Port forwarding
blog.azirevpn.com
blog.azirevpn.com
Mullvad runs the “random user generator” function for you and just gives you a random number. This lets you run that random generator yourself. If you’re concerned about personal information, the final result is the same.
Mullvad makes it so that you can’t even accidentally give them information they don’t need. This leaves it up to your own discretion. I don’t think it’s disingenuous.
You talking about the green checkmark?
If they're okay with allowing users to enter a personal username, email address, and a password that's probably not unique, and if the attitude is "privacy-concerned people should just know xyz" then I have to wonder what other things they apply this attitude to
> Service (B): click 'here' to generate a random username
(A) is claiming to not require any "personal data". (B) is claiming to not require any "personal data".
I'd agree with both A and B's statement. Neither of them are "disingenuous". (B) makes it bulletproof for the stupidest of the stupidest of users. If you use the username "DreadPirateRoberts" across all online services you use. Then act surprised because someone was able to correlate DPR between service X and service Y, It's not service X or Y's fault. You're just a dumbass. Mullvad didn't want to be even remotely in that business. Whether or not their users are bonafide dumbasses or not, they said "fuck it, you morons don't even get to pick your usernames". Which I'm honestly all for. People are stupid and will often and frequently (including the original DPR) get themselves into trouble by being stupid. But I don't see anything that's disingenuous as OP put it about them marking themselves as "don't require personal information"
Mullvad is always €5, Azire is only €5 if you pay an entire year upfront.
This would make me not choose them.
However a downside is that they'll be quite limited in reacting quickly and ramping up their network, which may happen if they get a significant inflow of users.
What is that supposed to mean? You could have a rack full of PXE-booting machines - or SAN-based storage and technically be honest calling them “RAM-only”.
A potential option for Mullvad refugees?
TFA seems to offer a solution for that problem with "Experience uncompromising privacy with AzireVPN's Blind Operator! Your port stays confidential as we don't store or log assigned ports in any database. Thanks to our secure Blind Operator backend, your assigned port remains private."
Ultimately you have to take their word that it works as well as described.
Port forwarding doesn't assist in deanonymization. Ultimately you either trust your VPN or you don't.
But fingerprinting isn't deanonymization anyways. And this is stretching the idea of "fingerprinting" in the first place -- a single port number provides the same amount of information as an IP address. With a VPN you can rotate both as often or as little as you like.
Compared with what other options?
Mullvad does not support port forwarding. You can try to defend it all you want, but if someone needs port forwarding and your alternative does not support port forwarding then you need to find another alternative or your point is moot.
This results in raids leaving empty-handed: https://news.ycombinator.com/item?id=35638917
This is in contrast to the flocks of VPN providers whose retention-related claims were either complete horseshit or not well-implemented.
Are there any VPN providers that offer an OAuth2 API that would let you set up VPN tunnels on behalf of users?
You could use a different protocol but developers are less likely to integrate with it.
Who else offers multihop+port forwarding?
But running Tor inside a VPN or a VPN inside Tor has unique risk profiles you should be aware of.