Why can't it aim to solve what it can do? TOR is a great example: the TOR network itself can't perfectly anonymize you due to browser fingerprinting, but users of the TOR Browser get both the TOR network resisting deanonymization on a network level and a browser with plenty of anti-fingerprinting measures built in. A VPN could aim to prevent deanonymization on a network level so that users who want to stay anonymous can use the VPN in combination with fingerprinting-resistant software.
The fact that Tor does not intend to tackle the timing problem is plainly stated on the Tor website.
> Tor does not intend to tackle the timing problem [as] plainly stated on the Tor website.
then that's not how I read the above claim about Tor "having been deanonymized". Yes, yes, it strictly fits within the meaning of what you wrote, but it's like saying bread has been made free before because someone found a place where they could plant wheat seeds and chop trees to bake it without having to pay for using the ground and wood: there is a roundabout way of getting there but it's not true in the common case (you can't just do this for everyone at will)
https://www.schneier.com/blog/archives/2013/12/tor_user_iden... https://www.schneier.com/blog/archives/2024/10/law-enforceme...
If law enforcement can do it, then intelligence agencies and anyone with a similar budget can do it.
I did not say there is an easy exploit available that anyone can use or that attacks have a 100% success probability.
"The FBI didn’t have to break Tor; they just used conventional police mechanisms to get Kim to confess."
Second link:
"From the limited information The Tor Project has, we believe that one user of the long-retired application Ricochet was fully de-anonymized through a guard discovery attack. This was possible, at the time, because the user was using a version of the software that neither had Vanguards-lite, nor the vanguards addon, which were introduced to protect users from this type of attack. This protection exists in Ricochet-Refresh, a maintained fork of the long-retired project Ricochet, since version 3.0.12 released in June of 2022."
Did you even read those links?
If I'm on a public VPN, I don't want anyone to know who is making the request, including the terminating IP.
Think about it. By your logic, VPNs shouldn't be used for torrents because VPNs shouldn't anonymize you to the terminating IP. Whereas they work gangbusters for that.
If you are talking about private VPNs.. Mullvad isn't one.
But today’s internet is essentially a giant ad network.
Privacy = hide what I am doing
Anonimity = hide who I am
If site A and site B share some backchannel, then they can share what I was doing on their site, but aside from "this person is on Mullvad endpoint A1", they can't infer who I am[0]. To those sites, I am anonymous but not private.
On the other hand, to my ISP, I am private but not anonymous. They can see a tunnel originating from my home IP to Mullvad, so they know exactly who is connecting to Mullvad. But they don't know what I am doing inside that tunnel or where it leads beyond Mullvad.
That is the whole crux of a public VPN. The ISP doesn't know who to tell who I am, and the sites (and other terminating IPs) don't know who to tell what I'm doing, because the VPN breaks the chain in both directions.
So, if you torrent a movie illegally, the movie studio can only send an angry letter to Mullvad about someone on endpoint A1 torrenting their movie at 22:34. If it were possible for them to tell your ISP that you downloaded something illegally (privacy, the what), your ISP would have to give your address to the movie studio for a settlement fine (anonimity, the who).
It is kind of hilarious I am at -3 when parent is still in the positive, when he is so utterly wrong. But that's modern HN for ya.
[0]Fingerprinting obviously can throw a spanner into that, but that has nothing to do with the VPN. And it can be mitigated.