Some time ago, decompiled the Windows client and presented my findings here: https://hackernoon.com/poking-the-bear-is-tunnelbears-client...
Nice writeup. Not sure I agree about DNS transparent proxying being rampant in ISPs (at least in the US).
TunnelBear Publishes Security Audit
11–20 of 61 posts
Re: TunnelBear Publishes Security Audit
#12Re: TunnelBear Publishes Security Audit
#13The test looks good, down from 3 criticals and 3 high to just 1 high. I'd be interested if they could expand on the 4 medium findings found. It's not the full report.
Re: TunnelBear Publishes Security Audit
#14Some time ago, decompiled the Windows client and presented my findings here: https://hackernoon.com/poking-the-bear-is-tunnelbears-client...
Re: TunnelBear Publishes Security Audit
#15Earlier quoted context omitted.
Nice writeup. Not sure I agree about DNS transparent proxying being rampant in ISPs (at least in the US).
Pretty sure T-Mobile still does it.
The link is a test tool.
Re: TunnelBear Publishes Security Audit
#16Is there some way to be notified of a TunnelBear ownership change? For example, if Facebook buys them, how would we know?
Re: TunnelBear Publishes Security Audit
#17Earlier quoted context omitted.
I think your judgment is too harsh. Very few software deployment systems make it possible for binaries to be independently reproduced from published sources by the public. AFAIK, it's limited to systems like Nix, Guix, recent Debian, and other participants in the Reproducible Builds project. However, even within those systems, if you are downloading a compiled binary instead of building it yourself, how can you be su…
There's NO value in 3rd party vouching for the security (read, quality) of some specific version of the software, because this opinion will be rendered null and void with the next software update. There is some value in 3rd party verifying the system design (the architecture, the protocol, etc.) and general engineering practices in the company, but this still hinges on the need to trust this company not to be (or bei…
Re: TunnelBear Publishes Security Audit
#18Can official binaries be independently reproduced from published sources by members of the public? If no, then an audit has little to no value as it still implies trusting the vendor not to fudge the binaries or, more broadly, be malicious.
Re: TunnelBear Publishes Security Audit
#19Earlier quoted context omitted.
I think your judgment is too harsh. Very few software deployment systems make it possible for binaries to be independently reproduced from published sources by the public. AFAIK, it's limited to systems like Nix, Guix, recent Debian, and other participants in the Reproducible Builds project. However, even within those systems, if you are downloading a compiled binary instead of building it yourself, how can you be su…
There's NO value in 3rd party vouching for the security (read, quality) of some specific version of the software, because this opinion will be rendered null and void with the next software update. There is some value in 3rd party verifying the system design (the architecture, the protocol, etc.) and general engineering practices in the company, but this still hinges on the need to trust this company not to be (or bei…