arstechnica ,
@arstechnica@mastodon.social avatar

Novel attack against virtually all VPN apps neuters their entire purpose

TunnelVision vulnerability has existed since 2002 and may already be known to attackers.

https://arstechnica.com/security/2024/05/novel-attack-against-virtually-all-vpn-apps-neuters-their-entire-purpose/?utm_brand=arstechnica&utm_social-type=owned&utm_source=mastodon&utm_medium=social

crash_course ,
@crash_course@todon.eu avatar

@arstechnica
"The researchers believe it affects all VPN applications when they’re connected to a hostile network and that there are no ways to prevent such attacks except when the user's VPN runs on Linux or Android."

Really?!

Sigh of relief.
That's what I'm running : Linux & Android... 😆 🙏

pcherry ,
@pcherry@genomic.social avatar

@arstechnica Interesting and concerning exploit. Are there legitimate uses for Option 121? If Android OS can get on without it, it must not be critically important.

MotherEarth ,
@MotherEarth@mastodon.social avatar

@arstechnica

I didn't understand anything you wrote, but can you tell me: will it kill me or ask me for money? Lol

thomascoven ,
@thomascoven@vivaldi.net avatar

@arstechnica
Can I ask a noob question?
If all my devices have individial IP's set and my router has DHCP disabled, am I subject to this attack? If I go further and set static leases for each device in my router firmware, does that improve things?

formlessone ,

@arstechnica Didn't 2600 cover this, like, nearly two decades ago?

atatassault ,
@atatassault@universeodon.com avatar

@arstechnica

>or to connect the VPN to the Internet through the Wi-Fi network of a cellular device

What if you connected your phone to your computer via cable, to get around carrier limiting the amount of hotspot data you get?

not2b ,
@not2b@sfba.social avatar

@arstechnica It seems that this attack isn't an issue for people working from home and using a corporate VPN, or using a VPN to pretend to be in another country to get access to media, because the attacker has to control DHCP on the home network, and if they can do that the user has worse problems than just with their VPN. It could make it unsafe to access sensitive work sites from a coffee shop if I understand correctly.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • All magazines