“Maybe there’s a book or something.” #TheAmazingRace #TunnelVision
Hey #Toronto,
Has #DougFord explained "how bike lanes cause traffic congestion, but on-street parking, which transports no one, doesn't cause problems."
#TunnelVision #ontario #onpoli #topoli #bikeLanes via// @mikepmoffatt
‘TunnelVision’ Attack Leaves Nearly All VPNs #Vulnerable to #Spying
#TunnelVision is an attack developed by researchers that can expose #VPN traffic to #snooping or tampering.
This Week in Security: TunnelVision, Scarecrows, and Poutine - There’s a clever “new” attack against VPNs, called TunnelVision, done by researche... - https://hackaday.com/2024/05/10/this-week-in-security-tunnelvision-scarecrows-and-poutine/ #thisweekinsecurity #hackadaycolumns #securityhacks #tunnelvision #github #gitlab #news
New #TunnelVision Attack Allows Hijacking of #VPN Traffic via DHCP Manipulation
https://thehackernews.com/2024/05/new-tunnelvision-attack-allows.html
'TunnelVision' bug potentially allows snooping on all VPNs
Operating system features can be manipulated to divert traffic away from encrypted VPN tunnel
https://www.computing.co.uk/news/4205875/tunnelvision-bug-potentially-allows-snooping-vpns
Je ne connaissais pas le RFC 3442. #mercrediConfession
C'est lui qui normalise l'option DHCP 121 qui permet l'attaque #TunnelVision contre les #VPN.
#TunnelVision attack against VPNs breaks #anonymity and bypasses #encryption https://www.ghacks.net/2024/05/07/tunnelvision-attack-against-vpns-breaks-anonymity-and-bypasses-encryption/ In a surprise to no one, the attack has worked against all non-Android OSes since 2002. #Windows #VPN
Man, I missed out having a cool named vulnerability. I bumped into #TunnelVision two years ago and chased it down. I ultimately left it at a shoulder shrug thinking: this is one of those things that's not an actual vulnerability, it's just a weak feature of a technology our entire network stack has used for decades.
Good on the Leviathan team for following through on it and not letting an RFC stop them from raising the alarms.
Newly discovered #TunnelVision attack (CVE-2024-3661) exploits DHCP to decloak VPNs, potentially exposing user traffic without triggering VPN disconnect alerts. Mitigation includes using network namespaces, mainly on Linux systems. More on this deep-dive into routing-based VPN vulnerabilities:
A "new" VPN vulnerability dubbed #TunnelVision (CVE-2024-3661), published by Leviathan Security and reported on by @briankrebs has been known for many years. However, most people had never thought about this whenever I mentioned it in the past, which explains why this is making the rounds now.
I personally have known it for ~10 years and posted about it on Mastodon+ years ago.
I didn't request a CVE or write half a book's worth of a blog post about it, though :D
I’m also interested in growing food but keep that to insta and tiktok #tunnelvision