summaryrefslogtreecommitdiffhomepage
path: root/docs
diff options
context:
space:
mode:
authorLinus Färnstrand <linus@mullvad.net>2019-12-18 13:44:29 +0100
committerLinus Färnstrand <linus@mullvad.net>2020-01-07 21:50:38 +0100
commit2b3d044e8776d35f661f6e436296e8a0deb7e0b3 (patch)
treeb0ab5b4de0a06ea4d5283a845fc23a67a3c5f168 /docs
parent912cc72d966894297019c1755f9ed70f068cda98 (diff)
downloadmullvadvpn-2b3d044e8776d35f661f6e436296e8a0deb7e0b3.tar.xz
mullvadvpn-2b3d044e8776d35f661f6e436296e8a0deb7e0b3.zip
Shorten text on "kill switch"
Diffstat (limited to 'docs')
-rw-r--r--docs/security.md11
1 files changed, 4 insertions, 7 deletions
diff --git a/docs/security.md b/docs/security.md
index a0b8b7a7eb..fc5d3cd145 100644
--- a/docs/security.md
+++ b/docs/security.md
@@ -168,16 +168,13 @@ to unlock the firewall and get access to the internet again.
## Kill switch
-The app has an always on kill switch that can't be disabled. There is no setting for it.
+The app has an always on "kill switch" that can't be disabled. There is no setting for it.
This means that whenever the app changes server or temporarily loses tunnel connectivity it will
ensure no network traffic leaks out unencrypted.
-We usually don't like the term "kill switch". Because it makes it sound like a big red button
-that the VPN client pushes when it detects a problem. This in turn gives the impression there
-might be a time window of insecurity between when the problem occurs and the app manages to "push"
-this virtual red button. Maybe that is how the clients who coined the term implemented it,
-but this app is much more proactive about stopping leaks.
-This app applies [strict firewall rules](#app-states) directly when it leaves the [disconnected]
+The app avoids the term "kill switch". Because it sounds like a red button
+That has to be *engaged when a problem arises*. This app is much more proactive and applies
+[strict firewall rules](#app-states) directly when it leaves the [disconnected]
state and keeps those rules active and enforced until the app comes back to the [disconnected]
state via an explicit user request again. Said strict firewall rules unsure that packets can only
leave or enter the computer in a few predefined ways, most notably to the selected VPN server of