• Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
Tech News, Magazine & Review WordPress Theme 2017
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
  • Home
  • Blog
  • Android
  • Cars
  • Gadgets
  • Gaming
  • Internet
  • Mobile
  • Sci-Fi
No Result
View All Result
Blog - Creative Collaboration
No Result
View All Result
Home Android

Report: Popular VPNs have a dangerous security risk. Does yours?

April 20, 2022
Share on FacebookShare on Twitter

Ankit Banerjee / Android Authority

TL;DR

  • Some popular VPNs are employing questionable security practices.
  • These VPNs leave their users vulnerable to attack.

A new report indicates some popular virtual private networks (VPNs) may be leaving users exposed to a significant security risk.

VPNs are a popular option for businesses and consumers alike, providing a measure of security and privacy when browsing the web. Unfortunately, a new report by AppEsteem has found that a number of popular options — including Surfshark, Turbo VPN, Atlas VPN, VyprVPN, VPN Proxy Master, and Sumrando VPN —  put their users at risk with questionable practices.

AppEsteem discovered that all six of the listed VPNs installed their own root certificate. A root certificate is an important component in cryptography and encryption, essentially proving the validity of an encryption key. Because a root certificate is self-signed, the most trusted ones are issued by established certificate authorities (CA).

Read more: What is a VPN and why do you need one?

Rather than using a root certificate from a trusted CA, each of the six VPNs installed its own self-signed root certificate. While this may not seem like an issue, it leaves users of those VPNs vulnerable to attack since root certificates give the issuers the ability to capture almost any data a computer sends and receives. That risk is why it’s critical to trust the CA implicitly and try to limit the number of root certificates installed on a device.

In addition to the privacy implications, self-signed root certificates also represent a point of possible attack by bad actors, hackers, and rogue governments. Rather than attack a high-profile CA, a hostile entity would only need to compromise the VPN provider and its self-signed certificate to then compromise any devices with that certificate installed. As a result, it’s a highly questionable practice for a VPN provider to use their own certificate, rather than one from a trusted CA.

Unfortunately, at least in Surfshark’s case, installing its Trusted Root Certificate wasn’t the only questionable practice. Surfshark also installs the Surfshark TAP Driver Windows app, Avira, and Open VPN, all without asking for permission.

To make matters worse, Surfshark continues with the installation of its Trusted Root Certificate even if the user cancels the installation process. The app also runs numerous processes in the background and fails to completely remove those processes when uninstalled.

See also: How to use a VPN

Surfshark contacted TechRadar to let them know it was working with AppEsteem to address the issues raised. The company defended its use of its root certificate — despite the fact that top-tier providers don’t do this — although it said it is working on deprecating the IKEv2 protocol, which “will eliminate the need to install the certificate.”

Despite the changes Surfshark has committed to, users would do well to wait for third-party confirmation that all six of these providers have made the necessary changes to be compliant with industry best practices. Consumers interested in the best VPN security would do well to look at Mullvad or NordVPN instead.

Next Post

Toyota, Lexus recall more than 458,000 vehicles for stability control software glitch

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

No Result
View All Result

Recent Posts

  • Apple M4 iPad Air announced: Specs, price, release date
  • UK government consults on social media ban for under-16s  
  • Best Kindle deal: Save $30 on Kindle Paperwhite Kids 16GB at Amazon
  • After 5 minutes with the Samsung Galaxy S26 Ultra, its best new feature is something I didn’t expect
  • Tecno’s got the most modular phone ever

Recent Comments

    No Result
    View All Result

    Categories

    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi
    • Home
    • Shop
    • Privacy Policy
    • Terms and Conditions

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    No Result
    View All Result
    • Home
    • Blog
    • Android
    • Cars
    • Gadgets
    • Gaming
    • Internet
    • Mobile
    • Sci-Fi

    © CC Startup, Powered by Creative Collaboration. © 2020 Creative Collaboration, LLC. All Rights Reserved.

    Get more stuff like this
    in your inbox

    Subscribe to our mailing list and get interesting stuff and updates to your email inbox.

    Thank you for subscribing.

    Something went wrong.

    We respect your privacy and take protecting it seriously