financetom
Technology
financetom
/
Technology
/
ExpressVPN gives all-clear to macOS, Linux, Windows desktop apps after security audits
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
ExpressVPN gives all-clear to macOS, Linux, Windows desktop apps after security audits
Nov 10, 2022 10:43 AM

ExpressVPN on Wednesday (November 9) announced that it validated the security posture of its macOS, Linux, and Windows desktop apps through three new independent audits by respected cybersecurity firms, Cure53 and F-Secure.

ExpressVPN said in a statement that Cure53 tested both its macOS and Linux desktop apps through white-box penetration tests and source code audits from June to August 2022.

“They found a low volume of issues in our macOS app, uncovering only two security vulnerabilities and four informational weaknesses with low exploitation potential. We quickly addressed all relevant findings, with Cure53 reviewing the fixes to ensure no additional weaknesses were introduced,” it added.

Also Read: Elon Musk tweets poll asking if there are 'fewer bots/scams/spam' on Twitter; users give reality check

“In conclusion, this assessment of the latest ExpressVPN application for macOS iteration leaves an exceptionally solid impression in regards to security,” writes Cure53 in their report.

“All in all, the ExpressVPN team deserves high praise for its efforts to provide an exceptionally secure macOS client. Only a few minor hardening improvements are required to elevate the platform’s security posture to an exemplary level.”

Similarly, the audit of its Linux app returned a short list of security issues, according to the company. Out of the five discoveries, there were two security vulnerabilities and three general weaknesses with lower exploitation potential, all of which have since been reviewed by ExpressVPN’s internal team. “Absence of findings beyond a Medium rank is yet another strong positive indicator of the condition of the security premise at the ExpressVPN Linux targets,” notes Cure53.

F-Secure conducted a security audit on the Windows app (v12) from February 2022 to March 2022. The audit assessed two important features of the app:

That the app cannot be manipulated to leak information (such as a user’s IP address) outside the VPN tunnel

That the app is not susceptible to remote code execution attacks

Also Read: FTX halts addition of new clients, withdrawals and fresh deposits

“We’re pleased to share that F-Secure did not find any significant weaknesses. F-Secure’s independent auditors found only one informational issue in our Windows v12 app, which was not exploitable. The issue has already been fixed, which F-Secure confirmed in a retest in April 2022,” ExpressVPN said.

No critical, high, medium or minor issues seem to have been found. F-Secure concluded: “It was not possible to gain information about ExpressVPN’s clients or out-of-the-network traffic. Nor was it possible to execute code remotely through attacks such as Man-in-the-Middle (MitM), TLS downgrading, or packet injection.”

Also Read: Exotel receives licence from Telecom Dept to provide pan-India cloud-based solutions for remote working

(Edited by : Shoma Bhattacharjee)

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
10 Analysts Assess Klaviyo: What You Need To Know
10 Analysts Assess Klaviyo: What You Need To Know
Oct 18, 2024
Providing a diverse range of perspectives from bullish to bearish, 10 analysts have published ratings on Klaviyo ( KVYO ) in the last three months. The table below provides a concise overview of recent ratings by analysts, offering insights into the changing sentiments over the past 30 days and drawing comparisons with the preceding months for a holistic perspective. Bullish...
A Look Ahead: SAP's Earnings Forecast
A Look Ahead: SAP's Earnings Forecast
Oct 18, 2024
SAP is preparing to release its quarterly earnings on Monday, 2024-10-21. Here's a brief overview of what investors should keep in mind before the announcement. Analysts expect SAP to report an earnings per share (EPS) of $1.33. SAP bulls will hope to hear the company announce they've not only beaten that estimate, but also to provide positive guidance, or forecasted...
Satellite firm Visiona eyes growth as Brazil doubles down on aerospace
Satellite firm Visiona eyes growth as Brazil doubles down on aerospace
Oct 18, 2024
SAO JOSE DOS CAMPOS, Brazil (Reuters) - Brazilian aerospace company Visiona expects to advance in its satellite business at a time when the South American country indicates it is looking to expand its presence in the industry. Visiona on Friday revealed for the first time images obtained by a nanosatellite it launched last year, the VCUB1, Brazil's first locally designed...
Cracking The Code: Understanding Analyst Reviews For Microsoft
Cracking The Code: Understanding Analyst Reviews For Microsoft
Oct 18, 2024
Ratings for Microsoft ( MSFT ) were provided by 16 analysts in the past three months, showcasing a mix of bullish and bearish perspectives. The table below provides a snapshot of their recent ratings, showcasing how sentiments have evolved over the past 30 days and comparing them to the preceding months. Bullish Somewhat Bullish Indifferent Somewhat Bearish Bearish Total Ratings...
Copyright 2023-2026 - www.financetom.com All Rights Reserved