3 ms·
I have a hard time calling the first flaw a design flaw. VPN clients are geared towards the average person. The average person wants to be able to print a paper
by NetworkPerson 3y ago
I have a hard time calling the first flaw a design flaw. VPN clients are geared towards the average person. The average person wants to be able to print a paper to his/her printer while connected to the VPN. Though I could definitely see a policy which only allows such communication to private IP ranges and not public ones.
The second vulnerability is more interesting. It seems VPN clients should be better at verifying their communication with the VPN server. The article claims communication to the server itself isn’t encrypted to avoid encrypting packets multiple times. How much communication is directly to the server vs just relaying through? Even if it got double encrypted, it doesn’t seem like that would greatly impact the connection since that traffic would in theory be minimal.