{"id":16024,"date":"2019-08-08T06:30:04","date_gmt":"2019-08-08T14:30:04","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2019\/08\/08\/news-9767\/"},"modified":"2019-08-08T06:30:04","modified_gmt":"2019-08-08T14:30:04","slug":"news-9767","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2019\/08\/08\/news-9767\/","title":{"rendered":"Many VPN apps on Apple\u2019s App store can\u2019t be trusted, researcher warns"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/10\/ipsecurity-protocols-network-security-vpn2-100775458-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 08 Aug 2019 05:50:00 -0700<\/strong><\/p>\n<p>I\u2019m told Apple is at last looking into the privacy and security of free VPN apps made available across its platforms, <a href=\"https:\/\/www.top10vpn.com\/free-vpn-investigation-august-2019-update\/\" rel=\"noopener nofollow\" target=\"_blank\">following a report<\/a> from researcher, Simon Migliano.<\/p>\n<p>The researcher has flagged up several concerns that really should be recognized by anyone choosing a VPN service from both the Apple and Google App Stores:<\/p>\n<p>That last allegation is particularly concerning.<\/p>\n<p>Think about the nature of VPN services \u2013 while they make it much harder for third parties to access\/monitor your website traffic while you are using them, they do so by routing traffic via their own servers.<\/p>\n<p>That\u2019s fine when your traffic is kept in a private space, but much less fine when information about what you are doing online is sold on to third parties without any oversight.<\/p>\n<p>These could be data aggregators, hackers, or worse.<\/p>\n<p>Given that anyone using a VPN service is likely to prize privacy and potentially seeks to protect trade secrets or other important confidential data, weak spots in the security provision are a big concern.<\/p>\n<p>Your VPN service provider has good insight into what you do.<\/p>\n<p>Migliano published his data in late 2018.<\/p>\n<p>In his report, he accused both Apple and Google of not doing enough to protect users against second-rate VPN services.<\/p>\n<p>\u201cWe notified Apple and Google of our updated findings and formally requested they address the privacy risks identified,\u201d he told me.<\/p>\n<p>\u201cTo make it as easy as possible for them to resolve the issues, we supplied detailed lists of the apps that required their attention as they still posed a risk to users, along with recommendations on remedial steps to take.\u201d<\/p>\n<p>He explains that Apple is now looking into his claims, though no action has yet been taken.<\/p>\n<p>This follows Apple\u2019s decision in early June \u00a0to acknowledge that VPN apps require stricter regulation than other apps.<\/p>\n<p>Apple also banned such apps from sharing any data with third parties, though hasn\u2019t begun enforcing this policy yet, the researcher claims.<\/p>\n<p>\u201cHowever, unless Apple takes action to enforce these new rules and kick non-compliant apps from its App Store then it\u2019s simply paying lip service to privacy,\u201d he said.<\/p>\n<p>To its shame, given the nature of Miglianos claims, Google has not responded at all at time of writing, the researcher said.<\/p>\n<p>Apple meanwhile has <a href=\"https:\/\/www.applemust.com\/this-is-surveillance-warns-apples-tim-cook-in-blistering-eu-privacy-speech\/\" rel=\"noopener nofollow\" target=\"_blank\">a high-level commitment to protecting user privacy<\/a>, and recently moved to <a href=\"https:\/\/blogs.computerworld.com\/article\/3429601\/apple-suspends-siri-snooping-and-promises-more-control-for-the-rest-of-us.html\" rel=\"nofollow\">suspend human checks of Siri conversations<\/a>.<\/p>\n<p>What makes this all the more concerning is that those apps he has identified as insecure are responsible for over 210 million downloads on Google Play.<\/p>\n<p>Similarly, they are being downloaded 3.8 million times a month via Apple\u2019s App Store, he claims.<\/p>\n<p>All over the world, Internet users are waking up to the need to protect their privacy.<\/p>\n<p>This isn\u2019t just in terms of personal privacy, but as enterprise systems, workflows and infrastructure becomes increasingly digitized, privacy and security protection are becoming essential bulwarks against all manner of cyberthreats.<\/p>\n<p>With this in mind, Migliano said:<\/p>\n<p>\u201cEven putting aside the question of whether there\u2019s cause for concern that Chinese companies have quietly cornered the free VPN market, this category is crying out for proper regulation.<\/p>\n<p>\u201cThe privacy boom is happening against a backdrop of growing internet shutdowns around the world, which means conditions are ripe for VPN profiteering.\u201d<\/p>\n<p>There\u2019s a catch to all of these claims, of course:<\/p>\n<p>Migliano works for a company called Top10VPN, which claims to test existing VPN services.<\/p>\n<p>This means he certainly has a business case to justify exposing weak or insecure service, but may also mean his claims need to be challenged.<\/p>\n<p>On his part, the researcher says that he is not involved in the commercial side of his company, and is not involved in recommendations the company makes.<\/p>\n<p>Fortunately, if Apple is indeed acting on those claims, his claims will soon be challenged \u2013 and (when found appropriate) every user will benefit.<\/p>\n<p>Meanwhile, Migliano&#8217;s company recommends <a href=\"https:\/\/www.expressvpn.com\/\" rel=\"noopener nofollow\" target=\"_blank\">ExpressVPN<\/a>, <a href=\"https:\/\/nordvpn.com\/\" rel=\"noopener nofollow\" target=\"_blank\">NordVPN<\/a> and <a href=\"https:\/\/www.ipvanish.com\/\" rel=\"noopener nofollow\" target=\"_blank\">IPVanish VPN<\/a>, all of which are fee-based. I\u2019ve only used NordVPN, which I liked, but have never used the other services myself.<\/p>\n<p>How to choose a VPN service<\/p>\n<p>Here is a little advice on choosing a VPN.\u00a0<\/p>\n<p>&#8220;If I were pressed to recommend a free VPN, it would be a toss-up between TunnelBear and Windscribe as they operate on the freemium model, which means they don&#8217;t need to run invasive ad trackers and have revenue to fund a safe network,&#8221; Migliano said.<\/p>\n<p>I\u2019m hoping Apple will look into these claims.<\/p>\n<p>When it does, I\u2019d urge it to figure out some form of kite marking scheme in order that customers choosing to use a VPN service can more easily identify and choose a scheme they can trust, rather than those who subsidize their business by <a href=\"https:\/\/thenextweb.com\/contributors\/2018\/05\/28\/be-cautious-free-vpns-are-selling-your-data-to-3rd-parties\/\" rel=\"noopener nofollow\" target=\"_blank\">selling your data to data aggregators<\/a>.<\/p>\n<p><strong>Also read:\u00a0<\/strong><a href=\"https:\/\/www.computerworld.com\/article\/3339618\/how-to-stay-as-private-as-possible-on-apples-ipad-and-iphone.html?page=2\">How to stay as private as possible on Apple&#8217;s iPad and iPhone<\/a>.<\/p>\n<p><em>Updated: Additional information regarding Migliano&#8217;s work at his company and advice for identifying a VPN service.<\/em><\/p>\n<p>Please follow me on<em>\u00a0<a href=\"https:\/\/twitter.com\/jonnyevans_cw\" rel=\"nofollow\">Twitter<\/a>, or join me in the\u00a0<a href=\"https:\/\/mewe.com\/join\/appleholics_bar_and_grill\" rel=\"nofollow\">AppleHolic\u2019s bar &amp; grill<\/a>\u00a0and\u00a0<a href=\"https:\/\/mewe.com\/join\/apple_discussions\" rel=\"nofollow\">Apple Discussions<\/a>\u00a0groups on MeWe.<\/em><\/p>\n<p><a href=\"https:\/\/www.computerworld.com\/article\/3430899\/many-vpn-apps-on-apple-s-app-store-can-t-be-trusted-researcher-warns.html#tk.rss_security\" target=\"bwo\" >http:\/\/www.computerworld.com\/category\/security\/index.rss<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/images.idgesg.net\/images\/article\/2018\/10\/ipsecurity-protocols-network-security-vpn2-100775458-large.3x2.jpg\"\/><\/p>\n<p><strong>Credit to Author: Jonny Evans| Date: Thu, 08 Aug 2019 05:50:00 -0700<\/strong><\/p>\n<article>\n<section class=\"page\">\n<p>I\u2019m told Apple is at last looking into the privacy and security of free VPN apps made available across its platforms, <a href=\"https:\/\/www.top10vpn.com\/free-vpn-investigation-august-2019-update\/\" rel=\"noopener nofollow\" target=\"_blank\">following a report<\/a> from researcher, Simon Migliano.<\/p>\n<h2><strong>Who owns your VPN service?<\/strong><\/h2>\n<p>The researcher has flagged up several concerns that really should be recognized by anyone choosing a VPN service from both the Apple and Google App Stores:<\/p>\n<ul>\n<li><strong>Ownership<\/strong>: Migliano claims that almost 60 percent of the most popular VPN apps are actually owned (sometimes opaquely) by Chinese companies.<\/li>\n<li><strong>Privacy:\u00a0<\/strong>The researcher also found that as many as 77% of these VPN apps may have what he calls \u201cserious privacy flaws\u201d,including no privacy policy at all, generic policies with no mention of VPN or no detailed logging policy.<\/li>\n<li><strong>Data protection<\/strong>: Migliano claims Apple is not enforcing its third-party data-sharing ban against VPN apps, with 80 percent of the top free VPN apps \u201cin breach of the rules\u201d, he said. Many are sharing data with third parties, he claims.<\/li>\n<\/ul>\n<p>That last allegation is particularly concerning.<\/p>\n<p class=\"jumpTag\"><a href=\"\/article\/3430899\/many-vpn-apps-on-apple-s-app-store-can-t-be-trusted-researcher-warns.html#jump\">To read this article in full, please click here<\/a><\/p>\n<\/section>\n<\/article>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[11062,10643],"tags":[2211,10480,10554,714],"class_list":["post-16024","post","type-post","status-publish","format-standard","hentry","category-computerworld","category-independent","tag-apple","tag-ios","tag-mobile","tag-security"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16024","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=16024"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/16024\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=16024"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=16024"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=16024"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}