YouTube2Text

004 Security Source Code Audit of Mullvad VPN by X41 — Transcript

by Open Source Technology Improvement Fund (OSTIF) · 6,342 words · 895 segments · language en · Watch on YouTube

Full transcript

  1. 0:00Um I'm Marcus Vier. I'm yeah doing
  2. 0:03security for I don't know last 20 years.
  3. 0:06I've been part together with Eric. um uh
  4. 0:10in the this this review of Mulvat and
  5. 0:13yeah we thought that we bring this to uh
  6. 0:16the OST um because yeah it's also let's
  7. 0:20say open source uh open source project
  8. 0:23and I think it fits very well um into
  9. 0:26the topic of how to audit really complex
  10. 0:30um applications that are crucial for
  11. 0:32internet infrastructure and security um
  12. 0:36of everybody. But um yeah, let me pass
  13. 0:38on to Eric to also introduce yourself.
  14. 0:42Yeah, hi, I'm Eric. Um I only took a
  15. 0:45minor part, minor role in this audit. Um
  16. 0:49but yeah, I'm happy to present a bit
  17. 0:51with Marcus. Um we had two other team
  18. 0:53members um JJ and Robio who were part of
  19. 0:58this
  20. 0:59um and yeah, glad to be here.
  21. 1:05Okay, then um yeah, I guess we're going
  22. 1:07to jump right into it. Um I hope you can
  23. 1:11um all see uh the uh my screen share my
  24. 1:16slides. Yeah. Um so yeah, we're going to
  25. 1:19talk about the security audit of
  26. 1:21MulvatVPN and uh in particular about the
  27. 1:23client applications. Um and yeah to us
  28. 1:27has been mean very interesting audit as
  29. 1:29I said before um because it's uh it's an
  30. 1:34it's an application stack that is across
  31. 1:35multiple platforms it had been audited
  32. 1:38before um because that's what they do um
  33. 1:42I think every two years at least and um
  34. 1:46yeah the audit was I mean still kind of
  35. 1:48recent end of last year um as as Eric
  36. 1:52said team of um team of
  37. 1:56uh four people um and yeah in October
  38. 2:00November and um of course I want to say
  39. 2:02everything that we present here is
  40. 2:04already addressed so Mulvat addressed
  41. 2:06the issue swiftly and yeah was very
  42. 2:08cooperative in the audit uh which is I
  43. 2:12think one of the main points even
  44. 2:14today. So the scope or what we uh what
  45. 2:19we were kind of asked to review are um
  46. 2:23the client applications for different
  47. 2:25platforms and um the there are a bunch
  48. 2:28of them. Yeah. So you have Linux uh
  49. 2:32Linux clients, you have Mac OS, you have
  50. 2:34Windows, Android, iOS and um we reviewed
  51. 2:38uh my client applications in particular
  52. 2:42um kind of a shared codebase and demon
  53. 2:45services. Uh we reviewed graphical user
  54. 2:48interfaces, command line interfaces and
  55. 2:51configuration. Um what was out of scope
  56. 2:54of this audit were all the servers back
  57. 2:57end and infrastructure
  58. 2:59um and also most of the dependencies
  59. 3:02because I mean as you will see there's a
  60. 3:04lot of them um but we focused on really
  61. 3:07critical ones um in the set check um
  62. 3:12yeah the code is um yeah open source you
  63. 3:14can um find it on GitHub
  64. 3:17uh in this link slides will be shared
  65. 3:22Sure. Okay. Um yeah, on the bottom right
  66. 3:26you will see why we didn't uh review all
  67. 3:29the dependencies because there's a lot
  68. 3:31of them. Yeah. Um there's also a huge
  69. 3:34amount of code. Yeah. If you look at the
  70. 3:36commits even over time um uh there's a
  71. 3:40crazy amount of code that
  72. 3:44um um yeah uh this is kind of scary.
  73. 3:48Yeah. If you look at it and also the the
  74. 3:50rate that the that the code is being
  75. 3:52developed at I mean you can see as well
  76. 3:55is uh super
  77. 3:58high. Um yeah the codebase is uh mostly
  78. 4:03written in Rust. Yeah memory safe
  79. 4:06language uh also
  80. 4:08crossplatform. Um so Android, Linux,
  81. 4:11Windows and OSX or Mac OS nowadays is
  82. 4:14covered but um there's also iOS. So
  83. 4:17there was also a bit of swift code.
  84. 4:18Yeah. And also of course um dependencies
  85. 4:21and so forth. Uh so there was a huge zoo
  86. 4:24of different programming languages, code
  87. 4:28and so forth and um I mean as you can
  88. 4:31imagine full source code review that was
  89. 4:33completely out of the question even due
  90. 4:35to the size of that code base due to the
  91. 4:37complexity and um also because uh by
  92. 4:41nature the interaction of these
  93. 4:44applications is high with system
  94. 4:47operating system other systems back end
  95. 4:51and different photos.
  96. 4:54So naturally this led us to an approach
  97. 4:59that is not let's say the typical source
  98. 5:01code review. Yeah. Because it's just
  99. 5:03like impossible to review all that
  100. 5:05source code. Um which is more aligned to
  101. 5:09yeah a white box pentest with source
  102. 5:12code access. Um I have to say that uh
  103. 5:15our team focused um a lot or a lot of
  104. 5:19the efforts on actually reviewing source
  105. 5:21code. Um but uh we based that on a
  106. 5:26threat model that we developed um
  107. 5:29beforehand and also agreed upon with uh
  108. 5:31with the project. Yeah. And um yeah,
  109. 5:36doing that we applied a lot of manual
  110. 5:38code review, static code analysis and
  111. 5:40but also a lot of dynamic testing and
  112. 5:42also always came back to the threat
  113. 5:44model.
  114. 5:49Yeah. Um Eric, do you want to say
  115. 5:51something about threat modeling? Yeah.
  116. 5:54Um the the idea about the threat model
  117. 5:56is to better understand um the attack
  118. 5:59surface and um where the threats
  119. 6:02actually might come from. And
  120. 6:05um sometimes when when working with open
  121. 6:08source projects, you are lucky and
  122. 6:09people already have something like a
  123. 6:11threat model. Um with Matum, I think
  124. 6:13some parts were already there um from
  125. 6:16from former audits. Um quite often you
  126. 6:20don't have anything um from the project
  127. 6:23itself, right? Um so you start to look
  128. 6:27at the documentation um and get some
  129. 6:30pointers from there. Um some things that
  130. 6:33you can base your thread model on is
  131. 6:36like common sense. Um and you can also
  132. 6:39look at similar products. I mean um
  133. 6:41there are other VPN products out there
  134. 6:44as well. So you could look at them and
  135. 6:46see what are their assumptions and can
  136. 6:49we transfer them to to
  137. 6:51Mulvat and um in the end make sure that
  138. 6:55you agree with the thread model that
  139. 6:57it's there because um sometimes
  140. 7:00developers might have a completely
  141. 7:02different use case in mind than their
  142. 7:03users and um they they might have a
  143. 7:06thread model for one scenario but the
  144. 7:08way the users are actually using the
  145. 7:10product is um um different from what the
  146. 7:15developer thinks and that's quite often
  147. 7:17the case with privacy products I guess.
  148. 7:20Um and yeah in in this case um we made
  149. 7:23sure that the shrap model is something
  150. 7:25that Mulvat and we agreed on. Um next
  151. 7:29slide please.
  152. 7:34And um this um uh yeah, we made sure to
  153. 7:37do this by having several online
  154. 7:40meetings um where we um went back and
  155. 7:43forth on the threat model and um we even
  156. 7:48um made sure that we have time in the in
  157. 7:50the project to create a full thread
  158. 7:53model. Um quite often you do it like
  159. 7:56quickly before even writing the offer
  160. 7:59because um once you know the threat
  161. 8:02model you know what you have to look for
  162. 8:03right you know um do you need to look at
  163. 8:06the dependencies is there another way to
  164. 8:08target the application
  165. 8:12um and this might um influence the
  166. 8:15amount of time you need. In this case,
  167. 8:17the threat model was part of the
  168. 8:19project. Um, so we could spend a bit
  169. 8:22more time on that and uh um made it u
  170. 8:28like not completely formal but um still
  171. 8:32detailed enough uh so we could work with
  172. 8:35it. Next slide.
  173. 8:39And um when you look at the VPN client
  174. 8:42um at least one part for the thread
  175. 8:44model becomes quite quite clear um once
  176. 8:48you start drawing a diagram that shows
  177. 8:50you the actors involved right you have
  178. 8:51your client that wants to connect to to
  179. 8:55a peer that's um the um the the item on
  180. 8:59the right and it wants to connect to
  181. 9:03that pier through the tunnel. So you
  182. 9:05have the client, the peer and the mat
  183. 9:07relay that terminates the VPN, but you
  184. 9:11also have um the internet provider
  185. 9:14involved. You have um some third parties
  186. 9:17involved that do the routing. So you can
  187. 9:21get some parts of the shred model
  188. 9:22already quite easily from um your
  189. 9:25network diagram.
  190. 9:27Um but there are other parties that
  191. 9:29might be involved that um are not as um
  192. 9:32easy to to see. Um and one party might
  193. 9:37be another person on the client
  194. 9:39computer, right? If there's a second
  195. 9:40user account that might be
  196. 9:42compromised, is that something that you
  197. 9:44would um consider as a tech surface? And
  198. 9:48for move, this was quite clear. um the
  199. 9:51the target audience for the product is
  200. 9:54end users and they're um they they they
  201. 9:59can safely assume that there's only a
  202. 10:00single user in most cases and um all
  203. 10:04users on the computers are trusted
  204. 10:06anyhow. So they they clearly define that
  205. 10:10um a compromised second user on that
  206. 10:13machine or a compromised client is
  207. 10:16outside of the threat model. Um, another
  208. 10:19thing that's
  209. 10:21um that uh you might want to look at is
  210. 10:24um what about um malicious people at
  211. 10:27Mulvad, right? Um so what what kind of
  212. 10:32attacks could they perform? But that's
  213. 10:34also something that when you talk to the
  214. 10:36projects um you can see whether that's
  215. 10:39something they want to protect against
  216. 10:40or not. And um in this case it's also
  217. 10:44something that will be regulated in a
  218. 10:46nontechnical way, right? I mean
  219. 10:48um um
  220. 10:51the yeah if you have in a kind of supply
  221. 10:55chain or something that's nothing that
  222. 10:56you can prevent by modifying your code
  223. 10:59base right so these were not the things
  224. 11:01we were looking for um but we were
  225. 11:04looking for data leaking into the
  226. 11:07internet um can attackers on the local
  227. 11:10network perform attacks that might leak
  228. 11:12data
  229. 11:14um these were the kinds of attacks that
  230. 11:16were defined in the strat
  231. 11:19model. Next slide.
  232. 11:23Yeah. Um uh that's something that uh I
  233. 11:28want to stress uh that in this order um
  234. 11:32was was say very helpful and I I feel
  235. 11:36like now I I sound a bit nostalgic but
  236. 11:39um that has been a bit lost I think
  237. 11:40after co is that in this audit we kind
  238. 11:44of went onsite and um nowadays uh
  239. 11:48meaning 24 25 um most code reviews I
  240. 11:52think for most of the audit firms are
  241. 11:54performed remote and um that's uh it's
  242. 11:59fine. Yeah. And because also many of the
  243. 12:01teams are remote and everybody's used to
  244. 12:03working remotely together in video
  245. 12:05calls, chat and everything.
  246. 12:07Um in this case the the the MVA team
  247. 12:11there was in one place so in Gutenborg
  248. 12:14in Sweden and uh this is of course also
  249. 12:16fine but what is even better is that um
  250. 12:19we had two auditors was Robia and me
  251. 12:23that could visit them and um this was
  252. 12:27really really helpful um because uh the
  253. 12:32interaction with the developers on a
  254. 12:34personal level but also let's say the
  255. 12:37easiness of uh asking questions or
  256. 12:41talking about things uh with with
  257. 12:44developers maybe not with one but maybe
  258. 12:46a talk with two or three that helps a
  259. 12:49lot. So um and this is something that I
  260. 12:53I want to stress and this is something
  261. 12:55that I think um could be something for
  262. 12:58larger open source project as well.
  263. 13:00Yeah, just just a suggestion that
  264. 13:03um this kind of local interaction at
  265. 13:06least for a few days um uh yeah would be
  266. 13:09very beneficial and we um uh we did not
  267. 13:13do the full audit on site but we
  268. 13:15basically were one week together with
  269. 13:17the actual developing team and um yeah
  270. 13:22and the side effect also is that
  271. 13:25um um the auditors are also in one
  272. 13:28place. Yeah. meaning that even some
  273. 13:30after after after hours you have some
  274. 13:32discussions and that also helps with
  275. 13:34really deeper understanding for complex
  276. 13:36audits and this audit definitely was a
  277. 13:38complex audit. Um and there it is it is
  278. 13:42really good also to yeah to be to be
  279. 13:44kind of slow to
  280. 13:46that.
  281. 13:48Um yeah if uh Eric said about the threat
  282. 13:52model
  283. 13:54um it might sound a bit boring. Yeah,
  284. 13:56for some people that say like, yeah, I
  285. 13:58want to find bugs and I want to go right
  286. 14:00into it and I would call this is more
  287. 14:02the buck bounty approach. Yeah, which is
  288. 14:04also legit. However, if you review a
  289. 14:08complex product and you want to interact
  290. 14:10with people about this product and you
  291. 14:12want to also uh report valid bugs only.
  292. 14:17Yeah. Um then um you need to do a proper
  293. 14:20discussion about this threat model if
  294. 14:22nothing if none exists before. Yeah. So
  295. 14:26um you should do that of course with
  296. 14:28your co- auditors so you're also all
  297. 14:30aligned on the thr model with the actual
  298. 14:32developers of course and project
  299. 14:34managers but I mean also with yourself
  300. 14:38um especially discussing it with the
  301. 14:40developers is very often super fruitful
  302. 14:43because um in most cases you get the
  303. 14:45first few bucks for free um because um
  304. 14:49you're challenging the beliefs that the
  305. 14:50developers have about the threat model
  306. 14:53and quite often um that's when they
  307. 14:56recognize they they have some
  308. 14:58architectural or design issues in their
  309. 15:00code and um when when you ask about
  310. 15:03specific implementation syncs during
  311. 15:05this discussion um you quite often also
  312. 15:07get something like yeah we didn't do it
  313. 15:11that way but this way which is not good
  314. 15:14and if it's not good there it's also
  315. 15:15probably buggy in these other three
  316. 15:17cases and you can already start writing
  317. 15:20the report right it's um always
  318. 15:22useful Yeah. Yeah. Yeah. And um it's
  319. 15:26also good to to talk about the threat
  320. 15:28model and yeah, as Eric said, challenge
  321. 15:31it.
  322. 15:32Um and uh that also helps you a bit as a
  323. 15:36kind of reality check. Yeah. When you
  324. 15:37dive deep into the technical details or
  325. 15:40into bugs, but um I mean the threat
  326. 15:43model actually starts not at the
  327. 15:45technical level. And it's also a bit of
  328. 15:46a reality check if it's done right.
  329. 15:48Yeah. I mean there can be invalid threat
  330. 15:50models that excludes stuff that
  331. 15:52shouldn't be excluded but on the other
  332. 15:55hand um I mean as Eric said yeah before
  333. 15:58we uh for example had to decide our
  334. 16:01local users a problem or not yeah um can
  335. 16:04they just uh can they just pull the
  336. 16:06network plug yeah then um if they're if
  337. 16:09they are local user um or physical have
  338. 16:12physical access but maybe denied of
  339. 16:15service on the software level there is
  340. 16:17not that that bad So um or maybe it is
  341. 16:21so and that's what you what you
  342. 16:23discussed but I mean the most important
  343. 16:24thing is what must never happen. So
  344. 16:27that's actually a question that
  345. 16:28everybody even the most technical person
  346. 16:31uh and the least technical person at the
  347. 16:33same time they all should ask this
  348. 16:36question. So and um uh what is also
  349. 16:41important of course is past
  350. 16:42vulnerabilities and their impact because
  351. 16:44then you can also see how is the
  352. 16:46understanding of the of the project um
  353. 16:50uh in general or so far. Yeah. Um about
  354. 16:54certain things
  355. 16:58um yeah and then I mean at the end what
  356. 17:01you want to find of course is security
  357. 17:03defects and vulnerabilities. Yeah.
  358. 17:05That's your job as a as a code auditor
  359. 17:07there. And um for that one um and then
  360. 17:11also to avoid the discussions the threat
  361. 17:13model again is um is important. Yeah,
  362. 17:16discussions can can unfold with the
  363. 17:20developers. Yeah, if you are not on the
  364. 17:21same page about what is a bug and what's
  365. 17:23not. Uh or of course the internet and
  366. 17:26especially in the case here of the OS
  367. 17:27tiff where a lot of reports are
  368. 17:30published. Uh what you definitely want
  369. 17:32to avoid is um controversial let's say
  370. 17:35discussions about are these bugs valid
  371. 17:38or not. Yeah. So so that's important.
  372. 17:41Get familiar with your target and also
  373. 17:43um draft the threatment and write it
  374. 17:45down and also discuss it and um that's
  375. 17:49um that's uh yeah reality to check it as
  376. 17:52well. And usually um these discussions
  377. 17:56are in the form that people want to
  378. 17:58downgrade issues you find and somehow
  379. 18:01define that they are outside of the
  380. 18:03threat model. And if you define the
  381. 18:04threat model beforehand that's this is
  382. 18:06way easier to agree upon whether
  383. 18:08something is inside or outside. Um in
  384. 18:11the case of Mulvet we had the other uh
  385. 18:15situation where we said okay we found
  386. 18:17something that's outside of the thread
  387. 18:18model and they asked us to still include
  388. 18:21it and rate it as a high finding which
  389. 18:23is um I guess a nice approach um to see
  390. 18:26that the vendor is not trying to
  391. 18:28downplay bucks but to um yeah actually
  392. 18:31rate them as they are and make sure that
  393. 18:33they are addressed properly.
  394. 18:37Yes. And yeah, the findings um are the
  395. 18:42yeah they were distributed the following
  396. 18:43way. So we had three high findings, two
  397. 18:46medium, one low and then we had three
  398. 18:48informationals. Um I mean you can see
  399. 18:50the absolute number of findings is quite
  400. 18:52high especially if you is quite low.
  401. 18:55Absolute number of findings is quite
  402. 18:56low. Uh especially compared to the size
  403. 18:59of the code base. Um and that can be in
  404. 19:03our mind attributed to a very high
  405. 19:05baseline security. Um um and also on the
  406. 19:08focus uh on let's say maybe deeper
  407. 19:12deeper bugs um that require um more yeah
  408. 19:16focus. And that's also something audit
  409. 19:19teams talk about if you do audits talk
  410. 19:21about that with the audit team if they
  411. 19:24should go deeper or if they if it's more
  412. 19:27about broad u broad. So if the if the
  413. 19:31resources are limited uh for sure do
  414. 19:33that. Um we also always rate the finance
  415. 19:36by CWE and I mean you can see here that
  416. 19:39the distribution except for one I don't
  417. 19:42know that by heart but appeared two
  418. 19:44times they were all let's say kind of
  419. 19:47different types of issues.
  420. 19:50Um yeah, let's go to the first um
  421. 19:54finding. Um
  422. 19:56um we don't have enough time to go
  423. 19:58through all the technical details, so
  424. 20:00let's speed run a bit uh through it.
  425. 20:02This was a very interesting one because
  426. 20:04it um it was the one that um um crashed
  427. 20:10or that uh that that is an issue that um
  428. 20:14happened even though uh for example I
  429. 20:17would claim that nearly everything was
  430. 20:20done right in the Rust uh code meaning
  431. 20:23yeah that it was memory safety was of
  432. 20:27high value and I don't think we found
  433. 20:29any kind of memory corruption Um also uh
  434. 20:34I mean but um we found a corner case and
  435. 20:38that is that a signal handers alternate
  436. 20:41stack was too small and what that means
  437. 20:43I want to and that that was uh present
  438. 20:46in the mold demon. Yeah. Um and it was
  439. 20:50present in the crash handler. So uh what
  440. 20:53that means is that there was a crash
  441. 20:55handler installed that was getting
  442. 20:58installed and catching sigb 6 fp six ill
  443. 21:02sixes uh signals. Um these signals are
  444. 21:07when an application is crashing they are
  445. 21:09triggered and if a signal handler is
  446. 21:12installed then um these uh the signal
  447. 21:15hand is run it usually it should do
  448. 21:17something like um lock the arrow or
  449. 21:21gracefully exit and so forth. Yeah. Um
  450. 21:26um not all of them and you see here six
  451. 21:28segmentation fault. Okay. If you have a
  452. 21:30segmentation fault it's kind of a hard
  453. 21:31crash and might also be a security
  454. 21:33issue. Um uh but there's also others
  455. 21:36yeah s FP that could happen with
  456. 21:39division by zero depending on yeah uh
  457. 21:42some conditions and how how things are
  458. 21:45compiled but yeah anyhow uh things can
  459. 21:48these crashes can happen. Now we have to
  460. 21:51say that we didn't find a way to trigger
  461. 21:53them. Um but um if it was triggered.
  462. 21:57Yeah. Um the interesting point was okay
  463. 22:00then here the signal handler is
  464. 22:02installed. There's no way around using
  465. 22:05safe rust to install that signal
  466. 22:06handler. Yeah. Because by this is a
  467. 22:09low-level operation. Yeah. Just just
  468. 22:11just for the record. Um so but what
  469. 22:15happened is that signal handers they
  470. 22:17need to have their own stack. Why do
  471. 22:19they need to have their own stack? Yeah,
  472. 22:20because they uh run when something has
  473. 22:23crashed. So the original stack might be
  474. 22:25corrupted. So um yeah, the data of that
  475. 22:29signal handler needs to be stored in a
  476. 22:30location that is kind of clean. And for
  477. 22:33that one um here the developers um use a
  478. 22:38heap buffer. Yeah. Uh and in a vector in
  479. 22:41Rust um they um Yeah. I mean it's very
  480. 22:46an innocent bug. Yeah. So uh I think
  481. 22:50really everybody could have made that uh
  482. 22:52that mistake. Uh so the they used the
  483. 22:55lip six stack size. Yeah, this is like a
  484. 22:58default size. I think it's four in on
  485. 23:01x8664 it was 4 kilobytes. So page size
  486. 23:06and um they use that buffer and say like
  487. 23:09this is now a new stack. Yeah. And um
  488. 23:11you have to call the s stack. Yeah.
  489. 23:14because you have to um have to have to
  490. 23:17um yeah let's set that stack on that
  491. 23:19process.
  492. 23:21Now the problem is that this stack was
  493. 23:24too small for all cases. Uh meaning that
  494. 23:28if a signal is actually triggered um the
  495. 23:31stack could actually corrupt the heap
  496. 23:34and um um that uh is of course pretty
  497. 23:38bad. Uh yeah because st on the heap uh
  498. 23:41because then with a normal crash you
  499. 23:44can't get an exploit potentially
  500. 23:46exploitable condition.
  501. 23:49Um yeah, so there was a pretty
  502. 23:51interesting bug because it went kind of
  503. 23:53under the radar of the normal threat
  504. 23:54model, especially if you write a Rust
  505. 23:56application that you don't uh basically
  506. 23:58think about something could corrupt the
  507. 24:00heap. Um if you didn't do anything
  508. 24:04unsafe, obviously
  509. 24:06unsafe, but yes, your crash handler
  510. 24:09would kind of crash again potentially.
  511. 24:13uh uh I think it's something that that's
  512. 24:15not not expected for for most people. Um
  513. 24:19there was another issue uh which I think
  514. 24:22then the there was bit of a different um
  515. 24:26um let's say uh um or there's debate
  516. 24:31about it if this is uh how exploitable
  517. 24:34these conditions are but I mean we went
  518. 24:36with the this is undefined behavior
  519. 24:39there's um signal hander was using non
  520. 24:41async safe functions and non uh
  521. 24:44reentrren functions um meaning that this
  522. 24:49is uh the signal handler here and as I
  523. 24:51said the signal handler um should kind
  524. 24:54of print a back trace some lock. The
  525. 24:57problem is a signalander might be
  526. 24:59invoked in um an operation let's say in
  527. 25:03a lock
  528. 25:04operation and if then from this lock
  529. 25:09operation a s um inside the lock is
  530. 25:13called again logging
  531. 25:16um there might be invalid states. Yeah,
  532. 25:18because some of these functions output
  533. 25:20buffering and so forth, they have like
  534. 25:22internal buffers or internal states or
  535. 25:25pointers and so forth that
  536. 25:28um are not uh safe for um being caught
  537. 25:33again while they are running. Yeah. And
  538. 25:37um that uh is undefined behavior. Um
  539. 25:41um it might be hard to exploit or even
  540. 25:44trigger. Yeah. But uh this is still
  541. 25:47unrefined behavior and I mean as I said
  542. 25:49there could be uh things happening yeah
  543. 25:52corruption of pointers or other things
  544. 25:54depending on the function that is used.
  545. 25:56I think here the most of the issues
  546. 25:58should be output buffering. Um but even
  547. 26:01then yeah beta better be safe than
  548. 26:04sorry. So
  549. 26:08um Eric do you want to explain that one
  550. 26:10the site loading? Yeah I think from a
  551. 26:12technical point of view it's not that
  552. 26:14interesting. Um it's quite similar to DL
  553. 26:17site loading. Um the the Windows
  554. 26:20installer um is picking up an executable
  555. 26:23that's in the same um file directory and
  556. 26:27if it's there it will start executing
  557. 26:29it. And um this is um the the issue
  558. 26:34which for us was outside of the threat
  559. 26:37model because um if an attacker is able
  560. 26:39to write an executable um to a certain
  561. 26:42fast um it the the client machine um
  562. 26:47then I would consider that machine
  563. 26:48compromised right
  564. 26:51um there are these other examples where
  565. 26:54the installer might be on the file share
  566. 26:57and the attacker is able to access the
  567. 26:59file share And right but um this is
  568. 27:02something where we would have said um
  569. 27:04okay with the strap model given we would
  570. 27:07only do that um or only write it down as
  571. 27:10anformational
  572. 27:12um but requested us to um rate it
  573. 27:15properly um because it was an issue for
  574. 27:18them.
  575. 27:20Yeah. And um I I want to say that this
  576. 27:24is really a good example for
  577. 27:27um um for
  578. 27:31um a sensible approach uh to to real
  579. 27:34world security because uh theoretically
  580. 27:38um yeah I mean if an attacker places uh
  581. 27:41my manages files on your system and then
  582. 27:43somehow it's executed might yeah might
  583. 27:46say this there has been a problem before
  584. 27:48the execution. However,
  585. 27:52um yeah, if you visit a website and you
  586. 27:55download this
  587. 27:57taskill.exe or maybe the website has
  588. 27:59auto download and downloads it. Yeah.
  589. 28:01And it sits in your download folder and
  590. 28:03you didn't execute it, but then you
  591. 28:06download the trustworthy installer of
  592. 28:08your favorite VPN uh client. Um and then
  593. 28:11you execute that exter, uh unknowingly
  594. 28:14to you, it would execute also this
  595. 28:16malicious file. Um I mean there can be
  596. 28:20practical attacks obviously. Yeah. So um
  597. 28:22and that has happened before with DL
  598. 28:24site loading as well. Um or if you think
  599. 28:27about the installer sits on a network
  600. 28:30drive and there's also this weird task
  601. 28:33killi that you won't never execute but
  602. 28:36you execute the installer then um also
  603. 28:39that's um yeah kind of a practical
  604. 28:42attack that is uh in our mind also
  605. 28:46realistic.
  606. 28:50So um the next one is uh medium severity
  607. 28:55only. However, it was still an
  608. 28:57interesting one because it also cuts
  609. 29:00into this
  610. 29:02uh domain of operating system and um how
  611. 29:06networking works for example. Um so we
  612. 29:09found a leak of the virtual IP address
  613. 29:11of the um tunnel device. Meaning that if
  614. 29:15you have VPN tunnel inside the tunnel
  615. 29:18you have let's say an internet protocol
  616. 29:20address that um is is um yeah inside the
  617. 29:24tunnel and uh not visible normally to
  618. 29:27the outside. um in most VPN scenarios
  619. 29:31maybe it doesn't matter if it would be
  620. 29:33visible or not but in the case of a
  621. 29:36privacy um let's say preserving VPN use
  622. 29:40case
  623. 29:42um knowing that IP address and if it
  624. 29:45doesn't change that often might give you
  625. 29:49yeah some some evidence that a certain
  626. 29:51user is is you could kind of learn
  627. 29:55something about the user
  628. 29:56identity and This affected Linux and
  629. 29:59Android and um what happened is that the
  630. 30:03the Linux kernel um we found a quirk
  631. 30:06kind of in the Linux kernel network
  632. 30:08stack. I wouldn't say that is a bug
  633. 30:11because probably there's some kind of
  634. 30:13use case for it. But uh the point is
  635. 30:16that the Linux kernel if you have
  636. 30:17multiple network interfaces it will and
  637. 30:21you will ask on one interface for a
  638. 30:23certain IP address like do you have that
  639. 30:25IP address? Um
  640. 30:28then um it will answer even if the IP
  641. 30:31address is on another interface. Yeah.
  642. 30:33That you're not even that that's
  643. 30:34unrelated to it. Um you use this ARP
  644. 30:38address resolution protocol for that. Um
  645. 30:41and that's broadcast. It's super old
  646. 30:44protocol. I mean based off all
  647. 30:47the discovery
  648. 30:50um of of local devices IPS and um so you
  649. 30:54could we we found that we you could just
  650. 30:56query for um the the Mulvat range uh on
  651. 31:00and eventually you would get a response
  652. 31:02and then you like aha this
  653. 31:04user on that system is using MulvatVPN
  654. 31:07and also aha this is probably this user
  655. 31:10or it's the same user as
  656. 31:13yesterday and
  657. 31:15Um yeah, I'm not that great at doing
  658. 31:18diagrams, but um so this is uh if you
  659. 31:21imagine there's a victim device, uh it
  660. 31:23has a VPN connection with encrypted
  661. 31:26traffic and the attacker can just query
  662. 31:28that device and say like hey do you have
  663. 31:31that VPN IP that is I should be inside
  664. 31:34here. Yeah. So the uh interface on the
  665. 31:37right unrelated to the interface on the
  666. 31:39left but the Linux kernel would still uh
  667. 31:42let's say answer that and um in the
  668. 31:44report you find kernel setting to turn
  669. 31:46that off. So at least and I think uh
  670. 31:49move also filed like a um kind of a so
  671. 31:53submitted that to Android because
  672. 31:55Android by default also does that and it
  673. 31:58also affects of course other VPNs and
  674. 32:02devices.
  675. 32:05Um yeah so uh the next one um that's um
  676. 32:10also medium severity but also a very
  677. 32:12interesting one. It's a bit more
  678. 32:14complex. So let me start with some kind
  679. 32:17of preconditions
  680. 32:20um that uh also JJ asked me to to put in
  681. 32:25because a lot of people don't realize
  682. 32:27that
  683. 32:29um uh there's certain conditions when a
  684. 32:33VPN setup is is kind of in danger uh
  685. 32:36because if a network if an attacker has
  686. 32:39two critical network positions and these
  687. 32:42positions are they can observe serve or
  688. 32:45even inject into adjacent uh networks to
  689. 32:49the VPN client. Yeah. Where they can see
  690. 32:52the encrypted VPN traffic but right at
  691. 32:55the source. Yeah. They might not know
  692. 32:57which user that is or whatever but they
  693. 32:59can see there's somebody using a VPN and
  694. 33:02then they they generate and receive and
  695. 33:04submit traffic. Yeah. And then at the
  696. 33:07same time they are also able to see the
  697. 33:10tunnel exits. t exits or
  698. 33:14um even um the the the target of the
  699. 33:17communication. If you think about the
  700. 33:19the one of the first slides, this
  701. 33:22diagram. So, and if they can see both of
  702. 33:24them, then you can do things such as
  703. 33:27traffic correlation, but also there's an
  704. 33:30interesting injection attack that we
  705. 33:32that we found. Um I have to say that
  706. 33:35this was found is also by others a bit
  707. 33:38before a few years before. Um but yeah,
  708. 33:42we kind of want to feature it and I
  709. 33:44think we added some some aspects to
  710. 33:46that. So I uh painted this uh great
  711. 33:50diagram. So imagine you have a mullet
  712. 33:52client and they have a VPN connection
  713. 33:56with the Mulvat back end or a VPN back
  714. 33:59end and um they have an internal IP. So
  715. 34:04if they have an internal VPM IP, of
  716. 34:06course, there needs to be not network
  717. 34:07address translation. And so let's say
  718. 34:10they want to contact google.com. So what
  719. 34:12happens is they go over the VPN, the
  720. 34:16VPN, they go out of the VPN, but the VPN
  721. 34:20of course change their um uh change
  722. 34:22their IP address. So nobody knows that
  723. 34:24it's this client. So they go to
  724. 34:26google.com. Google says like, "Okay, I
  725. 34:28have a request here from this exit IP."
  726. 34:31and um they sent back sent back. So
  727. 34:34everything's great, right? Everything's
  728. 34:35protected.
  729. 34:37However,
  730. 34:39um if an attacker kind of assumes that
  731. 34:43there's a molvat user that is um talking
  732. 34:46to
  733. 34:47google.com and because um uh nowadays uh
  734. 34:52quick and other protocols use
  735. 34:54UDP you know there's a state on mobile
  736. 34:57that says like okay if the UDP packet
  737. 34:59comes from
  738. 35:00google.com I will forward it exactly to
  739. 35:02this client. I mean must be right how
  740. 35:05how else do you receive the response? So
  741. 35:08if the attacker knows that or wants to
  742. 35:10know google.com they can kind of flood
  743. 35:12and they can like fake the IP of
  744. 35:15google.com fake the answer. Yeah. And
  745. 35:18they flood the u the exit relay with
  746. 35:22different with UDP packets with
  747. 35:24different source ports until they hit
  748. 35:25one. And if they hit the right one then
  749. 35:29this traffic
  750. 35:31will be delivered to that client here.
  751. 35:35So now if the attacker can also observe
  752. 35:37how much traffic happens here on this um
  753. 35:40VPN uh tunnel at the client they can
  754. 35:43kind of easily correlate and say like
  755. 35:45okay there's um I send a lot of UDP
  756. 35:48packets and then there's a lot of
  757. 35:50traffic here. Yeah. So this is a kind of
  758. 35:52de anonymization attack that
  759. 35:56is not really a fault of move or any of
  760. 36:00the others. It's just how not and how
  761. 36:02this networking stuff works. Yeah. Um
  762. 36:07um so so I would call maybe design
  763. 36:09weakness or something that is the limit
  764. 36:11of
  765. 36:12what maybe the VPN in this way can
  766. 36:16provide. Um and um that's yeah that's
  767. 36:21that's a pretty interesting attack that
  768. 36:22we found. Uh it was found before or at
  769. 36:26least a variation of that uh called
  770. 36:29serverside attacks in us paper blind in
  771. 36:32on path attacks applications on two
  772. 36:34VPNs. Yeah. Um so that's uh after
  773. 36:39researching for for previous uh work
  774. 36:42then we found that as well. Yeah. We
  775. 36:44didn't know that before.
  776. 36:46Um what we found is that with increasing
  777. 36:51um usage of modern web protocols HTTP3
  778. 36:54quick and quick relies on UDP um you can
  779. 36:59also run this attack with TCP under some
  780. 37:02conditions but um yeah and uh present
  781. 37:05conditions is of course are of course to
  782. 37:07reiterate attacker can observe uh the
  783. 37:09network traffic of that client just not
  784. 37:11decrypt it just observe it and they have
  785. 37:15a list of potent potential move at exit
  786. 37:16IPs and they have the ability to spoof
  787. 37:19IP packets with a source IP of something
  788. 37:23on the clarinet some interesting site.
  789. 37:25Yeah, let's say you are let's say in a
  790. 37:26country that doesn't like you to visit a
  791. 37:29certain website and uh the the
  792. 37:33authorities there want you to want to um
  793. 37:36know if you did that they could try to
  794. 37:39run this attack. Yeah, because they
  795. 37:41usually also control all the ISPs and
  796. 37:43everything.
  797. 37:46Yeah. Um there's um uh a slight counter
  798. 37:52to that. Uh Mulvat has something called
  799. 37:55data and that is uh traffic generation.
  800. 37:57So they kind of generate random traffic
  801. 38:00um on your VPN connection that is kind
  802. 38:03of fake. Yeah. And that can at least
  803. 38:05partly mitigate it um I mean you could
  804. 38:09probably run some
  805. 38:11statistical attacks. Yeah.
  806. 38:13um or analysis on that but at least it
  807. 38:16will partly mitigate it uh by having
  808. 38:18this kind of decoy traffic. Yeah,
  809. 38:21there's a similar um one that we don't
  810. 38:25go into detail but by varying the MTU on
  811. 38:29the path uh between um the um the the
  812. 38:34exit and the um the target internet host
  813. 38:38and there you can uh the maximum
  814. 38:40transfer unit. You can also see if data
  815. 38:42is not used in normal VPN. You can see
  816. 38:45like wire guard. You can see that the
  817. 38:47sizes of the VPN packets change also.
  818. 38:50And then you can also dean anonymize
  819. 38:52kind of the user. Um same print
  820. 38:54positions as before the one
  821. 38:58before. Yes. So
  822. 39:00um uh some recommendations I mean you
  823. 39:04can read the report in detail on all the
  824. 39:06that it's public on the website of Tiff
  825. 39:08and also X41. Um so for the high
  826. 39:11security issues uh we uh I mean the
  827. 39:15increasing the stack size for the signal
  828. 39:17hers will mitigate this corruption. Um
  829. 39:21uh also not doing complex task in signal
  830. 39:25handlers is also something that um yeah
  831. 39:29um as it is from a security perspective
  832. 39:31advised. Yeah. um and only use async
  833. 39:34safe functions and um you can find that
  834. 39:37in man pages uh on at least on Linux um
  835. 39:41uh there's there's a there's an there's
  836. 39:44a dedicated man page for this one yeah
  837. 39:47and um um yeah for the site loading of
  838. 39:51course restricting execution of
  839. 39:54utilities to trusted code path
  840. 39:57um the medium severity ones uh if you
  841. 40:00randomize the virtual IP addresses per
  842. 40:02connection. I think that was done. Um of
  843. 40:05course this kind of leakage attack
  844. 40:07against the identity of pseudonym of
  845. 40:10that user is not possible. Um and um
  846. 40:15also this kind of obuscation techniques
  847. 40:17to mitigate this not based
  848. 40:19generalization
  849. 40:21um can help. Um we think that it's
  850. 40:26important that users know these
  851. 40:28limitations. Yeah. Um even the tour
  852. 40:31network has a similar kind of uh
  853. 40:34limitation. Yeah. If you have a um if
  854. 40:37you if you monitor let's say hidden
  855. 40:39service and then also a toll user and
  856. 40:42you suspect they using that service you
  857. 40:44can run similar attacks. So um so it's I
  858. 40:48think awareness is the key and yeah for
  859. 40:50the low severity issues um um I mean
  860. 40:54it's it's the same as for the other one
  861. 40:56uh MTEU um related. So that could be um
  862. 41:00could be mitigated by petting uh
  863. 41:05packets. Yeah. Um coming to the
  864. 41:07conclusion um yeah uh the target
  865. 41:10application demonstrated a high level of
  866. 41:12security that what made that's what made
  867. 41:14it um let's say um interesting audit
  868. 41:18because we had time to focus on um the
  869. 41:21non standard stuff and um that's
  870. 41:27contributes also to overall security of
  871. 41:29everybody. Yeah. So and uh I mean you
  872. 41:31could positive observations definitely
  873. 41:33you could see safe coding patterns and
  874. 41:34design patterns also having an effect
  875. 41:37positive effect on security uh also
  876. 41:40regular audits I mean they they writ out
  877. 41:43all the standard things yeah on the
  878. 41:45other hand of course there's always
  879. 41:46something to find yeah even due to
  880. 41:49changing the world is always changing
  881. 41:51and also something just that is let's
  882. 41:53say uh yeah was hidden for a while and
  883. 41:58um yeah I think having a good baseline
  884. 42:00security level uh which is something
  885. 42:02that the US tiff here is also uh what we
  886. 42:05like about the USF is um also the key to
  887. 42:09advancing security on the non-trivial
  888. 42:11stuff and to to go for deeper issues and
  889. 42:15uh enhance the security of protocols and
  890. 42:17also the awareness and about secure
  891. 42:20design. Eric, anything you have to you
  892. 42:23want to add? No, I think you summed it
  893. 42:27up quite nicely.
  894. 42:30Okay. And then I guess u that's the
  895. 42:34presentation part.

About this transcript

This page contains the full transcript of 004 Security Source Code Audit of Mullvad VPN by X41 by Open Source Technology Improvement Fund (OSTIF), generated from the public captions YouTube serves with the video. The transcript has 6,342 words across 895 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.

What you can do with it

Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.

Free YouTube transcript tool

YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.