mttaggart,

If I understand this "TunnelVision" thing correctly, a few things are important to note:

  1. We're already inside a Rogue DHCP, so anything else after that feels like details.

  2. Option 121 used as described would make a honkin' large DHCPOFFER, which would be a solid network detection.

  3. TLS-encrypted traffic is still TLS-encrypted traffic. You'd need an additional AiTM attack to decrypt it, even without the VPN encapsulation.

acdha,
@acdha@code4lib.social avatar

@mttaggart yeah, the scenarios I’d worry about would be information disclosure: you’re gay man in Dubai, trans kid in Florida public schools, etc. and are relying on a VPN to keep your ISP from knowing what you’re accessing, especially before ECH is pervasive.

Those are already high risk scenarios so I think it’d be reasonable to debate how much it’s really increased risk versus losing the illusion of protection.

  • All
  • Subscribed
  • Moderated
  • Favorites
  • random
  • tester
  • DreamBathrooms
  • osvaldo12
  • mdbf
  • everett
  • magazineikmin
  • khanakhh
  • Youngstown
  • rosin
  • slotface
  • modclub
  • kavyap
  • tacticalgear
  • ngwrru68w68
  • provamag3
  • thenastyranch
  • cisconetworking
  • Durango
  • ethstaker
  • InstantRegret
  • normalnudes
  • Leos
  • GTA5RPClips
  • megavids
  • cubers
  • anitta
  • JUstTest
  • lostlight
  • All magazines