Your China VPN might not be as safe as you think, especially if itβs ExpressVPN or Astrill (UPDATED)

UPDATE 2/15: ExpressVPN has upgraded its OpenVPN CA certificate strength from 1024-bit to 4096-bit. βThis upgrade to 4096-bit makes ExpressVPN best in class for OpenVPN,β a rep told Tech in Asia.
If you live in China and youβre reading this website, chances are youβve got a VPN. Itβs a virtual necessity for anyone who likes to browse the English-language internet in the Middle Kingdom because so many popular English-language sites are blocked by the Great Firewall. And at least in theory, using a VPN also keeps your connection safe from government snooping, since all of the data youβre sending and receiving is encrypted. But a recent blog post from former Google information security engineer Marc Bevand has raised some interesting questions about just how secure your VPN really is.
Bevand, who is currently traveling the world with his wife, did some experimenting with the Great Firewall while he was in China, and made an interesting discovery. When he used ExpressVPN β a popular commercial VPN service β he discovered that it did let him jump the Great Firewall, but it only used a 1024-bit RSA key to encrypt his connection. Thatβs weak enough encryption that the Chinese government could be listening in on ExpressVPN usersβs web traffic.
Tech in Asia contacted ExpressVPN for comment about this story last week, but never received a reply. Separately, Tech in Asia also discovered that VPN provider Astrill also uses a 1024-bit RSA key. UPDATE 2/15: Since this article was published, ExpressVPN has updated its OpenVPN CA RSA key to 4096-bit.
Bevand told Tech in Asia that RSA keys work essentially like a padlock and its key, with a public key (padlock) and private key (key) used to encrypt web data. The private key will be the factors of the public key, meaning that the data can be decrypted if you can figure out the factors of the public key. And with a key of just 1024 bits, Bevand says, the government could well be decrypting ExpressVPNβs traffic. It would require expensive computing equipment, but itβs probably possible. Thatβs why, Bevand says, a key of 2048 bits β double the size of Astrill and ExpressVPNβs keys β βis the minimum size recommended by most governmental, academic, and private organizations providing guidance on cryptographic security.β
βNo one in the InfoSec industry should use 1024-bit RSA keys anymore,β he said. βThis is irresponsible.β
Bevand also pointed out that from a technical standpoint, there are a number of ways Chinaβs government could block access to ExpressVPN and other VPNs that allow people to evade its censorship. So why isnβt it doing that? Bevand proposes one chilling possibility in his blog post:
One possible explanation could be that the Chinese government did factor the ExpressVPN root CA key and does spy on the network traffic of their users, but they prefer to not interfere with ExpressVPN in order to give their users a false sense of privacy. If China blocked the service, users would migrate to other more secure VPN services, and China would lose a SIGINT ability.
In other words: maybe China isnβt blocking your VPN because it isnβt trying to. Maybe it would rather just listen in on your conversationsβ¦and maybe it already has the power to do that.
Stay updated on the go with our mobile app.
Get latest insights with smoother, more personalized experience through TIA mobile app.




