https://news.ycombinator.com/item?id=36113215
They also work with Tailscale which makes per-device setup easier: https://mullvad.net/en/blog/tailscale-has-partnered-with-mul.... Tailscale was using a bit too much of my iPhone battery last I tried it out, but they're at least aware of it.
They have a good record of responding to various restrictive legislation around the world (eg pulling out of Italy after they passed an overly broad 'anti-piracy' law) and also haven't had any open scandals. That's about as good as I can really expect considering that I'm mostly just not interested in my local ISP knowing what I'm up to, and am not doing anything hugely illegal or pirating at a large scale.
For reference, the VPN I used before then offered no real controls besides a limited country selection and a randomly assigned port forward. It was bought up by a company owned by a guy known for running scams, after which I switched out. Now having seen all the customization I was missing out on, I can't really go back to a simpler VPN.
Our iOS users also report random delays turning it on, sometimes half a minute to connect. Sometimes full restarts are needed before connect.
And random ask -- could you enable a toggle for video conferencing to stay outside the tailnet? Teams, Zoom, WebEx, etc... You'd have to take on maintaining the IP lists, so users didn't have to. (This can be done today with features you have, but most users and even IT admins don't realize that.)
I set up wireguard and unbound on VPS in Amsterdam and share with 10-15 people by posting wireguard config in private telegram channel.
Ironically enough, but I block porn access using StevenBlack hosts converted into Unbound config by awk script, so porhhub dot com will return REFUSE dns response from unbound.
I know, that is not impressive idea of how to utilize computing power of the VPS, but I also used it for running tor snowflake (disabled because of eating too much ram), running tor obfs4_proxy (would also eat much ram, but that can be adjusted, I don't remember clearly why I disabled it at one point) and I used it as a server for Postgres that I tried to use for uni's coursework on databases.
Maybe I am too lazy to setup tools like zapret for bypassing deep packet inspection locally on my laptop or on router. But still there should be a ton of things that can be done on the same vps.
For bypassing Sharia-state firewalls like Texas', any VPN provider should be good enough, but GP is asking for recommendations for providers who can be trusted to ensure privacy.
If it is for more regular use or if the occasionally slowness/vpn blocking is too much, I would likely pick mullvad but I have not used their services. They do seem to spend some money on pro-privacy activism, so that is at least a point in their favor.
I set up an OpenVPN server on DigitalOcean for a friend visiting China. It took 10 minutes with the template in the DO marketplace.
It even allows downloading a client with the parameters baked in.
It’s not for every use case, but it’s helpful for me.