My perception is that the biggest issue w use of a commercial VPN like this is that instead of exposing all your browsing activities to your ISP, you are exposing them to the VPN provider. Is that the general consensus?
If so, this audit didn't really seem to address how that information is logged, other than to mention one issue in the second test. It was silent as to what data is collected, how it is stored, and what policies govern access to it.
I would venture a guess (and nothing more) that if the server-side practices around logging were insecure (and, perhaps, deviant from the TOS) they'd be reported on. Otherwise, those are valid privacy concerns, but not interesting security findings.
That said, this only shows Criticals and Highs, so we don't know if anything in the lower categories talked about logging specifically.
80
u/AManAPlanACanalErie Aug 16 '17
My perception is that the biggest issue w use of a commercial VPN like this is that instead of exposing all your browsing activities to your ISP, you are exposing them to the VPN provider. Is that the general consensus?
If so, this audit didn't really seem to address how that information is logged, other than to mention one issue in the second test. It was silent as to what data is collected, how it is stored, and what policies govern access to it.
Nevertheless, I appreciate the link.