The source code of the ProtonVPN client applications has been opened.

Proton Technologies, which develops a secure email service and VPN, announced has announced the opening of the source code of ProtonVPN client programs for Windows, macOS, Android and iOS (console Linux client was initially opened). The code is released under the GPLv3 license. Reports on the independent audit of these applications have also been published. No issues that could lead to the decryption of VPN traffic or privilege escalation were found during the audit.

The code is open as part of an initiative to ensure project transparency so that independent experts can verify that the code meets the declared specifications and monitor the correctness of the security audit. In collaboration with Mozilla, which develops a paid VPN service, Mozilla engineers were also given access to other ProtonVPN technologies for the audit. It is noted that the next step will be to open the remaining ProtonVPN applications to the public.

From previous incidents involving ProtonVPN, we can highlight the discovery of a vulnerability in the Windows application that allowed a user to elevate privileges in the system to administrator level (the vulnerability was caused by improper interaction between the unprivileged GUI client and the system service).

The code audit for the Windows application that concluded a few days ago identified 4 vulnerabilities (two medium severity and two minor): storing session tokens and credentials in the process memory, hard-coded VPN server keys in the configuration file (not used for authentication), inclusion of debugging information, and accepting connections on all network interfaces.

No vulnerabilities were found in the version for macOS . The iOS version found two minor vulnerabilities a vulnerability (SSL certificate binding is not used and operation is not blocked on devices after jailbreak). In the Android version, four minor issues were found (enabling debugging messages, lack of backup blocking using the ADB utility, encrypting settings with a hard-coded key, absence of SSL certificate binding) and one medium severity vulnerability (incomplete session termination allowing for session token reuse). four minor issues (enabling debug messages, lack of backup blocking with the ADB utility, encryption of settings with a predefined key, lack of SSL certificate binding) and one medium severity vulnerability (incomplete session termination allowing session token reuse).

Let us remind you that Proton Technologies was founded by several researchers from CERN (the European Organization for Nuclear Research) and is registered in Switzerland, which has strict privacy protection laws that prevent intelligence agencies from controlling information. The ProtonVPN project offers a high level of communication channel protection (the stream is encrypted using AES-256, key exchange is based on 2048-bit RSA keys and HMAC, authentication uses SHA-256, and there is protection against correlation attacks), does not keep logs, and focuses not on profit but on enhancing security and privacy on the Web (the project is funded by the FONGIT foundation, supported by the European Commission).

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster