Oh the irony! Popular VPN is compromised

Oh the irony! Popular VPN is compromised

Over 100 million people who use the free SuperVPN software that is available via the Google Play store have been told they should delete it immediately.

VPNs (virtual private networks) can be used to help mobile phone users navigate the web securely, even when they are using a free mobile connection that isn’t password protected.

However new research from the team at VPNpro.com suggests that one of the popular VPNs, SuperVPN, could be putting Android users at serious risk of a cyber breach, such as having their credit card details stolen when they shop online.

Apparently the free app has a number of vulnerabilities that leaves it open to “man-in-the-middle” (MITM) attacks where hackers intercept data passing from your phone (passwords, credit card details etc) to the internet.

Of course, ironically this is exactly the sort of thing that VPNs are supposed to prevent.

Google Play is a platform for millions of people and software developers, and this makes it an attractive target for cybercriminals. However many of the free apps in the Google Play Store are often free for a reason: some collect data maliciously and some are deliberately vulnerable (we are not suggesting this is true of SuperVPN) while others are simply flawed perhaps because their “free” or “freemium” business model means they can’t afford adequate development checks.

David Emm, Principal security Researcher at Kaspersky has the following advice: “It’s vital that people obtain security apps from a reputable source, i.e. one that they know and trust. Vendors of many Internet security products offer a VPN and some include it as part of an overall security solution. People would be wise to choose a solution from a trusted vendor, rather than an unknown app.”

There are many reputable VPN providers, some of who offer good free services. So you should ensure that, if you are on public wifi you are always using a VPN connection. But make sure the supplier you are using is safe and reputable.

Copyright Lyonsdown Limited 2021

Top Articles

Carnival Cruises hit by fourth data breach in 18 months

Carnival Cruises, one of the world’s largest cruise ship operators, has confirmed that it suffered another data breach in mid-March.

NHS Test & Trace Consolidates Cyber Security

NHS Test and Trace has teamed up with cybersecurity company Risk Ledger to proactively manage its supply chain cybersecurity risks.

The expert view: Accelerating the journey to the cloud

At a virtual seminar on 9 June 2021, sponsored by managed IT service provider Sungard Availability Services, eight senior IT decision makers gathered to discuss how organisations can accelerate their…

Related Articles

[s2Member-Login login_redirect=”https://www.teiss.co.uk” /]