-
TrustedServer: Deep dive into the security of our server tech
This article is written by Shaun Smith, an engineering fellow at ExpressVPN and the creator of TrustedServer. In this article, we’re taking a deep dive into TrustedServer, our industry-leading V...
-
Dev blog: A look inside Lightway
VPN protocols define how a client and a server authenticate each other, establish a connection, and transmit data through the created tunnel. Plenty of VPN protocols are available, each made for its o...
-
ExpressVPN leak testing tools
The ExpressVPN Leak Testing Tools are an extensible suite of Python tools designed for both manual and automated leak testing of VPN applications. Developed by ExpressVPN security researchers, the too...
-
How ExpressVPN keeps its web servers patched and secure
This article explains ExpressVPN’s approach to security patch management for the infrastructure running the ExpressVPN website (not the VPN servers). In general, our approach to security is: Make s...
-
How to use Ansible Variables and Vaults
This post was originally published on July 17, 2017. How we use Ansible extensively at ExpressVPN Our development teams work independently, that is to say, a team owns their product for its full life ...
-
How ExpressVPN authenticates its apps
This post was originally published on June 9, 2017. How do ExpressVPN servers know which app belongs to a customer and which does not? On most apps, the authentication happens in the background. Once ...
-
The facts about the OSTIF OpenVPN source code audit
This post was originally published on May 15, 2017. With funding from the Open Source Technology Improvement Fund (OSTIF), a group of security experts from QuarksLab spent the first few months of 2017...
-
How ExpressVPN apps confirm they’re talking to ExpressVPN servers
This post was originally published on December 7, 2016. When you connect to a VPN, have you ever wondered if you’re connecting to a genuine VPN server? What if a third party---like a government, ISP...
-
ExpressVPN and Heartbleed
This post was originally published on April 13, 2014. We'd like to give some more insight into how we dealt with the Heartbleed security bug that affected most of the Internet last week. The key point...