Mozilla gained good will over the years and I like the browser. The vpn is fairly seamless and permissive for number of devices. I understand it is a wrapper on Mullvad and we are paying a healthy overhead. Still, it is worth it because I’d trust that if the vpn service provider behaves in bad faith that Mozilla will be able to quickly respond and adopt another provider. Whereas if it were up to me I may hear of it years later and not necessarily know what service to adopt instead.
My use is merely hoping to reduce tracking based on ip. I wouldn’t trust it to be subpoena proof. I’m not into pirating music anyway.
Actually, they rather lost a lot over the last years, with various shady things, like tracking for advertisement enabled from the browser by default (called studys).
So sadly, I also would not trust them as a VPN. Way more than some random VPN service, sure, but not completely. But I also do not know of a better alternative.
I've lost track of the times a Mozilla misstep has resulted in people here saying that's the reason they're switching back to chrome, which I find frankly ridiculous. Also, the whole damn thing is open source, so it's not like they're really hiding anything, people just don't care until someone makes a stink and then all of a sudden everyone cares a lot.
No browser is perfect, but Mozilla is definitely one of the better ones for anyone privacy conscious.
We technical folks get it and can deactivate it.
Every non technical person I know, who still uses firefox does not know and has all the defaults activated, until I change it for them.
So sure, they are still better than google and microsoft, where I just assume that they track everything, but that is a really low standard.
Some of the other incidents were overblown but the Cliqz thing shows of a company culture where user data is something which can be sold to make a profit, which is essentially what they did, and not something which is vital to protect.
Yes, it was many years ago now but I have no reason to think that they cleaned up their company culture.
All Mozilla know is the mullvad username. Mullvad don’t know the credit card details of the purchaser. To link a given vpn ip to a specific credit card would require compromising mullvad and Mozilla.
(Or of course the normal way of fingerprinting which doesn’t rely on IPs)
Now sure you can buy mullvad via cash, but that’s far more work. Using Mozilla as a reseller feels like one more step in the chain
This might be useful:
I am also familiar with a recent police investigation where law enforcement subpoenaed NordVPN and the company replied, essentially, that they had no information connecting a particular IP address, at a specific date and time, to any specific user.
https://www.pcmag.com/news/nordvpn-actually-we-do-comply-wit...
They don’t keep traffic logs
Not sure about the links to Proton though.
I formerly worked in the consumer VPN space (an older, but once quite big player), and use cases go from content access (including everything from getting US Netflix from Germany, to sidestepping national firewalls), to general-purpose paranoia about IP logging by websites. There are also lots of cases that get marketed a bit too liberally by companies like Nord, Express, and the hydra that is Kape, like that VPNs can add meaningful security to submitting payment information online; this is despite the fact that it's harder than ever to MITM payment sites.
It's generally agreed that the state of public Wi-Fi combined with evolving web standards and sky-high HTTPS adoption makes VPNs largely, though definitely not completely obsolete for protecting yourself against someone sniffing traffic at Starbucks.
Having said all that: if you need a VPN and a lack of port-forwarding isn't a dealbreaker, I wholeheartedly recommend Mullvad. My former company never worked with them directly but our team had immense respect for their integrity, ethics, and approach to developing a quality product.
The problem I have with all the "checks" that press foundations do is that none of them seem to know what they're talking about in regards to what tech is trustworthy and audited, and what is not.
I found a nice article about it, skimmed through it and seems to be true and reflect my own research that I did for my cyber defense network [1]
[1] https://vpnpro.com/blog/hidden-vpn-owners-unveiled-97-vpns-2...
They shouldn't keep logs but even if they did there's no personal information metadata.
Just your personal IP, which is via your provider very tied to your person.
(In many places it can trivially linked to your real ID, if there is a court order)
Unless the use case is circumventing region barriers.
If you are just a file sharer or normal low level criminal I doubt the CIA (or whoever may have infiltrated Mullvad) would give anyone your IP.
1. https://www.svt.se/nyheter/lokalt/vast/husrannsakan-mot-vpn-...
Or NSO or some other private actor did so, and now every dictatorship has access to it, and we all know how broad their “terrorist” definition can be…
If you are a dissident in Iran, you really should not trust some random VPN. Tor is probably safe enough, but there is also no guarantee, that the chinese are not sharing with them, because as far as I know (but last time I checked has been some years), many nodes are china based. So they might know.
But if all you do is pirating some videos, then this is not something to worry about.
Just so everyone is clear on a few facts, it is possible for a TLA or agency from another large government to just try to blackbox the VPN nodes and be done with it without needing to infiltrate Mullvad. Just pressure the network provider of the VPN instances to get flow data, and at that point they can match up traffic going in and out and the VPN disappears from the picture.