Explain some of the security risks associated with VPNs.
During COVID-19 pandemic, employees had to work remotely from home. Perhaps most of
them had used virtual private network (VPN) to reach corporate resources. Virtual Private
Network (VPN) was only the way that enables secure communication between computers
used by employees and offices (Rash, 1). Since some VPN providers do not provide the
guarantee of privacy and security, there are some security risks associated with VPN which
are explained below.
VPN hijacking-This is a risk in which an unauthorized user takes a VPN connection from a
remote client.
Man-in -the-middle attack-In this attack, attackers can intercept data.
Weak user authentication-Authentication means verifying the identity of users. If the users
use weak username and password for verification, this may be the easy spot for hackers to
attack and steal sensitive data.
Split tunneling-In this attack,user accesses an insecure internet connection while also
accessing the VPN connection to a private network.
DNS leak-During this risk,the computer uses its default DNS connection rather than the
VPNs secure DNS server (Author, 2).
-
Describe how organizations can mitigate these risks.
To mitigate these risks, organizations should think carefully about VPN security features
when choosing a VPN product (Author, 2). Using free VPN products should be avoided
because providers share users’ data to third parties (Mocan, 3). Attackers try to find the