@@ -1084,6 +1084,19 @@ Threat: Unencrypted traffic exposes private information
: Warning when disabling encryption
If a VPN product is capable of disabling encryption, it **shall** provide a warning against disabling encryption
Threat: Deanonymization due to the use of unique egress identifiers (such as IPs)
Threat: Storing sensitive data in logs
Threat: Split tunneling mistakes
- TR: Route all traffic over the VPN by default
Threat: IPv6 leaks and dual‑stack issues
- TR: Secure IPv6 Handling
Threat: Metadata and traffic‑analysis risks
- TR: TODO (jeroen)
User interfaces, especially in regard to settings, shall be designed in a manner that prevents unintentional disabling of default security features.
User-manageable VPN settings shall be configurable in a manner that introducing unexpected punctuation or other formatting errors cannot result in a failure of encryption.