NordVPN Review
cnet.com
cnet.com
Honestly that is all you should ever use these VPN services for. Convenient access to blocked content (or flip to a different region to access alternative content).
Sure your own VPS running WireGuard or OpenVPN is better but that isn't as easy as just picking a different country on a pretty map in an app to get access to a show on BBC iPlayer or Netflix a second later.
Nord, Express, etc. are close to worthless from a privacy aspect but they're very convenient for watching blocked content and that is all anyone should use them for.
If you want/need privacy because you're on a network you don't trust (hotel, airport, whatever) then your own VPS and WireGuard are what you should be looking into. If you trust you home ISP and have decent bandwidth (both ways) you can easily run your own WireGuard server on pretty much anything from home and just connect into that so cost is pretty much zero.
But for other details, more significant in many use cases, a private VPN wins because you are protecting your activity from being viewed by those potentially untrusted networks.
Of course once traffic leaves your VPN it is once again at the mercy of the wider Internet between there and the destination sites & services, so use secure transports like HTTPS where-ever possible even over the VPN.
It all depends on what your threat model actually is.
In fact the advertised “access different media” use case isn't addressing an active threat at all, it is about gaining access to something rather than protecting you from someone/something.
I think that is the other side of it: You might have to know what you are doing, to get to similar security of a professional service. Trust is of course its own issue, as you are sort of hinting at, but I think it needs to be stated, that maybe not everyone is able to securely run their own VPN, depending on how hard it is to make it secure.
So far I haven't seen anything about mullvad that makes me doubt them.
This. However the critical point is that VPN providers are virtual, so there is in theory infinite competition; ISPs are an oligopoly in every country, so there is no real competition - If you don't like something about your ISP, like selling your metadata, it's usually tough shit because the other few will follow knowing there is no real competition and seeing a way to extract more money.
AWS Lightsail costs the same as a consumer VPN service while also giving you always-on compute and storage for sync and long-running jobs.
Having a stable, unchanging, unique IP (that is also tied to your identity via billing, etc.) for all of your traffic (like you would with a VPS VPN) is terrible for privacy and the cloud provider will often give out your info for any legal or governmental request.
Had a copyright notice and warning email within 6 hours. Deleted the content and they were happy. Learnt my lesson not to try that again.
Wasn't AWS but a reasonably big vps provider.
When they received a DMCA complaint they didn't provide our information and generally just didn't seem to care as long as we provided the bare minimum of ass-covering for them. We'd get a ticket opened against our account with a copy of the notice, reply "We've identified one of our users operating in violation of our TOS and have banned the offending user. All copyrighted materials referenced have been deleted." and they'd close the ticket every time.
I imagine if this was more than a once-every-three-to-six-months kinda thing the support burden would have had them drop us as a customer, but at no point did they share our information or did any rights-holder take it further.
Even in the low stakes situation of a lawyer going after you for torrenting, I see a high risk of a cloud provider giving out your information. They'd just have to reveal who rented your VPS instance.
Not only would companies not care about discretion when it comes to catching torrenters, they especially would not care for confidentiality about who rented their infrastructure.
If torrenting is the basis of your risk profile, seedboxes are a lot more safer.
This is something that they will probably do as a policy, simply because "AWS used for torrenting, storing and seeding CP" is a headline that can do far more damage to their business than some logging ever will.
But as useful as it might be for casual users, I think you'd be crazy to trust a large commercial VPN service to anonymize yourself if you are worried about being tracked by a nation-state actor or hiding serious crimes or something like that. No large business is going to protect you if they get sufficient pressure from a government that threatens their existence.
I am a NordVPN customer, but not for privacy, only for access to content in different regions.
It's one of the main reasons I like Mullvad. One price, month-to-month, no 'discount' for paying for multiple years at a time, no shady sales tactics.
Also, NordVPN does not support incoming connections to a listening port, so commonly can't download from two thirds of the seeds on a torrent. It is not unusual for there to be one to five seeders on a torrent, none with a port open for incoming connections, so people behind many commercial VPN's can't download the torrent.
There are other VPNs that support incoming connections, such as Mullvad, which are much more effective for torrents, if the users makes the effort to configure it.
You mean on a VPS that you also rented from someone else, therefore essentially moving your traffic from your ISP to...?
I would never do anything illegal via that VPN though, since it would be trivial to trace it back to me. I'm sure OVH wouldn't hesitate to hand over my details if the authorities requested them. But as a privacy protection on public wifi, it works well.
When choosing a VPN, you should think about what you're trying to achieve and what you're trying to protect yourself from. Most non-tech people I know that use VPNs, use them to bypass geo-restrictions. For that purpose, these giant commercial ones are probably fine.
A VPN provider that easily bows to authorities is a VPN provider that will lose a massive portion of their user base. Some server farm probably profits very little from VPN servers, so if some government (or even some IP lawyer) knocks on their door, then they won't take the risk.
You also don't get the benefit of your traffic getting mixed together under the same address, since VPS providers will assign you an individual address.
Because you need to give your name and credit card data to get a VPS, and in the end you're still sending encrypted data through someone's network.
VPN vendors are extracting value out of your monthly subscription like anybody else. Though the shadier ones might _also_ sell any metadata (to whom?), but we're not talking about these, and selling data is not a necessary precondition to being a VPN vendor.
In reality, the only people that are really interested in knowing in aggregate and in specific where people connect to when trying to hide are governments. And they don't pay, but just put a tap somewhere and if an alarm is triggered, send a court order to get logs and data upstream. That applies for both VPN and VPS vendors. So the goal is finding someone that has as minimal logs and invoicing data as legally possible.
Pick a cheap, untrusted VPS provider and you're getting just as exploited as if you were using a cheap, untrusted VPN provider.
It's also trivial to map the traffic of your VPS to you, since there's a 1:1 relationship between the IP your VPS uses and your actual IP.
Additionally IP lawyers may have much more success in threatening litigation to get your provider to rat you out. The provider would get little reward from not doing that, since harboring torrenters is probably not their main business.
The presumption is that the business of VPN providers is fully based on providing privacy, giving them a strong perverse incentive to abuse their access to this information and for whichever purposes. Plus, their whole infrastructure is orientated towards providing VPN services, with their own software, making the effort involved in collecting their customers' data and behaviour much smaller and more scalable.
VPS providers, on the other hand are in the business of offering hosting. What software their customer chooses to use on their VPS, and for what purpose, is anyone's guess. While the VPS provider could technically log and exploit the incoming and outgoing traffic from customers who happen to be running VPN software on their VPS, the effort involved in handling the myriad of bespoke VPN setups used by such a small proportion of their customers would be utterly pointless.
If you're implying that they'd do something illegal like blackmail, then I don't think that would be a wise course of action for a company to take. VPN companies are, in the worst case, still limited by TLS. So the amount of blackmail material is pretty small,meaning they would be taking a massive risk for very little reward.
A VPS server can easily log your connections. All they'd need to log are incoming packets to your VPS, and the destination address of outgoing packets from your VPS. No need to concern themselves with what software you are using under the hood.
For an analogy, if your motivation for using physical storage space was to hide your stuff from prying eyes, but were legitimately concerned that a business may have an economic or political incentive to take a peek, what would be a safer bet? Would it be to use a business specialising in storage, that uses standard storage modules all in the same location, and who knows most of its customers are interested in hiding their objects? Or would it be to rent an apartment from an estate agent that rents out all sorts of property for any number of purposes?
It’s trivial to pinpoint my location just based on IP. Setup a cloudflare worker and dump the request object, it gets very close, down to giving you the rough zip code area. Using something like NordVPN (even with a server in the same country I’m in) changes my IP proximity to something much more broad.
Then in cafes and public networks where I absolutely don’t trust the network
If you are paying with say your credit card, I guess the only benefit is that the vpn may have a better privacy policy and/or jurisdiction than your isp.
If you trust the VISP service to protect your privacy more than your physical ISP, they might be useful for privacy. Otherwise they're harmful to privacy, and only useful for getting around region locks.
Or do I test my ISP, who absolutely doesn't care about my privacy and would give up my data at a moment's notice?
As long as you've researched your VPN provider, there's almost no reason to trust your ISP over them.
Their last audit was published in June 22, 2022: https://mullvad.net/en/blog/2022/6/22/vpn-server-audit-found...
Being owned by a data mining company that also owns a residential proxy service (Nord uses it for unblocking streaming services: https://hiddenrouter.com/how-is-nordvpn-unblocking-disney-it...) is also baffling. Hard to trust a data mining company with data, when they make a profit from selling user data?
Other VPN providers like PIA have released transparency reports that contain requests from state, federal, and foreign law enforcement: https://www.privateinternetaccess.com/blog/private-internet-...
Nord’s own employee said they don’t want to publish transparency reports out of “obligations” to their investors.
The way it worked is by using using their service you'd actually reciprocally share your IP.
Thats dodgy on multiple levels.
Traffic coming from your IP would be mixed up with unrelated traffic
I'm sure that notion will keep the FBI from raiding your home when that unrelated traffic turns out to be involved in something illicit.
I need to change some stuff on my bank accounts in another country and I can't just go there so I need to use it once or twice just for that.
Finally, they keep providing service to a Russian market.