--> Apple’s iOS 13.4 hit by VPN bypass vulnerability | Top Tech Site
Apple’s iOS 13.4 hit by VPN bypass vulnerability

Apple’s iOS 13.4 hit by VPN bypass vulnerability


It’s less than a week since Apple’s iOS 13.4 appeared and already researchers have discovered a bug that puts at risk the privacy of Virtual Private Network (VPN) connections.

Publicised by ProtonVPN, the issue is a bypass flaw caused by iOS not closing existing connections as it establishes a VPN tunnel, affecting iOS 13.3.1 as well as the latest version.

The company said it was disclosing the issue despite there being no patch because it believed it was better that providers and users knew about it now. Remote working and VPN use has increased as more workers self-isolate to avoid COVID-19.

Luckily, ProtonVPN has also discovered a workaround which involves turning airplane (or flight) mode on and off to reset all connections (see below for full instructions).

VPN privacy


A VPN app should open a private connection to a dedicated server through which all internet traffic from the device is routed before being forwarded to the website or service someone is accessing.

This means the ISPs and public Wi-Fi routers can’t snoop on the user’s traffic while websites and services can’t see the real IP address of the user.

This is more comprehensive than HTTPS, which only secures connections to individual websites or installed apps, one at a time. HTTPS also doesn’t hide other revealing traffic such as that to Domain Name Servers (DNS), which ISPs monitor to see which web domains someone is visiting.

The bypass bug


A ProtonVPN researcher fired up a monitoring tool called Wireshark and noticed that even when the VPN was turned on it was still possible to see that traffic was passing between the device and third-party IP addresses.

That means that iOS wasn’t closing those connections when the VPN started. What it should have been doing was terminating them before reconnecting them once the VPN has been established.

In short, everything that starts after the VPN is loaded will be secure but everything before that moment might not be if it doesn’t reset the connection of its own accord (some being longer-lasting than others).

This wouldn’t expose the information being passed inside those connections, which on iOS will use HTTPS. However:


An attacker could see the users’ IP address and the IP address of the servers they’re connecting to. Additionally, the server you connect to would be able to see your true IP address rather than that of the VPN server.

The IP address might sound less important than the information passed from, say, an installed app, but it reveals the ISP location and, potentially, the identity of the end-user. It also leaks information on the IPs the device has previously connected to, for example, a website or service.

Workarounds


A patch might not appear for weeks, which leaves users with two workarounds.

The first, suggested by Apple, is to configure the Always-on VPN setting via mobile device management (MDM). That should be possible for some business users.

However, it won’t be an option for home users running a third-party VPN app they downloaded from the App Store, which leads us to the second option:
Connect to the app’s VPN server.
Turn on airplane mode. This will kill all internet connections and temporarily disconnect the VPN.
Turn off airplane mode. The VPN will reconnect, and your other connections should also reconnect inside the VPN tunnel (this is not guaranteed to work 100% of the time).

Of course, users still have to remember to do this each time they connect, possibly several times a day. It’s far from ideal.

At least Apple knows about the issue. ProtonVPN said:

We have been in contact with Apple, which has acknowledged the VPN bypass vulnerability and is looking into options to mitigate it. Until an update is available from Apple, we recommend the above workarounds

Read the original article on nakedsecurity.sophos.com

  1. thanks to sharing this bypass blog its really helpful for me
    Ship name generator

    Reply Delete
  2. Hi!. We are enthusiastic Tech list providers to your everyday life. We are happy to share with you our Youtube and Instagrams !
    We hope you will definitely like our contents and we are sure that it will help you one day.

    Show some love in the form of Like | Share | Follow

    @the_tech_list

    Checkout my youtube channel and don’t forget to subscribe.

    The Tech List


    Reply Delete
  3. i really admire how well you menage this blog! For Breaking news, sport, TV, radio and a whole lot more. 99 Live News informs, educates and entertains -
    wherever you are, whatever your age visit 99 Live News

    Reply Delete

Designed by TopTechSite
Name

Android,57,Apple,48,Artificial Intelligence,4,Bing,2,BlackBerry,2,Blogger,7,Blogger Templates,7,Blogger Tips,2,Blogging,7,Business,47,Cameras,2,Cars,9,Computer,2,Computing,5,Culture,1,Domain,2,Downloads,1,Elon Musk,2,EMail,3,Facebook,32,Feature,3,Galaxy Note 20,2,Galaxy Note 4,1,Galaxy Note 7,3,Galaxy Note 8,7,Galaxy Note 9,1,Galaxy S11,1,Galaxy S20,2,Galaxy S8,5,Games,12,Gaming,2,Gmail,2,GoDaddy,1,Google,43,Health,7,Hosting,1,How to,23,Instagram,7,Intel,1,ios,1,iOs 11,1,iOs 13,1,iPad,3,iPhone,69,iPhone 14,2,iPhone 6,1,iPhone 7,1,iPhone 8,19,iPhone 9,1,iPhone X,12,Laptops,8,LG,7,LG V30,6,LinkedIn,2,Meta,1,Microsoft,14,Moto X4,3,Motorola,5,Nasa,5,News,368,Nokia,2,Nokia 8,1,OnePlus,2,OnePlus 3,1,OnePlus 3T,1,p,1,Phones,148,Real Estate,1,Samsung,38,Science,4,SEO,2,Social Media,44,Sony,3,Source: BetaNews,1,Space,12,Success,50,Tablet,1,Technology,344,TVs,1,Twitter,8,WhatsApp,2,WordPress,1,WordPress Themes,1,Xiaomi,4,Xperia,1,Yahoo,1,YouTube,7,
ltr
item
Top Tech Site: Apple’s iOS 13.4 hit by VPN bypass vulnerability
Apple’s iOS 13.4 hit by VPN bypass vulnerability
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj79kHODeZWUwJ6HP3ebLq5fIH99twIWIteR0Ni22rqIkAfumZngs5Pzy85A3G_V_gKQKWGGFdoUE5xSUzndZJfxeEJcJJA3AlLTSLNo4tyWTQ-CB783OIeTO2icNmsYl_7J2psMHSR9UU/s640/iphone-3505728_960_720.jpg
https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj79kHODeZWUwJ6HP3ebLq5fIH99twIWIteR0Ni22rqIkAfumZngs5Pzy85A3G_V_gKQKWGGFdoUE5xSUzndZJfxeEJcJJA3AlLTSLNo4tyWTQ-CB783OIeTO2icNmsYl_7J2psMHSR9UU/s72-c/iphone-3505728_960_720.jpg
Top Tech Site
https://toptechsite.blogspot.com/2020/03/apples-ios-13-4-hit-by-vpn-bypass-vulnerability.html
https://toptechsite.blogspot.com/
https://toptechsite.blogspot.com/
https://toptechsite.blogspot.com/2020/03/apples-ios-13-4-hit-by-vpn-bypass-vulnerability.html
true
7908177386937608306
UTF-8
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share to a social network STEP 2: Click the link on your social network Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy Table of Content