122 karma · joined January 3, 2025
My Mullvad comparison was focused on the credential, not on the LAN model. Brute forcing the account was never the issue, I missed the point about device-to-device was the real threat, fair point. I'm starting implementing LAN connections as opt-in, not default.
Second point, you're also right, because I was mixing prevent and identify, preventions shouldn't need logs, we can't take an IP address and a timestamp and attach a user to it, and the AUP imply something else, I'll rephrase this.
on the local network point, thats only your own devices seeing each other. traffic between different customers is blocked.
logs, our thing is reactive, we're not sitting there watching everything. we act when we get an abuse report. some of it is just blocked structurally anyway, port 25 is closed so no spam is coming out of there. and we keep zero logs. child abuse material, account gets terminated if we get a credible report or a legal notice, but we dont proactively scan, thats not really possible when the traffic is encrypted and theres nothing logged to scan in the first place. the only thing counted is aggregate bytes per account for the quota and the trial. not what, not where.
and honestly, this is a one person project. code needs cleanup, secrets and config need to come out, and it needs a proper security pass before its safe to publish.