Post #4070342
2026-07-24 19:09 UTC
I know it was fashionable for a while for infosec to mock people that use VPNs (ala "Hello, it's 2026. Everything worth securing is transmitted over TLS anyways") but I still think it's an immature absolutist take.
TLS doesn't save you when Russia hacks the routers in your hotel to send you to phishing sites rather than actual login pages: https://www.bleepingcomputer.com/news/security/authorities-disrupt-dns-hijacks-used-to-steal-microsoft-365-logins/
Replies (2)
-
@ajn142@infosec.exchange 2026-07-24 19:46
@Lee_Holmes@infosec.exchange How do those sites present trusted certificates for e.g. microsoft.com? Or are they redirecting microsoft.com to microslop.com and relying on folks not noticing?
-
@john@cleary.au 2026-07-25 00:35
@Lee_Holmes@infosec.exchange But if you’re logging in with credentials that can be stolen, a VPN doesn’t necessarily save you either. Phishing resistant (eg passkeys +/or psso/wfhb tokens) creds is what’s really needed.