From the article: "After demonstrating that this is indeed how our service works"
Presumably, Mullvad employees showed this data does not exist live.
From the article: "After demonstrating that this is indeed how our service works"
Presumably, Mullvad employees showed this data does not exist live.
As someone who ran a VPN in the past, this blog post is extremely strange as well as the purported described sequence of events.
Police in any jurisdiction aren’t jokes - especially not Sweden where they can absolutely walk in and take your stuff according to mullvads website [1].
It’s 2023 - if a VPN is how you’re doing your privacy you’re probably doing it wrong.
Don’t trust. Verify.
I'm honestly interested, how could one 'do privacy' the right way then?
Private Internet Access, on the other hand, does not release up-to-date source code for its software clients:
- PIA Android client: latest source release v3.14.0 (Mar 18, 2022) vs. latest Google Play release v3.18.0 (Feb 22, 2023)[3]
- PIA iOS client: latest source release v3.14.0 (Mar 18, 2022) vs. latest App Store release v3.20.0 (Mar 1, 2023)[4]
- PIA desktop client: latest source release v3.3.0 (Feb 23, 2022) / v3.4.1-beta1 (Aug 18, 2022) vs. latest downloadable release v3.3.1 (unknown)[5]
- PIA browser extension: latest source release v3.1.0 (May 31, 2021) vs. latest Chrome Web Store release v3.2.0 (March 8, 2022)[6]
It's not clear to me how much of a say you still have in PIA's operations, but if you have any influence, I kindly ask you to direct them to release the source code of PIA's clients on time, every time a new client version is released. Open sourcing PIA's clients was something you promised PIA would do to reassure customers after PIA was acquired by the former adware/malware distributor Kape Technologies.[7]
---
[1] Mullvad's audits: https://mullvad.net/en/blog/tag/audits/
[2] Mullvad's GitHub repos: https://github.com/mullvad
[3] PIA Android client - GitHub: https://github.com/pia-foss/android/tags / Google Play: https://play.google.com/store/apps/details?id=com.privateint...
[4] PIA iOS client - GitHub: https://github.com/pia-foss/vpn-ios/tags / App Store: https://apps.apple.com/us/app/vpn-by-private-internet-access...
[5] PIA desktop client - GitHub: https://github.com/pia-foss/desktop/releases / PIA website: https://www.privateinternetaccess.com/download/linux-vpn
[6] PIA Chrome extension - GitHub: https://github.com/pia-foss/extension-chrome/releases / Chrome Web Store: https://chrome.google.com/webstore/detail/private-internet-a...
[7] Our conversation in 2019: https://news.ycombinator.com/item?id=21613267 (I appreciated your response at the time)
I salute Mullvad and consider it to be the top VPN in the world today, and specifically, the only one I would recommend to anyone looking for a VPN.
In terms of PIA, I am no longer affiliated with the company, but I agree that getting the source out for the clients out on time is something they should try to address quickly.
gerbilly (another poster in parallel) - In 2023, I don't think a VPN is not private, but, for sure this cannot be the only tool in one's arsenal to secure their privacy. Depending on your threat-levels, there are different things you may want to do. To be clear, if you're being targeted, you cannot maintain privacy.
For the absolutist:
1. Get cash but not from an ATM (traceable)
2. Go buy a computer (must be Purism or something with trustworthy hardware) with said cash but wear a disguise when buying it. Disable all the location/etc. stuff at store parking lot.
3. Purchase a T-Mobile Prepaid Hotspot with cash.
4. Purchase mullvad, but wear gloves, mask and a hairnet when working with the envelope to send cash.
5. Never login to any service of any kind that would leak your identity.
For everyone else:
1. Assume you're not private.