I'm looking at Mullvad and NordVPN. I know Nord had a MITM attack on a Finnish datacenter a few months ago and didn't immediately notify affected users. I'm having trouble understanding what it says about Nord's culture and likely behavior in the future. On a technical level, it's pretty bad when users of a VPN like this can be MITM'd. Blaming the datacenter's remote admin tools doesn't help me as a user because the same thing could happen again. I know they have a bug bounty program and audits now, but still I'm concerned that they didn't notify people which might indicate a cultural problem.
How would Nord handle a problem like this in the future, and can we still trust them?
It's just that one wonders whether the people whose devices are being used as proxies are aware of the situation.
They are seemingly sketchily using "residential proxies" at least for Disney+. These proxies seem to be coming from their customers, or customers of a company NordVPN is closely tied to - likely without their knowledge.
When your business is privacy and trust, any acquisition is problematic. Let alone an acquisition from a company with a similar track record.
They're among the oldest VPN services. Not as old as Cryptohippie, but almost.
Personally I'm using Mullvad atm. For windows I use their client, but you can also download configuration files for wireguard if you want to do that.
Also, using a private VPN proxy, you're the only user. So there's even less anonymity than using a VPN service.
The safest bet is arguably Tor. Although the connection to the US government is troubling. And then there's the issue that many sites block Tor users with difficult or impossible CAPTCHAs.
Using nested VPN chains is a reasonable compromise. It's much faster than Tor, and you don't need to trust any one VPN provider.
Tor is not operated by the US government; it's founded by them and partly funded by them. One reason is certainly to spy on Tor users; another reason is so that their own spies have anonymous internet access to exfiltrate stolen information; a third reason is to enable political dissidents in countries like Australia with onerous censorship regimes to access uncensored information.
If you want to use a nested VPN chain that isn't Tor, how do you authenticate to the last provider in the chain, the one that knows which website you're connecting to? Are you using a VPN provider that you pay in ZCash? Or do they allow anyone to use their server without paying, like a Tor exit?
All other VPNs in my chains, I pay with Bitcoin that's been mixed multiple times. I have a bunch of Whonix instances that I use for mixing and storing Bitcoin. They all hit Tor through nested VPN chains.
Each one has an Electrum wallet. It gets its Bitcoin from another Whonix instance through a mixing service. In any given mixing chain, I use a different mixing service for each step.
So then, generally, VPNs that I use less directly get paid with Bitcoin that's been mixed more times. And I never use the same Bitcoin wallet to pay for VPNs at different "levels".
Edit: You say:
> But many people already trust Amazon with ...
I trust Amazon with all those things. As my meatspace identity.
But I wouldn't trust them with information that associates my meatspace identity with Mirimir.
But Amazon, less so. Because they're totally profit driven. And wouldn't think twice before pwning me.
I want to remain pseudonymous. Basically so I don't need to worry about damaging my meatspace reputation.
And what would be the point of going to all that trouble, if I were going to compromise myself?
You've answered that, but it definitely seems a lot of effort to go to.
And an expression of my commitment to privacy, freedom, etc.
It was lots of effort. Some years ago. Mostly in learning how to do it.
But now it's only maintenance.
Not much more than maintaining my perimeter router.
Those are all relatively old, compared to mainstream VPN services. So there's been more time for bad news to come out.
I've also used older ones, such as Cryptohippie and Rayservers. They're among the first OpenVPN-based services. Cryptohippie used to be quite expensive, with a ~low usage limit. But now its price is comparable to many others, and I don't see a usage cap. It's not as fast as many others, but arguably far better secured against adversaries.
Rayservers is extremely old school. They only accept gold-based electronic currencies (Truledger and Loom). Those are pre-Bitcoin. I'm not sure whether they still work.
There are others that I use. But I'm not going to talk about them.
Connecting to your own VPN on a VPS is miles better than a retail VPN service, but even for that I wonder what threat model it serves.
• You can ban outgoing unencrypted network traffic without a VPN (a VPN doesn't solve this either btw).
• You can use DNS-over-TLS without a VPN; that solves a big part of traffic analysis.
• If you only have one VPS and only ever connect through that one tunnel, all you accomplished was moving your effective IP to another place. Oh, and you added an extra counterparty in the middle.
The utility of VPNs is, almost as a dumb proxy, to patch malicious/missing functionality from your first-party connection, e.g.: you live in a country that bans IP ranges outside of its borders, your ISP bans BitTorrent traffic, or your ISP is more cooperative with LEO than your VPN provider is. This has nothing to do with anonymization. The VPN or VPS knows who you are.
It's a confusion between privacy and anonymity.
https://www.securityweek.com/protonmail-accused-voluntarily-...
https://www.neowin.net/news/protonmail-confirms-it-helped-in...
"Drug dealer post" with ProtonMail response: https://www.reddit.com/r/ProtonMail/comments/dd5dkk/warning_...
Search for "court order" on ProtonMail subreddit: https://www.reddit.com/r/ProtonMail/search/?q=court%20order&...
Payment options: https://protonvpn.com/support/payment-options/