Hacker News new | past | comments | ask | show | jobs | submit login

Can you explain further, how can you be sure things weren't aded to the software?



When you use a VPN service that supports openvpn, you:

a) Install OpenVPN yourself (open source)

b) Download an OpenVPN profile from the VPN company

c) Configure OpenVPN with the profile

Specifically, you don't have to install any binary software from the company itself.


To the client side or the server side? On the client side, you should download the code from a location you trust. On the server side, it is irrelevant if something is added to the software for the attack we are discussing.


You can use your own OpenVPN client.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: