New research from High-Tech Bridge found 90 percent of all SSL VPN servers are hopelessly insecure The firm scanned more than 10,000 publicly available virtual private network (VPN) servers for common vulnerabilities. Over 40 percent of servers use 1024-bit keys for RSA certificates, considered much less secure than their 2048-bit cousins. Three out of four VPNs relied on untrusted SSL certificates, making it possible for attackers to launch man-in-the-middle (MitM) attacks. 10 percent of VPNs scanned are still using versions of OpenSSL vulnerable to Heartbleed.”]

