Open source (and can therefore be readily vetted for back doors and other NSA style tampering).
Although a man-in-the-middle attacker can reset the TCP connection between an OpenSSH client and an OpenSSH server (which does not support roaming it cannot exploit the information leak without breaking server host authentication or integrity protection. OpenVPN has become the default VPN connection type, and while natively supported by no platform, is widely supported on most through third party software (including both iOS and Android). The information leak is exploitable in the default configuration of the OpenSSH client, and (depending on the client's version, compiler, and operating system) allows a malicious SSH server to steal the client's private keys. Moreover, these non-interactive SSH commands (for example, backup scripts and cron jobs) commonly employ public-key authentication and are therefore perfect targets for this information leak. Using this exploit, pptp has been cracked within 2 days, and although Microsoft has patched the flaw (through the use of peap authentication it has itself issued a recommendation that VPN users should use L2TP/IPsec or sstp instead. Adhrit is an open source Android APK ripping tool that does a basic recon on the provided APK file and extracts important imformation.

Usually considered very secure but see cons.
Easy to set up, available on all modern platforms Cons.
Many VPN providers get around this configuration problem by supplying customized VPN clients. OpenVPN is a fairly new open source technology that uses the OpenSSL library and SSLv3/TLSv1 protocols, along with an amalgam of other technologies, to provide a strong and reliable VPN solution.