Infrastructure audit completed by Radically Open Security
mullvad.net
mullvad.net
Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers, so my connection mysteriously failed one day and I was left with several months of prepaid service.
I'm a bit bitter for that, but honestly their technical writing and security decisions have earned enough good will from me that I want them to keep the money. As the only VPN that doesn't feel shady, I wish them all the best.
[1] https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...
Announcing the removal of a feature such as this a mere 30 days ahead is not how we like to conduct our business in the general case. I expect those of our customers who relied on this feature to be disappointed by its removal as well as the manner in which it was done.
Nevertheless it was the right thing to do. The manner and extent in which it came to be abused in recent months made it unacceptable for us to continue providing it. This feature should have been removed a long time ago, with a longer grace period. It wasn't - a mistake on our part - and some of our users suffered for it, including you. For this I am sorry.
Affected customers can get their money back for any prepaid service they can not use, of course.
If you used port forwarding to (I) make a service reachable (II) from the open Internet there are plenty of good hosting providers which will happily take your business.
If you used port forwarding to (III) stay anonymous while (I) making a service reachable we can highly recommend Tor's "onion service" feature. It was built with that use case in mind.
If you used port forwarding to (III) stay anonymous while (I) making a service reachable (II) from the open Internet, there are no good options that we can recommend.
Port forwarding needed to be removed on moral grounds. It needed to be removed because it was causing too much of a disturbance to our core mission of making mass surveillance and censorship ineffective.
I hope my explanation has - if not allayed your disappointment - at least provided some clarity.
Best regards, Fredrik Stromberg (cofounder of Mullvad VPN)
I really hope you guys stick around, Mullvad has exactly the posture that we need from security services.
[1] https://blog.azirevpn.com/port-forwarding/ [2] https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec...
Our decision to remove port forwarding was not a question of margins - it was a moral and practical decision.
Port forwarding is a feature with many legitimate use cases. This year it became clear that we had become popular for use cases we didn't want to support. Undesirable content and malicious services is a good summary. I'm not privy to more details than that as my main focus is research.
Technology is often a double-edged sword, but thankfully it is often also a net benefit to its users and society in general. Privacy online is exactly that kind of technology. Enabling anyone to host any service anonymously on the open Internet is another matter.
I hope AirVPN and AzireVPN somehow succeed with providing that feature while steering clear of its downsides. That would be awesome.
Nitpick: Mullvad is older than both Air and Azire. :)
It feels like VPN for apps is very different than a VPN for browsing. While in both cases I want my traffic to be mixed in with a lot of other people's traffic (so service provider dealing with complaints about neighbors is part of the value proposition), browsing use case is tied to IP reputation (so don't want someone to run a Tor exit on the same IP), whereas the app use case is much less IP reputation-sensitive but definitely benefits from port forwarding (e.g. to anonymously run nodes that powers distributed infrastructure like crypto).
I'd definitely pay premium, with longer commitments up front for "this server might be useless for browsing but run all your anonymous crypto nodes behind forwarded ports" type of service. Maybe if port forwarding is active only if you have 6+ months of outstanding service commitment (and you forfeit the balance if your port gets used for C&C or whatnot) is enough of a deterrent. Some VPNs are doing some traffic segregation already, e.g. having dedicated servers for P2P, though nothing exactly like this.
> The manner and extent in which it came to be abused in recent months made it unacceptable for us to continue providing it.
Probably the difference between Mullvad and AirVPN/AzireVPN is how popular the service is, which also usually dictates how popular it is for people to try to abuse it.
Maybe 1% of each service's traffic is abuse, which for AirVPN/AzireVPN is not that much, but on Mullvads scale it becomes a whole nother beast.
According to Mullvads blog [2] the police raid was related to a blackmail attack in Germany.
[1]https://www.ivpn.net/blog/gradual-removal-of-port-forwarding
[2]https://mullvad.net/en/blog/2023/5/2/update-the-swedish-auth...
So you can still seed, it just won't be as usable.
[1]: https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...
[1] https://www.pcmag.com/news/mullvad-vpn-hit-with-search-warra...
For example, say someone wanted to run their botnet distribution server. Now, unless you’re a state actor working for North Korea or some such, that generally gets a rather angry knock on your door in a rather short period of time.
Being able to hide your IP/traffic for $5/mo is going to save you a significant amount of trouble.
I’m certain AWS and other hosting providers keep track of any activity that’s too strange, and the authorities will have your hosting provider give you the boot even if they can’t figure out who you are exactly.
Developing a reputation for allowing, if not quite condoning such behavior will quite quickly get you shut down as a business. Even if they can’t “prove” anything, you’ll get hassled, harassed, and investigated to death because your existence goes from being a nuisance to being a problem.
Some guy torrented a few movies on your VPN? Whatever. Some guy used your VPN to break into their local government’s servers? If they can’t find him, they’ll take it out on you.
This situation seems avoidable: what if the payment/signup flow had a big loud warning that you need to configure your own polling of an RSS endpoint using a client capable of pinging you?
I wish RSS had more surface area with general computer users, but I reckon even being called RSS makes it unlikely. Folks in tech often forget how intimidating opaque names can be for nontechnical users.
For what's worth, I eventually went with Proton VPN, but it's more expensive and gives a used-car-salesman feeling.
I really don't like the aesthetic direction Proton's been taking in the last few years, from top to bottom. I'm finding their mail apps, both in desktop web browser and on mobile, less and less usable. In addition I get this feeling from their design choices as well. I know their mission is to grow enough to challenge predatory providers like gmail, but it makes me wary and makes me feel as if I won't be using them in 5 more years.
The only other service I have any brand loyalty to gog.com. For some reason I feel the same about them.
Basically you have a thin proxy on some not so cheap but ‘anonymous’ Bitcoin payed VM, that then (http) links to your vpn endpoint.
You need the dual setup as using the btc vm for storage of terabytes of data as well as for TB of traffic is too expensive for a volunteer run project.
Try creating a new torrent with some random file, seeding it from a Mullvad device and downloading it from a different Mullvad device. That should only work if you have port forwarding set up (or if you're not actually going through Mullvad - you will see that by the peer IP in the torrent client).
In the wireguard config section of their tutorials, there’s a spot to put a custom port - it’s really unclear from the docs but this allows you to expose out a service within the higher limits of the port ranges, and only on dedicated servers.
Really hard to find but they call this “city ports” over global ports because you have to set them up beforehand.
A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my professional career as the cloud providers must adhere to US sanctions, meaning if you are from Cuba, Iran or Crimea you can't play the games I made. -- which is annoying because you could buy our game legally in Russia and Ukraine, but if you happened to be in occupied territory then no play time for you.
Sidetracked a bit, but it's really refreshing from the outside to see a company that isn't scummy that values liberty.
The thing is, I somewhat understand why the sanctions were placed decades ago, but... is that rationale still valid? Anyway, and sadly, the sanctions affect "regular" people like me the most. The ruling elite? Not at all.
Thank you for your position, BTW!
Let me give you an example: I can't open dell.com, at all. What I want to believe is that they blocked all access because it was easy, just a geo thingy flipped on. It is their decision though, but it is supported on existing sanctions. So... yes, the law compels them to do it, indirectly or not. And there are hundreds, thousands of other examples that I can provide, if you're interested.
This confirms my secondhand knowledge of financial sanctions. It seems to universally be this way and makes me wonder why we still tout them as if they were effective. They sure don’t seem to be.
False. There's a lot (the majority) of people from my close circle who were and are "upset", if I can put it this way. I don't have the statistics, but let's say that's 80/20 ratio (supporters/non-supporters), even though I personally believe it's closer to 50/50.
> fast-food, clothes
So you really think that limited access to the Internet and the fact that McDonalds is gone would force these 20% to get on the streets and fight against the heavily armed government forces AND the rest 80% of the country population? I mean, among the other reasons that come to mind, sanctions (movies, cars, clothes - what??) are somewhere at the very bottom of my list, if matter at all.
That being said, many people consider sanctions as an act of war[0] and if you think of them like that, well obviously it sucks, it's war and war-like consequences always suck for the people on the ground.
Just make sure when your boss asks you to implement geoblock bans for sanctions, do what you need to do and not more like trying to block VPN users or other shenanigans. Don't break the law but don't make it harder for people on the ground to use their right to internet access.
[0] https://moderndiplomacy.eu/2022/06/29/economic-sanctions-as-...
And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance.
We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicated.
I certainly believe Crimea is an invaded territory of Ukraine, but I cannot pretend that it's a wise notion to demerit the entire conflict down to "Crimea is in Ukraine".
It does nothing to help the people there, and is completely meaningless in the face of my initial comment: that while I could sell games to Ukrainians, I could not allow them to play from within Crimea... a territory you claim; is Ukraine. The implicit argument you just made is that we have created sanctions against Ukraine itself.
And, most likely, your personal allegiance would be Russian.
[1] https://en.wikipedia.org/wiki/Demographics_of_Crimea#Ethnici...
And I'm not saying considering yourself Russian means you have allegiance to Russia, but I think there is a strong correlation between the two. Even if there's less of a correlation than I think, the percentage which considers themselves Russian is over twice that of the percentage which considers themselves Ukrainian. Maybe the Tatars align more with Ukraine than Russia, improving the balance, but idk.
Even though you have the results of "demographics" survey of 1989 that put "Russian" populace at 67%.
This gives us a great idea of how likely a Crimean who considers themselves Russian would actually vote between the two and that while the correlation is strong, it might not be strong enough to suggest Crimeans would favor Russia and while Crimea is still clearly, the most Russian-friendly Ukrainian state, the decision between the two is much closer than I previously thought.
Edit: to add, I have talked with a Crimean who supports Ukraine, but they say the outcome of a vote would very likely be pro-Russia, even before they started shipping Russians in and pre-occupation.
> but they say the outcome of a vote would very likely be pro-Russia, even before they started shipping Russians in and pre-occupation
I heard similar opinions too, but it might vary on who you ask. E.g. we talk about information bubbles on the Internet, but they exist IRL too. That is to say, hearsay is not proof. And even if it were true, one might keep in mind that the reasons for that might not be obvious. E.g. there had been a fair amount of anti-Ukrainian propaganda on the Russian state TV (which broadcasted in Crimea as well) starting with 2000s or so.
Or here's a thought exercise, from another perspective: would you say if US made a poll in Monterrey (Mexico) about whether the people in there wanted to join US, and >50% of them said yes, it would have been justifiable (in at least some practical sense) to annex it? Or Montreal/Canada, for example. It's close enough to the border.
If you want to work for them, reach out to them. Maybe they need more people like us still :)
I was firmly planted in Malmö (3hrs train away) and had just signed to buy an apartment.
However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet.
I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytics.
That being said, knocking those two things off the board is a huge benefit to privacy and absolutely should be done.
..where?
Which realize, is 100% of what most people think about VPN's, a nasty side effect of dishonest marketing.
Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?
At which point your VPN becomes just another hop in the trace.
VPNs, no matter how secure they themselves are, are effective for accessing lightly geo-locked content and defeating unsophisticated analytics and tracking. They are really not a serious privacy solution in any sense, unfortunately.
/question from ignorance
If they merely monitor your computer and the end service, the correlation weakens a little with plausible deniability.
The real win is when the ISP adversary is monitoring your computer and the WG servers and NOT the end service. In that case, say they see you go to WG1, and then they see WG1 going to an end service. This is also correlation, and pretty undeniable. But say they see you go to WG1, then they see WG1 go to WG2, and they have no visibility of WG2's traffic. Then the tracking's broken; the footprints run off into the surf.
So multiple hops buy you defense in depth assuming it eventually gets you outside your adversary's monitoring range.
Circling back to this statement: aren't they also useful on public Wifi?
The most likely is that ISPs are just respecting the local laws, and doing the minimum retention as required by the law (because more data storage = more costs),
and that their actual fear is that someone leaks this data and causes reputation damage, so they'd avoid storing anything if they can.
1: https://www.bleepingcomputer.com/news/security/ftc-isps-coll... 2: https://surfshark.com/blog/isp-selling-data
Ehh, not really. China Telecom for example is 70% owned by the State. You aren't going to be able to buy shares in Parsnet.
Edit: u/progbits is 1 minute faster than me https://news.ycombinator.com/item?id=37060828
They didn't find anything of course (in the the system I was responsible for) beyond a couple of remarks (which I believe we had already explicitly marked with comments as they were marked for improvement by our static analysis tools; think "you can use a better variable name here" and "this can be simplified by using guard clauses" level). Not bad for something built under extreme circumstances and very little sleep (6-month-old-baby + COVID + crunch + 2 other busy young kids = hell).
I am thankful that Mullvad is doubling down on their commitment to integrity, because there isn't an alternative.
Edit: I just had a look through your post history and you seem to have been claiming this for months, without providing any evidence. Shady.
The trail is a rabbithole, and you might not be personally satisfied with the standard of evidence. Here is a start for you: https://news.ycombinator.com/item?id=23571653
Note in the link above [1] doesnt work anymore since Nord actually removed the product page for their white label product, but it does exist and you can see it in the Products dropdown as NordWL.
And since the link to [2] in what I linked above is broken, here is the archived version: https://archive.is/iZ2l2
There was definitely overlap between the companies (and tech), but, to my knowledge, that hasn’t been the case for several years now.
HN title stripping strikes again, OP can you please fix the title to correct the company name?
Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info).
Maybe I’m wrong someone pls lmk. But I’m not convinced a test of this calibre demonstrates Mullvads claims of no logging.
I believe it is relevant to the threat model of an attacker gaining (partial) access to a production server (eg no accidental logging), not to the threat model of mullvad deploying malicious code.
I feel like this is a meaningful audit but would have liked if they had stated this more explicitly
Mullvad is a nice middle ground for those who don't see that as worth their time or don't know how. Its good to see they're at the very least trying to keep up appearances.
I don't really see how it's more secure to run some software that you haven't audited on a VPS somewhere at a provider you haven't audited. I'd trust a company with resources to run their own hardware, investing into a more secure setup [1] and contributing to more open infrastructure [2] much more than I trust myself to run something securely which isn't my sole occupation.
[1] https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur...
[2] https://mullvad.net/en/blog/2019/8/7/open-source-firmware-fu...
1. |Router| -> Wireguard / OpenVPN -> |VPS|
2. |Device| -> Wifi -> |Router|
3. |Device| -> app -> |Mullvad|
= |Device| -> |VPS| -> |Mullvad| -> Internet
Can do various mixing and matching if you have more than one VPS. Again, it rearranges rather than removing the vulnerabilities, and it's pure window dressing against an organised, financed actor.
I've done this as an intellectual challenge more than anything else.
This could have led onto auditing a live server.
Auditing an in use customer facing server would definitely require a good amount of controls to ensure the auditors didn’t log any possible customer data.
I think they might have even spun this out into a separate project. With this, you can "trust" Mullvad that what's audited is really what you're using.
1. ensure that the company isn't misconfiguring things and accidentally breaking their own policies
2. provide a paper trail that would directly implicate people in the event of fraud, removing plausible deniability for the folks involved.
A self hosted VPS may also work if the company is small enough to avoid the coming BlanketBans, but only time will tell.
It should also be pointed out that OVPN[1] is an option as well. They were taken to court and won[2], so they demonstrated above all reasonable doubt that OVPN no-logging means no-logging.
See the link for the detail, but I quote: "the Rights Alliance and their security experts have not been able prove any weaknesses in OVPN's systems that could mean that logs are stored. "
[1]https://www.ovpn.com/en [2]https://www.ovpn.com/en/blog/ovpn-wins-court-order
Simple, buy the number of gift vouchers on Amazon that meets your budget.
There is no limit on the number of gift vouchers you can apply to a single account.
That being said, I wonder why we arent hearing about any cases involving them and cybercrime. Letter soup agency smear campaigns or actual cybercrime.
They operate totally in the clear as opposed to Tor and other overlay networks, but unlike with Tor, there are no "opinion articles" or biased news articles slamming them as pedophile enablers.
I just find this odd. /Paranoid schizo mode off
I expect VPN usage is easy enough to unmask by state level actors with timing attacks.
> Servers that ROS was given access to for testing purposes should be isolated from production data, but we found that the Wireguard host was receiving production user traffic via multihop configuration
Ouch
Deleted comment
Either way, if you don't trust them it hardly matters if your connection to their server is secure - they're the ones decrypting it!
Mullvad accepts my payment for a month of use at a time, and I manually renew it (after I receive a reminder) each month. If I don’t need a vpn the following month, I don’t pay for another month. I also find Mullvad works a bit better on Linux too.
I just got hit with a 2 year auto renewal charge from proton for my old proton account (email, storage, vpn) for roughly $200 with no email reminder. I thought I had cancelled the auto renewal, but I apparently hadn’t. When I went to cancel it after receiving the charge, the process was full of dark patterns and offers to continue my service, ending with the inability downgrade because it required me to manually delete emails for 30 minutes to free up storage to downgrade to the free account.
It feels like proton has shifted their focus to metrics and profit growth over user experience while Mullvad simply provides a great product with no trickery.
However, as soon as you downgrade the account yourself and cancel the subscription, we will automatically refund you for the unused time. The refund is automatically issued in the form of Proton credits which you can use for a Proton paid service in the future, or you can request the credits to be refunded back to your original payment method by contacting our support team: https://proton.me/support/contact.
> We cannot downgrade a subscription for you automatically, as only you can choose what data should be removed from your Proton account - it is impossible to downgrade the account to a Free subscription if it exceeds the limits of the Free subscription.
Add a button to delete all data in my account that appears when you tell me you can’t downgrade.
> The refund is automatically issued in the form of Proton credits which you can use for a Proton paid service in the future, or you can request the credits to be refunded back to your original payment method by contacting our support team
What is a proton credit? You chose to issue an unauthorized payment on my card in USD.
To summarize my experience, in order to cancel a subscription at the end of its period, one must:
- Set a reminder to cancel the subscription potentially years out because they cannot disable auto renew
Failing to cancel before being charged without a warning email, they must:
- Discover how to manually delete all of their files across various proton services to get their storage below a free tier threshold
- Email support to ask that their refund issued in proton credits be converted into their payment currency
- Respond to support’s email asking if they are sure they want a refund
Proton VPN is very questionable - sleuths have figured out that it's just a white-labeled version of NordVPN. But the trail is a rabbithole, and you might not be personally satisfied with the standard of evidence. Here is a start for you: https://news.ycombinator.com/item?id=23571653
And since the link to [2] in what I linked above is broken, here is the archived version: https://archive.is/iZ2l2
The only piece of evidence in your linked comment is the now defunct blog post: https://web.archive.org/web/20200629163107/https://vpnscam.c...
In addition to reading like it was written by an angry 12 year old, it makes some enormous logical leaps. The facts given are that Proton has an official legal entity in Lithuania called PROTONVPN LT, UAB, and another company called Tesonet shared Lithuanian offices and apparently some business services with them. The article claims that Tesonet is a "data mining company" based on the following evidence:
> Tesonet has its hands in “Machine Learning Solution, cybersecurity, and collection of business intelligence data” in efforts to create algorithms, that best suit their client business needs. If you read their about page, the company openly states it employs many different technologies to structure data, which is run on various services like MySQL, Anisble, collectd, StatsD, ElasticSearch, Grafana, Influx DB, Python, and Couchbase.
> ALL of these names rely on HEAVY USER INFORMATION, which makes sense, considering that Tesonet is a DATA MINING company. Now, let us not forget that Lithuania itself is a NATO member that regularly holds NAZI marches.
Let's just say that I'm not immediately convinced that Tesonet is in the business of selling user data.
The article also claims that in one online Lithuanian business services directory, the CEO of Tesonet was listed as the head of PROTONVPN LT, UAB. I have no idea of the legitimacy of this claim, but it stretches plausibility to claim that Proton is secretly not a Swiss company and secretly has a Lithuanian data mining company CEO as its head.
The article then goes on to make some completely unsupported allegations: "the real question is not whether ProtonVPN is working with Tesonet, but if the provider is owned by the data mining company" and "Under the name of a FREE VPN service, they’ve been collecting USER DATA all along."
Furthermore, the original source of most of this information actually comes from a Hacker News comment. The article links to a comment by the head of Private Internet Access! https://news.ycombinator.com/item?id=17258203
Unfortunately this gives the game away, because the comment is "retracted and removed by author's request". Dang comments:
> In addition to the redacting the above comment, we deleted several comments below by request of their authors. My understanding is that the dispute has been resolved and that the allegations are retracted.
In other words, it appears to me that the true source of these rumors has retracted them and no longer believes that Proton has the claimed ties to Tesonet.
Ironically, as a result of looking into this, I feel slightly more confident about ProtonVPN than I did previously.
Edited to add: you're also stretching even the blog post's unsupported allegations in your comment, when you say that ProtonVPN is "white-labeled" Nord. The article makes the unsupported insinuation that ProtonVPN and Nord are both owned by Tesonet, but this is different from the claim that ProtonVPN is just Nord repackaged as a different product, as you claim here.
I was nodding along, until this.
Seeing someone retract a pretty specific claim like that by calling on the admins to delete, instead of leaving it up for posterity and/or and discussing how they made the error, feels more like a legal threat was received, and some pants were shat.
Edit: To make this constructive, you could add why people think so and share a related link or something.
apart from the price (nordvpn is cheaper) can someone please help me make a decision if to switch or stay with nord?
based on the comments in the thread I assume mullvad is better in terms of privacy, security and probably more.
in addition, I don't use streaming services so the netflix selling point does not apply to me.
thanks in advance!
If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.
Exactly what the hell kind of magical knowledge does it take to compromise a VPN? They could own the thing completely.
If you ever find yourself thinking that massive intelligence agencies with budgets in the tens or hundreds of billions of dollars aren't doing anything and have no function, you've been watching too much TV news. If you think that governments require the magical knowledge of gods, wizards and aliens to compromise a VPN service, you've completely retreated into fantasy.
Its less "super top secret spy agency hires a hitman to take out Castro" and more "we're just going to throw whatever we can at the wall and see what works". Plans included literally mailing him exploding cigars (on the assumption that Castro liked smoking so mailing him one might just work), hiring his ex to try and kill him on a plane ride (which just resulted in the ex rebounding with Castro) and some campaigns to try and make him look weak that can only be described as "hilarious" like flying a plane over the country and dropping leaflets with a bounty of 0.02$ on his head with the idea that he was so weak that the bounty wasn't worth anything (although this one was rejected, they also attempted to make him look foolish by lacing a radio broadcast room with LSD).[1]
To pull a quote from Alan Moore: "If you are on a list targeted by the CIA, you really have nothing to worry about. If however, you have a name similar to somebody on a list targeted by the CIA, then you are dead."
[0]: https://en.m.wikipedia.org/wiki/Acoustic_Kitty
[1]: https://en.m.wikipedia.org/wiki/CIA_assassination_attempts_o...
Understand that direct contradiction is not terribly helpful, but this seems important so: no it isn't. (supported by years of public evidence, and also some personal experiences that I can't go into due to <reasons>).
The NSA was getting $10.5bn to spend in 2013[0]. I can only imagine it's gone up since then year on year. That's not a bad fraction when your whole goal is signals intelligence.
[0] https://www.washingtonpost.com/world/national-security/black...
You're the one making grand claims about the NSA controlling the world. It's a lot easier to argue with claims you made up.
(Based on the available data, not spending their budget on FT talent; they apparently get that with their logo.)
And the Best People aren't at FAANG. They are at hedge firms.
Mullvad never changes
Mullvad never is compelled to change by coercion
The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion
That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago.
All VPNs have this limitation. They’re just internet resellers that amusingly try to differentiate an audience based on privacy.
Are you even printing your own chip wafers?
Do you ever key your passwords outside places where you have total physical control?
On that note, do you let your love person stay over for the night (have physical access to your flat)?
Your incompetent and flabby security posture makes me want to puke. At the very least, admit that your security posture is „typical educated HN reader“ and you’re not serious, so the rest of us can continue on our business without your mind numbing puerile distractions.
[okay that rant was really just a „holier than thou“ parody about how if you’re going to maintain a security posture that’s more tense than 90% of your peers, at least acknowledge what threat model you espouse and acknowledge that others may have a different one. If you had been like: „is this your threat model? Then why don’t you care about this…“, you would have my upvote not my snark. Even if that weren’t my threat model I would have found that exposition commendable.]
What investment do you have in people trusting VPN providers that would cause you to make an argument like that? I bet none, it's just a bad instinct.
I didnt expect the sarcastic tone of responses but I also dont understand why people act like sports team fans of VPN providers. there are other solution, easily accessible, that do more than VPNs can do, depending on your threat model
a VPN user that supposedly just wants to avoid adtech tracking doesnt need annual audits about how little data one VPN stores over the other
Even if you have built that thing, you can't trust any semi-capable chip to not log, change, or exfiltrate data in any way possible.
So, the hole has no bottom.
I don't know whether I can trust the company which made it.
there are options to have privacy from additional kinds of parties. i2p, tor. whonix distribution of linux, tails…
Edit: Also, questioning trustworthiness of VPNs and them putting them forward as a solution is... a bit unorthodox.
They're not. Spectrum is my true adversary. My VPN may also be an adversary but that's a possibility, whereas Spectrum is a certainty.
like ones you pay to use their VPN servers...?
In the U.S, VPNs are not effective against targeted surveillance. But they very well may be effective against government passive surveillance programs like the President’s Surveillance Program.
The Snowden leaks revealed many things. What stood out most to me about them was that the government _tried_ to stay within the confines of the law. It was a very twisted, contortionist, interpretation of the law, but they did try very hard to stay within the bounds of the legal theory that allowed the program to exist.
Based on the leaks, if you’d have been running HTTPS over a VPN during the PSP, it’s likely a good portion of your traffic would have evaded the program.
I am worried, at least a little bit, about an authoritarian government coming to power and basically weaponizing past data collected against it's citizens. I've seen the inferences facebook and google can make with privately collected data. I don't think it's too outlandish that governments would be able to quickly and easily create detailed dossiers on everyone that protested against x or voted for opposition candidate y.
this attracts people that want a subpoena to yield nothing
I can think of at least one.
Unless you're de-facto part of the government like Google and Microsoft - I see no good reason to log anything more than what's legally required.
1. Browsing habits would hardly have an affect on the vast array of data to have an effect on ads presented to you, unless you care about your privacy. Its all target auidence and marketing (look at ExpressVPN or Surfshark. They all offer privacy but never follow up)
2. Their algorithms can avoid showing you ads derived from the VPN if it detects the usage of your actual IP
I don't know if they are logging or not. They say they aren't. The audit says they didn't see evidence that they are.
It's impossible to prove a negative.
actually a very interesting experiment
It's quite common for servers to boot from the network and have no disk, and have application logs actually sent to a log server via http/udp [0].
[0] For example: https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/HECE...
I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0].
[0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
Note also, that the case pertains to Proton Mail, and not Proton VPN. Proton Mail is considered to be a communication service, and in most countries (including Switzerland), communication services are regulated to some extent. The treatment of VPNs is different. There are no Swiss laws compelling us to log IP addresses, personal identifiers, traffic or browsing history, as proven in a 2019 legal case (we were not able to provide the requested information because we don't keep any: https://protonvpn.com/blog/transparency-report/).
I guess it's handled by this finding in the audit:
“VPN servers accept remote logins from administrators, who technically have the ability to tap into production users' VPN traffic”
https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec...
In short, they immediately and helpfully complied with police... by letting them know they did not store any data about customers whatsoever.
They literally had no choice, it was a court order.