| Thread Tools |
30th March 2020, 12:52 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,575
| Apple’s VPN software exposes users Software genii strike again The fruity cargo cult Apple’s software genii have had yet another success developing VPN software which reveals all its users secrets and stops traffic from being encrypted. The unpatched security vulnerability affecting in iOS 13.3.1 or later blocks virtual private network (VPNs) from encrypting all traffic and can lead to some Internet connections bypassing VPN encryption to expose users' data or leak their IP addresses. According to ProtonVPN, while connections made after connecting to a VPN on your iOS device are not affected by this bug, all previously established connections will remain outside the VPN's secure tunnel. Apparently, the software genii thought it was not important to terminate existing internet connections when the user connects to a VPN and having them automatically reconnect to the destination servers after the VPN tunnel is established. But what apparently they were not aware of was that some are long-lasting and can remain open for minutes to hours outside the VPN tunnel. “During the time the connections are outside of the VPN secure communication channels, this issue can lead to serious consequences. For instance, user data could be exposed to third parties if the connections are not encrypted themselves, and IP address leaks could potentially reveal the users' location or expose them and destination servers to attacks.” Until Apple provides a fix, the company recommends using Always-on VPN to mitigate this problem. "However, since this workaround uses device management, it cannot be used to mitigate the vulnerability for third-party VPN apps such as ProtonVPN", the report adds. https://fudzilla.com/news/mobile/505...-exposes-users |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Another Google+ data leak exposes info for 52.5 million users | Stefan Mileschin | WebNews | 0 | 11th December 2018 09:01 |
Apple Watch Series 4 teardown exposes all the big changes | Stefan Mileschin | WebNews | 0 | 25th September 2018 14:28 |
Uber had software designed to diddle drivers and users | Stefan Mileschin | WebNews | 0 | 11th April 2017 06:00 |
Windows 10 DRM exposes Tor users | Stefan Mileschin | WebNews | 0 | 4th February 2017 14:58 |
Trend Micro anti-virus software leaves users open to attack | Stefan Mileschin | WebNews | 0 | 14th January 2016 10:39 |
Apple refutes survey that says Apple Music users are jumping ship | Stefan Mileschin | WebNews | 0 | 19th August 2015 10:44 |
The software and services Apple needs to fix | Stefan Mileschin | WebNews | 0 | 10th January 2015 07:52 |
Microsoft is hand-picking users to test Xbox One's next software update | Stefan Mileschin | WebNews | 0 | 21st February 2014 09:38 |
Apple brings two-step verification to iCloud and Apple ID users | Stefan Mileschin | WebNews | 0 | 22nd March 2013 09:43 |
Flawed Wordpress plug-in exposes users | Stefan Mileschin | WebNews | 0 | 28th December 2012 08:14 |
Thread Tools | |
| |