In this article we (FindVPN.com team) would like to tell the study which was focused on security of Personal VPN Service Providers. It is a well known fact that hackers quite often sniff public Wi-Fi hotspots and eavesdrop (perform MITM atttack) Internet traffic, and moreover they are capable to collect confidential information from unprotected laptops, tablets, smartphones which are connected to these public Wi-Fi hotspots. The attack is called “Man in the Middle” or MITM and it is very dangerous, because in some circumstances the attacker is able to capture encrypted data transferred over HTTPS tunnels. The success of an MITM attack depends on multiple factors, one of them is improperly configured web server. The attacker could exploit weakly configured SSL/TLS protocols and possibly intercept and decrypt over a secure connection. The only way to protect from an MITM attack is proper configuration of the webserver and Web Application Firewall (WAF).
Study Methodology
For the study we enumerated all known to us (as of December 23, 2015) Personal VPN Service providers and performed free SSL tests. Each VPN Service website was tested with free online “SSL Server Test” tools: one is High-Tech Bridge and the other is Qualsys.
Results of our study are provided in the table below, and scores rank from F to A+. Where F is the lowest score and A+ is the highest. Separate article about Worst VPN Providers will be provided later this month.
Provider | URL | HTB | Qualsys |
---|---|---|---|
VPNLand | Visit | A+ | A |
StrongVPN | Visit | A+ | A |
TunnelBear | Visit | A+ | A |
PureVPN | Visit | A+ | A |
Private Internet Access | Visit | A+ | A |
ExpressVPN | Visit | A+ | A+ |
ibVPN | Visit | F | F |
HideMyAss | Visit | A+ | B |
VyprVPN | Visit | A+ | A |
NordVPN | Visit | A+ | A |
VPN.AC | Visit | A+ | A+ |
CactusVPN | Visit | F | F |
SwitchVPN | Visit | B | C |
Kepard | Visit | A | A |
VPN.S | Visit | A+ | A |
Hide.Me | Visit | A+ | A+ |
LeVPN | Visit | A+ | A |
Internetz.me | Visit | A+ | A+ |
VPN Area | Visit | B | B |
Astrill VPN | https://www.astrill.com/ | A+ | A- |
Proxpn | www.proxpn.com | A- | B |
Boxpn | www.boxpn.com | A+ | A |
IronSocket | www.ironsocket.com | A+ | A |
VPNGate | www.vpngate.com | F | T |
CyberGhost | www.cyberghost.com | No SSL | No SSL |
LiquidVPN | www.liquidvpn.com | A+ | A |
TorGuard | https://torguard.net/ | A+ | A |
F-Secure Freedom | https:// www . f - secure . com / | A- | B |
PerfectPrivacy | https://www.perfect-privacy.com | A+ | A+ |
OverPlay | www.overplay.net | A+ | C |
BlackVPN | www.blackvpn.com | A+ | A |
VPN.ASIA | www.vpn.asia | A- | C |
ZPN | https://zpn.im/ | A+ | A- |
SlickVPN | www.slickvpn.com | A+ | A |
iPredator | www.ipredator.se | A+ | A+ |
VPNUnlimited | https://www.vpnunlimitedapp.com/ | A+ | A+ |
VPN Shield | https://www. vpnshield app.com/ | A- | B |
WiTopia | www.witopia.com | timeout | timeout |
PrivateVPN | www.privatevpn.com | A+ | A |
EarthVPN | Visit | A | A |
Buffered | www.buffered.com | A+ | A |
ZoogTV | www.zoogtv.com | A+ | A |
Trust.Zone | https://trust.zone/ | A+ | A |
Privatoria | https://privatoria.net/ | A- | B |
MyExpatNetwork | http://www.my-expat-network.com/ | A+ | A |
VPNTunnel | www.vpntunnel.com | F | C |
SurfEasy | www.surfeasy.com | A+ | A |
Tunnelr | www.tunnelr.com | A- | C |
FrootVPN | www.frootvpn.com | A+ | A |
Smart DNS Proxy | https://www. smartdnsproxy .com/ | A+ | A |
Blockless | www.blockless.com | A+ | A |
Disconnect | https://disconnect.me/ | A- | B |
NoLimitVPN | www.nolimitvpn.com | A+ | A |
AceVPN | www.acevpn.com | A+ | A |
VikingVPN | www.vikingvpn.com | A+ | A |
Proxy.Sh | https://proxy.sh/ | A | С |
TowerVPN | www.towervpn.com | F | F |
MyPrivateNetwork | https://www.my-private-network.co.uk/ | A+ | A |
Mullvad | https://www.mullvad.net | A+ | A+ |
AirVPN | https://airvpn.org/ | A+ | A+ |
HotspotShield | www.hotspotshield.com | F | F |
BolehVPN | https://bolehvpn.net/ | A+ | A |
UnblockUs | https://www.unblock-us.com/ | A+ | A |
HideIPVPN | www.hideipvpn.com | F | F |
ShadeYouVPN | www.shadeyouvpn.com | A | A |
WaselPro | www.waselpro.com | F | F |
CryptoStorm | https://cryptostorm.is/ | A+ | A |
WorldVPN | https://www.worldvpn.net/ | A+ | A |
GoTrusted | www.gotrusted.com | A | B |
BeeVPN | www.beevpn.com | C+ | C |
UkProxyServer | www.ukproxyserver.com | F | C |
OkayFreeedom | https://www.okayfreedom.com/en/ | A+ | A |
Anonine | www.anonine.com | F | C |
BTGuard | www.btguard.com | F | F |
VPN4All | www.vpn4all.com | F | C |
TvWhenAway | https://www.tvwhenaway.co.uk/ | A | A+ |
ExpatSurfer | https://www.expatsurfer.co.uk/ | A+ | A |
LibertyVPN | https://www.libertyvpn.net | C+ | F |
ClearVPN | http://clearvpn.net/ | No Cert | No Cert |
Faceless.me | https://faceless.me/ | F | C |
VPNJack | www.vpnjack.com | No Cert | No Cert |
MyVPN.Pro | http://www.myvpn.pro/ | No Cert | No Cert |
iVPN | https://www.ivpn.net/ | A+ | A+ |
TellyPortVPN | www.tellyportvpn.com | No Cert | No Cert |
iPinator | http://ipinator.com/ | B | B |
ZorroVPN | https://zorrovpn.com/ | A+ | A |
DoubleVPN | https://www.doublevpn.com/en/ | A+ | A |
Hideme.ru | http://hideme.ru/ | F | F |
AproVPN | http://aprovpn.com/ | A+ | A- |
HotVPN | http://www.hotvpn.com/ | F | F |
Cheap-VPN | http://www.cheap-vpn.com/ | F | C |
TheSafety.us | TheSafety.us | F | C |
ProstoVPN | http://prostovpn.org/ | No Cert | no cert |
CryptoVPN | https://www.cryptovpn.com/ | A+ | A |
WebmasterVPN | http://webmastervpn.com/ | F | C |
Safe-Inet | http://safe-inet.com/en/main | F | F |
V-P-N.RU | http://v-p-n.ru/ | F | cert mismatch |
Wafers.cc | http://wafers.cc/index/ru/ | F | cert mismatch |
Elite VPN Service | https://vpn-service.us/ | B | C |
Secretsline.biz | http://secretsline.biz/ | A+ | A |
Kebrum.com | https://en.kebrum.com/ | F | C |
http://pogodi.nu/ | http://pogodi.nu/ | No Cert | No Cert |
TrustVPN | http://trustvpn.info/ | A+ | A |
IPVanish | https://www.ipvanish.com | A+ | A |
ZenVPN | https://zenvpn.net/en/ | A+ | A+ |
BananaVPN | https://www.banana-vpn.com/ | C+ | F |
VPNAccounts.com | http://www.vpn-accounts.com/ | B | cert mismatch |
http://12vpn.com/ | https://12vpn.net/ | A+ | A+ |
https://www.securevpn.pro/eng/ | https://www.securevpn.pro/eng/ | F | C |
http://in-disguise.com/ | http://in-disguise.com/ | A+ | A |
Ivacy VPN | https://www.ivacy.com/ | A+ | A |