Virtual Private Networks (VPN) have evolved from a technology used mostly by businesses to one that is used by more and more home users as well.
Reasons are manifold, but improved privacy and security are certainly two key features that make a growing number of home users use VPN services and apps.
Without going into too much detail; a VPN protects a device’s IP address as traffic flows through it instead of directly to the user’s system.
Google’s Android operating system supports native VPN clients since Android 4.0 released in October 2011 through the Android VPN Service class.
When enabled, VPN applications on Android intercept and take full control of a device’s traffic.
A team of researchers analyzed more than 280 Android VPN applications for privacy and security issues. The results, revealed in a research paper, reveal that many free and premium VPN applications on Android are insecure.
The research paper does not include the full list of tested Android VPN applications, and the issues identified in each of them. That’s unfortunate, as it would have helped users make an educated decision on which Android VPN application to install on their device, and to verify that installed VPN apps are not misbehaving.
Some VPN apps are mentioned however. The research paper lists all VPN apps that were flagged as potentially malicious by Virustotal, and apps that have “egress points in residential ISPs”.
The researchers suggest that Google needs to rethink the VPN permission model, as the current one is putting users, who are mostly unaware, at risk.
The ability of the BIND_VPN_SERVICE permission to break Android’s sandboxing and the naive perception that most users have about third-party VPN apps suggest that it is urging to re-consider Android’s VPN permission model to increase the control over VPN clients. Our analysis of the user reviews and the ratings for VPN apps suggested that the vast majority of users remain unaware of such practices even when considering relatively popular apps.
Now You: do you use a VPN application on your mobile device?
Advertising revenue is falling fast across the Internet, and independently-run sites like Ghacks are hit hardest by it. The advertising model in its current form is coming to an end, and we have to find other ways to continue operating this site.
We are committed to keeping our content free and independent, which means no paywalls, no sponsored posts, no annoying ad formats (video ads) or subscription fees.
If you like our content, and would like to help, please consider making a contribution:
Ghacks is a technology news blog that was founded in 2005 by Martin Brinkmann. It has since then become one of the most popular tech news sites on the Internet with five authors and regular contributions from freelance writers.