dormi.zone
  • Communities
  • Create Post
  • heart
    Support Lemmy
  • search
    Search
  • Login
  • Sign Up
@jeffw@lemmy.world to Technology@lemmy.worldEnglish • 1 year ago

Novel attack against virtually all VPN apps neuters their entire purpose

arstechnica.com

external-link
message-square
135
fedilink
  • cross-posted to:
  • security@lemmy.ml
  • protonprivacy@lemmy.world
  • privacy@lemmy.ml
  • technology@lemmy.ml
503
external-link

Novel attack against virtually all VPN apps neuters their entire purpose

arstechnica.com

@jeffw@lemmy.world to Technology@lemmy.worldEnglish • 1 year ago
message-square
135
fedilink
  • cross-posted to:
  • security@lemmy.ml
  • protonprivacy@lemmy.world
  • privacy@lemmy.ml
  • technology@lemmy.ml
TunnelVision vulnerability has existed since 2002 and may already be known to attackers.
  • Nyfure
    link
    fedilink
    49•1 year ago

    To be fair, any proper VPN setup that only relies on the routing table like this is flawed to begin with.
    If the VPN program dies or the network interface disappears, the routes are removed aswell, allowing traffic to leave the machine without the VPN.
    So it is already a good practice to block traffic where it shouldnt go (or even better, only allowing it where it should).

    Many VPN-Programs by Providers already have settings to enable this to prevent “leaking”.

    • @corsicanguppy@lemmy.ca
      link
      fedilink
      English
      5•1 year ago

      aswell

      Not a word.

      • @paf0@lemmy.world
        link
        fedilink
        English
        28•1 year ago

        You’re going to be ok.

      • Nyfure
        link
        fedilink
        23•
        edit-2
        1 year ago

        Strong argument, anything else?

      • @Pulptastic@midwest.social
        link
        fedilink
        English
        9•1 year ago

        A swell

      • @PlexSheep@infosec.pub
        link
        fedilink
        English
        2•1 year ago

        It might aswell be one

      • @corsicanguppy@lemmy.ca
        link
        fedilink
        English
        1•1 year ago

        Still not a word.

Technology@lemmy.world

!technology@lemmy.world

Subscribe from Remote Instance

Create a post
You are not logged in. However you can subscribe from another Fediverse account, for example Lemmy or Mastodon. To do this, paste the following into the search field of your instance: !technology@lemmy.world

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


  • @L4s@lemmy.world
  • @autotldr@lemmings.world
  • @PipedLinkBot@feddit.rocks
  • @wikibot@lemmy.world
  • 4.02K users / day
  • 9.38K users / week
  • 17.1K users / month
  • 35.7K users / 6 months
  • 69.9K subscribers
  • 14.7K Posts
  • 636K Comments
  • Modlog
  • mods:
  • @L3s@lemmy.world
  • enu
  • Technopagan
  • L4sBot
  • L3s
  • @L4s@hackingne.ws
  • BE: 0.19.3
  • Modlog
  • Legal
  • Instances
  • Docs
  • Code
  • join-lemmy.org