Jump to content

Tunnelbear Releases Security Audit Results

In a blog post today, VPN Service Tunnelbear posted the results of a 2016 independent security audit of their VPN to find vulnerabilities. Cure53, the cybersecurity company that was paid to perform the audit, managed to find "vulnerabilities in the Chrome extension" that they were not happy about, but they hope to improve their VPN and remain transparent about their software.

 

The blog post can be found here: https://www.tunnelbear.com/blog/tunnelbear_public_security_audit/

The results of the security audit can be found here: https://cure53.de/summary-report_tunnelbear.pdf

 

While disappointed in part of the results, I am most pleased to see a company that is willing to be transparent about its security and practices. I am most curious what LTT thinks of Tunnelbear maintaining honesty with the public.

Link to comment
Share on other sites

Link to post
Share on other sites

Admitting their faults and improving on them definitely helps me trust a company.

 

Edit: OP you might want to add some quotes so this thread doesn't get moved.

Current LTT F@H Rank: 90    Score: 2,503,680,659    Stats

Yes, I have 9 monitors.

My main PC (Hybrid Windows 10/Arch Linux):

OS: Arch Linux w/ XFCE DE (VFIO-Patched Kernel) as host OS, windows 10 as guest

CPU: Ryzen 9 3900X w/PBO on (6c 12t for host, 6c 12t for guest)

Cooler: Noctua NH-D15

Mobo: Asus X470-F Gaming

RAM: 32GB G-Skill Ripjaws V @ 3200MHz (12GB for host, 20GB for guest)

GPU: Guest: EVGA RTX 3070 FTW3 ULTRA Host: 2x Radeon HD 8470

PSU: EVGA G2 650W

SSDs: Guest: Samsung 850 evo 120 GB, Samsung 860 evo 1TB Host: Samsung 970 evo 500GB NVME

HDD: Guest: WD Caviar Blue 1 TB

Case: Fractal Design Define R5 Black w/ Tempered Glass Side Panel Upgrade

Other: White LED strip to illuminate the interior. Extra fractal intake fan for positive pressure.

 

unRAID server (Plex, Windows 10 VM, NAS, Duplicati, game servers):

OS: unRAID 6.11.2

CPU: Ryzen R7 2700x @ Stock

Cooler: Noctua NH-U9S

Mobo: Asus Prime X470-Pro

RAM: 16GB G-Skill Ripjaws V + 16GB Hyperx Fury Black @ stock

GPU: EVGA GTX 1080 FTW2

PSU: EVGA G3 850W

SSD: Samsung 970 evo NVME 250GB, Samsung 860 evo SATA 1TB 

HDDs: 4x HGST Dekstar NAS 4TB @ 7200RPM (3 data, 1 parity)

Case: Sillverstone GD08B

Other: Added 3x Noctua NF-F12 intake, 2x Noctua NF-A8 exhaust, Inatek 5 port USB 3.0 expansion card with usb 3.0 front panel header

Details: 12GB ram, GTX 1080, USB card passed through to windows 10 VM. VM's OS drive is the SATA SSD. Rest of resources are for Plex, Duplicati, Spaghettidetective, Nextcloud, and game servers.

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, sazrocks said:

Admitting their faults and improving on them definitely helps me trust a company.

So true, they knew they fucked up and yet they actually fix the problems that they had, unlike a lot of VPN vendors (ahem, Hola)

idk

Link to comment
Share on other sites

Link to post
Share on other sites

13 minutes ago, sazrocks said:

Admitting their faults and improving on them definitely helps me trust a company.

This makes me trust Tunnelbear more despite the fact that their headquarters is in Canada which is a member of the Five Eyes intelligence alliance. I wonder what are the results for other VPNs. 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, hey_yo_ said:

This makes me trust Tunnelbear more despite the fact that their headquarters is in Canada which is a member of the Five Eyes intelligence alliance. I wonder what are the results for other VPNs. 

What results? This is the first known VPN security audit. Many VPNs don't actually care that much about this sorta thing.

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, MisterNoodle said:

What results? This is the first known VPN security audit. Many VPNs don't actually care that much about this sorta thing.

Well I want to see other VPN providers get their source code audited as well 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

I agree, I've been on the fence about getting a VPN, but after seeing tunnel bear being open and fixing their problems I'm more convinced to try them

Fanboys are the worst thing to happen to the tech community World. Chief among them are Apple fanboys. 

Link to comment
Share on other sites

Link to post
Share on other sites

42 minutes ago, hey_yo_ said:

Well I want to see other VPN providers get their source code audited as well 

Oh I don't disagree at all, my sassy side just wanted to point out that I am doubtful most would care enough. Then again, a competitor (Tunnelbear) just gained some popularity by doing this, and they need to compete in order to stay afloat.

Link to comment
Share on other sites

Link to post
Share on other sites

Good to hear. Always liked Tunnel Bear and their fun little branding haha. Everything involving bears that is. 

- Fresher than a fruit salad.

Link to comment
Share on other sites

Link to post
Share on other sites

8 hours ago, hey_yo_ said:

This makes me trust Tunnelbear more despite the fact that their headquarters is in Canada which is a member of the Five Eyes intelligence alliance. I wonder what are the results for other VPNs. 

Five Eyes Intelligence Alliance? You've got to be kidding me.

Link to comment
Share on other sites

Link to post
Share on other sites

Good on them for doing a security audit and post it publicly.

The only bad thing is that TunnelBear is a terrible VPN provider since they do things such as block all torrenting.

Link to comment
Share on other sites

Link to post
Share on other sites

Please update your post in accordance with the posting standards:

 

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Ryan_Vickers said:

Please update your post in accordance with the posting standards:

 

Screenshot_20170813-103219.thumb.png.7989259643b58ba3ee43c6a64112123e.png

Hmmmmm, needs more Amazon ehh? 

I spent $2500 on building my PC and all i do with it is play no games atm & watch anime at 1080p(finally) watch YT and write essays...  nothing, it just sits there collecting dust...

Builds:

The Toaster Project! Northern Bee!

 

The original LAN PC build log! (Old, dead and replaced by The Toaster Project & 5.0)

Spoiler

"Here is some advice that might have gotten lost somewhere along the way in your life. 

 

#1. Treat others as you would like to be treated.

#2. It's best to keep your mouth shut; and appear to be stupid, rather than open it and remove all doubt.

#3. There is nothing "wrong" with being wrong. Learning from a mistake can be more valuable than not making one in the first place.

 

Follow these simple rules in life, and I promise you, things magically get easier. " - MageTank 31-10-2016

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

9 hours ago, Bananasplit_00 said:

 

Hmmmmm, needs more Amazon ehh? 

xD wow, that should not be happening @colonel_mortis @nicklmg

I know there was an issue with the ads previously, looks like it's back?

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

21 minutes ago, Ryan_Vickers said:

xD wow, that should not be happening @colonel_mortis @nicklmg

I know there was an issue with the ads previously, looks like it's back?

yah i was the one that originaly reported it i think lol

I spent $2500 on building my PC and all i do with it is play no games atm & watch anime at 1080p(finally) watch YT and write essays...  nothing, it just sits there collecting dust...

Builds:

The Toaster Project! Northern Bee!

 

The original LAN PC build log! (Old, dead and replaced by The Toaster Project & 5.0)

Spoiler

"Here is some advice that might have gotten lost somewhere along the way in your life. 

 

#1. Treat others as you would like to be treated.

#2. It's best to keep your mouth shut; and appear to be stupid, rather than open it and remove all doubt.

#3. There is nothing "wrong" with being wrong. Learning from a mistake can be more valuable than not making one in the first place.

 

Follow these simple rules in life, and I promise you, things magically get easier. " - MageTank 31-10-2016

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

19 hours ago, LAwLz said:

Good on them for doing a security audit and post it publicly.

The only bad thing is that TunnelBear is a terrible VPN provider since they do things such as block all torrenting.

Depends.

I personally never used torrent. I got my VPN mainly to watch BBC content and some champions league games.Oh and of course to circumvent our recent newest anti "hate speech" law that blocked one youtube channel entirely.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Ryan_Vickers said:

xD wow, that should not be happening @colonel_mortis @nicklmg

I know there was an issue with the ads previously, looks like it's back?

I have this all the time xD

 

Want to custom loop?  Ask me more if you are curious

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Damascus said:

I have this all the time xD

 

Not to drag this off topic any more but the ads are not supposed to interfere with the content of the page, it's just supposed to be additional, like a banner here or a square here, etc.  Blocking out the actual page content is not OK

Solve your own audio issues  |  First Steps with RPi 3  |  Humidity & Condensation  |  Sleep & Hibernation  |  Overclocking RAM  |  Making Backups  |  Displays  |  4K / 8K / 16K / etc.  |  Do I need 80+ Platinum?

If you can read this you're using the wrong theme.  You can change it at the bottom.

Link to comment
Share on other sites

Link to post
Share on other sites

I get that people are happy with tunnel bear being honest with their report,  but I have to wonder if they would have released the results had it been worse. Also, given the general consumer doesn't respond well to honesty (there is a reason unethical advertising practices abound in spades),  I wonder if this approach is targeted directly at enthusiast users.

Grammar and spelling is not indicative of intelligence/knowledge.  Not having the same opinion does not always mean lack of understanding.  

Link to comment
Share on other sites

Link to post
Share on other sites

Im glad they are being open about it.

System

  • CPU
    Ryzen 7 5800x
  • Motherboard
    Asus ROG Strix B550
  • RAM
    Corsair Vengeance Pro RGB 3200MHz 32GB (16x2)
  • GPU
    EVGA Nvidia RTX 2080TI
  • Case
    Fractal Design Define R5
  • Storage
    WD Black SN750 500GB NVMe SSD | WD Green 2TB HD | WD Green 3TB
  • PSU
    EVGA Supernova 850W
  • Display(s)
    Asus 1920x1080p 144hz
  • Cooling
    Cooler Master Master Liquid 240
  • Keyboard
    Logitech Pro TKL
  • Mouse
    Logitech G502
  • Sound
    Logitech G733
  • Operating System
    Windows 10 Pro 64 Bit
Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, Teddy07 said:

Depends.

I personally never used torrent. I got my VPN mainly to watch BBC content and some champions league games.Oh and of course to circumvent our recent newest anti "hate speech" law that blocked one youtube channel entirely.

What do you use to watch champions league games through your VPN? I always just have to try to find one of those ad-infected streaming sights. Maybe getting a VPN is the way to go.

Link to comment
Share on other sites

Link to post
Share on other sites

5 hours ago, Boonji said:

What do you use to watch champions league games through your VPN? I always just have to try to find one of those ad-infected streaming sights. Maybe getting a VPN is the way to go.

Switzerland's public TV shows one game each champions league game a day which is kinda nice for me as a German. I think it is not worth buying a VPN only for that because the quality is the same as those pesky ad streams. It just doesn't have ads. 

 

EDIT: Welcome to the forum and gratulations to your first post. I feel a bit honored :)

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×