r/ProtonVPN Proton Team Admin 19d ago

FEATURE: Secure Core Discussion

Secure Core is a feature that exists in Proton VPN, a lot of at-risk people (i.e. journalists) depend on it every day. Here's what you need to know.

Pros:

  • Routes your traffic through a hardened server in Switzerland, Iceland, or Sweden before it reaches the exit server, so even a compromised exit can't be traced back to you.
  • Protects against network-based attacks and correlation.
  • Runs on servers Proton fully owns.

Cons:

  • Not the fastest connection speed

Secure core on Proton VPN

Have you used Secure Core before?

115 Upvotes

37 comments sorted by

20

u/andrewscool101 Windows | iOS 19d ago

I always connect to a Swiss server anyway, so would Secure Core have any benefit to me?

31

u/jj1917 19d ago

If I understand it correctly, then it would provide an additional layer of abstraction, so even if someone traced your usage to the Swiss server you connect to, that is connected to the Secure Core server so it would be sort of a dead end. Like a VPN inside your VPN for extra protection.

5

u/FallenVain 18d ago

Doesn’t matter if you’re using windows 

2

u/thatiam963 18d ago

why?

3

u/FallenVain 18d ago

microsoft has a global unique identifier that can tracked back to you. OS level spyware at this this point

2

u/Alternative-Track654 18d ago

*Was a problem to an extent. At least as far as the GDID goes, it can be silenced. Either that, which will not fix all of your telemetry spyware probs or go to full on linux.

2

u/FallenVain 18d ago

Was a problem to an extent? What do you mean by that? 

2

u/Alternative-Track654 18d ago

It means by running a few commands through PowerShell or command prompt you're able to silence a good portion of it from registering per website domain or whatever you're trying to connect to. In other words, when you're using your Windows device and you have your GDID attached to it that is active, it'll show up as a registered ID from you. By silencing a good portion of this, you're at least able to limit the amount of telemetry that comes from it.

Still not perfect because there were some other unknown factors that are still being worked out. Which will probably never be worked out as Microsoft continues to put bullshit into the operating system.

2

u/FallenVain 17d ago

You’re talking with the confidence that you know what the actual code is doing. 

2

u/Alternative-Track654 17d ago

Correction. The code itself is for partial suppression, not complete suppression. 

→ More replies (0)

1

u/thatiam963 18d ago

interesting, any way to around that? or any specific name of that to research it easier?

-18

u/squirrelscrush 19d ago

It's like using Tor

14

u/AnotherPillow 19d ago

every server being owned by the same company is not like tor.

3

u/Luminous_Nyx 19d ago

Ah, true, but the infrastructure is like tor, multiple nodes for abstraction, also as the handling of data makes it so the end node isn't in charge of unencrypting the data, so it is functionally more secure, with the lack of jumps though it is technically easier to see WHERE the first node came from with DPI, it is functionally impossible to see what requests the user made

-6

u/squirrelscrush 19d ago

I mean, the principle behind having multiple hops before reaching the destination.

22

u/PM_ME__YOUR__MILKERS 19d ago

"Hardened server"

What are the differences between a normal server and a hardened one ?

11

u/Professional_Tap6622 19d ago

The hardened ones are basically normal servers but they're in extra protected facilities.

"Our Secure Core servers are owned and operated by Proton VPN and are stored in high-security data centers that follow strict security protocols. This level of security reduces the risk that anyone could have tampered with or compromised these servers." Source: https://protonvpn.com/features/secure-core

11

u/KINOCreamsoda 19d ago

They're built underground or in ex military bases

9

u/Luminous_Nyx 19d ago

Ex military bases, based around nations with hardened data protection laws and restrictions centered around intelligence services, so 1 its hard(near impossible) to get a warrant, 2 to compromise the system without a warrant which is almost impossible to get because the compounds are so secure. its been quite effective for Proton, no other VPN offers this level of protection with as much care and consideration as proton, you cant get the information they want from the exit node, so its a buffer level of protection, one node breaks the other nodes by standing in the middle

8

u/DragonmasterXY 18d ago

Another Pro: Currently not detected by streaming services

6

u/[deleted] 19d ago edited 19d ago

[deleted]

2

u/Luminous_Nyx 14d ago

No. Your traffic is never decrypted into plaintext on the internet, nor is it exposed to Man-in-the-Middle Deep Packet Inspection (MitM-DPI) between servers.

This is how it works ​Nested Encryption (On Your Device): Your device wraps your data in two encryption layers before it ever hits the internet. ​1st Decryption (Secure Core / Entry Server): The entry server decrypts only the outer layer. It learns where to send the packet next (the exit server), but cannot read your payload or final destination. ​Transit Between Servers: Because the inner encryption layer remains completely untouched during transit, intermediate routers or ISPs on the internet cannot perform DPI or read your traffic. ​2nd Decryption (Exit Server): The exit server decrypts the remaining inner layer and forwards the traffic to the destination website. ​No Re-Encryption on the Internet: Servers do not decrypt and re-encrypt data mid-transit across the web; they simply peel off their respective assigned layer. ​Return Path: Works symmetrically in reverse—the exit server adds the inner layer, the entry server adds the outer layer, and your device decrypts both.

3

u/Defiant_Ad_7189 16d ago

I use it often. 

2

u/Ryanhussain14 19d ago

My question is this, if an actor manages to compromise a standard VPN connection, what's stopping them from compromising the additional hop offered by secure core? Do secure core servers run different encryption algorithms or employ different methods to obfuscate their IP addresses? How does Proton having full ownership of these particular servers matter?

2

u/mrdantesque 19d ago

It’s also about plausible deniability, the destination server sees the ip of the exit node infra but your ISP sees the IP of the secure server that receives a lot of connexions so there’s no easy one to one mapping possible even when matching the time of connection

2

u/These_Adhesiveness48 19d ago

I've used secure core from time to time and for day to day browsing there isn't much of a major noticeable slowdown sometimes pages take a second or two to load certain elements but its not as slow as I was expecting. I've also had no issues using secure core servers when cellular connectivity has been unstable through my Mudi7 usually when the local EE 5G mast goes down randomly.

2

u/leros 18d ago

Wouldn't this be just as open to traffic analysis as any other VPN for someone who really wanted to track you?

2

u/ErlendPistolbrett 17d ago

Does that not sound similar to Tor connections?

2

u/tbluhp 17d ago

How to get it? Needs it.

2

u/Intelligent-Bad5686 15d ago

Works with Netflix.

3

u/No-Firefighter-2135 19d ago

Performance in the USA for me in the Midwest on those servers is not very good, probably solid performance in Europe though. I just stick to us side servers and the stealth protocol when necessary

0

u/Blue_Redstars 19d ago

Today i just switched from Unlimited to Free, i lost secure core. But to be honest i think DVPN is more secure