Latest Mozilla VPN features
blog.mozilla.org
blog.mozilla.org
I'm already a Mullvad customer, and if I were to switch to Mozilla VPN:
* It would not be available in my country (Germany) right away
* I would have to join a waitlist
* I would have to pay with my credit card, instead of cash-by-mail. (Great privacy improvement! /s)
* I would have to use Mozilla's GUI instead of the wg-quick CLI. (The use of wg-quick is documented by Mullvad in addition to Mullvad's GUI, but I haven't found any wg-quick documentation on Mozilla VPN)
All of this for the same infrastructure, the same service (number of devices, ...) at the same price. What the hell are you doing Mozilla?!
Obviously they could log your IP address (which they promise not to), but that's an issue even if you go through Mozilla to purchase the service.
A lot of consumers are interested in a quality VPN but wouldn't do this kind of research.
Mozilla provide additional eyeballs and billing support, and mullvad provides the service itself. It's a mutually beneficial transaction.
They're not in competition for your money, they're targeting different demographics.
This is the question though: who are these demographics?
I know Mozilla likely have a lot more data on this than I, but who is using Firefox / interested enough in Mozilla to read their marketing & research their VPN offerings, but is simultaneously not someone who would research VPN providers in general / use Mullvad? What is this techie/non-techie interested/not-interested hybrid person?
I just asked "who knows what VPN means" in IM group of non tech savvy folks, most under 35. No one knows.
Perhaps among us Firefox users that's different but certainly "most people under 40 today" wouldn't know even what VPN means.
VPNs are heavily marketed to regular consumers these days. Mostly for region shifting or vague privacy/security benefits.
I'm not sure "watching" is the correct word.
> those with any consciousness of their own vulnerability want to take action to minimize their surface area
This is a pretty small minority, as demonstrated by the number of people that continue to use Google and Facebook properties by choice (refering to their actual services, not their pervasive tracking around the Internet at large)
> firefox with container extensions
As a more-technical-than-average person, my experience is that attempting to get all Google services running in a specific google-only firefox container is a non-trivial and extremely painful experience, as there doesn't appear to be a way to simply add *.google.com to the 'always open in this container' list, so each subdomain needs to be added individually. And then youtube.
> adblockers
Adblocks can break the check-out flow on multiple ecommerce sites. "Don't shop there" doesn't fly when that's the only online outlet that has the shoes she wants. What's the workaround? Spend a while working out what's causing the flow to break, and find a way to explicitly whitelist that domain for that site? Nope, just disable the adblock entirely and hope you remember to re-enable it once you're done.
I think you might be in a bubble of you think the average person is using container extensions. There aren't even that many average people using Firefox anymore, least of all any extensions beyond adblockers (which still only reach at most 20% in general, including the all round more average Chrome users)
<off-topic-rant> Add to that there aren't even any container extensions that work well: the official Mozilla one doesn't support management of domain lists, and the best alternative (Containerise) is still limited and poorly supported (has outstanding bugs with things as simple as the www prefix). As for the individual site-specific options, the Google one is an all or nothing affair; there is no way to separate your traffic within Google's ecosystem, nor outside it: there's effectively two "zones", similar up Private Mode.
I wouldn't recommend containers to an average user in their current state
When these people say "surveillance" they mean they think that Facebook magically hears it when they say something out loud and they start seeing ads for it. We engineers overestimate the awareness average user has about technology.
Not "magically" - they don't trust their device. And can you blame them? Their device likely isn't trustworthy in so many different ways.
Hell, when accelerometers can be repurposed as rudimentary microphones, and when just about every modern device/app defaults to maximum "yes please track me," I tend to be paranoid myself!
To give an example, after the recent WhatsApp PR crisis because of the change of toc, I see a whole bunch of my contacts changed to Telegram. They could have chosen Signal but no. They switched from an end-to-end encrypted app to an unencrypted app! That's what paranoia gets you unless you know what you're doing. I've pretty given up on the average user on these matters.
It sounds funny, because I do acknowledge exactly what you're saying. I'm in tech, interested in using VPN for years. I researched some, but was put off if they would mishandle my data. In the end, it will be Mullvad who will be dealing with my data, after all. But now I kinda trust them more after Mozilla.
I know it sounds illogical, just explaining how I feel about this.
At least I can point at Mozilla VPN and make an appeal to authority.
In that case, they will probably use NordVPN or ProtonVPN
Even the front page is already freely giving away tons of data to multiple analytics providers.
Basically any VPN with an affiliate scheme you should stay away from. NordVPN, Ivacy, VPN Unlimited, FastestVPN, etc explicitly, run like fuck. The more "YOU ARE UNPROTECTED REGISTER NOW!" the faster you should run.
NB: I am a power user/developer, but I do not use either company. Objectively, a basic eyeball comparison (match bullet point indexes):
Mullvad:
- Says "Not using Mullvad" / "Using Mullvad" (a neutral statement)
- Shows their company address and registered location at the bottom of every page
- No on-page analytics
- No third party includes
- One price
NordVPN:
- "Your Status: Unprotected"
- "Copyright NordVPN.com" only
- Multiple on-page analytics and third parties
- Loads google tag manager, google analytics, bing marketing, youtube, third party web surveys, zendesk, twitter ad pixel, google ads, bing, cloudflare, ada chatbot, ravenjs, processout, multiple fingerprinting and persistent device identification/tracking services (also performs webgl/font iteration/plugin iteration/canvas fingerprinting, etc)
- Repeated upsells, lying to you about price (see JS for fake "sale ends in x seconds" countdown timers that attempt to induce FOMO and more), packed with dark patterns; "9 hours left easter special TODAY ONLY" - same sale that has been running for years
Is this the case? Is income from Mozilla VPN put toward Firefox development?
If it is, that info should be front-and-centre; they'd have a lot more customers I think.
There may be some clues in their public accounts but I guess VPN is too new a product to appear their yet https://www.mozilla.org/en-US/foundation/annualreport/2019/
1. It was priced in USD.
2. The price is a flat monthly $5. They don't offer discounts for longer contracts.
This is something Mulvad has been doing since 2009..
If a regular consumer searches for a VPN product they get a million results, all with different deals and they'd have to figure out how to find the best one and will still be around in a year. If they already trust the Mozilla brand they'll go with that. Just like people go with stock apps on their computer over some maybe better third party app.
If a regular consumer searches for a VPN product
they [...] have to figure out how to find the best
one and will still be around in a year.
Yep! It's a Mozilla product, so there's no guesswork and no worry. You know it won't be around in a year!To someone who isn't a leet hacker or SW dev, that is the ball game. Firefox and Mozilla aren't household, but millions of less-technical people know of them. Rather than getting their VPN (if they even know the value proposition) from some podcast advertisement, Mozilla is saying "Hey, this kind of service gives you privacy and we stand behind it".
I use it upon occasion. It's dead simple to purchase, set up on any OS and I trust Mozilla not to send me to a shady backend.
If you already have VPN and they don't offer it in your country, they clearly aren't targeting you.
You could use a VPN to make it look like you are in a supported country.
Isn't it the most important thing for a VPN provider? You want a company that is privacy-conscious, not one that logs your traffic and sells it or open it to the various TLAs of the world.
Supporting browser development instead of Mozilla Foundation.
This way at least they pass through the hands of the organization that does the most important work.
(Nothing against the other issues but right now the browser should be their top priority and I was massively annoyed when I found that donations towards the foundation couldn't be used for browser development and the browser.)
But is it going towards Browser development though? https://calpaterson.com/mozilla.html
Or is it going towards executive salaries?
I have a hard time coming up with an alternative that isn't just playing the ball into the hands of Google so that they can kill ad blocking right away?
That has been enough for me. I generally trust Mozilla when they say privacy first and if I'm going to give my money to a VPN provider I rather give it to Mozilla than say NordVPN.
The incentive for you is that Mozilla will keep Mullvad under close watch and make sure promises are kept - so you don't have to. Furthermore, there is no limitation for Mozilla to not seek other partnerships and/or develop the server side service themselves - they have the in-house dev talent to do so.
So, yes, they do bring quite a lot to the table besides their brand name.
Do you download your configurations from the Mullvad website over Tor via their onion service 100% of the time?
Do you connect to Tor before connecting to Mullvad in your VPN client?
I'm not afraid of governments knowing who/what I do. I'm afraid of private companies holding private data about me.
I suspect that if they get enough traction they'll roll their own. Until then reselling was a quick and simple way to get going.
As far as I know, in a lot of country (like France) it is a legal obligation to keep logs and be able to identify one of your customer if the police demands it. Therefore, if you have server in France or any country with similar rules, you can't operate a "0 log" service. And since those kinds of services have servers everywhere (and it is even one of their selling point), it is extremely unlikely that they don't keep you data and will hand it to the police (willingly or not) if requested.
And if their own server get breached, you can get the info of all the customers who used the breached server.
So I find the claim of those services that they provide "more privacy" pretty lousy. Yes they do hide your IP addresses, but that's far from being the only data use to fingerprint you. And if it is to protect you against a Wi-Fi that you don't trust or your ISP, sure it works, but you move the trust from them to your VPN provider.
Fighting against geofencing is good though.
- Shifting traffic over a VPN when using untrusted/sketchy wifi hotspots
- Spoofing your geo-location to use geo-specific content
And that's it. If privacy is your goal, Tor is much more suitable since it's not a single-hop proxy like a VPN and compartments all your traffic. (But of course Tor is not a silver bullet and there are caveats).
This sweeps the entire benefit under the rug. If someone isn't determined enough, a VPN solves your problem.
- Censorship circumvention
In some countries, censorship circumvention usually require sophistication that not all VPNs provide. A few like getoutline.com, getlantern.io, and psiphon.ca specialize in that.
In most countries, VPNs aren't even needed to circumvent censorship. Apps like getintra.org, GreenTunnel employ simpler techniques to bypass firewalls.
> Routing traffic over untrusted home/office ISP
With TLS v1.3 and DoH / DoT, I think VPNs may no longer be required if "hiding traffic" is the only need. Hiding IPs, however; (of both the client's from the server and the server's from the ISP) would continue to require the use of VPNs.
You, as a user, have little control over whether the servers you connect to support TLS 1.3 and eSNI / ECH.
ExpressVPN is HK/CCP owned, so I wouldn't worry too much about my privacy being violated for petty copyright infringements (BitTorrent).
Thank you for this callout. Had no idea.
Comparing VPN services, I’ve found ExpressVPN to be highly rated. The aforementioned callout means ExpressVPN may not be the best service for me.
In lieu of specific technical criteria regarding VPN services, who are the go-to (aka “top of mind” or “A list”) providers that privacy conscious, technically adroit (e.g. web dev with some sysadmin knowledge but little networking knowhow) users prefer?
In other words, I’m looking for VPN recommendations but no longer trust my own Google-fu (advert rabbit hole) to discern what is a “good” choice.
[1] https://en.wikipedia.org/wiki/ExpressVPN [2] https://www.quora.com/Who-owns-Express-VPN
With the CCP taking over HK, ExpressVPN could be used to gather information on domestic dissidents and foreign visa holders. Assuming it's not already.
(Weather or not they are owned by CCP or anything like that I have no idea, I'm just saying that being registered in BVI doesn't mean it's not possible for them to be owned by a CCP or anyone else)
That's what a VPN is really for. The other uses are more side effects exploiting the encryption and tunnelling properties of VPN rather than the original intended purpose of a VPN.
Thats a bit separate from a road warrior, corporate vpn or even one that one may host on a VPS that they have full control over and are willing to allow the hosting provider still see the traffic. As in, they trust the hosting provider more than the transit provider. Think University/Campus networks, public gov networks, or even some ISP's or corp networks.
Even Comcast has been known to inject ads. The core tenant of these VPN services is trust, with it they dont survive, but for an ISP with a de-facto monopoly thats a non factor. There are also plenty of sites and services that use IP tracking. Google is really bad but others are doing it behind the scenes and not telling you. Reddit 100% does. Amazon too. To the point that if i proxy my connection and try and login to one of my google accounts i sometimes have to verify or go through recovery.
So in some cases its better than no vpn. And I wouldn't use any authenticated service over tor that i wish to keep. There are so many malicious relays and exit nodes.
TOR is easily tracked at the nation-state level. China can axe tor traffic, even with bridges and OBFS4 configured.
With a service like nord, you can get on and do your thing to bypass the great wall for the most part. And the the great firewall drops that connection you have a very large pool to choose from for your next.
So there are definitely some reasons I could understand some would use them based on their own assessments/needs.
I have piholes with dnssec running at least upstream for privacy. And a vps I use as both a socks proxy and vpn here and there. But I have the technical know how to implement that.
Let’s say, my parents just wanted a way to make sure their traffic was encrypted from either their ISP or Corp provided iPhone. I wouldn’t tell them to go build a Linode or use Pi-hole. They don’t care. But a vpn with a decent trust rating with nothing more than a login would do it and is easily achievable.
Would I still advise them to be congnizant that other lower level spyware may be on their Corp phone, sure, absolutely. But that’s not always the case. My org doesn’t do that. We give you a phone and pay for service. You can use your iCloud and we have the ability to lock it/decom it because we own it. And can lock them out of email but we can’t run find my iPhone on it.
There have been requests to our provider for more traffic data for x user. So even I run a vpn when using their data.
Another example. I had a buddy going to China for a couple months bye wanted advice on how to secure his stuff. I advised him to use burner devices and chnage passwords yadda yadda. But then the question of accessing email, such as gmail came up. The great firewall is pretty nuts. I set him up an account on my vps and enabled obfs etc on the vpn.
But he also used nord as a backup because he had ton of options there geographically dispersed. In the end, all he needed was nord at all. And when the firewall dropped his states to one node he would just reconnect. It worked just fine.
Sure there are use cases like getting around georestrictions, and like you mentioned you can use it to get around tracking. Except that for privacy and evading tracking you need more than just a VPN, you need to be doing things like adblocking, tracker blocking, clearing all of your cookies, not signing in to anything because then the service gets to link your new VPN IP with you again. VPN ads that sell "privacy" is snake oil unless it is paired with a guide on the additional things you should be doing.
It depends on how you use Tor. For example, visiting your own personal homepage and then using the same relay to visit a NSFW site would be bad OPSEC. Also, Tor comes pre-installed with HTTPS Everywhere, and you can toggle a setting that disables all http traffic if you're worried about sketchy exit nodes analyzing your plaintext traffic.
Remember: Tor can't read your mind. If you want true anonymity you have to go through extraordinary lengths to achieve it, and even then, you could make mistakes.
Also HTTPS everywhere isn't enough; you also need ESNI, which requires server support.
1) Piracy (the most common, I would imagine) 2) Evading content-blocking. For example, going to Facebook at work.
Check out IVPN for instance. They do a lot of things right:
Comcast basically has automated the process of sending you a cease and desist if they detect you are torrenting something you shouldn't. Mozilla doesn't.
Not for all types of services. ISPs are sometimes under obligation to log, but VPN services don't belong in that category.
I can't speak for others but we have contacts with legal experts (in a few jurisdictions) that alert us to changing laws. Ultimately if a country required us to start logging we would just cancel all of our machines there and leave.
On the topic of trustworthiness, you are completely right of course that VPN users put a lot of trust in their VPN provider. There is also the lemon market aspect - the information and competence asymmetry between user and operator. That begs the question of how to ascertain trustworthiness.
We think things like this help:
https://mullvad.net/blog/2018/10/17/signals-trustworthy-vpns...
https://mullvad.net/blog/2019/6/3/system-transparency-future...
You could then use Firefox Multi-Account Containers to bind a container to the SOCKS proxy, and whenever you need to access a site that doesn’t support a VPN you can just open it with in said container.
FWIW, I've looked into Mullvad and even had beers with some of their programmers (all of whom appeared to be Scandinavian anarchist/anti-authoritarian types) and I think Mozilla made an good choice with that partnership. (Of course, don't take my word for it; do your own research, or just host your own VPN.)
I want to give Mozilla my money for this, but it's really annoying how unfriendly its implementation is.
1: https://www.mozilla.org/en-GB/products/vpn/#faq-compatibilit...
I can't speak for Mozilla, but we have our own desktop and mobile apps because it enables us to do more privacy-preserving things with a higher assurance. Consider for instance DNS leaks, Teredo leaks, IPv6 leaks, esoteric DHCP directives that can hack your routing tables, and so on.
And these are just a few of the things we were early in mitigating correctly. Consider also the tight relationship between UX and security, and it is clear that we can't rely on "generic VPN clients" to always agree with our design and security preferences. That doesn't mean they are wrong and we are right of course. It's just that we have a very specific mission.
One architecture decision we made for our app was to write its backend in Rust, and integrate tightly with the firewalls on Windows, macOS, and Linux. It facilitates stability and therefore reduces the risk of states where data leak outside of the tunnel. Check it out, it's open source. As all security-related things should be.
Sure, I could make it work with a separate Linux server running your app and some routing but that's far more work than most other VPN providers.
I'm fine with warnings in your UI about connections with these protocols being "less secure" like how Zoom handles E2E with phones.
Mozilla seems to make it really hard to pay them for goods and services.
I should perhaps have been clearer when I referred to generic VPN clients, I was talking about the original WireGuard implementation by Jason Donenfeld, not just some random software, which I would hope you agree is a (sufficiently) secure implementation when used by technically proficient users? I do appreciate that there are reasons for having a specific client for your service, and it is absolutely necessary for those who are new to VPN apps, but I would hope you appreciate the reasons for providing implementation-agnostic WireGuard/OpenVPN config files, since your own service does so?
Regardless, thanks again for the work you're doing in this sector, and best of luck for the future.
There are plenty of VPN clients, some by big enterprise-y networking companies, that at least historically have behaved in ways that leaks the user's traffic when interfaces change, on DHCP issues, tunnel disconnections. It's just easier to make our own app and be able to say what it does and doesn't. And that nothing will change tomorrow because of someone else's design decision. :)
Any deviation from the standard implementation, open source or not, is a hindrance.
Not an employee I just like the service.
Any reason why you don't use a PPA or something to auto-release updates? I've postponed an update quite a few times because the friction of going to your website, downloading it, and then upgrading the package is just a bit too much in certain situations.
Other than that my only gripe with the app is that I can't close it from the app indicator, but have to re-open it, click on the settings, and then choose "quit app".
Sad that PIA tanked their rep because their Linux support was top notch. They even had a script that would set up NetworkManager profiles for you.
It uses WireGuard, an open VPN protocol, so it's not necessarily forever anchored to Mullvad.
It's Mozilla white labeling an anonymous VPN service (ie, we don't know who runs it).
I thought it's owner regularly comments / joins in on hacker news... I didn't feel like I don't know who's running it?
Edit : quick search turns two very relevant posts:
"Who owns Mullvad? The Mullvad VPN service is operated by Mullvad VPN AB which is a subsidiary of Amagicom AB. Both companies are 100% owned by founders Fredrik Strömberg and Daniel Berntsson."
Location, Company name, individual names of founders/owners. What other "identifying information" would satisfy?
I found their FAQ, blog and guides tremendously helpful, transparent and upfront. There's a wealth of info with just a couple of clicks.
Being on an "unsecured" local network shouldnt be an issue for security.
I can't find any good reason for encouraging people to circumvent network controls, or throw more networking complexity into what was previously very simple for users.
The constant marketing of 'you need a vpn' is super counter productive for users because they have no idea what it even is, what it can break, or why they needed it in the first place. I've run into plenty of folks that said they use vpn because someone offered it to them for free, not because they needed it for any reason.
It's stupid shit like this that makes the development of their key software languish.
Recently visited family in a different state and stayed with them for a week. They had a fast internet connection but something in their router made establishing a new TCP connection take forever. I bought a subscription to Mozilla VPN and viola, now my TCP connections open quickly again. Also bonus: I don’t pollute their ad results with my searches.
While yes I could dig into their router problem, they had no issues with how things worked and I needed to get work done.
Since this is Mozilla, how about a Firefox extension that passes all Firefox traffic through a VPN, like Tor Browser does, but doesn't touch any other app? That would differentiate it from most of the other VPN offerings out there. Currently my go-to solution is to set up a local SOCKS proxy with an SSH tunnel and point Firefox at it. It's good enough for testing, but not all services work properly when accessed that way.
A VPN for the whole system I can use other providers who's main business is VPN.
I see the point of having a VPN to my own network but paying for a tunnel to some random place.... why ?
- You trust the VPN provider more than your ISP
- You want to circumvent geoblocking (Netflix, Sports broadcasts, etc...)
- You have to use an untrusted Wi-Fi
- You want to circumvent your government blocking certain websites/services
> No logging of your network activity
Does it mean I can torrent whatever I want? I mean, if there's a copyright notice, how're they going to know it was me?
Yes
Also, it's available in New Zealand, but not Australia, which is a fairly large anglophone population.
Is Mozilla VPN going to be available in other countries in near future? I would like to hear the roadmap from Mozilla folks. I live in Japan and am wondering when it would become available in my country...
seems like a way for mozilla to gain shares without much effort? kinda disappointing
Argle bargle Mozilla bad something something Pocket integration, Firefox isn't even that fast grr Brendan Eich, one time Thunderbird loaded a tracking pixel.