Novel attack against virtually all VPN apps neuters their entire purpose

For discussions about security.
Post Reply
User avatar
Jasper
Posts: 1630
Joined: Wed Sep 07, 2022 1:20 pm
Has thanked: 698 times
Been thanked: 368 times

Novel attack against virtually all VPN apps neuters their entire purpose

Post by Jasper »

Dan Goodin @ arstechnica.com - 5/6/2024

Researchers have devised an attack against nearly all virtual private network applications that forces them to send and receive some or all traffic outside of the encrypted tunnel designed to protect it from snooping or tampering.

TunnelVision, as the researchers have named their attack, largely negates the entire purpose and selling point of VPNs, which is to encapsulate incoming and outgoing Internet traffic in an encrypted tunnel and to cloak the user’s IP address. The researchers believe it affects all VPN applications when they’re connected to a hostile network and that there are no ways to prevent such attacks except when the user's VPN runs on Linux or Android. They also said their attack technique may have been possible since 2002 and may already have been discovered and used in the wild since then.

Source:
https://arstechnica.com/security/2024/0 ... e-purpose/

Post Reply

Return to “Security”