Skip to content

Leadership1 publisher3 min readPublished

More than half the Windows VPN apps in a TechRadar audit shipped year-old open source code

Writing in Forbes, OpenVPN chief executive Francis Dinha names Turbo VPN and VyprVPN among providers found on a 2019 build and puts the exposure in what vendors did with the code after they took it.

The Board Room · Leadership desk

Illustration accompanying More than half the Windows VPN apps in a TechRadar audit shipped year-old open source code

What happened

  • OpenVPN CEO Francis Dinha, writing in Forbes, reported that a TechRadar audit of Windows VPN applications found more than half the apps examined running open source code more than a year out of date.
  • Turbo VPN and VyprVPN, both built on the OpenVPN open source protocol, were among the providers the audit found running a version of it dating from 2019.
  • GitHub's Secure Open Source Fund reported that participating projects resolved more than 4,000 CodeQL security alerts and blocked over 100 exposed secrets in a single six-month period.
  • Black Duck's 2026 report, drawn from audits of nearly 1,000 commercial codebases, found the average number of open source vulnerabilities embedded in an application rose 107% year over year.

Compiled by The Board RoomSomething wrong?How this is made

Why it matters

  • decision Component version and release date is one of the few vendor security claims a buyer can test without the vendor's cooperation, which puts it in a different diligence tier from pen-test summaries and bounty programs.
  • constraint A current version number still does not prove the shipped binary came from the published source, so signed releases and bills of materials set the ceiling on what open code lets a customer verify.
  • exposure The customer of a vendor pinned to an old build carries every flaw fixed upstream since; the project's patch record does nothing for a network running the stale binary.
  • contradiction The finding reaches operators through the chief executive of the project those vendors depend on, whose interest lies in locating fault downstream, and the sample size behind it is not in the column.

Neglect of this kind is rarely a decision anyone makes twice. The library works, and upgrading a network protocol dependency means requalifying a product that already passes its tests. Francis Dinha, the CEO and cofounder of OpenVPN Inc., wrote that "OpenVPN itself has continued to patch, harden and improve its codebase in the years since" [4]. He put the problem in "what individual vendors chose to do or not do with it downstream" [5].

The case against publishing code, in the version Dinha quotes, came from a technology CEO who told a reporter for ZDNet that "open-source code is basically like handing out the blueprint to a bank vault" [6]. Dinha's answer is that closed source does not eliminate vulnerabilities but narrows the population able to find them before an attacker does [7]. That leaves a customer "evaluating a vendor's account of its own security rather than the security itself" [8]. He is not a disinterested party. He sells enterprise network security software built on the same project the lagging vendors took their protocol from [1].

The audit makes his point on its own terms. Between the 2019 version and the column's publication in September 2026 sit seven years of published fixes. An attacker could read them straight out of the upstream repository and compare them against what those vendors were shipping [14].

Buying software built on a published component gives a buyer one question with a checkable answer: which version ships, and when was it released. A closed product does not offer that question at all. What the open answer costs is a dependency on the vendor's release discipline, and in this sample most of them lacked it.

The same column also says where the version question stops. A customer can read every line of a public repository and still have no guarantee the binary on their server was built from that code. Closing the gap takes signed releases, software bills of materials, reproducible builds and cryptographic attestations, verified continuously [11]. A version string and its release date can come out of a supplier in a week. Attestation across a whole dependency tree takes years.

The Open Secure AI Alliance has said AI can audit a codebase and surface critical vulnerabilities in minutes, work that used to take skilled researchers weeks [9]. The same tooling raises the volume being reviewed. Black Duck attributed much of its 107% rise to the amount of code AI tools now let developers produce [12][15]. That leaves the average application at about 2.07 times its prior-year count of embedded open source vulnerabilities.

The audit reaches operators secondhand. Dinha's column omits the number of Windows VPN apps examined and any response from Turbo VPN or VyprVPN [16]. It does not establish what either provider ships now. It does support putting a dependency-currency question in the diligence pack.

What to watch

  • Whether TechRadar publishes the audit's sample size and per-app version data, which would let buyers name specific builds.
  • Whether Turbo VPN or VyprVPN ships an updated OpenVPN build or answers the finding.
  • Whether Black Duck's next report separates AI-generated code from other drivers of the per-application vulnerability count.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories