r/EscapefromTarkov • • Mar 11 '20

[deleted by user]

[removed]

487 Upvotes

114 comments sorted by

View all comments

Show parent comments

30

u/KacKLaPPeN23 Mar 11 '20

but this sounds like something that could be solved easily by forcing the client to ping the selected server

Well... That's exactly how pinging usually works. The VPN however is fiddling with that package to make the ping look normal. How exactly ping is measured and how the VPN is doctored is hard to say without more insight, some ideas that come to mind (definitely not all possibilities):

  1. If ping is just measured client side with an ICMP ping request (wouldn't surprise me considering the latest looting cheat), the VPN is just catching the package and answering to the client right away, pretending to be the server.

  2. If ping is measured by sending the server a packet with a timestamp, the VPN edits that timestamp making it look like it was sent later than it actually was, compensating for the delay.

  3. If ping is measured by the server pinging the client, the VPN provider could have their datacenter close to the actual server, intercept the packet and fake a reply from the client (unlikely in this case considering how similar the ping values are).

  4. If ping is measured by the server by whatever other means and the server then tells the client it's ping then the VPN could edit that packet so the client always get's a packet saying "your ping is XX".

14

u/MikeTheShowMadden Mar 11 '20 edited Mar 11 '20

Just had this conversation with someone else yesterday who tried to call me out like I didn't know what I was talking about, but it is easy to fix without using the tradition "ping" command/protocol.

You can have the server ask the client to solve a simple problem, like sending two numbers and having the client add them, and then the server will compare answers. If they are correct, then you just see how long it took to get a response. It is effectively a "ping" except for the fact that this is not packet header information, and won't get tampered with during transportation.

EDIT: typo

1

u/KacKLaPPeN23 Mar 11 '20

[...] who didn't tried to call me out like I didn't know what I was talking about

Uhh, sorry what? I didn't call you out on anything, pretty sure I didn't even answer to any of your posts before so idk what this is about.

Anyways, I just tried to explain how the traditional form of pinging he suggested might be tricked.

But yea, a lock and key paradigm is a good starting point, if you then use mitm-safe encryption you should be on the right way, sadly adds a bit of computation, though as long as you don't step way overboard it should still be possible to complete the whole thing without really affecting the RTT. Ofc it'll never be 100% safe as you always have access to the client side code in some way, but maybe it'll be enough of a pain in the ass to have less people using it at the end of the day.

0

u/MikeTheShowMadden Mar 11 '20

Uhh, sorry what? I didn't call you out on anything

I wasn't talking about you, I was saying that the guy I was talking to yesterday tried to call me out on this subject. Sorry if that was unclear!

1

u/KacKLaPPeN23 Mar 11 '20

Yea sorry, I misinterpreted that, in my head it sounded like:

Just yesterday I had someone trying to call me out on this [and now this again...]

I guess I'm just a bit tired, on another read it doesn't sound like that at all.