This Week In Security: TunnelCrack, Mutant, And Not Discord
hackaday.com
external-link
Up first is a clever attack against VPNs, using some clever DNS and routing tricks. The technique is known as TunnelCrack (PDF), and every VPN tested was vulnerable to one of the two attacks, on at…

Semi related but there has been so much anti VPN stuff of late on the web. I blame the big vpn providers for their miss marketing and poor ads from sponsoring deals. The repercussions are making it out like vpns are not useful. Noone thought they were silver bullet before. now they are made out to be a waste of money? All the “you don’t need a VPN” stuff needs to stop. Im concerned people are gonna stop caring about anonymity and enhancing privacy with VPN.

Possibly linux
creator
link
fedilink
-49M

VPNs are a waste of money for the most part

This pisses me off as well. All the advertising was/is “VPN! Privacy protected!” As if it’s that simple. All this fud about VPN feels like a combo of blowback from shitty advertising practices. When you combine that with government efforts to take away encryption, VPNs, and other privacy tools; what’s coming is gonna be a bleak panopticon.

Not a silver bullet, perhaps, but definitely a half decent internet condom

@XpeeN@sopuli.xyz
link
fedilink
3
edit-2
9M

deleted by creator

monk
link
fedilink
29M

It’s not a protocol vulnerability.

@XpeeN@sopuli.xyz
link
fedilink
2
edit-2
9M

deleted by creator

The mitigation is to disable local network access while the VPN is connected. Many clients do this, at least on some platforms. It was interesting to see that on iOS every tested app was vulnerable to this data leaking attack, and nearly every one of them on the macOS. It appears that the iOS API for working with VPNs has only recently introduced a control for how to handle local network traffic, leading to the abysmal results.

Not surprised mac OS sucks at this but is Linux vulnerable as well?

This isn’t exactly a platform specific problem because having local network access while using a VPN is actually a feature called “split-tunnelling”. The tunnelcrack issue goes beyond this but can be mitigated by using full tunnel VPN that resolves the server by IP address instead of DNS.

as long as you have a firewall via iptables or something similar forcing everything through the VPN only, you should be fine I would think.

if not I’ll have to change my configs a lot lol.

You are right, it’s very simple. Traffic will go wherever is shortest by default, because that’s just how networking works on your pc. Shut off the shortest path (or every other path) and it’s forced through your VPN connection.

@jsdz@lemmy.ml
link
fedilink
1
edit-2
9M

deleted by creator

Create a post

A place to discuss privacy and freedom in the digital world.

Privacy has become a very important issue in modern society, with companies and governments constantly abusing their power, more and more people are waking up to the importance of digital privacy.

In this community everyone is welcome to post links and discuss topics related to privacy.

Some Rules

  • Posting a link to a website containing tracking isn’t great, if contents of the website are behind a paywall maybe copy them into the post
  • Don’t promote proprietary software
  • Try to keep things on topic
  • If you have a question, please try searching for previous discussions, maybe it has already been answered
  • Reposts are fine, but should have at least a couple of weeks in between so that the post can reach a new audience
  • Be nice :)

Related communities

Chat rooms

much thanks to @gary_host_laptop for the logo design :)

  • 0 users online
  • 84 users / day
  • 537 users / week
  • 1.5K users / month
  • 6.58K users / 6 months
  • 1 subscriber
  • 2.31K Posts
  • 53.4K Comments
  • Modlog