visit
What Does a VPN Security Audit Cover?
Security audits vary in scale and scope. While some look to verify a company’s logging practices, others are more comprehensive.Following a 2018 data breach, NordVPN commissioned a full-fledged audit by PricewaterhouseCoopers, which covered the entirety of their operations, including their server network, code, and employees.But NordVPN isn’t the only VPN to be fully audited. Many providers, including ExpressVPN, Mullvad, and Surfshark, have since followed suit.While any security audit is a step in the right direction, you should pay close attention to the reputation of companies conducting these audits.What is a Warrant Canary?
Before carbon monoxide detectors were a thing, coal miners used canaries to protect themselves from poisoning. If the bird stopped moving, everybody knew it was time to pack and leave. A warrant canary works similarly. It is a simple statement that declares the company has not received any secret data request from the authorities. Its availability on the website indicates the “all clear.”A typical warrant canary can read as follows:“As of (date) we have NOT received any warrants from any government organization.”If your VPN provider receives a National Security Letter (NSL) or gag orders, they can simply remove the warrant canary to alert you without violating any laws.
What is WireGuard?
WireGuard is an open-source VPN protocol that is meant to deliver significantly better speeds than existing options.
Besides being fast, WireGuard is also well encrypted and utilizes state-of-the-art cryptography to keep your data safe.Despite WireGuard’s rapidly increasing popularity, only a few VPN services support the protocol. The key reason here is because the protocol is still under development and as such, can be a liability where privacy is of high importance.You should, however, expect to see more providers join in as the WireGuard moves towards a stable release. Already, VPNs like NordVPN and Mullvad offer the technology or a form of it.Advantages of WireGuard
Some of the key features of the WireGuard protocol include the following:Performance
While speed can be limiting to VPNs, it’s the one area where WireGuard shines. The protocol uses high-speed cryptographic primitives and system-level integration with the Linux kernel, which yield low packet overhead.
Stealth
Jason Donenfeld, the developer behind WireGuard, stated that the idea was born out of frustrations to bypass internet restrictions. Back then, he was living overseas and looking for a VPN that can access Netflix.As you probably know, Netflix employs powerful geo-restriction measures, which aren’t exactly easy to bypass. WireGuard works well against censorship and other internet blocks and is capable of not only bypassing Netflix but also the Great Firewall of China.Security
WireGuard uses an entirely different set of encryption compared to OpenVPN, IKEv2, L2TP/IPsec, SSTP, and other current protocols. The technology relies on cryptographic primitives like ChaCha20, Curve25519, BLAKE2s, and SiphHash24.WireGuard ciphers are modern, and in the world of cryptography, that holds some sway. Also, the , which gives it a minimal attack surface and makes it much easier to audit for security vulnerabilities.Disadvantages of WireGuard
Requires IP Logging
While WireGuard is highly promising, it does have its downsides. In its current state, WireGuard lacks dynamic address management and, instead, relies on static IPs. This is a big problem where anonymity is concerned.With proprietary innovations like NordVPN’s NordLynx and Mullvad’s Anonymous Account, the providers have found a way to leverage WireGuard’s incredible speed while eliminating the .