Sept. 17, 2023, 12:42 a.m. | DEFCONConference

DEFCONConference www.youtube.com

VPN Always-On is a security control that can be deployed to mobile endpoints that remotely access corporate resources through VPN. It is designed to prevent data leaks and narrow attack surface of enrolled end-user equipment connected to untrusted networks. When it is enforced, the mobile device can only reach the VPN gateway and all connections are tunneled.

We will review the relevant Windows API, the practicalities of this feature, look at popular VPN software; we will then consider ridiculously complex …

access always on attack attack surface con connected control corporate data data leaks def def con def con 31 device end endpoints equipment leaks mobile mobile device mobile endpoints networks resources security untrusted vpn

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC