You are viewing a single thread.
View all comments
61 points

there are no ways to prevent such attacks except when the user’s VPN runs on Linux or Android.

So . . . unix? Everything-but-Windows?

permalink
report
reply
34 points

Maybe it affects BSD and MacOS.

It also can affect some Linux systems based on configuration. Android doesn’t implement the exploited standard at all and is always immune.

permalink
report
parent
reply
-43 points
*

Everything-but-Windows?

No. Any device that implements a certain DHCP feature is vulnerable. Linux doesn’t support it, because most Linux systems don’t even use DHCP at all let alone this edge case feature. And Android doesn’t support it because it inherited the Linux network stack.

I would bet some Linux systems are vulnerable, just not with the standard network packages installed. If you’re issued a Linux laptop for work, wouldn’t be surprised if it has a package that enables this feature. It essentially gives sysadmins more control over how packets are routed for every computer on the LAN.

permalink
report
parent
reply
43 points

because most Linux systems don’t even use DHCP

This is the dumbest thing I’ve heard all day.

permalink
report
parent
reply
58 points
*

most Linux systems don’t even use DHCP

WTF are you smoking? WTF is wrong with you that you think such a dumb claim would go unscrutinized? I would play Russian roulette on the chances of a random Linux installation on a random network talking DHCP.

Edit, in case being charitable helps: DNS and IP address allocation aren’t the only things that happen over DHCP. And even then the odds are overwhelming that those are being broadcast that way.

permalink
report
parent
reply
9 points

As of this writing, 5 people who don’t know how DHCP works saw this comment

permalink
report
parent
reply

Technology

!technology@lemmy.world

Create post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


Community stats

  • 15K

    Monthly active users

  • 13K

    Posts

  • 567K

    Comments