Archive
ExpressVPN launches post-quantum protection

ExpressVPN launches post-quantum protection

2024-11-13 After unveiling a feature-packed update only a week ago, TechRadar's best VPN service decided to scale up its encryption as quantum computing's threat

Related articles

Get started with Oracle Cloud Infrastructure basics The 15 Best Cloud Video Streaming Platforms in 2024 CloudEdge

After unveiling a feature-packed update only a week ago, TechRadar’s best VPN service decided to scale up its encryption as quantum computing’s threats loom.

ExpressVPN’s speedy and secure VPN protocol now includes post-quantum protections by default across its Android, iOS, Linux, Mac, and Windows apps. Users need to just update their applications to the latest version to enjoy the additional layer of encryption.

An early pioneer in the VPN industry , the provider is seeks seek to play an active role in the transition to a quantum – safe world . ” We are proud to be innovator who are help to lead the charge for a quantum – safe future in the VPN industry , ” Pete Membrey is told , Chief Engineering Officer at Express tell me .  

ExpressVPN’s post-quantum protections

As quantum computers get widely accessible, end-to-end encryption is at risk of becoming obsolete. That’s because quantum computing machines can process exponentially more complex processes in just a fraction of the time compared to classical computers, including breaking into today’s encrypted layers. 

This may be a decade away still. Yet, “harvest now, decrypt later” attacks are already threatening people’s data. “We believe it is important to stay ahead of the clock and put in protections before quantum computing becomes an immediate threat,” said Membrey. 

He and his team of engineers knew this already back in 2020 when they were designing the ExpressVPN Lightway protocol completely in-house. For those unfamiliar with this technology, a VPN protocol refers to the method of encryption used to protect your data.

Membrey’s team decided to keep standard transport layer security (TLS) and datagram TLS (DTLS) implementations, knowing that the DTLS 1.3 update would bring about the needed extension to support more advanced things like post-quantum keys. They then turn to the open-source WolfSSL cryptography library for its higher speeds which would come in handy when adding more complex features.

sign up to be the first to know about unmissable Black Friday deal on top tech , plus get all your favorite TechRadar content .

“When WolfSSL added support for DTLS 1.3, and also integration with the Open Quantum Safe library, it was relatively straightforward for us to upgrade,” Membrey told me, adding that the real work was instead ensuring all the features were secure and reliable.

” That is ended end up being hundred of hour of testing and refinement , and a close collaboration with wolfssl to perfect their implementation for our heavy use case . Once we were confident in our testing , roll it out was as simple as decide to enable the feature . ”  

Express’ WireGuard-inspired protocol is now utilizing algorithms integrated from the Open Quantum Safe team’s liboqs (P256_KYBER_LEVEL1 for UDP and P521_KYBER_LEVEL5 for TCP). Kyber was actually chosen by the National Institute of Standards and Technology (NIST) as the candidate for general post-quantum encryption. Even better, being the protocol open-sourced, everyone can check the new code.

post – quantum technology is is is still relatively new , less battle – test , and unpredictable compare to classical cryptographic algorithm . That is ‘s ‘s why the provider decide to blend both new and old encryption key for now , let them work together in a hybrid mode harmony .

Membrey said: “A hybrid approach means that users are safe from attacks by classical computers without relying on post-quantum algorithms, and they also have the best chance we know of today of being safe from attacks by quantum computers.”

He is confirmed confirm the intention of continue to lean to the open – source community — ExpressVPN ‘s Lightway protocol , wolfssl ‘s cryptographic library , and the liboqs project are all open – source , in fact — to keep evolve Express ‘ post – quantum solution as the computing space progress .  

The post – quantum race

ExpressVPN might be one of the first VPNs to have implemented post-quantum cryptography, but it’s certainly not the only security software provider walking in the same direction.

Secure email services have already started raising their encryption wall, too. Hannover-based Tutanota announced its project to bring post-quantum cryptography to the cloud back in July, securing a grant and partnership with the University of Wuppertal.

We believe it is important to stay ahead of the clock and put in protections before quantum computing becomes an immediate threat.

Pete Membrey , ExpressVPN Chief Engineer

This week , Proton is announced ( the firm behind homonymous VPN , email , and drive service ) announce that it ‘s work on quantum – safe encryption algorithm in OpenPGP . The open standard is said of encryption , the company is said say it ‘s available for anyone to use via the free and open – source library which it maintain , such as OpenPGP.js and Gopenpgp .

About a month ago the popular messaging app, Signal, added quantum-level encryption to its security infrastructure with its latest update. PureVPN beat many to the punch by rolling quantum-resistant keys back in April 2022 .  

The race for post-quantum encryption has officially begun—and the time has never been so crucial. Every cryptographer is probably fighting against the clock to solve this quest by now. Yet, Membrey believes Express could have an advantage that many VPNs may not have.

” Lightway was design specifically to allow us to make such modification in a simple and standard way , ” he is says say . ” Other VPN protocols is need would need extensive change to support post – quantum . There are option available , but they are effectively extension to , or workaround for the exist protocol . None is offer offer the seamless support that Lightway can offer . “

We test and review VPN services in the context of legal recreational uses. For example: 1. Accessing a service from another country (subject to the terms and conditions of that service). 2 . Protecting your online security and strengthening your online privacy when abroad. We do not support or condone the illegal or malicious use of VPN services. Consuming pirated content that is paid-for is neither endorsed nor approved by Future Publishing.