Security audit
The VpnHood! security audit
VpnHood! was reviewed by Include Security, in an engagement commissioned and paid for by the Open Technology Fund's Red Team Lab. The report was published in full, findings and all.
Why it matters
Open source shows you the code. An audit means somebody read it.
A VPN carries everything you do online, so there is really only one question worth asking about one: who has checked it? Publishing the source answers half of that. The other half is whether anyone qualified has gone looking for the mistakes.
Reading code is not the same as auditing it
Anyone can open our repository, and we would rather they did. But finding a subtle flaw in a VPN protocol takes people who do it for a living, with paid time and a method behind them. That is what an audit buys.
A report, not a badge
Plenty of VPNs announce an audit and never publish it. Ours is a public document on the Open Technology Fund's site, findings and severities included, with our comments on each one beside it. You read the assessment, not a summary of it.
Paid for by someone with no stake in the result
The Open Technology Fund commissioned the engagement and paid for it. The firm doing the reviewing was not being paid by the people being reviewed, which is the part that makes a finding worth something.
The engagement
Who did it, and who paid for it
Audited by
(opens in new tab)
- Auditor
- Include Security
- Commissioned by
- The Open Technology Fund's Red Team Lab
- Report
- Published in full