Traffic handling

A VPN can be perfectly encrypted and still fail through how it routes and resolves traffic. DNS queries that escape the tunnel disclose the user's activity to the local network and the configured resolver, and allow an on-path attacker to redirect names. Routes that do not cover all intended destinations (or that a local attacker can override) send supposedly-protected traffic in the clear. And split tunneling, where only some traffic goes through the VPN, deliberately bridges the client between the internal network and the open internet, which an attacker on the client's local segment leverages to reach the internal network through the client. These are configuration and policy weaknesses, not crypto breaks.

Subtopics#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more