Mozilla bundles its VPN and email relay services for $7 per month
engadget.com
engadget.com
Why I use a VPN:
1. I don't want many of the sites I browse to know my IP.
2. My US ISP corrupted my government to allow them to steal my data. I don't know if I can trust my VPN provider, but I know for certain that I can't trust my thieving ISP.
3. I frequently connect through untrustworthy networks when traveling. Yes, SSL helps, but going through a VPN is an added layer of abstraction.
I am not a network security expert, so criticism of these three use cases is highly welcome.
>there are often posts which criticize the use of a VPN
Often they specifically critique the likes of NordVPN etc. The off the shelf solutions rather than personally setup VPNs. What disgusts me is that they charge fees that are multiples of what it costs to run a basic Linode or DO Droplet for a month and a virtual machine is far more useful than a commercial VPN.
You don't have to even use it, but every dollar of revenue that Mozilla can attribute to their privacy products and services means one less dollar is needed from their hostage deal with Google.
If you already have a droplet unused sure but otherwise being able to change ip in different countries adds some additional value for 2 dollars more.
That's the great, albiet unfortunate, value of retail VPNs; other people are using them and your traffic mixed with theirs. Being a totally anonymous but unique individual is less valuable in today's marketing morass is less valuable than being one of many in a VPNs IP space.
If you use any currently standard protocol such as wireguard, openvpn, IPSEC with Suite-B ciphers you are getting 'enhanced-privacy'* from eavesdroppers on your local network, which eliminates alot of low-tier/easy MiTM attacks.
A two-layer/double tunnel is pretty-good for mitigating against most commercial data collection by eavesdroppers. (Though your tunnel-exit/last-VPN-hop, (varying by client-destination protocol), and the destination IPs/sites will still be able to collect data of course).
*Consider privacy a vector. Suite-B ciphers are not perfect, letalone their freely-available implementations.
I use paid VPN services a lot as well as cloudflare warp. I understand and accept the risks the anti-vpn crowd keeps repeating. In the US, your local ISP and like you pointed out sites that sell and mine info about you are much higher risk of compromising your privacy or posing a security risk.
My traffic enters hostile network territory once it is delivered to my ISP router or the remote end of a VPN tunnel. Take NordVPN for example, I don't use them but it is more difficult but still possible for law enforcement or surveillance/ad companies to coerce or collude with Nord than with site owners and ISPs. TLS metadata including timestamp, SNI and other details along with my IP are known to Nord. To my ISP, they know my current location, usually social security number , birthday and whatever info their router can gather is known to them. Sites I visit without a VPN have my IP user-agent and whatever they collect with JS. A VPN removes the IP collection by sites and traffic sniffing by ISPs that can and do sell to whoever can pay them a fee.
VPN providers pause a significantly reduced risk than ISPs and they reduce risk from sites you visit. If you research a VPN provider and pick ones that have the most to lose by working against your interest, you reduce the risk even further.
Setting up a VPS and maintaining is a hard dealbreaker for me since I don't have the time and even if I did there is a shit-tom of more productive things I would rather do. But even if that is the case, which VPS provider should I trust more than a VPN provider? Digitalocean or cloud providers?
You know, few months ago I needed to setup a VPS fast, I must have tried 5+ including DO amd OVH. They needed to collect my email, some of them were picky about what card I used, others like DO wanted my phone to be valid, it was crazy! Only one weird vps provider let me but they didn't provision it after waiting a while. OVH wanted more info back and forth eventually after a few days supposedly they let me have a VPS but I no longer needed it after wasting money at so many places. Whether for anti-abuse reasons or anti-privacy VPS providers these days are hostile, they need too much info from you so how can you trust them with all your traffic?
Mullvad, PIA and Proton along with many others let you sign up with cash or giftcards and you can use a fake name/address. The only info they have TLS sni/metadata and your IP. They purposely get the least amount of identifying information from you.
I said cargo-culting because the people that oppose VPNs had some setup work for them and they think that and only that is ideal.
I see extremely talented security folk say that and similar cargo-culting on other subjects like how you shouldn't have an AV/EDR or just use only mac and Linux if you want to be secure lol.
But I think if a brand name like Mozilla would offer a standards based "internet suite" (think: mail and notes over IMAP, file cloud over WebDAV, calendars and todo's over CalDAV, VPN over WireGuard etc. so basically your online stuff without the proprietary device-locked walled garden implementation) it could become at least a sustainable business for people who:
- Care about not being locked in
- Do not want the hassle of self hosting
- Feel less comfortable about using a non-brandname NextCloud provider
This list really needs to expand a lot more, and quicker. Mozilla is “literally” leaving money in the table by not serving many other countries. The market size may not be as big, but there is the Mozilla brand name recognition among people who work in tech and there are people who’d like to support Mozilla Corporation directly.
it's not theirs, it's mullvad ones
The client isn't a reskin of Mullvad's client.
Mozilla uses Mullvad VPN, they built their VPN Client application using wireguard
Therefore, it's a VPN Client, not "their VPN", VPN = virtual private network, it's not their "network"
Chrome Browser = VPN Client
Google Services = VPN
Brave made a browser using chromium, but they do not use Google's servers/services, so its their browser
Understand the difference now?
Mozilla is a 3rd party with their own account system and payment system, that means you are traceable, you need to register to mozilla
Mullvad doesn't have any account system, and you can pay using cash
is it good, is it bad? it's up to you to decide based on the provided informations
mullvad is an average vpn provider
also its important to note, that many question that VPNs provide any security at all , i think for 7 dollars you pay their email relay and phone masking seem like the more interesting feature and value
I was under the impression that mullvad was best-in-breed. A lot of bad VPN companies running around these days and Mullvad is a clear HN favorite.
I wish there was a premium tier to let you pay for more bandwidth though, the fact that down speeds are capped at 300MBPS and up speeds much less made it not really usable for me
To name a few:
- no logging (no hdd in their servers even!)
- pay with cash (via post)
- audit of their infra
The Mozilla Foundation exists to support internet freedom. Firefox is a means to that end, but if they fired every Firefox developer and replaced them with a skin on top of Chrome that wouldn't be against Mozilla's goals.
Which means: if you want to support Mozilla you should sign up for this and some of that money will trickle down to Firefox. If you want to support Firefox then you should convince people to use it more.
It's probably still Google and I generally encourage people to get weaned off the Google product teat as much as possible, but that search engine integration is how Moz makes most of their money from what I understand.
For VPN, I'm already paying for Mullvad, not sure this bundling helps me. Curious to see if it takes off.