AnimeMembers
Videochat Extension
Videochat Extension

patreon


ome.tv attacks (?) - Videochat Extension Release v2.2.4 (2024-07-25)

Improved geolocation stability amid issues on ome.tv.

tl;dr: Between July 13, 2024, and July 28, 2024, Videochat Extension experienced a weird attack on our server infrastructure originating from the ome.tv side. It is still unclear whether this was intentional, as there are many forks in the wild, and no one has contacted us about it.

Before version 2.2.4, the Videochat Extension ultimately trusted the web page. During certain hours between July 13, 2024, and July 28, 2024, it hijacked the communication channel with the extension, generating 1,000 geolocation requests for each legitimate one.

We do not know if we were the target, as this communication channel was not identified in any way as ours, and there are third-party forks in the wild that are likely using the same approach.

Our servers experienced significant strain, and it also could have led to degraded chat performance if some specific geolocation-related features were enabled. While it wasn't a serious issue, it was still quite unpleasant.

You can close this page and return to enjoying your omegle-like experience if you have v2.2.5 or later installed. If you encounter any issues with version 2.2.5 or above, please report them on Discord.

------

The attack was active only during certain hours between July 13, 2024, and July 28, 2024, so most of you may not have even encountered the problem.

We also correlated the timing of the attacks with the possible work schedule of the mods team and addressed instances where their presence in conversations could be revealed by the extension. This was done in case ome.tv was attempting to communicate its concerns about the extension in this manner.

---

v2.2.4+ no longer fully trusts the chat page, and additional containment measures have been implemented, making it much safer for you to use. However, this assumes that ome.tv did not have a deliberate intention to cause harm to the Videochat Extension and its users.

If that assumption proves incorrect, we may have to discontinue full support for the hostile platform within the extension, losing most of its ome-specific features.

We could replace the geolocation feature with an alternative solution, such as dedicated desktop software that monitors your outgoing connections or a customized Chromium-based browser with modified chrome://webrtc-internals.

If you truly care, please consider joining our free Patreon community—it's free and serves as a newsletter, ensuring you won't miss any updates!

----

How much money we've lost, technical details, amount of uninstalls, investigation, attacker code, why the issue took so long to fix - all the behind-the-scenes details in latest report for our patrons (starting from just $4 per month).

----

The "attack" was actually just a remotely injected script that hijacked the communication channel with the extension, generating 1,000 fake geolocation requests for every real one.

Whether this was an intentional attack on our project or just a coincidence remains unknown. There is no evidence to indicate a targeted attack yet.

Our servers experienced significant strain, and it also could have led to degraded chat performance if any geolocation-related features were enabled. While it wasn't a serious issue, it was still quite unpleasant.

The attack was active only during certain hours between July 13, 2024, and July 28, 2024, so most of you may not have even encountered the problem.

The primary reason this type of attack was possible for two weeks is that none of those affected cared enough to report the issue on Discord with sufficient details for us to reproduce the problem!

It's important to note that this situation is not really our fault, as browser extensions rely on trust in web pages to function.

What's going on?

On July 23rd (originating from the 13th), we noticed strange behavior from ome.tv and its mirrors, causing interference with the extension's geolocation-dependent features at specific hours, leading to some users sending to our servers 1000 fake random geolocation requests per each real one.

The reason was the malicious script attacking the extension. This script was most likely injected by the ome.tv itself at specific hours. But we are not 100% sure as we did not go deep in our investigation. More details are in latest report for our patrons.

It could've led to lagging and some features not working as intended (such as target search). And obviously a huge non-cached load on our api.

v2.2.4 not only prevents this attack, but also limits its harm if its ever successful again. It is not trying to 'hide' - extension still relies on neighborly presence on the browser page.

Whether this was an intentional attack on our project or just a coincidence remains unknown. There is no evidence to indicate a targeted attack yet.

There are forks in the wild using the same simple unprotected publicly known IP grabbing approach we've used for the past 3+ years.

---

The 'attacks' were quite random and not present 24/7, so we linked timings of the attacks to the potential mods' work schedule and the possible display of their presence upon connection.

These are just speculations which were still addressed in this release, some more rare cases (like on stop) will be fixed in the next release.

---

The 'problem' started on July 13th:

There are a lot of details in our report for patrons, but the bottom line is that the issue's origin was misunderstood and we noticed the real problem only on July 23th, when a user reported weird behavior on Discord (video).

Fixed version was sent to review for Chrome & Edge on July 25th, approved by Chrome on July 27th.

Firefox is still at v1.9.0, Microsoft sometimes delays updates for weaks, so you should use another Chromium-based browser for now, we recommend Brave or DuckDuckGo browser.

---

New version is built to put a better defense against such attacks, intentional or not, but if we indeed were the target - then nothing could possibly help as the extension relies on neighborly presence on the browser page.

---

If attacks on our users persist, we will have to switch to more safe geolocation methods, reducing support for the COMC platform in the browser extension. It will not mean the end of the Videochat Extension project, but we will likely have to kill most ome.tv-specific features developed over the last 3 years.

The geolocation feature will be preserved. There are lots of options for alternative approaches to explore, which would be legal, easy to use and not require any special technical knowledge.

Our patrons will always have geolocation feature, even if the extension will stop working on ome.tv.

---

Our core feature is webrtc IP geolocation, we don't need to touch ome.tv in any way for it to work. It is YOUR computer that connects to somebody directly.

We could just maintain the chromium fork with direct webrtc-internals access or rely on the external "Little Snitch"-like desktop software communicating directly with the extension.

The only reason we use the extension approach is because the browser extension is easier for you to use, for us to maintain AND there are a lot of cool things we can do with it!

What's next?

Time will tell. No idea.

We will support you as long as you support us.

---

How much money we've lost, technical details, amount of uninstalls, investigation, attacker code, why the issue took so long to fix - all the behind-the-scenes details in latest report for our patrons (starting from just $4 per month).

You will actually support the project, receive improved geolocation accuracy, project status reports, discord role & more cool new patron-only features that are on the way!

Patrons will always be supported and have access to the geolocation feature via alternative approaches even if the extension stops working on ome.tv / the world stops spinning.

If you really care, consider supporting the project!

---

Google Translate this post

Arabic, Bulgarian, Chinese, Croatian, Czech, Danish, Dutch, Estonian, Finnish, French, German, Greek, Hebrew, Hungarian, Indonesian, Italian, Korean, Latvian, Lithuanian, Norwegian, Polish, Portuguese, Romanian, Russian, Serbian, Slovak, Slovenian, Spanish, Swedish, Turkish, Ukrainian, Vietnamese

What's new in Videochat Extension?

---

qrluke

ome.tv attacks (?) - Videochat Extension Release v2.2.4 (2024-07-25) ome.tv attacks (?) - Videochat Extension Release v2.2.4 (2024-07-25)

More Creators