Kaspersky VPN blabbed domain names of visited websites – and gave me a $0 reward, says chap

John H Woods

Re: Is this a bug at all?

Whilst I agree that the *user* of a corporate VPN might not care about DNS leakage, the corporation should.

Unnecessary information leakage is always a problem, even if it just enables social engineering attacks (eg which vendor support pages you are visiting).

As the tunnel is already there, there's really no excuse for not sending DNS queries through it.

