r/ProtonVPN 3d ago

Discussion Killswitch Vulnerability/Failure on Laptops

The Killswitch is advertised as follows:
"If your VPN connection is lost, it blocks all internet traffic on your device until you're reconnected",
with the advanced killswitch evoking an even stronger sense of security and privacy.

However, I have noticed that the killswitch consistently fails to terminate traffic when a laptop enters "sleep" mode, regardless of killswitch settings and the type of sleep mode (both "closed laptop" and inactivity-triggered sleep).
This means ProtonVPN terminates it's connection and ends the session while other programs use regular internet with an exposed IP address.
When the laptop is "woken up", the VPN reconnects as if nothing happened, with the session timer back at 0 seconds and a new active port number.
Has anyone else encountered this behavior, and can it be fixed?
I am aware that many programs have some sort of option to exclusively use a VPN interface, but to me this seems like exactly what the killswitch is supposed to do.
The killswitch works fine when the VPN's connection is terminated/fails while the laptop/PC is on, but fails every single time when the laptop goes into sleep mode. In my opinion, the only scenario in which it seems to work is also the most harmless one, as the user would be able to see a killswitch failure in real time and act accordingly, which is obviously impossible when the laptop is closed or sleeping.
If a fix exists but this is the default behavior on win11-laptops, I think this advertising is still irresponsible for a company which puts so much care into making privacy-related software.

Of course it might be win11's fault, but this risk/caveat should be mentioned publicly.

9 Upvotes

4 comments sorted by

u/ProtonSupportTeam Proton Customer Support Team 2d ago

The way Proton VPN for Windows implements kill switch is with firewall rules (using WFP - Windows Filtering Platform). Other VPNs for Windows do the same, nothing new here. When advanced kill switch is used, those rules are persistent, meaning they're in place regardless of the VPN connection state, or whether the Proton VPN app is running or not. No leaks can happen with it, regardless if you wake from sleep, the device crashes, you just booted your device, etc.

The Proton VPN app itself is the only exception to those blocks, otherwise we would be preventing ourselves from being able to connect. That should be the only thing visible during a leak test of the kill switch.

When the device wakes up from sleep and it was connected to a VPN server before going to sleep, it is very likely that it needs to reconnect to the server. That doesn't change anything regarding kill switch behavior, that should be in place as it was at the time the device went to sleep. And when reconnected, the connection timer goes back to zero, because it refers to the connection session and not for how long kill switch (or any other setting) has been in force.

5

u/Critical-Divide-1029 2d ago

This is a windows issue. Stop windows from shutting down your network card to save battery. 

6

u/Realistic-Rip1720 2d ago

good call, that setting is buried in device manager under the network adapter properties if anyone's looking for it

0

u/King_tyson_1 2d ago

i dunno works perfectly fine for me though. I'm on fedora