Many clientless SSL VPN systems operate in a way that bypasses fundamental web browser domain-based security mechanisms, according to a government warning this week.