Mozilla VPN Completes Independent Security Audit by Cure53
blog.mozilla.org
blog.mozilla.org
Edit: I use an always on VPN on my phone but I can only have one, and that's taken by my local wireguard so I can access the not-cloud services that I run remotely.
I've figured out how to connect Mullvad at the same time on that server, such that all traffic on the server goes through Mullvad. I can't figure out how to chain them. I want to make a request to my local network wireguard (wg0) and have any traffic that isn't local be routed through to the mullvad connection (wg1) so I can both access my local network and use the internet over the VPN. Has anyone don this or could anyone point me in the right direction? This is on a linux machine...
Chaining is doable using separate routing domains. Not for the faint of heart though.
Mullvad is €5/month, period.
Mozilla pricing starts to align once you pay 12 months at a time.
At least on the surface, Mozilla isn’t providing a benefit to the consumer aside from an account / subscription management approach that is slightly more “normal”, and it’s unclear if that’s actually a good (or bad) thing.
I haven't worked with wireguard and it may already have this feature built in, but the fundamentals remain the same.
Edit: Perhaps its "AllowedIPs" in the connection config.
ip route add <subnet> dev <device name> via <gateway or router>
Like this: ip route add 192.168.1.1/24 dev wg0 via 192.168.1.1 (which is the router, usually).
This really helped me https://unix.stackexchange.com/questions/666072/how-to-set-u...
No, since the client apps are different. However, Mullvad has completed several audits, including 2 of their client app:
This is how i use wiregaurd and it's pretty easy via the wg-quick interface. If using systemd you can also generate a unit for a particular config to bring it up at boot with: `systemctl enable wg-quick@config-name` where config-name is whichever one you want from your /etc/wiregaurd dir.
If you want to be able to check a file to see it's up, e.g for i3status bar or something, you can use /sys like this: `/sys/devices/virtual/net/mullvad*/dev_id` i'm using a wildcard but you can be more specific if you aren't going to be changing configs.
It’s a better experience.
Sorry, Web Safe has blocked this site
This site has been blocked by Web Safe. It's listed as
having content that’s inappropriate for children,
involving either pornography, hate, crime, drugs,
violence, hacking, self harm or suicide.
Thank you, Virgin Media. At least they actually tell you they're blocking them now rather than just forcing a DNS failure.So it's a Virgin Media thing.
It's only sites involved in pirating that you can't choose and have to use a VPN.
I need no advanced features, and I have no other WG servers to connect to besides Mullvad, so I’m simply using their app which handles everything for me.
It's only the client-side software in scope,not the VPN service itself.
https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak...
Policy based routing https://blog.scottlowe.org/2013/05/29/a-quick-introduction-t...
E.g:
A private virtual network between you and remote hosts won't be interrupted by the presence of a VPN service. The entry connection to the private network would be routed through the VPN service, though.
Mozilla VPN disadvantage: Mozilla is probably far less tolerant of all the things most people actually use a VPN for.
I can also see because of Mozilla's reputation employers offering these VPN free of cost to their employees.
One of the killer features of Mullvad is that their accounts are as anonymous as you can get, up to and including paying with envelopes full of cash.
The provided staging build contains the Mozilla VPN WebSocket Controller, which exposes a WebSocket endpoint on localhost. No additional authentication is required to interact with this port, thus allowing any website to connect and interact with the VPN client. At the beginning of the audit, Mozilla assured that this WebSocket server is only part of the staging build. However, later it was revealed that Mozilla would like to reuse this connection for communication with a browser extension in the future. Thus, Cure53 decided to report this issue."
A classic one.
Also interesting:
"On Linux and macOS, a helper shell script is called by the privileged daemon which sets up WireGuard and network configurations. This script is extremely critical for security and should normally get most of the security attention. However, prior to the test, Mozilla has announced that it will be replaced soon and, as such, does not warrant substantial reviewing efforts. This - in Cure53’s opinion - is rather unfortunate in relation to its criticality. Cure53 therefore recommends that the upcoming changes get comprehensively reviewed in terms of security before they are shipped in production releases."
It's like publishing that you passed health and safety inspection for a factory that makes safes. I don't think anyone would reasonably confuse a company publishing that its factory passed inspection for a claim that its safes are hard to break into.
They released the full report here and it's pretty clear on what they did and didn't audit: https://blog.mozilla.org/security/files/2021/08/FVP-02-repor...
(I know plutonium is not a good choice for the comparison as in the VPN case, we don't know if what will replace the script will be secure or not whereas plutonium is known to be unsafe, but the idea remains that changing something critical to safety after the audit is not nice to hear at all.)
That's fair, but also I don't know any companies in the industry that pay for a fine-toothed-comb audit like this one for every major/minor release because it's simply not practical. I don't think this report pretends or is intended to pretend that a one-time audit is representative of future code any more than a negative COVID test is representative of whether you have COVID two weeks later. But that's not an argument against disclosing that you came up negative on your last test a few days ago, because disclosure is still better than the opposite.
The way Mozilla is handling this is a textbook implementation of typical pretty-good transparency/disclosure practices. A post discussing the big issues, and the full report available publicly. I think it's a cynical take specifically because it's the least charitable take on someone following best practices.
I am not saying that I am against Mozilla's transparency, especially as they were clear on this issue and said by themselves they intended to change this code before release. I'm simply explaining why some may find it either a bad faith or strong security issue.
People all too frequently confuse software and services. They aren't the same. This is a software audit, and the thing that needs trust is the service.
https://mullvad.net/en/blog/2021/1/20/no-pii-or-privacy-leak...
Not sure how to handle updates later though. What level of udpates would require an entirely new audit?
Thats the most important question for a VPN.
And how well organized you are in providing them info/how much trouble it seems like you're going to be for them.
And how well known the vendor doing the work is.
And lots of other factors. Possibly somewhat discounted for OSS or high-profile projects, this is also an advertisement for Cure53 to some degree.
But as a random guess for a random project, at least low 5-figures.
[1]: https://www.cnbc.com/2019/11/12/iowa-paid-coalfire-to-pen-te...
I've worked on a number of projects where bill rate is something like $250-$400/hr per engineer depending on complexity, access to source code, size of the project, etc.
Usually equating to something like 10-12k for a single engineer on a project for a week. For bigger projects like this I would think it's totally reasonable to see anything from 4 engineering weeks -> 12 engineering weeks depending on different pieces and especially given this is a very high profile project. Based on that estimate of something between ~40k-120k. I know that's a huge range, but just wanted to share what I do know.
[0]: The founder of a (Germany-based) IT consulting firm recently told me that, as an estimate, pretty much any engineer at a tech firm costs at least 100,000€/yr.
The sibling commenters are right, though, that the hourly rates charged by the company are not very related to how much you earn as a person. I wish I got my hourly rate as salary, but I see what kind of organisational crap the founder has to do and it's just not worth the headache to me.
It's expensive, but it helps you land customers, which pay you enough to cover it.
Furthermore, I wouldn't underestimate the positive press that having a third party security firm assess your product and share the results publicly. VPN Services have been under special scrutiny lately so I think something like this makes total sense for Mozilla, regardless of the cost.
If throwing money at a problems solves, that's rarely a hard argument to make.
If you throw engineers at a problem it might get solved, or it might not. Hiring an engineer to work on something is a high risk investment.
side note: Mozilla does have great engineers, when I was there a few years ago the security was also very competent. But it's probably not the same as getting specialized consultants.
So this one off audit would have to hit them, say, 6000 extra 1 year subscriptions to pay itself off, let alone turn profit. Sounds like a stretch.
It would certainly be hard to measure.
On that note, how many customers do these public customer oriented VPNs have, typically? 1k's? 10k's? More?
First consideration point is quality of the team and the seniority of the people ACTUALLY DOING THE TESTING (a lot of pentest shops do bait and switch senior presenting but juniors do the actual work.)
Next consideration is location of company; EMEA and Asia are lower hourly rates than US teams.
Next consideration is scope. Do you want the front door checked, or the entire house inside and out? In this case Cure53 spent 25 work days on this asmt, which gives quite a lot of time to analyze the software and check lots of different avenues of attack.
Next consideration is type of attacks to try and security assessment methodology. Do you want just fuzzing? Perhaps you can get that for free from Google's OSS-Fuzz, they will sponsor people to set up your FOSS app with their fuzzer via CI/CD. Do you want static analysis from some big COTS vendor like coverity/fortify/checkmarx/etc. that could be useful and they often have discounted/free scans they will do for FOSS. Or perhaps you want super smart hacker pentesters to code review and dynamically attack your app (that's what my team does)
Next consideration is publicity, do you want this reporting public? Some charge extra for that.
There's a million other thing to consider when hiring a pentester, but this message is already too long. To give you a ballpark, estimate $10k to $40k for small projects, $40k to $80k for medium sized projects, and $80k to $150k for large projects. YMMV of course, but those ranges and the consideration points should get you well on your way.
Hit us up if you need more tips, happy to help via email <myfirstname>@includesecurity.com
The cost can be adjusted depending on how experienced the testers are, timing (I need it now vs I need it next month), and how much time they are expected to spend writing up executive reviews. We always opted to just get a list of vulns and passed on the executive reviews as they tended to take up at least a whole day or so of the budget.
You can also save a lot of time by having a really well prepared dev system set up and ready to go for them. Getting someone familiar with your setup while also trying to sort out VPN access, GitHub permissions, etc... costs time and money, so doing that ahead of the engagement saved me about a day of budget.
You can get things that are a lot cheaper, but that's usually just going to be a newly hired tester running burp suite or some other automated testing tool. It's still worthwhile to do though if you haven't, an OWASP top 10-20 automated scan may cost less than $5k but still can be helpful/insightful if you want to reduce your risk surface area.
Is this figurative or do you really get a discount for planning it one month ahead where you're from? From my (n=2 employers) experience, projects are usually planned at least two months ahead (if it's not busy; end of year you can expect 4-5 months).
The executive summary thing is also interesting. We take maybe 30 minutes at the end to sum up what we tested, which issues we found (particularly the impact in semi-layman's terms, depending on the impression we got from the contact person), and sometimes if there are big omissions from the scope that smell foul and someone (us or another company) really should still have a look at then we might remark that there as well. But we don't charge a day's rate for a short summary. I guess what you mean is more substantial than this?
For the summary: we always got the short summaries, list of vulns, recommended remediation. Tbh - I never paid for the exec summary, but my guess is that it was just taking all that stuff, spiffing it up into a PDF with clickable sections, and making it a lot more flowery? It sounded like something more desired by larger enterprise companies (maybe like this blog post!) than small ones like the one that I managed these engagements for.
Yes, there is another company, Altius IT, that audited PureVPN for their no-log policy. But they found nothing, and refused to answer my email inquiry with a simple question: "if PureVPN were have caught not storing any logs or connection data, but immediately sending them to a third party, would that have been reported as a finding?". The question was asked because on paper, this is not a violation of the published policy.
So my solution was to use a (hardware) VPN router which ensures all your traffic is tunneled through the VPN and you don't have to worry about edge cases like this leaking your real IP. Also: many users don't even turn off WebRTC which can expose you too. Many people it seems, don't know about the WebRTC VPN vuln that was disclosed many years ago.
Edit: I reported these extension vulns and they got fixed, but I still don't trust them.
DNS leaks are a subset of the problem where not all of your traffic goes through the VPN routes. If your only connection to the internet is through the VPN, the odds of that happening approaches 0%. If you're using some browser extension, the odds of that happening approaches 100%
Everytime I try to browse with a VPN (currently using Windscribe) I just see those nasty captchas everywhere. Google won't even let me do a simple search without letting me tag zebra crossings and school buses. Same with Cloudflare which also adds CAPTCHA before showing me a site which is basically most of the internet now.
Really don't understand why they do this to VPN users. Anyway, Anybody know how to fix this?
If you're trying to somehow set an example of where it's OK in one context and not OK in another, that's really not a fair comparison.
(Inb4: yes, the philosophy and circumstances behind protected classes are different. However, it's relevant prior art.)
I didn't encounter any serious CAPTCHA issues when I tried out Mullvad and Mozilla VPN. Windscribe is probably worse for CAPTCHAs because of its free tier and the lifetime membership that it previously sold for a low price. VPNs that require ongoing paid subscriptions tend to have higher-quality traffic.
https://github.com/privacypass/challenge-bypass-extension/bl...
Cloudfare, on the other hand, sometimes just decides that the website said "nope" and blocks you. It's such a giant PITA. I spend a lot of time in two countries because of my job and family -- and one restaurant near my home in one of them has decided to block all IPv4 (but not ipv6...) connections to it with cloudfare. I used to look at their menu online, often on the days that I flew back (in the 'before times'). I have to use a VPN to get around that (their food is good!). Cloudfare recently started introducing obnoxious captcha requirements and occasionally outright blocking.
The more people who use VPNs -- and I am sure they are on the rise -- the more it becomes normalised hopefully the more that this goes away. To be honest, it's a price worth paying for privacy at any rate.
[1] https://grumpy.website/post/0RzW4elEN [2] https://news.ycombinator.com/item?id=20147015
If you're on a VPN with a fresh ASN and IP range you won't have any issues (until people start using it for other reasons).
If you wanted to "fix it" the dirty method, there's extensions for chrome/firefox/etc that will automatically submit your captcha to a captcha solving service and it costs some tiny amount.
tldr; Mischievous basically has to go through VPNs, and they rotate through IPs getting them flagged. You can join the dark side with a captcha solving service and extension, and there's some "solutions" like privacy pass you can try.
I think third-party assessment reports like these are a real problem in our industry. There are firms that are worse about them and firms that are somewhat better but it's a near-universal problem.
I don't at all object to technical vulnerability reports being shared. It's good to know when third-party auditors have spotted problems in products (and it's also good for prospective customers of consulting firms to know what kinds of vulnerabilities that firm is likely to spot, and how padded out some of these reports can be with low-quality findings). I also think it's worth remembering that the overwhelming majority of security assessment engagements are never reported out to the public; even when vendors do publish reports, more often than not it's after previous unpublished engagements have been run.
But the way these reports get written creates a huge conflict of interest. They're not simply reports of (1) what was tested and (2) what was found. Too often, they're also product marketing documents, beginning and concluding with "overall assessments" of the target software that is almost invariably positive, even on projects that reduced the target to a smoking crater (to say the least, that didn't happen here, but when it does, it's always framed as "[vendor] has made great strides in improving their security in the wake of this important engagement").
There are firms that specialize in writing public audit reports, and firms that specialize in finding excellent vulnerabilities, and the Venn of those firms is practically two disjoint circles† --- at least in the sense that there's a sort of insider chatter about who the quietly bad-ass firms are, and who the "most credible for shutting down sales objections" firms are.
Even when they're not intended to be tools of persuasion, public audit reports tend to function that way systemically. That's because vendors control the terms on which these audits are done, what's to be tested, when the testing will occur, how much time will be allotted and who's staffing. Vendors pay for public-facing reports, as an extra line item in the SOW, and in some circumstances get to review drafts.
Meanwhile, the public that reads these reports is in no way qualified to weigh or contextualize the report. If you're reading an audit report from a commercial vendor, it is invariably presented as a "clean bill of health". But even if you somehow get principals at Azimuth to assess your system, there is no such thing as a clean-bill-of-health audit. Different teams of auditors will find different bugs (even different teams from the same vendor!).
I think we need a new norm in the industry, and that it can only come from the auditing firms themselves. I think that, roughly, that norm should be that public-facing reports can be provided only in the same dry, technical form they're presented to development teams in ordinary, non-public projects: a methodology, a scope and rules of engagement, and a list of findings. No editorializing and no editorial review by vendors. Probably, though I'm less clear on the mechanics of how this would work, it should also stop being OK to charge different amounts for projects that do and don't have public reports.
I know there are consultants that disagree with me about this; I look forward to reading their takes.
† I'm not editing this out but on reflection this is pretty imprecise and it's probably easy to come up with a counterexample.
⃰ And that it's even remotely readable to be an asterisk, which my terrible vision can't make out in the text input field on HN, and that it's wrapped correctly (which it's not), and that it's spaced far enough away from the previous character (which it's not) and that <SPACE> <ZWJ> <COMBINING ASTERISK ABOVE> are handled properly by the website (which is still not universal† yet‡).
† Emoji have helped, though HN specifically removes them.
‡ Note, however, that in the HN text input field, the dagger and double dagger are not shown superscript, as they are in the resulting comment you're reading now. It seems to be up to the font to decide what to do, as Unicode opted out of superscripting concerns.
4. paragraph symbol (¶),
5. section mark (§),
6. parallel rules (||),
7. number sign (#).
If more are required, they can be doubled up: double asterisks (**), double single daggers (††), double double daggers (‡‡), etc.
^ one
^^ two
^^^ three
^^^^ four
The problem is the ultimate consumer[1] of these reports, legal and procurement agents at buying companies, themselves don't care about the actual quality of the report except insofar as it satisfies their own transitive legal/sales requirements, and it's turtles all the way down. This harms users/customers at the end of the day because they don't have time to scrutinize the details of each individual report or have any real power. If we care about the end goal (secure, accessible software), we need for the auditing firms to collaborate we the government, judiciary, and ancillary vendors to tighten standards to include random[2], uniform checks (same auditor, same methodology, multiple vendors at once).
In the US, OSHA designates NRTLs like UL to perform safety testing, which are required everywhere from workplace standards to insurance requirements. In comparison, at least for accessibility, merely having your vendor have any assessment report is likely enough CYA to withstand a legal challenge. I acknowledge the power of recent website lawsuits to use the broader ADA to raise the bar here, but ADA's "enforcement through private lawsuits" enforcement mechanism is spotty and I think won't result in enough structural improvement.
[1] - These reports also serve as PR/marketing, which is probably moreso the case with Mozilla VPN, but in most enterprise software where these assessments are taking place, the marketing side is very much a secondary goal compared to the individual legal/sales relationship that hinges on the report.
[2] - I think removing the opportunity for vendors to fine-tune scope or prepare or respond to concerns (at least until the next review cycle) is a big step in the right direction, but unfortunately, the legal climate is very much all-or-nothing and not good at nuance. Section 508 (I'm not personally familiar with PCI/SOX/etc. but suspect those are similar) is formally speaking "all or nothing" check all the boxes things, and in that climate, good random audits will basically be always-failing, and if you make too hard a standard that even reasonable vendors can't meet with an earnest effort, you'll end up constricting the market into a meta-game of who can hack the auditing process. See federal government procurement.
I think you mean "later unpublished engagements".
Audit reports like SOX and SSAE 16 that tie back to financial risk can be more staid, because of the legal risk to both the auditor and auditee. Even though it appears to be tied to financial audit, we could still accomplish a lot on the infosec side because of the close relation between infosec failure and significant financial impact. Final reports contained a section specifically for the company's own statements, and a section for the auditor statements that was almost always boilerplate straight from legal. Flourish and marketing were nowhere to be found.
As a former auditor I enjoy reading these reports but I always find myself asking: who are these "auditors" and how are they held accountable, besides not being invited back by the auditee? And: Have I ever seen such a report that concluded the product contained critical exceptions or findings that should discourage consumers from using the product? I can't think of any, maybe someone else can.
We have some customers that clearly come to us to get reports they can share with investors, and not that many come back so either they weren't happy or (I like to think) they've checked that box and aren't doing further tests. But never did one of them ask us to rephrase something for overt marketing reasons or provide even a single sentence of marketing material to include. Perhaps we were clear that this is not something we do and that's why they don't come back, though since they also don't ask and still order a test, that doesn't seem logical.
I also can't say that I've seen a Cure53 report where this is the case, including this one. If anything, the statement about a critical vulnerability in the previous pentest could make one weary, so I applaud Mozilla for publishing this rather than silent fixing and keeping it under wraps.
> Vendors pay for public-facing reports, as an extra line item in the [statement of work]
This is the first I hear of that, though the public scrutiny does mean we spend quite a bit of extra review time on such reports (from spell checking to going over every substantial statement and rating) so I could understand if Cure53 has different practices from ours. That does not mean they were bought (assuming, for the sake of argument, that a premium was paid, which I don't think there was).
> that norm should be that public-facing reports can be provided only in the same dry, technical form they're presented to development teams in ordinary, non-public projects
That is exactly what we do, and I am quite sure Cure53 works the same way in this regard. We review more deeply if we know ahead of time it's going to be public, as I wrote above, to make sure things are correct (especially since English is none of our native languages), but we don't alter the contents.
> I think third-party assessment reports like these are a real problem in our industry.
I really don't understand where this comment is coming from unless you have very different experiences with customers or public reports where you are based. At a minimum it doesn't apply to the report at hand. Too often these things are kept secret and it's a rare opportunity that we don't have to swear silence on our work. I'd love to do that more.
Much of the security of VPNs though depends on the configuration of the servers/endpoints. Does it keep logs (on purpose or accidentally), are logs/traces of connections wiped from the RAM as well when you disconnect ... So even if you VPN client is perfectly secure, if someone is listening on the server nothing matters. Importantly, it's probably not unlikely that they were even set up by a "subcontractor" so even if Mozilla does everything right, there is the chance that a subcontractor still made a mistake and logs are being saved for example.
So a proper security audit would do lots of spotchecks on servers to see how well they are configured.
A proper security
I should probably clarify that I didn't really mean that Mozilla (or mullvad) is unsecure, simply that reports like this don't really tell us a lot, because the infrastructure is quite significant and it might be changing continuously. On the other hand I don't think there's anything better.
As for intelligence agencies, famously ProtonMail which works from Switzerland operates in a country with information sharing partnerships with the 5eyes, yet they are not all too concerned about it, nor interested on having their server-side software audited, so that to me raises eyebrows
In the past we have had the cryptoag scandal and BCCI which was an entire huge international bank with branches all over the world which basically only existed to be a front to CIA money laundering.... I personally believe that these guys are now operating with Deutsche bank and Cryptocurrencies which is just what would make sense for them as Deutsche bank is a corruption ridden company and Crypto is can be obfuscated so much as to be basically nontraceable
I have personally moved away from ProtonMail, I have 0 sources but they give me too much of a bad cryptoag vibe/honeypot, sad as it is, if you want secure email you must self host it which can be quite a pain in the arse, but these are the costs to have peace of mind
As for their VPN I would not use it, I don't like that ProtonMail centralized so many "privacy things" into a single point of failure
Assuming that social engineering is hard (for example, the target are computers operating machinery), while Windows is... not bulletproof, most applications (especially in-house apps) tends to be nothing more than a wooden gate, and therefore it's more expedient to do that than monitoring encrypt communications (obviously, it's has some benefits but it also has a lot of chaff, so it's better to have a wiretap directly).
What would be cool, if Mozilla partnered with multiple VPN providers and had a multi-hop VPN with at least 3 nodes and multi layered encryption, similar to TOR.
i don't get what is the reasoning behind this
(I worry that foundation income goes to activism and corporation income goes to the CEO’s pockets...)
There was also a report Baker had a >$1M "stipend" (uncharitably a bung) from Google, though I've been unable to refute/corroborate it.
Seriously, "Chair pay is .5% of revenue" seems fair.
And I haven't heard this "bung" rumor but Mozilla's revenue and usage were shrinking long before Baker became CEO in late 2019.
My limit on reasonable salary is 5 times the UK median graduate salary.
If ".5% of revenue is reasonable" surely there's no excuse not to increase salaries of everyone working for a company -- pay everyone ludicrous sums as each salary is small!
IIRC studies have shown exec salary doesn't correlate with increased company success, why should revenue come into it.
As for the rest, I also dislike standard corporate practices but Mozilla is more or less forced to follow them to compete at all in this world.
I'm sure they're flooded with great applicants for that gig. And again I doubt the CEO salary is still over $2 million. It would have been negotiated in April 2020 right before the layoffs.
1. Those who are aware of VPNs but have the money and would like to support Firefox can do so by using their product.
2. Those who aren't very aware of the vpn scene can trust a relatively more prevalent name in Firefox while still getting a reliable service and giving them money.
It's not ideal from a value perspective but I don't feel like it is egregious.
That's me.
On Mullvad VPN right now!
Any privacy benefit if I go through Mozilla?
Mullvad has a flat monthly fee (5€) and only stores a randomly generated 16 digit account number that you can stop filling up the day you want. You can pay with almost anything, crypto, credit card, even via post mail+.
Mozilla's VPN requires you to create a Firefox account and provide them your email, your age and a password. Optionally you can enable 2FA authentication.
So you trade off a bit more of your privacy in exchange of the same service you already have. It only makes sense if you want to support the Mozilla Corporation and Firefox's development (after all, money donated to the Foundation doesn't go to the Corporation).
+Fixed
Does Signal count as post-email message system? I heard they have a great payment system these days.
Mullvad's pricing page explains their available payment methods quite well: https://mullvad.net/en/pricing/
https://blog.mozilla.org/security/files/2021/08/FVP-02-repor...
But which product would you rather use: one where you have to trust the developers, or one where you have to trust the developers plus an independent team got 5 weeks of paid time to study it for any flaws?
As someone working in this industry, I can also say it's significantly harder to find exploitable bugs after another audit team went over it already. A criminal would have the same problem and might chose another target instead.