Follow

iOS VPNs Are Broken.

Third-party VPNs made for iPhones and iPads routinely fail to route all network traffic through a secure tunnel after they have been turned on, something Apple has known about for years, a longtime security researcher has claimed.

mjtsai.com/blog/2022/08/18/ios

This looks bad folks.

The links on this story

macrumors.com/2022/08/18/vpns-

arstechnica.com/information-te

michaelhorowitz.com/VPNs.on.iO

To date, roughly five weeks later, Apple has said virtually nothing to me. They have not said whether they tried to re-create the problem. They have not said whether they agree on this being a bug. They have not said anything about a fix.

@mcfate
Ok …yes.
But I do, on my iPad, when not on my own network.

@corlin

Just pointing out that there are plenty of people to whom this admitted flaw is completely immaterial.

I don't use networks I don't control.

@mcfate @corlin
Yes, but there are a great number of people for whom this is a potentially serious issue. I am on a Wireguard tunnel back to my home network right now to take advantage of my filtering on the go. Sure, I could live without it.

But what if I was sending sensitive legal documents through a corporate VPN, for example? The fact that even some of the traffic can bypass the tunnel means what you thought was encrypted might actually be grabbed in the clear.

@voltronic @corlin

Yes, but I'm not one of those people.

If I were sending sensitive documents, I'd be encrypting the documents themselves. That's "due diligence".

@mcfate
That is indeed the safest way to go, but I think we all know that the vast majority of people won't take that step. They will assume their corporate VPN is secure.

@corlin

@voltronic @corlin

I'm not paid to worry about the "vast majority" of people who don't take the measures I take.

@mcfate @corlin
The other thing that strikes me is that the tunnel bypass might go unnoticed if you are just using a site like dnsleaktest.com to check your DNS servers.

Sign in to participate in the conversation

CounterSocial is the first Social Network Platform to take a zero-tolerance stance to hostile nations, bot accounts and trolls who are weaponizing OUR social media platforms and freedoms to engage in influence operations against us. And we're here to counter it.