Privacy and Security Risks of Android VPN Permission-enabled Apps
blog.csiro.au
blog.csiro.au
Install and configure your own VPN services (IPsec or OpenVPN), use strongSwan (Android native client which works great with RSA authentication with x509 certs, now supports importing VPN profiles in json format, cool) and OpenVPN.
Several past discussions on hacker news to start with:
[0] https://gist.github.com/spaze/558b7c4cd81afa7c857381254ae7bd...
Furthermore, kids find increasingly shady free vpns as IT blocks more and more free vpns.
Lots of kids will use free vpns to get their SAT/ACT/AP scores a day or so early.
I don't understand - how does a VPN help there? Are schools actually blocking the websites that publish the test results?
The corollary is that ones you pay for should not be trusted either: a service can both take your money and insert ads.
huh.... reminds me of pay/cable tv....
I think that's why more and more open source tools (scripts or automation {cook,play}books, etc.} have been made available to enable people to self serve and build their own VPN service ;-)
This may not be an issue for some people and for those who it is an issue, there are ways around it (I'll leave that part of the post for someone more experienced than I as I don't want to risk giving out bad advice). But it's worth baring in mind when signing up for a VPS in view of running a VPN.
That all said, I'm not excluding the possibility of providers logging network connections passively. The way around that is to run more than one VPN; that way any particular provider only has visibility of either the destinations but not the source, or the source but not the destinations. I'm not recommending that people need or should run two VPNs though - just adding it as a workaround against passive snooping by hosting providers.
People should NOT trust free services at all
FTFU.
> We test individually each one of the 150 VPN apps under consideration.
> Two people executed a total of 5,340 tests manually for three months and connected to all end-points mentioned in the GUI of a given VPN app.
Okay, that's brilliant, but I'd love to see the actual data as well. Even if it's impractical to include the data in an appendix (page number limitations in the published work, et cetera), hosting it online and linking to it in the article would be great.
I'm a scientist and geek. Show me the data!
Would be good to see the actual list of VPNs that comply with basic security requirements.
Personally, I prefer the "roll your own" approach mentioned above. A VPS from DigitalOcean or something beats most providers' pricing.
Does it? A VPN subscription costs around $40 a year, DigitalOcean starts from $60 a year for the lowest level standard droplet. Am I overlooking something?
I'm currently posting through a VPN running on a VPS I discovered through Low End Box, works just fine for browsing and downloading. 500GB transfer per month for $10 a year.
I talked to one guy who was utterly incompetent and another one who was really shady...
Would I trust them as a production server for an income generating app? Nope. But for my light/trivial uses they've been perfectly suitable.
The whole idea of VPN providers is that a lot of users have a connection to the same server so it's hard to monitor who talks to who.
A lot of people are using VPN providers to download illegal content via torrents. And in case there are no logs on the servers (which most providers advertise) the copyright holder has no way of knowing who you are since they only see that the traffic is coming and going from the providers IP address.
Because the consensus seems to be that if you use any VPN besides OpenVPN you're a moron, and therefore some build-in solutions for some OSes only support OpenVPN.
Tha being said I've been quite happy with http://privateinternetaccess.com/. A good Android client, fast, don't ask any personal information when you register, they say no logging, the Android app doesn't ask any permissions and so on. I can choose the key length and additionally block all connections if the VPN is not connected.
In the general case, it's because most folks don't have the knowledge and skill required to set up either - nor should they have to.
With the increasing adoption of IoT devices and their generally crap (but not actively malicious) security, it would seem like a no-brainer for ISPs to offer VPN capability on the CPE as part of the basic service package, with UPnP configured to expose on the VPN interface rather than the public one, and with dynamic name resolution included to make configuration an easy one-time process. It'd help with customer retention, I think, and it'd surely improve network stability and throughput by reducing the quantity of attack traffic.
[1] [ https://research.csiro.au/ng/wp-content/uploads/sites/106/20... ]
67% of Android VPN apps claim to provide traditional VPN services (labeled here as “VPN clients”) including enhanced security and privacy, anti-surveillance or tunnels to access geo-filtered or censored content. Note that we consider Tor clients (e.g., Orbot, Globus VPN] and TorGuard VPN client) as a separate category.
That seems a pretty fair distinction.
Notably, the report doesn't include the word "onion" in it at all, so I'm not sure where you got "[they] think it's related to the onion router" from.
[1] https://research.csiro.au/ng/wp-content/uploads/sites/106/20...
TorGuard == something completely unrelated to Tor. Per the TorGuard website (https://torguard.net/faq.php):
"Is TorGuard related in any way to the “tor” project? No, The reference to "tor" in TorGuard relates to "torrents" and guarding one’s privacy when using bitorrent. We are not related in any way to the “tor” project however the company does support through donations."
Orbot, OTOH, is part of the Tor Project (https://www.torproject.org/docs/android.html.en) and Globus (https://play.google.com/store/apps/details?id=com.globus.vpn...) claims to support Tor.
Ok, I entirely agree they (and I) are wrong. But obviously I'm going to take the position that it isn't unreasonable to think something called "TorGuard" has something to do with Tor.
I would assume it to be insecure against a motivated attacker.
But yeah "free VPN" sounds exactly like "free credit card check"
1. bypass content restrictions by geoip (e.g. pandora, netflix)
2. a vpn that is just a local traffic monitor to tweak iptables(?) and block apps from using the network (to download ads). (e.g. netguard)
Of course. People don't install these VPN apps because they want their traffic to be "secure" or "private". They install them because they want to bypass geographical restrictions for content.
Nobody cares about traffic being insecure, or ads being injected in pages--users just want to see that geolocked video and get on with it.