Skip to main content

Posts

Showing posts from February, 2018

Psiphon Completes Another Third Party Security Review

In late June 2017, Psiphon continued to prove its commitment to open source development (you can access our code repository here ), by commissioning Cure53 to perform a security audit of our services. The security review took 22 days and a total of 9 testers to complete what was described as a review with a “vast scope” and the Cure53 testers were very thorough. This is our 2nd security audit of this kind in 3 years (you can see the results of the 1st one, performed by iSec here ). The report’s description of what was included in the scope reads: “In scope were multiple components of the Psiphon software compound, including the tunnel-core client and server, the library glue, the Psiphon iOS app and, last but not least, the Psiphon iOS browser. This very broad premise and scope explain the necessity for involving a rather large number of testers with properly matched expertise in different arenas. In sum, the tests included code audits, actual penetration tests, protocol