this post was submitted on 01 May 2024
154 points (77.5% liked)

Technology

76949 readers
4794 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related news or articles.
  3. Be excellent to each other!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, this includes using AI responses and summaries. To ask if your bot can be added please contact a mod.
  9. Check for duplicates before posting, duplicates may be removed
  10. Accounts 7 days and younger will have their posts automatically removed.

Approved Bots


founded 2 years ago
MODERATORS
all 50 comments
sorted by: hot top controversial new old
[–] mindlight@lemm.ee 154 points 2 years ago (2 children)

PCWorld:

Microsoft’s latest Windows update breaks VPNs, and there’s no fix

What Microsoft actually said:

Windows devices might face VPN connection failures after installing the April 2024 security update, or KB5036893. We are working on a resolution and will provide an update in an upcoming release

I'm so fed up with everyone trying to make a quick buck on our constant struggle to stay safe.

[–] w2tpmf@lemmy.world 35 points 2 years ago* (last edited 2 years ago)

The reality is that it broke "something* in certain lpt2/ipsec connections using certain authentication protocols, although they haven't yet specified which particular connection technologies are affected.

However this does not mean that a blanket affect of ALL VPN connection not working is an issue.

So far we are unaffected on clients using ipsec and PAP protocol authentication, nor connections using Anyconnect (aka Cisco Secure Connect).

I have also not seen any affect on private VPN clients such as PIA or Nord on machines that have this update.

I suspect what broke was clients using MSChap, Microsoft's own protocol for authentication for VPN clients.

Source: an admin with 200+ client machines with VPN connections that are not impacted after installing this update.

[–] nublug@lemmy.blahaj.zone 10 points 2 years ago

absolutely bonkers take

[–] Imgonnatrythis@sh.itjust.works 70 points 2 years ago (4 children)

I dunno man. I'm convinced that pretty much any mention of VPN these days is just an ad for vpns. That's with this article looks like.

[–] zaemz@lemmy.world 42 points 2 years ago (1 children)

Yeah, you're not wrong that the article kinda sets itself up for the "lookit our recommended VPNs" pitch.

There's no way Microsoft would purposefully disable VPNs from working. I can guarantee that they require VPNs for thousands of roles in the company, let alone breaking it for government agencies that require VPNs, etc.

It is good to know that a specific update can break something ahead of time, though. Then at least you can avoid it.

[–] Kiernian@lemmy.world 16 points 2 years ago

There's no way Microsoft would purposefully disable VPNs from working

No, but they've done it accidentally before.

One time a few years ago it broke all LT2P VPN's unless you removed a specific KB########.

IIRC, six months later there was still no fix.

I think it's been fixed now, though.

[–] db2@lemmy.world 26 points 2 years ago (1 children)

And now a word from our sponsor, Nor-

[–] cyborganism@lemmy.ca 15 points 2 years ago (1 children)

Skip 10 seconds. Skip 10 seconds. Skip 10 seconds.

[–] lvxferre@mander.xyz 23 points 2 years ago (2 children)

Give up and install SponsorBlock.

[–] Kolanaki@yiffit.net 8 points 2 years ago (1 children)

But it's NordVPN.com/BigMoney. The ad is the best part of the video.

[–] 4am@lemm.ee 6 points 2 years ago (1 children)

Bounced on my boy’s Raycons to this for hours

[–] db2@lemmy.world 3 points 2 years ago

I do hope you were playing an invigorating game of Raid Shadow Legends at the time.

[–] metaStatic@kbin.social 6 points 2 years ago

all ad copy is an ad for sponsor block

[–] NGC2346@sh.itjust.works 0 points 2 years ago

Its actually real news

[–] cy_narrator@discuss.tchncs.de 26 points 2 years ago

It may be unintentional bug. People in the enterprise world need VPN for corporate purposes, they will fix it dont worry

[–] sgibson5150@slrpnk.net 22 points 2 years ago (4 children)

Doesn't seem to have impacted Wireguard.

load more comments (4 replies)
[–] MakePorkGreatAgain@lemmy.basedcount.com 22 points 2 years ago* (last edited 2 years ago) (1 children)

thats going to be an issue - at my work roughly 60% of the userbase is connected via VPN at any given point - so, ~40,000 people or so

[–] Qwaffle_waffle@sh.itjust.works 0 points 2 years ago

That's a paddlin.

[–] BaroqueInMind@kbin.run 8 points 2 years ago* (last edited 2 years ago)

Looks like their policy to prefer cheap labor they hire from Asia rather than paying local U.S. developers a living wage is starting to bite them in the ass.

[–] tsonfeir@lemm.ee 7 points 2 years ago

Obligatory Linux plug.

[–] Holzkohlen@feddit.de 5 points 2 years ago

You are gonna test the software for a multi-billion dollar cooperation and you are gonna like it!

[–] Melatonin@lemmy.dbzer0.com 4 points 2 years ago (1 children)

Is it too late to turn off security updates and avoid this issue?

[–] BearOfaTime@lemm.ee 1 points 2 years ago (1 children)

And this is exactly why I don't do auto updates (and people around here berate me for it, saying my systems are unsafe).

Hell, Windows LTSC only gets updates twice a year (which is what I run).

LTSC is great.
Much less bloat and bs too.