ExpressVPN bought for $1bn by Brit biz with an interesting history in ad-tech
theregister.com
theregister.com
Second you can get some very useful data monitoring at the network level and not keeping “user logs” for example how often are people from country X connecting to country Y to visit plane ticket sites or like Facebooks VPN to predict what the next hip new thing was so they could get in early. No need to log what each user is doing, just “look” at the network traffic patterns in and out of their servers.
Also there does seem to be fuck tons of money being thrown about when it comes to VPN (look how many YT sponsorships there are as an example)
In short, they can either spy on your browsing history and sell your data or they can hijack your bandwidth and resell it to shady people and you inevitably become part of some botnet.
Get 3 million VPN users through your funnel and you get eyes on all of their browsing habits... valuable data you can funnel in to serving better ads.
People using VPNs are also probably the people using adblock and are harder to market to.
Doing all the right things of making it fault-resilient and robust in the face of attack, etc… are all the sorts of things I don’t want to have to do for a home-built system. If I wanted to do that, I’d go start my own VPN company and sell that service to others.
They all claim to not keep logs. They all get caught time and time again keeping logs.
Mullvad has, so far, managed to keep a rather clean reputation and have been leading the pack on the technical side for quite a while. They were the first major provider to support wireguard, they make it easy to pay them via all sorts of anonymous methods (including just sending cash in an envelope), and so far all info I have been able to discover shows that they are actually running and controlling their hardware in every location where the make that claim. Maybe there are better options, but among the major providers they seem to net out at the top of most lists created by people interested in privacy. As a supporting data point, the Firefox VPN is basically fronting Mullvad so if you think the Mozilla people did their due diligence homework you may consider that an additional point in Mullvad's favour.
It depends on your threat model. But at some point you need to trust someone. I believe Amazon have more to lose by getting caught monitoring egress traffic than VPN operators who’ve been caught doing precisely that.
Amazon has nothing to lose by providing the RIAA with your instance netflow data and avoiding the legal costs alone would make it worth their while. Amazon has already built an interface to this data in CloudWatch Logs to show you that they are keeping the data, so why would you presume they would lose any reputation by providing this information to a third-party upon the presentation of a valid court order?