ExpressVPN open-sources Lightway protocol and unveils security audit results

New Logo and Look
Ny logo och look för ExpressVPN. (Image credit: ExpressVPN)

Virtual private network provider ExpressVPN today announced the full public release of Lightway, its new custom VPN protocol. The company also unveiled what it called two new 'trust and transparency initiatives' for Lightway: the results of an independent security audit by cybersecurity experts Cure53 and the full open-sourcing of Lightway's code.

"Speed, performance, privacy, security, reliability—no one protocol had them all. That’s why we invested resources to build Lightway from the ground up for modern VPN needs. The two latest trust and transparency initiatives give us even more confidence to fully launch Lightway at scale...” said Harold Li, vice president, ExpressVPN.

The company backs up its words with some impressive Lightway stats. It claims tests show on average Lightway connects 2.5x faster than older protocols, improves reliability (that's few disconnections) by 40% and doubles speed. The protocol is also now available on all ExpressVPN's supported platforms: Android, iOS, Windows, Mac, Linux and routers.

Independent audit

In a welcome transparency move, ExpressVPN has released the results of a full Lightway source code audit (read more in the company's blog post) by Berlin-based penetration testers, Cure53.

In March 2021 the auditing team spent 22 person days working through the source code, using test binaries and talking to ExpressVPN. The final report lists its 'fourteen security-relevant discoveries', classifying five of these as security vulnerabilities, but none of those were critical. 

 The report conclusions raised some questions, but was broadly positive overall, saying the code is 'high quality', 'makes a relatively robust impression', and "the implementation should be good for production use..."

ExpressVPN patched the highlighted issues after the March 2021 audit, and Cure53 verified the fixes in a June 2021 follow-up. The full audit report is now available on Cure53's site.

Analysis

ExpressVPN has put itself through audits before, including a browser extension checkup in 2019 and a full no-log server audit by PricewaterhouseCoopers. But while they were important, the latest audit is something new.

Several other VPN providers have their own proprietary protocols, including Hotspot Shield's Catapult Hydra and NordVPN's Nordlynx. VPN protocols are absolutely key to your privacy and security, so it's vital they're properly implemented. But, unfortunately, there's no way to judge if this is true, because none of the other top proprietary protocols have been audited or open-sourced.

(Hotspot Shield has a support article stating "Catapult Hydra security code is evaluated by 3rd party security experts from more than 60% of the world’s largest security companies that use our SDK to provide VPN services to their users. That's not the same as looking at the source code, though, and being able to read exactly what those security experts think of the protocol's strengths and weaknesses.)

Put it all together and this looks like a great show of confidence by ExpressVPN. Will it persuade others to open up about their own protocol secrets? Watch this space.

  • We've also highlighted the best proxy service providers
TOPICS
Mike Williams
Lead security reviewer

Mike is a lead security reviewer at Future, where he stress-tests VPNs, antivirus and more to find out which services are sure to keep you safe, and which are best avoided. Mike began his career as a lead software developer in the engineering world, where his creations were used by big-name companies from Rolls Royce to British Nuclear Fuels and British Aerospace. The early PC viruses caught Mike's attention, and he developed an interest in analyzing malware, and learning the low-level technical details of how Windows and network security work under the hood.

Read more
ExpressVPN Lightway Protocol
ExpressVPN Lightway: Everything you need to know about the protocol
ExpressVPN Lightway protocol in Rust – promo image
ExpressVPN's latest upgrade to Lightway hopes to create "the VPN protocol of the future"
ExpressVPN's Lightway Turbo upgrade – promo image
Can fast be faster? ExpressVPN promises it’s possible
ExpressVPN apps running on a laptop and mobile during TechRadar's testing
What's new in Lightway 2.0? Here are the 4 biggest changes I'm excited for
Aircove router, smartphone and laptop with ExpressVPN app on screen on a wooden table
ExpressVPN's Aircove becomes the first device equipped with Lightway 2.0 – and the upgrades don't stop there
ExpressVPN Lightway Protocol
ExpressVPN upgrades to post-quantum encryption NIST standards
Latest in VPN Services
ExpressVPN's Lightway Turbo upgrade – promo image
Can fast be faster? ExpressVPN promises it’s possible
AdGuard VPN during TechRadar tests
AdGuard becomes the latest VPN to add post-quantum encryption
ExpressVPN's new Linux app interface
ExpressVPN releases a major upgrade to its Linux app
ExpressVPN apps running on a laptop and mobile during TechRadar's testing
What's new in Lightway 2.0? Here are the 4 biggest changes I'm excited for
A VPN running on a mobile device
A new era for VPN testing? ATMSO publishes the first-ever testing standards in an "important milestone"
Aircove router, smartphone and laptop with ExpressVPN app on screen on a wooden table
ExpressVPN's Aircove becomes the first device equipped with Lightway 2.0 – and the upgrades don't stop there
Latest in News
A close up of Captain America with Thor and Hulk in the background during the Assemble scene in Avengers: Endgame
'We will draw inspiration': Joe and Anthony Russo reveal which of Marvel's Secret Wars comic book series have influenced Avengers 5 and 6's plot
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
An AMD Radeon RX 9070 XT made by Sapphire on a table with its retail packaging
Want to buy an RX 9070 or 9070 XT but fed up of the GPUs being out of stock? AMD promises that “more supply is coming ASAP”
Cece Carroway (Sara Silva), Caroline Merteuil (Sarah Catherine Hook), and Lucien Belmont (Zac Burgess) in Cruel Intentions.
Cruel Intentions has been canceled after one season on Prime Video, but I'm not surprised by its cruel fate
iOS 18 Control Center
iOS 19: the 3 biggest rumors so far, and what I want to see
Doom: The Dark Ages
Doom: The Dark Ages' director confirms DLC is in the works and says the game won't end the way 2016's Doom begins: 'If we took it all the way to that point, then that would mean that we couldn't tell any more medieval stories'