Mullvad VPN now accepts Monero payments
mullvad.net
mullvad.net
I hope I don't live to see you turn into every other shady VPN service.
I suppose this is inevitable to some degree with any VPN service, it's part of the deal for more privacy, you have to share an IP with potential sources of abuse. But it seems to have gotten really bad recently to the point that I end up server hoping throughout the day because different websites will have blocked different mullvad servers - to complicate matters some of their newer server IPs hosted by another company are misidentified as russian and blocked by many sites and services.
I'm not blaming Mullvad, but it's changed my use of their service from a set and forget to a constant reminder that i'm on a VPN... I don't know what the solution is beyond some crude cycling of IPs.
Welcome to the world of Tor users. People who value online dignity need to work together against privacy hostile web technologies. My present bugbear is Cloudflare, who seem to do a lot to disrupt privacy respecting technologies. Ultimately though, the power lies with web service designers. One can no longer pretend "I didn't know" when turning over delivery to some cheap (free) but shady CDN who then blocks millions of legitimate users because they don't want to be tracked and spied on.
One of the weird realities is that in order to combat fraud you need to be able to identify the source, which is a hard reality as a privacy advocate.
Bam - I am anonymous, but have (mostly) proven I am a real person with (mostly) reasonably good intentions.
I joined HN for one or two reasons. To research a book. But also to promote my last book. Anyone can post here with a throwaway, yet I didn't want to be an interloping dick who felt entitled to hit and run posting links to my own vanities... so I decided; join, contribute, participate, earn. After a few months I don't feel bad about plying my own wares a little. Reputation (social capital) is natural and ancient and doesn't really need crypto.
Most of the Web isn't that though. As an information system, as Sir Tim first coined it, it's a publishing machine: You advertise a service, I send "requests", you send "responses", we part ways without complications. Quick anonymous sex on the beach. So-called Web2.0 f-cked that massively. Web2.0 wants to exchange phone numbers. And once the surveillance capitalist creeps latched on to stalking everyone around the neighbourhood... well here we are.
I think what some Web3.0 people think is that crypto can repair some kind of "middle ground", where Web2.0 type behaviours can take place but anonymously and under conditions controlled by "stakes". I think this won't work for psychological and game theoretical reasons we can't get into here. Instead I think we need to repair the Web1.0 layer at least, and since transport level security and anonymity have become necessary in a post-Snowden era, for me that means getting rid of the selective prejudice inflicted by systems like Cloudflare.
Its a put up or shutup kinda system. Fund your wallet with $100, hold it, and we will let you post that reaction to a news article after its been held continiusly for 30 days, and automatically delete is as soon as its unfunded.
"Sinners look just like saints, so it's necessary to punish all, to
destroy the riches of the many in order that wicked few do not
escape."
Is that a fair framing of the "ethics" of what you said? (I'm not
attributing that as 'your' argument, I understand you're kinda just
trying to 'explain' something as you see it).Do you think this kind of thinking can continue to stand if technology is ever going to be fair and useful to everyone? Or do we just accept that technology always amplifies as least as many problems and injustices as it solves?
I'm trying to map the technical explanations people give onto what may be going on for them at "ethical reasoning" level.
You're welcome to add your interpretation of course.
You probably guessed I'm looking to distinguish a Bentham from Mill sort of utilitarianism.
A reasonable challenge would probably be fine. But so many sites block, or sometimes use obnoxious unfair challenges.
I added some of my own experience here: https://news.ycombinator.com/item?id=31252676
If an army is attacking your border and somebody walks through them saying, "It's okay, I'm totally legitimate!" that person is probably still going down in the crossfire. Enter from the direction where the attacks aren't coming from and your odds will increase significantly.
Ultimately, companies will either adopt a very strict security policy on their own or they will respond to the problems that they are experiencing. If you are a US only company and you start getting malicious traffic from Romania, it's fairly common to just block all of Romania. When you're using tools like Maxmind for network identification, VPNs and Tor are just another traffic source that you can choose to block if it's causing you problems.
What I'm getting is that you consider the "attack" an immediate mortal threat and the granularity of tools and techniques for discerning enemy/friendly identity and behaviour are lacking. The principle ethical stance is really self-preservation.
> "It's okay, I'm totally legitimate!" that person is probably still going down in the crossfire.
Nice analogy. I may have to steal that :)
Given that we can't rely on identity [1], can we improve analysis and response to behaviour?
[1] I see in an earlier response you talk a bit about fingerprinting, and of course anyone serious about privacy will modulate OS and browser FPs without malicious intent.
For example, at the site where I worked we needed much stricter protection but we didn't want to bother the established users of the site...so we setup trust scores and implemented stricter controls on a sliding scale. The higher your trust score, the less strict we would be with our policies.
As a brand new user, your score was a flat 0. You could boost it by verifying a credit card, phone number and address (without using a VPN/Tor). Successful transactions rewarded your score. Transactions with established users are more valuable than transactions with other new users, etc.
All the security was virtually invisible to the established users and it worked like a charm.
Regarding the fingerprinting, at the time that we were doing this anti-fingerprinting technology barely existed. We had some other tricks in the bag too to fingerprint based on behavior. It was a lot of fun working on that stuff though. Very much a cat and mouse game.
ssh bruteforce top 5 offenders:
147 (Tor: 0) TENCENT-NET-AP-CN
133 (Tor: 0) DIGITALOCEAN-ASN
31 (Tor: 0) CHINANET-BACKBONE
17 (Tor: 0) BAIDU
13 (Tor: 0) CHINANET-SH-AP
Overall there where 737 unique IPs from 241 ASNs and 1 was a Tor node.
access log top 5 offenders:
76 (Tor: 0) DIGITALOCEAN-ASN
58 (Tor: 0) CONTABO
54 (Tor: 0) AMAZON-AES
50 (Tor: 0) KAZTELECOM-AS
34 (Tor: 0) CORBINA-AS
Overall there where 1672 unique IPs from 618 ASNs and 4 where Tor nodes.
I spent a recent chunk of my career combating fraud on a niche-eBay style site and the people trying to defraud other users, pay with stolen credit cards, login with phished credentials, etc were consistently trying to hide their origin.
Until we started using fingerprinting techniques to track them across multiple accounts and IPs, we had no way to spot this. It was a shock to me when I realized there were legitimate uses for fingerprinting technology because I'd always associated it with ad networks and trackers. They're fairly necessary for combating fraud though.
When we stopped letting any untrusted users run a credit card if their connection couldn't be trusted, our charge backs virtually stopped. That experience makes me completely understand sites scrutinizing anonymized traffic.
HTML isn't cached by default with cloudflare
In the end they are going to drive their honest non-abusive customers elsewhere.
The reality is that "anonymous payment" is kind of pointless, it's basically never the payment method that determines abuse potential as abusers have all kinds of ways of making payment anonymously even when only e.g. cc is accepted. What matters is the level of time and effort put into monitoring usage.
To be honest, on a pure sniff test your traffic coming from DO is probably more suspicious. There are lots of legitimate uses of commercial VPNs. There are not many legitimate users of consumer web-browsing from DO.
I am currently hosting head scale with an exit node on hetzner, and sometimes i am banned from websites.
But back when I used contabo it was a rareity to get blocked, even though its a more "shady" host, maybe because its not as well known ?
Online stores are more likely to flag your purchase as suspicious on the admin side(e.g the Shopify console)
You will run into captchas and prompts for authentication more often
You may not be able to log into some of your more sensitive services(like banking)
Streaming sites will block your server eventually
Even if you spin your own wireguard instance on any major cloud provider you're going to run into the same issues.
I'm not sure a VPN provides much utility when you're already punching your (billing|shipping) address and CC number into a website - that is, unless you're using a drop site for your packages, which definitely will make you look like someone who has stolen CC digits and is trying to cash in on them.
And i, very happily, continue on without those 'many websites'. Of which, there are actually, very, very few for me. Nevertheless - fuck 'em; and not missed.
1) if you do this for unauthenticated websites you are bad and I will not use you
2) if you do this for authenticated websites (especially if I pay you) I will stop using you and you will lose my money.
The most I will accept is a captcha (because it's 2022 and this is where we are)
As a Swede, it's easy to remember, but I can see why it can seem a tad esoteric to native English-speakers :)
New order require mandatory logging and storage of customer details for 5 years for digital infra providers post June.
https://entrackr.com/2022/04/it-ministry-orders-vpn-provider...
Impose a penalty on the citizen side as well.
The latter is fine
People talk about crypto like offshore bank accounts and cash never existed.
How does the revolutionary leader of a Sub-Saharan country who suspects the deposed leader has funds in an offshore bank account in a jurisdiction that doesn't even recognize the incoming regime get the money? Violence.
In hyper-legalistic societies like the U.S., yes, the police may sometimes have trouble finding proof that survives court scrutiny. (Though I'd guess most people aren't practicing good opsec around their crypto.) But that isn't most of the world. I don't see the Indian police having any trouble arresting and searching someone on reasonable suspicion of operating a hidden wallet.
It's a feature, not a bug.
Devs have to eat and all, but I wonder sometimes if a longer and slower emission curve would have helped here. Monero is mostly emitted at this point.
For a project that means so much to the world and still has much work to do, its a shame how things turned out with MRL.
people deciding if they want excess holdings of Monero shouldnt base their confidence on a standing committee
Monero communities arrogance and in-grouping has segregated them just like they desired. That technology and user experience is an evolutionary dead end, it can exist and that has enough utility. But in the multichain world the user experience is better and the funding models are better, even gitcoin grants streamline development of projects.
>Tornado cash is good enough tbh
I hold neither of these, but as someone with a significant amount of experience in the field, the facts are clear. "Good enough" is not an objective measurement of the binary quality of fungibility. Monero is fungible.
Is this me saying everyone should go out and buy some Monero, no, it is me saying that when you consider the mechanics of the way these two scantly comparable technologies function, there is one clear winner because only one is fungible.
I don't have a response to the social issues of those that use or perpetuate Monero adoption, just as I don't have a response to the social issues of those that use or perpetuate USD, or any other asset. It's not my business what other people do, and I don't feel associated by virtue of using the same utility.
> That technology [ ... ] is an evolutionary dead end
This will need a source.
The fact that Monero has been growing the minimum ring size over time, as well as refining the decoy selection algorithm, shows that fungibility, in the sense of transaction graph obfuscation, is more of a spectrum.
MRL work is progressing on Seraphis[1] which will allow for significantly higher ring sizes without increasing the transaction size. A proof of concept is currently in development.
[1] https://www.getmonero.org/2021/12/22/what-is-seraphis.html
The emission schedule was changed when the tail emission was added, however that was early on, to your credit. Smooth was the one who proposed it iirc, then it was added shortly after. It was not part of Bitmonero originally, as Smooth, Fluffyponyza, et al did not arrive until ThankfulForToday abandoned the project.
Maybe someone with less gray in the beard can put some dates on that, I'm just going by memory.
There are also some monero whales that could probably stand to contribute to further development even if they don’t do it themselves (like fluffy pony) but unfortunately it looks like they are/he is in the early stages of getting Assanged
If you had intrusions on GPU servers it would be a very different story.
You might think it's because it's private and confidential but it's actually because it's suited for CPU mining.
2. Buy your product with kickbacks
3. Resell your product at a discount for clean money
Congrats, you now get to meet all the alphabet people in person and spend a lot of one on one time with them. Hope you didn't have any traveling planned cuz you aren't getting on any airplanes.
This was 5 times as expensive compared to when you paid by debit or credit card.
This offering was extremely popular amongst drug dealers and people needing a burner to call in a bomb threat. (Maybe there were legislate uses too - I never found out.)
The problem for the telco was that this was generating hundred fold the number of request for wire tapping and logging by the courts and the police. And by law the telco was required to service these request free of charge.
So in the end the business simply wasn’t there even though the margins were sky high.
Moral of the story: selling stuff to criminals might seem like easy money but may not be worth the trouble.
In other words the cost associated with the extra business that comes via Monero might be higher than the extra money that comes in.
Interesting that you think only criminals want privacy. I use Signal and TLS too, I must be Pablo Escobar's second coming?
No, that's not how this works. You don't need criminal activity to provide you with anonymity. You just need ANY other activity in order to get lost in the crowd[1].
Your flawed view is that nobody should have privacy because some bad guys might use privacy to do bad things. Privacy advocates are the opposite. We say everybody deserves privacy as a human right, even if on occasion some bad guys take advantage of the privacy.
[1] https://www.getmonero.org/resources/moneropedia/ringsignatur...
And that's irrelevant because these tools are explicitly built for criminals to use them. I'm actually quoting what the designers of these systems have said, this isn't my opinion. When you say "ANY other activity" that also means criminal activity gets lumped in there, I don't know why you're denying this. You're probably not a criminal but if you're using this then you're intentionally making criminals your company and you will pay for the effects of that in one way or another. That's the part where I'm speaking to you from experience. You just can't make an anonymized system like this that also isn't a lucrative target for criminals, such a thing doesn't exist. Is it unfortunate for those who aren't criminals and actually need privacy? Absolutely, but this is the reality of the situation. There's no easy solution. If someone is telling you that this isn't an issue then they're just lying to you, get mad at them instead of me.
>Your flawed view is that nobody should have privacy because some bad guys might use privacy to do bad things.
No, this also isn't even remotely close to what my actual view is. You just blatantly made this up for no reason. Why are you doing this?
This is yet another reason that it's so exhausting to talk about this, not only are you spreading misinformation about this project but you're also spreading misinformation about me. Misinformation and disinformation is actually incredibly common in these low-trust environments. If you think it's bad, I agree, it's actually incredibly shameful that some people try to use "privacy" as a cover to spread misinformation, but that's something else that you have to accept and deal with and insulate yourself from if you take this route. Please do a better job in the future and don't bring yourself down to this level of empty rhetoric. You're letting the liars and criminals win.
If you're acting this way because you see this route as some kind of moral outlet, I would suggest that you stop and find another one. This one is ethically gray and if you stick with it, you'll be peer pressured into excusing a lot of things that you're probably not comfortable with in the name of "privacy" at the expense of everything else. The moral rationalizations coming from these projects are strong, but are ultimately willful blind spots informed by money-making and capitalism just like everything else. Don't say that nobody warned you.
The end result is that if you're one of few company that offer privacy to your customers you'll find your customer base has a higher ratio of criminals as they'll all flock to you.
Will we reach a point where self hosting is seen as criminal?
People need to understand this. There is no solution for mobile device compromise other than to stop using these devices.
And if you cannot stop using them, then you must understand that everything you type, say and do on or around your mobile device is (or will be) public. So treat it like a public device at all times.
And all major telcos have departments dedicated just to serve the authorities.
So there is bi-directional access to and from the broader crypto ecosystem without centralized exchanges and without the selectively scamming shapeshift-style sites, and for the pros: without OTC desks either.
That said Secret is interesting. Another thing to note though in terms of privacy is that Secret token transactions aren't anonymous afaik, despite the name suggesting otherwise. Only the smart contracts are. It's an interesting design choice, there are probably arguments pro and contra both.
Correct, yes, on SECRET network, smart contract variables are private, which means all token transactions are while the native currency is not. There are a variety of ways to leak data anyway.
So SCRT is the native currency while sSCRT is the token version that therefore has the variables (to, from, amount) private.
sXMR is the token version of XMR there.
I personally use IVPN and Mullvad.
When a service isn't being honest in their advertising, it makes you think about what else they're being dishonest about.
And yeah, then I'd agree, if Mullvad started lying or pushing useless services down my throat, I'd definitely dump it quickly.
I used NordVPN back quite a few years ago. Once they started advertising on cable tv shows, I knew it was time to jump ship. A VPN service spending that kind of money is either burning through cash too quickly to survive, selling user data, or a government honeypot.
Check out what vpn have been sued over the last year (they all have been no log companies) and you will quickly realize that logs are being shared by anyone of size. The smaller the service the better.
I do this as well! Annoy me with to much ads and I'll avoid you and your product out of spite.
Only ever use it on public wifi, and it isn't meant to be "private", just good enough to prevent accidental data leakage at Starbucks/doctors' offices/wherever else my 5g doesn't reach and I'm forced onto public WiFi.
You can use openvpn or wireguard as clients (or their own), and while i was writing this I just saw they accept payments with different crypto (bitcoin, ethereum, litecoin, bitcoin cash, dash, doge, monero)
The other big point in AirVPN's favor is configurable port forwarding. Makes it much easier to quickly expose something to the internet on any network.
I don’t have a “hide from websites” need, but a “don’t trust public internet” need.
It's either your ISP or the VPN provider, which can log the websites you have visited, so there isn't a clear advantage of using a VPN. Sure the VPN provider may claim to log nothing, but that's hard to confirm and not proven to be true in some cases (related thread regarding Protonmail: https://news.ycombinator.com/item?id=28443449).
For researching confidential topics, TOR appears to be fine. VPN may have better network bandwidth, or may be blocked from less websites than TOR exit nodes I guess.
For example Formula 1 has F1TV that you can only sign up for in some countries (where they didn't sell out to Sky essentially).
Like, I don't even mind paying for a service if it's good and actually available!
That answers it for many people, I would guess. Even without censorship, many ISPs have a much worse track-record for gathering and subsequently selling information than, say, Mullvad does.
Is it an absolute that Mullvad doesn't log/sell information? No, of course not. But they make a much more convincing case than my ISP does.
Geoblock avoiding is another common answer. My ISP also sends out letters if you torrent, which can be annoying to receive - Mullvad alleviates that.
The German government also threatened to ban Telegram which would have put them in line with places like China, Russia, Cuba and Iran. I think Telegram folded and now removes channels at their request in order to avoid being fully censored.
That's not the only deciding factor though, is it? Mullvad (not singling them out, but just for sake of illustration) is in many ways is more attractive to bad actors because it centralizes users seeking privacy. On top of that, you're adding additional software and network complexity which equals attack surface. There's more to consider than what appears at face value when considering whether a VPN is appropriate.
The trade-off is worth it, for me personally, including when those other factors are considered.
Current example: https://news.ycombinator.com/item?id=31248250
In contrast I can choose any VPN provider in the world. It's a competitive market and they have strong incentives to respect privacy because it's one of their main selling points. Any VPN that is discovered to not be respecting privacy will lose a lot of business in short order.
Sure you can say that they can violate privacy in secret, but that's a big risk for them. It's no risk at all for an ISP because their customers have no choice. It's no guarantee, but it's definitely a better situation to use a company that actually has incentives aligned with yours.
Try routing all your traffic through TOR and trying to navigate the modern web or common apps. It is _extremely_ punishing when you connect through TOR exit nodes.
On top of that there's also the value of just having privacy even if the ISP can be trusted. E.g. I might not mind being seen naked by a friend, but I would still prefer for that to not happen.
In general I think a lot of the big providers who have gone without incidents (and without major changes) for a long time can be trusted. I feel the incidents with Proton were somewhat overblown, since their page on legal notices received did mention that they could be compelled to log IP addresses (or at least that's how I remembered it). But even without that, I think Mullvad has been pushing for "system transparency" where users can verify all the software that's running on their servers, which is a step in the right direction towards providing confidence that they are indeed not logging anything.
I’ve had it where I was served an add from a server that had previously been implicated in a bot net operation. The university told me I was infected and that my computer was not allowed back on the network until I came in person to show them that I had done a full wipe and reinstall of my OS.
I personally use it to evade IP-based tracking, for random example LinkedIn. Try browsing LI from your home. LI will suggest that you connect to others in your home. Even though I have a fake LI profile, not linked to other members of my household, so this doesn't actually invade my privacy, it's still yucky that they maintain a shadow connection between us. There are tons of sites/services that do this kind of simple yet invasive tracking.
I also use it in rare cases for torrenting or downloading content. I normally have other methods for torrenting and seeding privately but in some cases I want another level of privacy (nothing illegal/bad/censor worthy, and therefore would be ok with law enforcement connecting the dots through VPN), a level that VPN serves well.
I am glad that the VPN providers sell people on nonsense, on protections they can't guarantee (to Western countries anyway). This makes the service actually available at all. To me it's an analog of the https-everywhere cargo cult, that makes it super easy these days to get a free SSL cert.
No technology is perfect. It doesn't make it useless.
I find it's a convenient way to prevent services beyond my ISP from knowing where am I based on IP address.
All of those apps you have on your devices presumably have permanent connections back to their servers and they can very easily tell if you're at home, out on mobile data, in an office, or in a cafe/public library or even in a different country.
With a VPN, they currently think I'm in Dallas; which I'm nowhere near right now.
And the only app that has access to GPS on my device is: https://organicmaps.app/
And Googling "where am I" indeed shows me at my VPN exit [with my always-on and enforced VPN].
Therefore, you are trading trusting your ISP for trusting your VPN, but at least you are getting someone who says they care about your privacy (rather than someone who has a track record of not caring) and someone who would face significant business repercussions if they became untrusted, rather than someone that would face almost no business repercussions.
If you are ok with skipping that, you can use something like CakeWallet to create a wallet on your phone and then give someone a receiving address
To automate payments: run a node and use any of the RPC libraries available for various languages.
The same goes for anyone else reading this. Are you worried that we are too good to be true? What could we do to become more trustworthy in your eyes?
Cheers, Fredrik Stromberg (cofounder of Mullvad)
So I know you do the absolute maximum you can do to know as little about me as possible. As far as not keeping logs and not spying on me, I suppose I'll have to trust the audit reports.
Not much more you can do in my opinion. It's definitely good enough for me! Thanks for this great service!
Thank you. I happen to think there's a lot more we can do. Look forward to future blog posts. :)
Was it just on the backlog and took a bit of time to implement? I appreciate that you built your own implementation for crypto by the way.
Thanks for the great service.
EDIT: I've heard a rumor that you've shared a user IP because of a government subpoena (live during a connection, so it wasn't logged). Has this happened? I think according to your swedish-legislation page says "However, the Swedish police authority may have access to information by way of coercive measures such as seizure and search of premises." which would allow for this to happen in theory? I.E. intercepting or seizing control of your router to see what IP a connection is on?
EDIT: One other question - is there plans to add more IPs? Services seem to flag most mullvad IPs but I'm not sure there's much you can do about that.
Some third-parties did sell gift-codes using Monero before Mullvad had native support although I had no experience with them.
> I've heard a rumor that you've shared a user IP because of a government subpoena (live during a connection, so it wasn't logged).
Got any details?
FWIW: Correlating the origin IP with real-time traffic out of a single-hop VPN tunnel can be done using traffic-analysis by third-parties that are not the VPN provider themselves.
I do not - it's not an accusation, I have no evidence, just a rumor I was curious if they'd care to comment on.
I don't work with payments and the surrounding systems so I don't know the details of the project itself. As an organization we've certainly been aware of the feature request, but until now we've prioritized other projects.
> EDIT: I've heard a rumor that you've shared a user IP because of a government subpoena (live during a connection, so it wasn't logged). Has this happened?
To my knowledge it has never happened in the history of our service.
> EDIT: One other question - is there plans to add more IPs? Services seem to flag most mullvad IPs but I'm not sure there's much you can do about that.
I'm sure my colleagues in the Operations and Support teams are aware of it. You'll get a better answer from support@mullvad.net.
Another use case you missed is downloading/uploading pirated/copywrited content. Good VPNs receive DMCA notices and throw them in the garbage.
You are right that VPNs are not useful for many use cases and they can give users a false sense of security.
You're definitely right to point out that DoH helps with the VPN DNS privacy problem and DNSSEC doesn't.
I disagree with your assessment of the use cases for a VPN. Just one example: Your IP address is often a great identifier, making a VPN or Tor a useful starting point for online privacy. This is more or less what we say on our website as well.
Based on your comment however I think you might find the follwing links to IVPN refreshing:
See, this is exactly why I don't trust you. This is used car salesman talk. IP addresses are only one minor tracking mechanism out of many which defeat obscuring originating IP by means of VPN altogether (canvas fingerprint, cookies, font/screen tracking, etc.) You're trying to say if I use a VPN, I get privacy because websites don't know my IP, but this isn't even remotely accurate. Do you explain this anywhere in your marketing materials? If not, it doesn't really help me, it just helps you sell the product.
I agree. This is why I said "useful starting point". A user looking for browsing privacy needs to do more than just use a VPN or Tor. Obscuring your IP address somehow is necessary but not sufficient. This is what I meant.
Category: [Misunderstanding]
> You're trying to say if I use a VPN, I get privacy because websites don't know my IP, but this isn't even remotely accurate.
No, I said it's a "useful starting point". I did not say it's sufficient. I could have been more clear, but I was in a hurry when I wrote it.
Category: [Misunderstanding]
> Do you explain this anywhere in your marketing materials?
We do! On our landing page you are met with this:
"... a ... VPN is a good first step toward reclaiming [your right to privacy]."
Right below is a button ("What is a VPN?"), which leads to a page containing a header ("How a VPN protects your privacy"), which explains further:
"Using a VPN is a great first step toward protecting your privacy, but it's not the ultimate solution (we wish it was!). However, it's easy to improve your privacy ninja skills."
The quote above links to a guide explaining what is necessary to protect your browsing privacy: https://mullvad.net/en/help/first-steps-towards-online-priva...
Category: [Question]
With this reply I believe I have shown you that we (Mullvad) do "reason about this in a transparent and objective way", both on your website, and with people giving us feedback.
As an aside I think IVPN's approach might be more to your liking, but nevertheless none of your stated concerns apply to us. As I've shown above they came down to two misunderstandings and a question.
If you have any other concerns I'd love to hear them. I appreciate your feedback. If we only spoke with people who gave us positive feedback we wouldn't improve as much.