M
M
MykeTyson2015-04-08 17:50:19
Journaling
MykeTyson, 2015-04-08 17:50:19

What does the provider see when I use the messenger?

I'm sorry for the probably amateurish question, but what does the provider see when I use a messenger (say, Telegram)? Can it be seen in the logs that I use it? Or does it just see the amount of data sent to some server? If it is a crypto-messenger (like silent text, wickr, etc.) - will there be a noticeable difference?
What will change if I turn on the VPN?
Thank you!

Answer the question

In order to leave comments, you need to log in

3 answer(s)
V
Vladimir Martyanov, 2015-04-08
@vilgeforce

Wireshark to the rescue. Pr will be able to see exactly the same thing.

M
Moskus, 2015-04-09
@Moskus

There is such an area in information security - traffic fingerprinting. The subject of the area is the recognition of certain types of traffic, their association with certain protocols, applications, services. Quite often it is possible to do this even if the traffic itself is encrypted. That is, the content of the transmitted data remains unknown, but the fact of using some service or application becomes known. Signs for this can be very different - from very specific bytes in an IP packet or specific addresses of the servers you are accessing, to statistical analysis.
From the first two options, for example, the same VPN saves by wrapping the connection in a tunnel, from which it leaves only after the VPN server that you use (which is probably out of reach of your provider). But the provider will most likely be able to determine the presence of the VPN connection itself.
As for specific messengers, you need to study each case and read studies on this topic. Traffic analyzers (including commercial ones) may have lists of detected protocols in their documentation.

T
throughtheether, 2015-04-09
@throughtheether

I'm sorry for the probably amateurish question, but what does the provider see when I use a messenger (say, Telegram)?
As you have already been answered, take wireshark and have a look.
Can it be seen in the logs that I use it?
If the servers used by the messenger have some peculiarities (hostnames, PTR records, BGP ASs announcing prefixes that include their addresses), then based on the logs, you can conclude whether you are using this messenger.
If it is a crypto-messenger (like silent text, wickr, etc.) - will there be a noticeable difference?
The previous thesis is valid for this case as well.
What will change if I turn on the VPN?
If you send all your traffic through the VPN, then the ISP will only see traffic (presumably encrypted) to the VPN. He, in the general case (without conducting a deep analysis), will not be able to conclude whether you use any messenger or not.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question