Freedome VPN encryption

Scholar

Freedome VPN encryption

Hi,

 

just wanted to ask which cipher suite is used for the encryption of the VPN.

 

Best regards,

Cryptoman

1 ACCEPTED SOLUTION

Accepted Solutions
Former F-Secure Employee

Re: Freedome VPN encryption

An update: This response concerns our Freedome clients for Android only.

 

Hello,

 

I'm sorry for the delay with our response. It has just been a busy week with some sick leaves, no intention to hide the information.

 

Control channel: TLS, 2048 bit RSA auth, typically AES256+SHA1 HMAC but depends on client capabilities
Data channel: Blowfish with 128-bit key + SHA1 HMAC

 

For data channel we're about to switch to AES-128 instead of Blowfish.

 

Best regards,

Päivi, Freedome product manager

15 REPLIES 15
Scholar

Re: Freedome VPN encryption

Hi again,

 

I noticed that the User psillanp has asked some questions a few days ago which have still not been answered yet (technical specs).

 

Is the information about the used cipher suite in Freedome really that mega-classified and ultra-top-secret?!

 

I believe that users would feel much more comfortable with Freedome if you would reveal at least the used cipher suite (as there are a lot of weak cipher suites available, e.g. RC4)...

 

Cheers,

Cryptoman

Advocate

Re: Freedome VPN encryption

I'm curious too and I've searched Knowledge Base and everywhere else without luck. My guess is because Freedome is quite a new product everything isn't updated in the KB (yet).

 

As a comparison they have a detailed description in the KB of the encryption for the Password Manager "F-Secure Key", so I don't think they intend to keep it a secret:

http://community.f-secure.com/t5/F-Secure-Key-KB/F-Secure-Key-data-encryption-in/ta-p/36851

Scholar

Re: Freedome VPN encryption

Come on, no official info from the F-Secure staff?

Former F-Secure Employee

Re: Freedome VPN encryption

An update: This response concerns our Freedome clients for Android only.

 

Hello,

 

I'm sorry for the delay with our response. It has just been a busy week with some sick leaves, no intention to hide the information.

 

Control channel: TLS, 2048 bit RSA auth, typically AES256+SHA1 HMAC but depends on client capabilities
Data channel: Blowfish with 128-bit key + SHA1 HMAC

 

For data channel we're about to switch to AES-128 instead of Blowfish.

 

Best regards,

Päivi, Freedome product manager

Scholar

Re: Freedome VPN encryption

Thank you for your response, Paivi Smiley Happy

 

Is there a plan when AES-128 will exactly be ready for the data channel?

Former F-Secure Employee

Re: Freedome VPN encryption

We're getting ready for the migration, support for AES is already deployed on our gateways. Migration likely happens in June.

Scholar

Re: Freedome VPN encryption

Hi Paivi,

 

just wanted to ask if the migration from Blowfish to AES for the data channel has been completed.

 

Best regards,

Cryptoman

Highlighted
F-Secure

Re: Freedome VPN encryption


@Cryptoman wrote:

 

just wanted to ask if the migration from Blowfish to AES for the data channel has been completed.

 

New gateway sites deployed recently (Canada, Spain, Netherlands, Italy) already use AES for data encryption from the beginning. We'll also have a new US East Coast site set up soon, with the new VPN parameters.

 

We're still waiting for a bit more of the old Android clients to get upgraded to support a smooth transition to the new crypto settings on the existing older sites. We found an issue where the client did not figure out the new settings quickly enough on a site which switched VPN parameters, and was left in an unhappy state for quite a while. An updated Android client has already been released a while back, but it takes time before a good percentage of users have upgraded.

 

Clients which are able to use UDP for the VPN connection are easy, since we support old and new parameter sets on different UDP ports to support the old clients through a transition period, but many clients behind various firewalls are only able to make a VPN connection on TCP port 443, and we'll just have to switch that one to the new parameters at some point.

Aspirant

Re: Freedome VPN encryption

Will there be possible to customize the Freedome encryption settings like you can in openvpn software for windows?

 

Im looking for maximum security similar to these settings:

 

Data encryption: AES-256

Data authentication: SHA256

Handshake: RSA-4096