN traffic. This is a blunt approach, but it’s common on school and workplace networks.

IP blocking

Some networks maintain lists of known VPN server IP (Internet Protocol) addresses and block connections to them.
Streaming services and certain websites also use this method to restrict access from VPN users.

Protocol-based blocking

Some firewalls are configured to block specific protocol types entirely. If a firewall recognizes a connection as WireGuard or OpenVPN, it drops the connection regardless of port or destination.

These detection methods explain why a regular VPN isn’t always enough and why stealth VPN protocols can be useful.

How does a stealth VPN work?

A stealth VPN works by wrapping your VPN connection inside an additional layer of obfuscation, making your VPN traffic look like regular HTTPS traffic.
Here’s how the general process works:


Tu6PcEl.png



1. You connect to a VPN server using a stealth-enabled protocol.
2. The VPN encrypts your traffic as usual.
3. The obfuscation layer wraps the encrypted VPN packets inside standard TLS/SSL encryption, which is the same type of encryption secure websites use.
4. The disguised traffic is sent over port 443, the same port that HTTPS web traffic uses.
5. To outside observers like an ISP, DPI firewall, or network admin, your VPN connection looks indistinguishable from someone browsing without a VPN.

Different VPN providers implement obfuscation in different ways:

  • Using OpenVPN wrapped in an SSL tunnel. Services like Surfshark also scramble OpenVPN traffic into random patterns that resemble neither VPN traffic nor regular browsing;
    Building custom protocols[/b] that use obfuscated TLS tunneling over TCP from the ground up;
    Skipping a dedicated stealth protocol and instead offering
    Zaloguj lub Zarejestruj się aby zobaczyć!
    . These are specialized VPN servers that apply obfuscation at the server level, disguising your VPN traffic regardless of protocol.

The technical approach varies, but the goal remains the same: to make VPN data unrecognizable.

Key insight: In most cases, blocking obfuscated traffic would mean blocking all HTTPS traffic, something that would essentially make the internet unusable for everyone on the network in question. Most firewalls or censorship systems aren’t willing to take such drastic actions, which is what makes stealth VPN technology so effective.

What is VPN obfuscation?

VPN obfuscation is a cybersecurity technique that disguises encrypted VPN traffic as regular HTTPS traffic.
While stealth VPN and VPN obfuscation are often used interchangeably, it’s worth noting that obfuscation is the underlying method that lets a stealth VPN function properly.

VPN obfuscation isn’t the same as encryption. Here are the main differences:

  • Encryption scrambles the content of your data so nobody can read it. A normal VPN encrypts traffic;
  • Obfuscation disguises the appearance of your data so nobody can tell it’s VPN traffic. This is what a stealth VPN adds.

In practice, obfuscation works by stripping or modifying metadata in VPN packet headers that would normally identify traffic as VPN traffic. It then re-packages that traffic to mimic standard HTTPS connections.

Note: Obfuscation doesn’t make you invisible online. It hides the fact that you’re using a VPN, but it doesn’t hide everything. Websites you log into still know who you are, and your browser fingerprint can still be tracked.

Obfuscation is a tool for bypassing VPN blocks — not a solution that offers total anonymity.

Stealth VPN vs. regular VPN
A standard VPN connection provides most users plenty of online protection. As a result, not everyone needs a stealth VPN.

Here’s a side-by-side comparison of a stealth VPN and a regular VPN.


LouhpqS.png



If you’re using a VPN for general privacy, protecting your data on public Wi-Fi, or accessing content while traveling in countries that don’t restrict VPN usage, a regular VPN connection works fine. Your traffic is still encrypted, and you can’t be easily tracked because your activity gets routed through a remote server.

However, if your VPN connection keeps getting blocked or you’re in a situation where VPN traffic is actively detected and restricted, then a stealth VPN can make a real difference.

When should you use a stealth VPN?

Stealth VPN features are designed for specific situations and generally aren’t needed for everyday use. Here are the most common scenarios where stealth mode matters:

  • Traveling to countries that restrict VPN usage: some governments use advanced DPI systems to detect and block VPN traffic. A stealth VPN can bypass censorship and give you access to the open internet;
  • Using school or workplace networks: many institutional networks configure firewalls to prevent VPN connections. Stealth protocols route traffic through port 443, making it look like regular web browsing;
  • Avoiding ISP throttling of VPN traffic: some ISPs throttle connections they identify as VPN traffic. Obfuscation hides the VPN signature, so your ISP treats your connections like any other HTTPS session;
  • Connecting on public Wi-Fi with VPN restrictions: hotels, airports, and cafés sometimes block VPN connections. Stealth mode helps connect you to a VPN server on these restrictive networks;
  • Bypassing internet filters: if you’re behind a firewall that blocks standard VPN protocols by signature, a stealth protocol is often the best way to establish a VPN connection.

Pro tip: Use a stealth VPN when you need it, not as a default. Stealth mode adds processing overhead that can needlessly reduce your connection speed when doing routine tasks like browsing at home.

Does a stealth VPN make you anonymous?

No, a stealth VPN doesn’t make you anonymous.

Here’s what a stealth VPN actually does:

  • Encrypt your traffic so your online activities can’t be easily monitored;
  • Hide the fact you’re using a VPN from your ISP, network, or firewall;
  • Help you bypass VPN blocks to access online content and services.

And here’s what a stealth VPN doesn’t do:

  • Hide your identity from websites you log in to: if you sign in to Google, Facebook, or your bank while using a VPN, those services know who you are;
  • Stop browser fingerprinting: websites can identify your device based on browser type, software versions, hardware configurations, and other signals — even if you have a VPN;
  • Prevent all tracking: tracking pixels and ad networks can follow your activity across the web. Agreeing to cookies makes you trackable as well;
  • Guarantee untraceability: users may want an anonymous VPN that makes tracking significantly harder, but your behavior, accounts, and digital footprint all contribute to maintaining your online privacy.

How to use stealth VPN features with Surfshark

Surfshark includes several VPN features that help you use a VPN in restrictive environments without needing any complex configuration. Refer to Surfshark VPN features
Zaloguj lub Zarejestruj się aby zobaczyć!


Key takeaway: stay undetected with a stealth VPN

A stealth VPN makes your VPN usage harder to detect, but it doesn’t make you anonymous. And while it’s great for restrictive networks, a regular VPN connection is usually enough for enhanced online privacy.


Zaloguj lub Zarejestruj się aby zobaczyć!


Data and info derived / lifted from Surfshark with permission



Supplemental Information:

Zaloguj lub Zarejestruj się aby zobaczyć!


Zaloguj lub Zarejestruj się aby zobaczyć!


Zaloguj lub Zarejestruj się aby zobaczyć!
 
Do góry