So I figure that authorities still obtained a search warrant to atleast see what data they can get their hands on and to verify that this is true. In that case, it doesn't really illustrate any disconnect.
> Basic knowledge and a quick investigation would make clear that Mullvad is not storing any customer data.
This is something more along the lines of trust. Sure you don't have to provide PII but Mullvad could supppsedly still be recording other data which would count as customer data.
As mentioned in another comment, at least they would have to be lying + the external companies who've done the third-party audits would have to be lying too (including companies like Cure53).
A VPN company is also not a monolith: They have servers literally distributed around the globe. Ensuring physical security for all of them is not trivial, and I doubt that their auditors have visited every single data center. This is to say nothing of global traffic correlation capabilities of state-level actors; access to their servers network uplink is all that's needed to deanonymize many connections.
Besides that, they have human staff as well, and while it's possible to distribute permissions and require four eyes for all important changes, there's always loopholes in a complex system.
I have no reason to doubt that Mullvad is being truthful about any of their efforts or aspects of their service, but even if they're not, this is by no means equivalent to absolute security.
They also need to follow process and make a reasonable attempt to follow a lead.
They can’t just read a company’s website, assume that no evidence exists, and then give up on that line of exploration. Note that in several high profile cases, companies have publicly claimed to not be storing data but later been found to have incriminating logs.
It would be irresponsible for them to not follow up with Mullvad, despite what they advertise.
It doesn’t make sense to suggest that this is a disconnect with law enforcement.
List of the audits can be found here: https://mullvad.net/en/blog/tag/audits/
Could they? Sure.
Do they have anything on me?
* One BTC transfer
* IPs where I'm connecting from (if they are lying and storing them)
* My traffic (if they are lying and storing it)
* My unencrypted traffic (if they are lying and storing it)
Do they have ... on me? * Email? - nope
* Phone number? - nope
* Credit card? - nope
* My first name, family name? - nope
* My address? - nope
* My mother's maiden name? - nope
Because I never provided it to them because they never asked for them.You can pay a Bitcoin lightning invoice on this site and get a redeemable Mullvad voucher instantly. Extremely convenient. Since you've only done 1 BTC transaction, I assume it was a large one for lots of time. However, when your time runs out, this option is great. It's an extra layer of privacy and you don't have to wait for the transaction to settle on chain.
If someone comes to exchange - they could identify me (and they can just tap their server to listen to email which do have all the transaction info, including CC# in the plaintext, lol).
To establish a correlation between my wallet and Mullvad account someone needs to find that transaction in Mullvad customer data. Which - they claim they don't have.
So yes, someone can identity what I bought services from Mullvad and... nothing more?
Double (triple|quad) hop, tied to different entities is necessary if you want at least plausible deniability. Thankfully I don't do things what may be of the interest of someone who can raid Mullvad offices.
But I recently discovered a VPS provider who only needs an email address to confirm an order, so it can be used as a bootstrap for a something pretty anonymous. Still needs an email, but as I said in some other comment recently, you can do that (if you are okay with leaving some traces) with a Google device with WiFi only capability.
Authorities have to follow their process and collect evidence, or document the absence of discovered evidence. They can’t simply read the website, shrug their shoulders, and decide not to investigate a key part of a criminal case because the website says the company won’t have the data.
They are obligated to explore the possibility of data existing and to document the fact that it could not be found. Assuming the evidence doesn’t exist isn’t an option. They have to document it.
I know Mullvad is generally trusted by the community, but you also have to remember that several VPN companies have claimed to not keep logs but were later found to have data useful to criminal cases.
I think the real disconnect is in the comments from people who think this is the government being dumb. They’re not, they’re just doing their job correctly.
From the article: "After demonstrating that this is indeed how our service works"
Presumably, Mullvad employees showed this data does not exist live.
As someone who ran a VPN in the past, this blog post is extremely strange as well as the purported described sequence of events.
Police in any jurisdiction aren’t jokes - especially not Sweden where they can absolutely walk in and take your stuff according to mullvads website [1].
It’s 2023 - if a VPN is how you’re doing your privacy you’re probably doing it wrong.
Don’t trust. Verify.
I'm honestly interested, how could one 'do privacy' the right way then?
Private Internet Access, on the other hand, does not release up-to-date source code for its software clients:
- PIA Android client: latest source release v3.14.0 (Mar 18, 2022) vs. latest Google Play release v3.18.0 (Feb 22, 2023)[3]
- PIA iOS client: latest source release v3.14.0 (Mar 18, 2022) vs. latest App Store release v3.20.0 (Mar 1, 2023)[4]
- PIA desktop client: latest source release v3.3.0 (Feb 23, 2022) / v3.4.1-beta1 (Aug 18, 2022) vs. latest downloadable release v3.3.1 (unknown)[5]
- PIA browser extension: latest source release v3.1.0 (May 31, 2021) vs. latest Chrome Web Store release v3.2.0 (March 8, 2022)[6]
It's not clear to me how much of a say you still have in PIA's operations, but if you have any influence, I kindly ask you to direct them to release the source code of PIA's clients on time, every time a new client version is released. Open sourcing PIA's clients was something you promised PIA would do to reassure customers after PIA was acquired by the former adware/malware distributor Kape Technologies.[7]
---
[1] Mullvad's audits: https://mullvad.net/en/blog/tag/audits/
[2] Mullvad's GitHub repos: https://github.com/mullvad
[3] PIA Android client - GitHub: https://github.com/pia-foss/android/tags / Google Play: https://play.google.com/store/apps/details?id=com.privateint...
[4] PIA iOS client - GitHub: https://github.com/pia-foss/vpn-ios/tags / App Store: https://apps.apple.com/us/app/vpn-by-private-internet-access...
[5] PIA desktop client - GitHub: https://github.com/pia-foss/desktop/releases / PIA website: https://www.privateinternetaccess.com/download/linux-vpn
[6] PIA Chrome extension - GitHub: https://github.com/pia-foss/extension-chrome/releases / Chrome Web Store: https://chrome.google.com/webstore/detail/private-internet-a...
[7] Our conversation in 2019: https://news.ycombinator.com/item?id=21613267 (I appreciated your response at the time)
I salute Mullvad and consider it to be the top VPN in the world today, and specifically, the only one I would recommend to anyone looking for a VPN.
In terms of PIA, I am no longer affiliated with the company, but I agree that getting the source out for the clients out on time is something they should try to address quickly.
gerbilly (another poster in parallel) - In 2023, I don't think a VPN is not private, but, for sure this cannot be the only tool in one's arsenal to secure their privacy. Depending on your threat-levels, there are different things you may want to do. To be clear, if you're being targeted, you cannot maintain privacy.
For the absolutist:
1. Get cash but not from an ATM (traceable)
2. Go buy a computer (must be Purism or something with trustworthy hardware) with said cash but wear a disguise when buying it. Disable all the location/etc. stuff at store parking lot.
3. Purchase a T-Mobile Prepaid Hotspot with cash.
4. Purchase mullvad, but wear gloves, mask and a hairnet when working with the envelope to send cash.
5. Never login to any service of any kind that would leak your identity.
For everyone else:
1. Assume you're not private.
So for example, going to their office and asking them ?
I understand that some people are more less clued in than others, but your snarkiness really misplaced.
The VPN industry is notoriously shady, and that’s not just code for “fights for users’ rights against law enforcement”.