8 ms·
TunnelBear Publishes Security Audit
- brndnmtthws 9y agoTunnelBear is a great product, one which I've been using for a few years, and I trust them with my business. I wish services like Netflix didn't blacklist their IPs, but it's easy enough to get content off alternative sites when I'm traveling outside the US. Thanks for the good work!
- sunsetMurk 9y agoWhat do you do when you want to watch Netflix while traveling outside of the US?
- pandemicsyn 9y agoI just used Cloak while in Poland a few weeks ago with HBO Go (don't think i watched in any netflix).
- sunsetMurk 9y agothanks - I'm going to try that. I'm in Italy right now and a show I was watching isn't available!
- huhtenberg 9y agoCan official binaries be independently reproduced from published sources by members of the public? If no, then an audit has little to no value as it still implies trusting the vendor not to fudge the binaries or, more broadly, be malicious.
- lfam 9y agoI think your judgment is too harsh. Very few software deployment systems make it possible for binaries to be independently reproduced from published sources by the public. AFAIK, it's limited to systems like Nix, Guix, recent Debian, and other participants in the Reproducible Builds project. However, even within those systems, if you are downloading a compiled binary instead of building it yourself, how can you be sure that you get the "right" binary every time? Does the binary download system periodically "challenge" the binary provider by building from source and comparing with the downloaded binary? If so, does it report its findings anywhere? It seems to me that even within a software deployment system that enables users to reproduce binaries, you still end up trusting whoever runs the deployment system, because there are no methods of challenging the reproducibility in a meaningful way. The systems I mentioned above sign the binaries, which means that you implicitly trust the holder of the signing key to send you the right binary. But it doesn't mean anything about the relationship of the binary to some source code. Having said that, if I am using some program by downloading binaries, I am trusting whoever provides the binaries. If I trust them, then a source code audit is valuable to me, even though I can't be sure the compiled binary is related to the source code.
- huhtenberg 9y agoThere's NO value in 3rd party vouching for the security (read, quality) of some specific version of the software, because this opinion will be rendered null and void with the next software update. There is some value in 3rd party verifying the system design (the architecture, the protocol, etc.) and general engineering practices in the company, but this still hinges on the need to trust this company not to be (or being coerced to be) malicious. TunnelBear hasn't established the latter, so - yes, there's little to no value in former. There is some marketing value in it though. PS. Zimmerman's original secure VoIP project was rooted in the idea of reproducible builds. It was open source, but with a license that prohibited any use except for verifying binary builds. It was 20 (?) years ago.
- lfam 9y agoRegarding Zimmerman's VoIP, Tarsnap does the same thing. The client source is available but you aren't allowed to use it for anything except building the client for the Tarsnap service.
- michaelmior 9y ago"NO value" is a huge stretch IMO. Sure, it's entirely possible for gaping security holes to be introduced in future releases, but if past versions have been consistently vouched for as secure, that's still going to increase my confidence in future versions being secure. Or if I'm paranoid, then where possible I can just stick to a specific version which has been vouched for as secure.
- burkaman 9y agoLittle to no value? There's a pretty big gap between trusting a vendor to not lie and trusting them to not make mistakes.
- huhtenberg 9y agoIt's a moot point for a security vendor to establish its competence without establishing its trustworthiness.
- zimbatm 9y agoThe trouble with VPN providers is that even with reproducible client builds, it's much easier for them to intercept the traffic on their side. Plus there is a near-zero chance of detection, unlike on the client side where the binary can be decompiled.
- jlgaddis 9y agoI work for an ISP and believe deeply in online privacy. I've had the idea of offering up an as-private-as-I-can-make-it VPN service a few times, but I always end up at the same point: wondering how I could prove that the service wasn't doing anything malicious or nefarious -- "taps", Netflow data, etc. would all be easily available to me. What would it take to convince you that a VPN service was trustworthy?
- ehxcaet 9y agoI feel like people who complain about this are people who wouldn't be satisfied with anything unless they rolled it themselves. Of course, you could purchase your own server, use OpenVPN, etc. But anything that you haven't touched yourself is just one more thing that's potentially malicious.
- pnutjam 9y agoperfect is the enemy of good enough
- zimbatm 9y agoRandom audits from trusted third-parties would be a nice thing. Allow people to come in at any time and check the systems. Trust is better when distributed over multiple neutral parties. In terms of features, allow clients to regularly change IP and don't log who is using what IP. Also mix client traffic with Tor exit nodes to add noise to the traffic.
- 0xffff2 9y agoAm I missing something? Nothing TunnelBear produces appears to be open source, so the obvious answer to your question is no. Members of the public can't build binaries at all.
- elithrar 9y ago> If no, then an audit has little to no value as it still implies trusting the vendor not to fudge the binaries or, more broadly, be malicious. Given they provide a VPN service, trusting the binaries is only going to take you so far.
- minxomat 9y agoSome time ago, decompiled the Windows client and presented my findings here: https://hackernoon.com/poking-the-bear-is-tunnelbears-client-safe-to-use-5960f756f4ea https://hackernoon.com/poking-the-bear-is-tunnelbears-client...
- LogicX 9y agoNice writeup. Not sure I agree about DNS transparent proxying being rampant in ISPs (at least in the US).
- molestrangler 9y agoI still have issues with a VPN provider who insists on using their VPN client.
- bg0 9y agoAre there any nice free VPN Clients out there? I haven't been very lucky in finding any in the OS X realm
- codefined 9y agoOpenVPN is free and I use it pretty often. Supports both CLI & GUI. Would highly recommend it as an excellent client.
- atlgeek007 9y ago
- preinheimer 9y agoGetCloak has also done a 3rd party audit, and is planning their next one: https://support.getcloak.com/faq/technology/#have-you-had-any-third-party-security-audits https://support.getcloak.com/faq/technology/#have-you-had-an...
- ehxcaet 9y agoAre there results anywhere? Can't seem to find anything on their link to https://www.securityinnovation.com/ https://www.securityinnovation.com/
- clamprecht 9y agoIs there some way to be notified of a TunnelBear ownership change? For example, if Facebook buys them, how would we know?
- iraklism 9y agoGoogle news alerts. Alternatively you can pay someone to do it for you.
- orf 9y agoReport PDF: https://cure53.de/summary-report_tunnelbear.pdf https://cure53.de/summary-report_tunnelbear.pdf The test looks good, down from 3 criticals and 3 high to just 1 high. I'd be interested if they could expand on the 4 medium findings found. It's not the full report.
- ericzawo 9y agoTunnelbear is a dead-simple VPN (like, "so easy Mom can do it" simple) and their branding is killer. Who doesn't love cuddly privacy bears?
- Ethereum 9y agoTheir marketing team is really on point. I was a happy customer of theirs until I started searching around for a cheaper alternative. Their price is probably their only downside.
- aphextron 9y agoNever trust a 3rd party VPN for anything sensitive ever, period. Words of assurance and "security audits" are completely meaningless. HTTPS interception and forwarding is a trivial thing to do. For the public who are unable to setup their own VPN, they will have to accept that everything they do is being monitored by a random internet company rather than their ISP now. There can be some use for these services if you are very careful with everything you do while connected. But the risk of transmitting usernames, emails, passwords, and CC numbers accidentally while still connected is too great IMO.
- ehxcaet 9y agoI'd rather give my internet traffic to a company that doesn't sell my info versus my ISP, which almost certainly would sell my info.
- drdaeman 9y agoA VPN provider is no different than ISP. Seriously. Both get paid and provide Internet connectivity. Both have incentives to do something to your traffic, would it have no negative consequences (financial, legal or just moral) for them. The only non-technical difference is that VPNs have a lot of competition (so free market actually works) and in some countries/areas telcos have near-monopolistic positions. That doesn't mean that VPNs are universal friends of your privacy and ISPs are its foes. Just that there is some disbalance.
- ehxcaet 9y agoYeah, I agree. I don't think there's an intrinsic good guy/bad guy. But I have pretty much zero faith in ISPs in Canada. Maybe it's better where you live.
- Godel_unicode 9y agoJust because there are options doesn't mean there's competition n the free market sense. In order to have competition, the market requires complete information (or as complete as possible). VPN providers are not competing on security as there is (as others have stated on this thread) no ability to validate their relative security claims. Many people are advocating for VPNs as a pure knee-jerk reaction to monitoring by traditional ISPs.
- cJ0th 9y agoOFFTOPIC: Does anyone know whether TunnelBear will be available for Linux (or at least Firefox) one day?
- melanus 9y agohttps://www.tunnelbear.com/blog/linux_support/ https://www.tunnelbear.com/blog/linux_support/ Their Linux support is limited (ie no client), but it is there. You just need to do the configurations (somewhat) manually. Works pretty well when I used it a few months ago on my Mint box.
- 5706906c06c 9y agoGreat, what happens to the release iterations between now and when the next test is going to be conducted? Show me the build logs, what changes, etc.
- sigjuice 9y agoThe claims of transparency would be a bit more meaningful if they simply published their source code. It is hard to imagine anything too precious to disclose in the code. Instead what we have is a pdf (4 pages long) with the title "TunnelBear Security Assessment Summary 07.2017" and an equally long web page claiming how awesome and transparent this is.
- tolgahanuzun 9y agoIronic, I cant even enter the tunnelbear website in my country. (Turkey) :/