3 ms·
This doesn't sound too good for VPN users
by NullPrefix 5y ago
This doesn't sound too good for VPN users
- XorNot 5y agoIt's an operating system issue. OS's are really difficult to give absolute invariants that you can trust. If network connectivity security is vital, then the only real solution is to setup your environment in a VPN or on a separate box that will lose the adapter routing info if it goes down.
- thakoppno 5y agoThere’s a huge gap in operational security for a hack of this size. At minimum, use a burner IP address and hardware from Craigslist.
- karmajunkie 5y agoit sounds like a misconfigured VPN to me, like he didn’t have the interface set to block traffic on failure.
- kobalsky 5y agoif a security tool lets the user shoot themselves on the foot it's a problem of the security tool not of the user.
- sgjohnson 5y agoI’d be willing to bet that for most of the VPNs that are getting advertised by YouTubers (NordVPN, SurfShark, ExpressVPN, PIA, et al) it’s 100% marketing and they don’t actually care whether their “kill switch” works 100% of the time. After all, they are not as trivial to implement as it sounds.
- _jzti 5y agoSomething I don't understand is that he executed it fairly well... With the exception of using a weak, evidently broken, vpn instead of something like mullvad + tor. If you are going to do something like that (which is already a big "why???"), why put such little effort into your own security?
- Const-me 5y agoThe suspect allegedly stole gigabytes of data, need bandwidth for that. Last time I tried to use tor, I was getting like 32 kbit/sec, on top of a symmetric 100 mbit/second internet connection. That was many years ago but I doubt they fixed the speed, very hard to do without centralized servers.
- rtpg 5y agoTo be clear, at least ExpressVPN has a "prevent traffic going through outside the VPN" mode which would handle this case, and it's on by default. I am not sure how it's implemented, but it's pretty easy to imagine someone deciding to not use it cuz "it's slow/annoying" or whatever.
- 1_player 5y agoThat option isn't enough, it works only when the VPN connection is up. If your internet connection is flaky and lose connectivity to the VPN itself, your OS will revert to using its default gateway, and your home IP, which is how the guy got caught. You need your firewall to block any internet access when the VPN is down. I have something like that set up in a Docker container for my torrenting VPN system, so I never connect with my residential IP.
- rtpg 5y agoThat's incorrect. If you lose access to the ExpressVPN VPN connection then (while the VPN software is active) you _completely lose access to the internet_, until you disable a switch in the software. You get network errors and the like. at least with the ExpressVPN tool. This is a proprietary application, not just using the OS-integrated VPN software. Given your comment, I imagine it sets up firewalls.
- 1_player 5y agoI don't use ExpressVPN and apparently the guy with Surfshark thought his VPN functioned like this but it didn't. When in doubt, write the firewall rules yourself, especially if you're going criminal.
- deleted 5y ago[deleted]