I've yet to see an example verifiable safe server configuration, but some people have claimed that SGX might do. I'm pretty sure that wouldn't work with stock OpenVPN or StrongSWAN today.
Are there any other practices they could adopt that would ease your worries?
Also why do you trust your VPS provider over a VPN provider? They can inspect your VMs memory and do whatever else they want to the machine. Same with whoever owns the real estate that you co-locate your own physical servers.
They simply don't have the resources to log every single memory read/write and every network connection of all their hosts. Thus you would have to already be a known target for them to want to do that. Whereas a VPN provider has a limited scope of what they can log and thus needs a fraction of the resources to log everything.
There are probably logging systems already in place to detect abuse, that would be extended to detect VPN style usage on top of that.
In general, though, if a three letter agency wanted to spy on interesting web traffic, the traffic of people who "have something to hide", then targeting VPN servers would be more fruitful than the general Internet.
Things that have irked me so far about their service:
- That their applications were not open-source so far. Why even sponsor open-source, when clearly you don't care for it too much yourself.
- Google Analytics on their webpage. Literally a service supposed to protect your IP address and the first thing they do when you dare to even look at their service, is tell the biggest data broker on the planet about it. (This is a problem with most VPN providers.)
- The company behind it, London Trust Media Inc., operates from the USA, putting it into one of the least privacy-friendly and least predictable jurisdictions on the planet.
- Their privacy policy isn't bad, aside from the aforementioned Google Analytics and that they use your e-mail address for promotional mails, but it's not good either. If you're so great on privacy anyways, then use your privacy policy to legally bind yourself to your standards and provide your customers with a service that has at least any kind of insurance of what it promises.
As for the US jurisdiction, I couldn't care less, being from Europe.
And well, you should care for the US jurisdiction, whether you're from Europe or anywhere else on the globe. It means that the various three-letter agencies there probably have access to your internet traffic.
Privacy-wise, you are right. I have all my data in Google so the key parts are already there.
Isn't this inherent to the model of a paid VPN service? (Could one run a VPN through a blockchain?)
You can encode any information you want on a blockchain, and it can be anonymous and specific to the user.
But it would be ///painfully/// slow.
you joke, but if you trust intel/arm, you can conceivably run a provably trusted (via remote attestation) VPN on SGX/TrustZone.