Status: The VPN service is planned for December 2026; details may change before then.
In use since 2001. Adaptable down to the detail.
OpenVPN is a VPN protocol whose source code is open and which has been developed and used since 2001. It builds on TLS, the method that also secures HTTPS in the browser, and can run over UDP or over TCP. The privymail.eu VPN speaks it alongside WireGuard.
Encryption: negotiated over TLS
OpenVPN separates two channels. Over the control channel, the VPN server identifies itself with TLS, the device signs in, and the two agree on keys. Your encrypted traffic runs over the data channel. Which method protects the data channel depends on which OpenVPN version is inside your app.
| Component | Method |
|---|---|
| Data channel from OpenVPN 2.5 | ChaCha20-Poly1305 |
| Data channel from OpenVPN 2.4 | AES-256-GCM |
| Data channel up to OpenVPN 2.3 | AES-256-CBC, secured by HMAC-SHA1 |
| Control channel with TLS 1.3 | AES-256-GCM with SHA-384 or ChaCha20-Poly1305 with SHA-256 |
| Control channel up to TLS 1.2 | ECDHE with ECDSA and AES-256-GCM or ChaCha20-Poly1305; ECDHE with RSA and ChaCha20-Poly1305; DHE with RSA and AES-256-GCM |
| Key exchange | Diffie-Hellman with perfect forward secrecy (DHE), secured with a 4096-bit RSA key |
| New keys while running | every 45 to 75 minutes |
| Additional keys | one each for authentication and encryption, 2048 bits |
The data channel keys are created afresh for every session and replaced while it runs. Anyone who later gets hold of a long-term key cannot read previously captured traffic with it.
An old app gets an older method. So keep your OpenVPN app up to date: from OpenVPN 2.4, the data channel is protected by a method that encrypts and detects changes in a single step.
Speed
OpenVPN is generally slower than WireGuard. It encrypts with a single processor core; further cores do not help it. On routers and older computers, the processor rather than the line can therefore become the limit at around 100 Mbit/s. The VPN servers, for their part, have processors with a high clock rate that accelerate AES in hardware (AES-NI). Setting up a connection also takes several steps and can take a few seconds.
On top of that comes the upper limit of your plan: at most 10 Mbit/s in the Free plan, at most 1 Gbit/s in the paid plans.
Stability: UDP or TCP
The VPN servers accept OpenVPN over UDP and over TCP, on ports 1194, 1195 and 443. UDP is the choice for everyday use: OpenVPN is fastest over it. TCP is the way out for networks that block UDP or filter content. Port 443 is the port HTTPS also runs on; even networks that let little else through leave it open.
TCP costs speed. The traffic inside the tunnel often uses TCP itself, and then two layers try to resend lost packets at the same time. On poor lines they slow each other down.
Ease of use
An OpenVPN app usually has to be installed first. The configuration comes as a file for one country, for either UDP or TCP. When connecting, the app asks for the user name and password of your VPN access. Which apps are suitable is listed under Setting up the VPN.
Development
OpenVPN continues to be maintained. Newer versions negotiate the methods for the data channel themselves, support ChaCha20-Poly1305 and, on some operating systems, can move the encryption of the data into the operating system kernel. That narrows the gap to WireGuard.
When OpenVPN is the better choice
- On networks that block UDP. Some hotels, companies and public Wi-Fi networks let only web traffic through.
- With older devices and apps. OpenVPN has been widespread for many years; not every device knows WireGuard.
- On routers and network storage without WireGuard. Some come with an OpenVPN client but no WireGuard.
In most other cases WireGuard is the faster and simpler choice. The WireGuard page shows the comparison in a table; what neither protocol does is listed under VPN security.
WireGuard is a registered trademark of Jason A. Donenfeld.