Using a virtual private network is a surefire way to keep your information private when browsing the internet. But a new report from Proton, released on Wednesday, exposes some major holes in that concept.
A VPN is a tool that encrypts your internet behavior and hides your IP address and physical location, with the goal of keeping your identity and identifying information secure. But 64 of the VPN apps downloaded in the US, Proton found, are owned by Chinese companies and contain trackers that collect all sorts of user information, including device IDs, network information, device models and mobile carrier data.
And 25% of the apps in question were found to actively track your location.
Data from millions of VPN users is going to China
In June alone, these apps were downloaded over 13 million times.
Narrowing down the numbers further, Proton found that 31 of those Chinese-owned VPNs use shell companies registered in jurisdictions such as Singapore, Hong Kong and the UK to further hide their identities.
An authoritarian government like China’s could use this information to track a person’s location. So if a public official, someone in law enforcement, a journalist or even someone attending a protest was using one of these VPNs for safety, this flaw would expose them to potential threats.
It should be clear that China isn’t the only country where companies harvest the data these apps collect, but it’s near the top of the list. Israel, Russia and the Five Eyes countries — Australia, Canada, New Zealand, the UK and the US — all have companies collecting tracking data from millions of people.
Stronger privacy guardrails are needed
Transparency is a big issue here, with a load of bad VPN apps being readily available for download through Apple and Google. Proton’s report points out that both companies require developers to submit their own paperwork to verify their apps, with little verification (and no independent audits) being done on Apple’s or Google’s part. Apple and Google didn’t immediately respond to requests for comment.
... continue reading