Bug #3758

Orbot reveals my real IP address

Added by Anonymous over 3 years ago. Updated over 3 years ago.

Status:NewStart date:09/14/2014
Priority:UrgentDue date:
Assignee:n8fr8% Done:

0%

Category:-Spent time:-
Target version:-
Component:

Description

The following flaw is reproducible: I need to uncheck "Tor everything" to choose which apps are going through Tor, since I want to use a WiFi File Transfer application and also an app that enables my Android phone to use the landline. Both apps are not accessible otherwise and I'd like to keep them if possible. "Google Play Music All Access" is also unticked to reduce the load on the Tor network. Anything else remains checked and in return the Notification panel shows me an nice list of Tor-Relays, so I assumed to have a secure connection.

However, a quick check on http://showmyip.gr or on my own domain does reveal my real IP. This has been tested in Google Chrome and Firefox. Firefox keeps the connection to the Tor network for a while, perhaps due to the use of the plugin. However, after an hour or so it also falls back to use my real IP while the notification panel tricks me to believe my connection is stable. Please also note that Firefox does ask for favicons of already visited websites repeatedly. If the website doesn't provide one, the real IP is also registered in the log-files of the visited domain.

This has been tested with the last two versions of Orbot on a rooted Nexus 5 with Kitkat 4.4.4. To reiterate: I just unchecked "Tor everything" enabled "Expanded Notifications" and picked my own list of apps under "Select Apps". "Transparent Proxying" and "Request Root Access" are granted.

A solution would be really appreciated.

History

#1 Updated by n8fr8 over 3 years ago

  • Assignee set to n8fr8

What happens when you visit https://check.torproject.org with the browser you say is leaking?

Also available in: Atom PDF