We all know the benefits of using a VPN, but their security is only as solid as the provider’s honesty. With that in mind, how robust are the mobile VPN apps for Android? According to a team of researchers from four international institutions, we must be very careful. In addition to leaving the user unprotected, some of them are using malware to track their activity, they request excessive permissions, and intercept TLS traffic, among other things.

Android VPN Apps Are Insecure
VPN

When a piece of software does not do what it promises and goes in the exact opposite direction, it is one of the greatest betrayals a user can suffer. We deposit our digital lives in those applications, but there are many unscrupulous elements out there that disguise themselves as protectors, when in reality they are the opposite. One of the most striking examples is what happens with VPN apps for Android. Google released version 4.0 Ice Cream Sandwich in October 2011, and several developers took advantage of the native VPN module in the operating system to create clients. If they had done a good job, we would probably be recommending one of them, but according to a study carried out by the Australian CSIRO, the University of New South Wales, the American ICSI, and the University of California, Berkeley, we need to keep the greatest possible distance from these apps.

Android VPN Apps Are Insecure
Ridiculous permissions, integrated trackers, VirusTotal alerts... What kind of VPN are these?

Out of a total of 283 VPN applications analyzed, more than a third (38 percent to be exact) showed at least one positive identification of malware, whether Trojans, adware, or spyware. 67 percent claim to offer security mechanisms on par with a traditional VPN, but the truth is that 75 percent of that 67 have an integrated tracker developed by a third party. To that we must add that 82 percent request permissions to access private material, such as user accounts and text messages. Wait, it gets worse: 18 percent of the apps do not apply any kind of encryption. 84 percent do not pass IPv6 traffic through their tunnels, and 66 percent commit the same infraction with DNS traffic. 18 percent do not inform the user about the entity responsible for hosting the VPN server, and 16 percent basically resort to P2P in order to redirect traffic among their users.

Unfortunately, the study does not include the complete list of applications processed, but it gives us enough information to conclude that the vast majority of them are not worth it. Another suggestion from the researchers is that Google needs to re-evaluate its VPN permissions model, since it puts users at risk. Some of the apps record more than a million downloads in the store...

Access the study: