Firewalls Don't Stop Dragons Podcast

TunnelVision, VPNs and You


Listen Later

Two security researchers showed how many modern VPN services are vulnerable to malicious misconfiguration, exposing some or all of your internet traffic. While this is not likely to impact most of us, it does expose the limitations of Virtual Private Networks and why they are not silver bullets for security of privacy - despite many marketing claims to the contrary. Today we'll discuss how TunnelVision works, how it can be mitigated, and how this affects different privacy threat models with the two researchers from Leviathan Security, Dani Cronce and Lizzie Moratti.
Interview Notes
Lizzie Moratti: https://www.linkedin.com/in/lmoratti/ 
Dani Cronce: https://www.linkedin.com/in/danicronce/ 
TunnelVision: https://www.tunnelvisionbug.com/ 
ProtonVPN threat model: https://protonvpn.com/blog/threat-model 
Dani’s GitHub: https://github.com/superit23 
Leviathan Security blog: https://www.leviathansecurity.com/blog 
Veilid: https://veilid.com/ 
Willy Wonka scene: https://www.youtube.com/watch?v=pvS3j8VtanM 
Linux network namespaces: https://blog.scottlowe.org/2013/09/04/introducing-linux-network-namespaces/ 
What is DeFi? https://www.investopedia.com/decentralized-finance-defi-5113835 
Further Info
Help me brainstorm ways to reach more people!: https://fdsd.me/awareness2 
Send me your questions! https://fdsd.me/qna 
Check out my book, Firewalls Don’t Stop Dragons: https://fdsd.me/book 
Subscribe to the newsletter: https://fdsd.me/newsletter 
Become a patron! https://www.patreon.com/FirewallsDontStopDragons 
Get your Firewalls Don’t Stop Dragons Merch! https://fdsd.me/merch 
Give the gift of privacy and security: https://fdsd.me/coupons 
Support our mission! https://fdsd.me/support 
Generate secure passphrases! https://d20key.com/#/ 
Table of Contents
Use these timestamps to jump to a particular section of the show.
0:01:23: Reminder: brainstorming survey
0:01:47: Podcast chapter markers!
0:02:54: Interview setup
0:05:55: What is a VPN and what isits intended purpose?
0:10:27: If most connections are secured today, why do we need a VPN?
0:12:40: Why do we trust a VPN provider more than our internet access provider?
0:17:40: What are you trying to do with a VPN?
0:19:13: Who can see my internet traffic?
0:25:30: What is TunnelVision and what are the implications for VPN users?
0:29:42: What's a less technical way to understand TunnelVision?
0:33:06: Why might I not want all my traffic to go through the VPN?
0:35:02: How dangerous is TunnelVision for the average person?
0:42:30: How did the VPN companies respond?
0:51:19: What VPN features can mitigate the risk?
0:57:42: Have any VPN makers fixed this problem? Do OS vendors have responsibility here?
1:02:11: Do you have recommendations for VPNs? Is there new tech that might help here?
1:04:00: Would privacy regulations help here?
1:06:24: What are you working on next?
1:08:51: Interview wrap-up
1:13:31: Looking ahead
...more
View all episodesView all episodes
Download on the App Store

Firewalls Don't Stop Dragons PodcastBy Carey Parker

  • 4.9
  • 4.9
  • 4.9
  • 4.9
  • 4.9

4.9

65 ratings


More shows like Firewalls Don't Stop Dragons Podcast

View all
Security Now (Audio) by TWiT

Security Now (Audio)

1,985 Listeners

Risky Business by Patrick Gray

Risky Business

364 Listeners

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec by Jerry Bell and Andrew Kalat

Defensive Security Podcast - Malware, Hacking, Cyber Security & Infosec

369 Listeners

Grumpy Old Geeks by Jason DeFillippo & Brian Schulmeister with Dave Bittner

Grumpy Old Geeks

6,019 Listeners

Hacked by Hacked

Hacked

180 Listeners

CyberWire Daily by N2K Networks

CyberWire Daily

1,014 Listeners

Smashing Security by Graham Cluley

Smashing Security

316 Listeners

Click Here by Recorded Future News

Click Here

405 Listeners

Darknet Diaries by Jack Rhysider

Darknet Diaries

7,962 Listeners

Cybersecurity Today by Jim Love

Cybersecurity Today

166 Listeners

Hacking Humans by N2K Networks

Hacking Humans

316 Listeners

Defense in Depth by David Spark, Steve Zalewski, Geoff Belknap

Defense in Depth

77 Listeners

Surveillance Report by Techlore & The New Oil

Surveillance Report

95 Listeners

Cyber Security Headlines by CISO Series

Cyber Security Headlines

128 Listeners

Hacker And The Fed by Chris Tarbell & Hector Monsegur

Hacker And The Fed

168 Listeners