Security Expert Comments On VPN Bug Lurks In iOS, Android, Linux Distros, MacOS, FreeBSD And OpenBSD

As reported by The Register, researchers from the University of New Mexico have found a bug in the way Unix-flavored systems handle TCP connections, which could put VPN users at risk of having their encrypted traffic hijacked. CVE-2019-14899 is a security weakness that they report to be present in “most” Linux distros, along with Android, iOS, and macOS. If exploited, encrypted VPN traffic can be potentially hijacked and disrupted by miscreants on the network. Once the victim connected to their VPN, the spy would be able to tamper with the TCP stream to do things like inject packets into the stream.


EXPERTS COMMENTS
Jake Moore, Cybersecurity Specialist,  ESET
December 06, 2019
The majority of people will not be directly targeted in this type of attack.
VPNs should ideally be seen and used as another tool in the cyber security toolkit, rather than something to use constantly. There have been a few stories mentioning breaches to VPN services this year, but I think they still have a role to play in data privacy. The majority of people will not be directly targeted in this type of attack, however they may be part of an untargeted breach of data if ....
[Read More >>]

If you are an expert on this topic:

Dot Your Expert Comments

SUBSCRIBE to alert when new comments are posted on this news. :




In this article