Start United States USA — IT VPNs have a trust issue: Here's what TunnelBear did about it

VPNs have a trust issue: Here's what TunnelBear did about it

150
0
TEILEN

TunnelBear’s third-party security audit helped the VPN service fix vulnerabilities and prove its seriousness about protecting its customers.
The popular virtual private network (VPN) provider TunnelBear wants to earn your trust. The company just announced what it says is the first third-party public security audit in the consumer VPN industry. In short, a security company looked at TunnelBear’s servers, apps, and infrastructure to see if everything was up to snuff.
The VPN provider hired Germany-based penetration testing company Cure53. The security company was given full access to TunnelBear’s systems and code for 30 days in late 2016 and another eight in early 2017. The end result was two audits, which TunnelBear and Cure53 published Tuesday.
During the first audit, Cure53 found two critical vulnerabilities in TunnelBear’s Chrome extension, one of which allowed a malicious actor to turn off the extension. The auditors also found a critical vulnerability in TunnelBear for Mac that could allow a hacker to take over a user’s machine. All three vulnerabilities have since been patched.
Cure53 also found three high vulnerabilities—since patched—in the TunnelBear API as well as the Android app.
TunnelBear says it wasn’ t proud of those results, but at least the vulnerabilities were discovered. During the shorter redo this summer, Cure53 said it found 13 other problems, but only one was of “high” severity. The others were medium to low threats that did not require urgent fixes.
The one thing this audit didn’ t address were the contents of TunnelBear’s privacy policy, such as its no-logging claim for users’ browsing habits. On that issue, it’s still up to you to decide whether you trust the company.
TunnelBear says its experience with Cure53 has inspired it to carry out an annual security audit from now on.
If you want to check out the audit results for yourself, you can read a summary on Cure53’s website (PDF) .

Continue reading...