4 ms·
Right -- I'm looking for a white-paper level of detail somewhere behind the landing-page level of detail. What threats (internal and external) did you consider,
by JackC 8y ago
Right -- I'm looking for a white-paper level of detail somewhere behind the landing-page level of detail. What threats (internal and external) did you consider, what evidence convinced you they were addressed, and what acceptable risks remain? What would you as an engineer want to be told by another engineer who did the audit, for you to say "great, that's what I would have done, sounds like you did your due diligence, I'll use that"?
The white paper won't be read by everybody and shouldn't be targeted at everybody, but it will be read by the most knowledgeable folks and be a source of confidence that filters out to everyone else.
This all depends on there actually being an audit -- so far the landing page doesn't even say that! From the text on the page there's no way to tell if Mozilla just read the published policies for a bunch of VPNs and made a recommendation, or has an employee embedded in ProtonVPN's security team and a seat on the board, or somewhere in between. Without knowing the details, it's hard for me to say whether I'm looking for more documentation of the audit that already happened, or a stronger actual relationship behind the endorsement.