19 ms·
Infrastructure audit completed by Radically Open Security
- dijit 3y agoMy biggest professional regret is not joining Mullvad when their founder emailed me. A seriously large chunk of their values aligns with my own, and it's woefully few technical enthusiasts that continue to place liberty over convenience -- meaning most of us tend to use hyperscaler cloud providers under the purview of the US Government. -- and before anyone mentions it; yes that has been an issue for me in my professional career as the cloud providers must adhere to US sanctions, meaning if you are from Cuba, Iran or Crimea you can't play the games I made. -- which is annoying because you could buy our game legally in Russia and Ukraine, but if you happened to be in occupied territory then no play time for you. Sidetracked a bit, but it's really refreshing from the outside to see a company that isn't scummy that values liberty.
- rvnx 3y ago[flagged]
- lnxg33k1 3y agoWhat are you doing about western governments pursuing journalists who reported war crimes in iraq? This moral superiority about expecting people from other places to do what we don’t would be hilarious if it was completely outrageous We’re expecting normal people to stand up against armed regimes while around the world our governments commit the worst human crimes while we’re zapping on netflix I have absolutely no words, I’m terrified
- apples_oranges 3y agoIf you tallied it all up in an excel sheet you would probably be shocked about the abuse going on “here and there”
- dijit 3y agoThe world is not as black and white as you paint it, taken from an outside perspective the US has also done many things that we would likely go to war for if it was anyone else, including chasing journalists across borders, forcing down diplomatic aircraft and spying on allied governments (Merkel in particular). Regardless; your enemies are not my enemies. Even then: Sanctioning occupied territories only serves to push the occupied territory further into the occupiers hands.
- dancemethis 3y agoI mean, I'm super against supporting hostile government countries, but a lot of stuff is made in the US. It's hard to avoid money going there.
- jasonvorhe 3y agoHostile to Western interests. Sanctions are nothing but legitimatized bullying of the strong over the weak. Thanks, but not. Multi-polarity is coming.
- apples_oranges 3y agoIsn’t trading with certain states like sanctioning of how they treat their population? Withholding trade seems fair. We don’t want to deal with you because you start murderous wars for example seems fair. As for “multi polarity”.. seems so far like the catchphrase of shitty governments and unhappy people here that dream of some radical change.. It’s a false word somehow
- rvnx 3y agoThe only time I've heard the expression about multipolar was from Chinese and Russian Foreign Minister playbook. Add "NATO", "Russophobia", "Nazis", "Western" and other keywords in the soup and you have the perfect anti-Western speech. It's not even a Western tool. Sanctions are a tool to refuse to trade with opponent regimes, and it works both ways (China has sanctions on the West too, for example on semiconductors. Russia has sanctions too against the West). It's not perfect, and it has side-effects, but overall it deters other countries / terrorist organizations to follow the same path of taking an hostile posture against you. If you let people go around sanctions, then becoming hostile will simply have no consequences. If there are no consequences to actions, and there is a big prize to win, then the politics will do it, no matter what.
- jasonvorhe 3y agoIf all you read is propaganda by one empire or another, it's no wonder you immediately associate a term with propaganda. https://en.wikipedia.org/wiki/Polarity_%28international_relations https://en.wikipedia.org/wiki/Polarity_%28international_rela... Interesting quote: > In April 2023, the Australian government released their 2023 national review where it is outright stated that the age of American unipolarity and primacy in the Indo- Pacific is effectively over, paving way to great power competition and a more fractious world order. It's new to me that Australia is known to spread Russo-Chinese propaganda either.
- unixhero 3y agoIt is probably not too late
- codetrotter 3y agoLast time I was in Gothenburg in Sweden, about one year ago, I even saw advertisements on the trams about Mullvad hiring people. If you want to work for them, reach out to them. Maybe they need more people like us still :)
- euazOn 3y agoSidenote: I know a bunch of people from Crimea and many things we take for granted are surprisingly complex for them. People from Cuba or Iran at least have the certainty of which country they are in.
- varispeed 3y agoCrimea is in Ukraine.
- dijit 3y agoYet, if you lived there you would be issued a Russian passport, your official documents would be from the Russian state; your police would be Russian. And; if you lived in Laos, Cuba, Cambodia or Afganistan: you would currently be taking the opposite stance. We owe it to ourselves to not permit the affectations of propaganda to convince us that we are consistently right, the truth on the ground is much more complicated. I certainly believe Crimea is an invaded territory of Ukraine, but I cannot pretend that it's a wise notion to demerit the entire conflict down to "Crimea is in Ukraine". It does nothing to help the people there, and is completely meaningless in the face of my initial comment: that while I could sell games to Ukrainians, I could not allow them to play from within Crimea... a territory you claim; is Ukraine. The implicit argument you just made is that we have created sanctions against Ukraine itself.
- Entalpi 3y agoCrimea is de jure in Ukraine per international consensus. Crimea is de facto occupied by Russia. These are orthogonal statements are both valid. Everything else you listed derives from these premises.
- varispeed 3y ago[flagged]
- leesalminen 3y agoAre you saying these passports can’t be used for travel? If they weren’t, then why would anyone bother going to get one?
- GoToRO 3y ago[flagged]
- pc86 3y ago"The people" value different things depending on who they are. I'm sure you can find Russians who value liberty and peace, and I'm sure you can find Americans (or Germans, or Canadians, or Australian Aboriginals) who don't.
- GoToRO 3y agoYrs, there are russians that value liberty, I'm just dissapointed by how few there are.
- antihero 3y agoBit of a generalisation there, how many of us in the west were against and protested against the various wars we’ve been involved in and been basically just ignored because the government just does what it wants?
- GoToRO 3y agoNot many but two wrongs don't make a right.
- dijit 3y agoI am speechless; I can think of a dozen or so glib responses to put down this line of reasoning in a combative way. I will do my best to go against that instinct and instead say; 1) I don't believe necessarily that Crimeans are "Russian" 2) I don't believe that we can talk about a countries people as being homogeneous. 3) I don't believe we should be deciding what liberty people should be entitled to, that feels decidedly totalitarian to me, it would be very easy to decide that you dear reader are not entitled to liberty either, since you implicitly support *gestures broadly*.
- GoToRO 3y ago
- vasco 3y agoI also got upset when I had to implement geoip tracking to block specific countries and thought about the people that wouldn't have access to the free service we were providing, which I thought could help someone bootstrapping their small business and potentially improve their lives. That being said, many people consider sanctions as an act of war[0] and if you think of them like that, well obviously it sucks, it's war and war-like consequences always suck for the people on the ground. Just make sure when your boss asks you to implement geoblock bans for sanctions, do what you need to do and not more like trying to block VPN users or other shenanigans. Don't break the law but don't make it harder for people on the ground to use their right to internet access. [0] https://moderndiplomacy.eu/2022/06/29/economic-sanctions-as-an-act-of-war/ https://moderndiplomacy.eu/2022/06/29/economic-sanctions-as-...
- PentiumBug 3y agoYup. As a Cuban, sometimes it is annoying and sometimes go beyond that. Some cloud providers are totally off limits for us, some are fine with us (the minority and less known), some let us use some services but no others, some even have valid OFAC licenses but still deny access (because ACL complexities, I suppose)... it's all over the place. That's why I'm 95% of the time on crappy VPNs both to escape/evade US sanctions and my own country censoring mechanisms. The thing is, I somewhat understand why the sanctions were placed decades ago, but... is that rationale still valid? Anyway, and sadly, the sanctions affect "regular" people like me the most. The ruling elite? Not at all. Thank you for your position, BTW!
- leesalminen 3y ago> Anyway, and sadly, the sanctions affect "regular" people like me the most. The ruling elite? Not at all. This confirms my secondhand knowledge of financial sanctions. It seems to universally be this way and makes me wonder why we still tout them as if they were effective. They sure don’t seem to be.
- actionfromafar 3y agoThat’s a very broad statement, almost automatically untrue. All countries, all situations, all financial sanctions?
- pessimizer 3y agoIt obviously isn't too broad, because instead of this comment you could have posted a single counterexample to disprove it.
- actionfromafar 3y agoThe onus isn’t really on me, I’m not the one making blanket statements.
- GoToRO 3y agoThe idea is that "the many", the poor, will overthrown the elite.
- 2OEH8eoCRo0 3y agoWhat caused you to pass on that opportunity?
- dijit 3y agoIt was before (or during the beginning of) COVID and it required on-site in Gothenburg. I was firmly planted in Malmö (3hrs train away) and had just signed to buy an apartment.
- worldsayshi 3y agoFYI it seems they are still looking for people. They are advertising on buses here in Gothenburg.
- sneak 3y agoThought experiment: design an architecture that passes this audit scope as written that allows for logging of user activity. I can think of at least one.
- jiehong 3y agoLike sending logs over the network? It's quite common for servers to boot from the network and have no disk, and have application logs actually sent to a log server via http/udp [0]. [0] For example: https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/HECExamples https://docs.splunk.com/Documentation/Splunk/9.1.0/Data/HECE...
- drexlspivey 3y agoThought experiment: build your own VPN company that doesn't log anything and try to convince people like you that you don't do any logging
- zirgs 3y agoIf you don't do any logging and don't want to know what your users are doing - it means that you won't have to deal with the cops as much. And there won't be any risk of those logs getting leaked or stolen . Unless you're de-facto part of the government like Google and Microsoft - I see no good reason to log anything more than what's legally required.
- radicalriddler 3y agoPicked up Mullvad a couple months ago, I love it's concept of just paying for the time I use.
- gorbypark 3y agoIs that an option? I've been paying 5 euros a month for a number of years and probably use it for 10 minutes a month, on average. I would love to just plunk down 20 euros and be good for the foreseeable future, if it was a couple cents per minute.
- OJFord 3y agoIt's not on the pricing page (I was surprised too) - I think maybe GP means that it's rolling monthly, and that they no longer do card subscriptions (on a pro-privacy stance, not wanting to store them, Know their Customer, etc.) so you can pay (say, Amazon) for the time (1 month, 94 months, however many months) you need.
- traceroute66 3y ago> I would love to just plunk down 20 euros and be good for the foreseeable future Simple, buy the number of gift vouchers on Amazon that meets your budget. There is no limit on the number of gift vouchers you can apply to a single account.
- stjohnswarts 3y agoI just send them enough cash for a year at a time. No issues yet. I suppose there is a chance someone grabs it out of the mail but I'm willing to risk it.
- gorbypark 3y agoBut it's still 5 euros a month, right? I thought OP was saying there was some sort pay by the minute/hour/day pricing.
- 3y ago
- progbits 3y ago> by Radically Open Security HN title stripping strikes again, OP can you please fix the title to correct the company name?
- Aachen 3y agoTitle is missing the word "Radically". I didn't know "Open Security" but "Radically Open Security" is the place I've written a thesis at Edit: u/progbits is 1 minute faster than me https://news.ycombinator.com/item?id=37060828 https://news.ycombinator.com/item?id=37060828
- radicalbyte 3y agoOne of the projects I worked on a couple of years ago was audited by Radically Open Security - I was extremely impressed with the quality of their specialists. They didn't find anything of course (in the the system I was responsible for) beyond a couple of remarks (which I believe we had already explicitly marked with comments as they were marked for improvement by our static analysis tools; think "you can use a better variable name here" and "this can be simplified by using guard clauses" level). Not bad for something built under extreme circumstances and very little sleep (6-month-old-baby + COVID + crunch + 2 other busy young kids = hell).
- brapachin 3y agoIt appears in this audit. They only reviewed test production servers. Playing devils advocate, what would be stopping Mullvad from providing the Open Security team with a version of Mullvad stripped of logging features? I hate to be this skeptical, but shouldn’t an actual audit review customer facing servers (within bounds to prevent the auditors from logging info). Maybe I’m wrong someone pls lmk. But I’m not convinced a test of this calibre demonstrates Mullvads claims of no logging.
- nemo8551 3y agoI would have liked it if the audit had also provided a number of logins to be used on that server to act like typical users. Just so it was operating as a normal server would. This could have led onto auditing a live server. Auditing an in use customer facing server would definitely require a good amount of controls to ensure the auditors didn’t log any possible customer data.
- amarshall 3y agoIt wouldn’t make that much of a difference, I think, since they could just do the same with the real servers but only for the period of the audit. There has to be some faith that the subject isn’t actively deceptive and malicious, or the audit has to be random and at any time.
- stonepresto 3y agoAt some point of paranoia people should really look into selfhosting a VPN service. Sure, your VPS provider can see one side of the traffic so its not bullet proof, but that can be mitigated. Mullvad is a nice middle ground for those who don't see that as worth their time or don't know how. Its good to see they're at the very least trying to keep up appearances.
- dewey 3y agoI doubt that's the better way. How is self-hosting helping with the paranoia vs. using Mullvad? I don't really see how it's more secure to run some software that you haven't audited on a VPS somewhere at a provider you haven't audited. I'd trust a company with resources to run their own hardware, investing into a more secure setup [1] and contributing to more open infrastructure [2] much more than I trust myself to run something securely which isn't my sole occupation. [1] https://mullvad.net/en/blog/2022/1/12/diskless-infrastructure-beta-system-transparency-stboot/ https://mullvad.net/en/blog/2022/1/12/diskless-infrastructur... [2] https://mullvad.net/en/blog/2019/8/7/open-source-firmware-future/ https://mullvad.net/en/blog/2019/8/7/open-source-firmware-fu...
- yieldcrv 3y agoYou’re still trusting that Mullvad never changes Mullvad never is compelled to change by coercion The data center Mullvad uses - a separate company - never compromises them out of curiosity, preference, coercion That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. All VPNs have this limitation. They’re just internet resellers that amusingly try to differentiate an audience based on privacy.
- Jolter 3y agoWhich data center company do they use?
- blfr 3y agoAt least for the DC compromise, you can multihop through servers from different providers.
- r3trohack3r 3y ago> That governments skip the private sector coercion entirely and just add their own devices and logging in the middle, which came out of the Snowden leaks as normal 10 years ago. In the U.S, VPNs are not effective against targeted surveillance. But they very well may be effective against government passive surveillance programs like the President’s Surveillance Program. The Snowden leaks revealed many things. What stood out most to me about them was that the government _tried_ to stay within the confines of the law. It was a very twisted, contortionist, interpretation of the law, but they did try very hard to stay within the bounds of the legal theory that allowed the program to exist. Based on the leaks, if you’d have been running HTTPS over a VPN during the PSP, it’s likely a good portion of your traffic would have evaded the program. https://everytwoyears.org/2020/07/13/tactical-privacy.html https://everytwoyears.org/2020/07/13/tactical-privacy.html
- puppymaster 3y agoHence the archive records of their yearly audit dating back to their founding year.
- bayindirh 3y ago
- deleted 3y ago[deleted]
- gigatexal 3y agoI switched to Mullvad after teh last article i read here on HN about how they didn't log and couldn't offer logs to the authorities. I don't have the link but I was impressed and these audits are further proof that that decision was correct.
- traceroute66 3y ago> I switched to Mullvad after teh last article i read here on HN about how they didn't log and couldn't offer logs to the authorities It should also be pointed out that OVPN[1] is an option as well. They were taken to court and won[2], so they demonstrated above all reasonable doubt that OVPN no-logging means no-logging. See the link for the detail, but I quote: "the Rights Alliance and their security experts have not been able prove any weaknesses in OVPN's systems that could mean that logs are stored. " [1]https://www.ovpn.com/en https://www.ovpn.com/en [2]https://www.ovpn.com/en/blog/ovpn-wins-court-order https://www.ovpn.com/en/blog/ovpn-wins-court-order
- waithuh 3y agoFYI their monthly subscription doesnt have multihop and thus offer an easier avenue for metadata matching
- burnaway 3y agoOVPN was recently bought by the parent company of HotSpotShield. Make of that what you will. https://www.ovpn.com/en/blog/next-chapter-for-ovpn https://www.ovpn.com/en/blog/next-chapter-for-ovpn
- 2-718-281-828 3y agoany competent opinions on protonvpn vs mullvad vpn?
- salad-tycoon 3y agoThere is a pretty heavy bias against proton anything here, imo. They are seen as a marketing company is my interpretation of the sentiment.
- sdfzguf 3y agoIf you experience something, it's already subjective. No need for the "imo" -escape. Same goes for sentiment. The sentiment is already what you observed, no need to further interprete that. Just share what you see. This is overly careful to a point where it almost lacks any content. Edit: To make this constructive, you could add why people think so and share a related link or something.
- stOneskull 3y agothey're a bit lazy on their linux software. you have to a little hacking for the vpn to work nicely, like just having a systray icon.
- buzzy_hacker 3y agoI think those two are the most reputable VPNs. I’ve used ProtonVPN for years just since I wasn’t aware of Mullvad at the time and can’t be bothered to switch. I believe ProtonVPN hasn’t had infrastructure audits, which Mullvad has had.
- deleted 3y ago[deleted]
- sotix 3y agoBoth are fine for vpn performance. However, Mullvad has won me over with their business practices. Mullvad accepts my payment for a month of use at a time, and I manually renew it (after I receive a reminder) each month. If I don’t need a vpn the following month, I don’t pay for another month. I also find Mullvad works a bit better on Linux too. I just got hit with a 2 year auto renewal charge from proton for my old proton account (email, storage, vpn) for roughly $200 with no email reminder. I thought I had cancelled the auto renewal, but I apparently hadn’t. When I went to cancel it after receiving the charge, the process was full of dark patterns and offers to continue my service, ending with the inability downgrade because it required me to manually delete emails for 30 minutes to free up storage to downgrade to the free account. It feels like proton has shifted their focus to metrics and profit growth over user experience while Mullvad simply provides a great product with no trickery.
- YPPH 3y agoMullvad looks like one of of the best VPN providers out there. However the use of a customised Linux Kernel and Ubuntu distribution gives pause for thought. Are they going to be able to integrate security patches quickly? Wouldn't it be better to use a standardised security focused OS?
- dontupvoteme 3y agoGiven that it's in the West I still think it's probably NSA compromised, but I'm not nearly important enough for the government to blow their cover about.
- p-e-w 3y agoThat's tinfoil hat nonsense. The NSA aren't gods, wizards, or aliens. They don't have the best people (those are mostly at FAANG), and their total budget is a fraction of Big Tech's. If you ever find yourself assuming that the NSA/CIA/etc. have magical knowledge that's decades ahead of everyone else, or have "assets" in every village on Earth, you know you've been watching too much TV.
- robertlagrant 3y ago> their total budget is a fraction of Big Tech's The NSA was getting $10.5bn to spend in 2013[0]. I can only imagine it's gone up since then year on year. That's not a bad fraction when your whole goal is signals intelligence. [0] https://www.washingtonpost.com/world/national-security/black-budget-summary-details-us-spy-networks-successes-failures-and-objectives/2013/08/29/7e57bb78-10ab-11e3-8cdd-bcdc09410972_story.html https://www.washingtonpost.com/world/national-security/black...
- p-e-w 3y agoVolkswagen's research budget was $21 billion in 2022. $10.5bn is nothing in the big picture, and certainly not enough to "control the world" or whatever grand claims are commonly made about the NSA.
- robertlagrant 3y agoNo one said control the world. Just that a VPN provider is probably compromised by the NSA.
- pessimizer 3y agoDo you think Volkswagen could compromise or secretly own a VPN service? You're the one making grand claims about the NSA controlling the world. It's a lot easier to argue with claims you made up.
- stonepresto 3y agoUp front, I believe Mullvad is the best commercial VPN solution and is doing a great job at making good privacy more accessible. However, a lot of the comments here seem to be hailing VPNs in general as the solution to privacy on the internet. I would like to remind people that VPNs only really protect you against two things: your ISP and the endpoint. And that's assuming that your ISP isn't doing some shady analytics. That being said, knocking those two things off the board is a huge benefit to privacy and absolutely should be done.
- wwfredrogersdo 3y ago> that's assuming that your ISP isn't doing some shady analytics Can you elaborate on this? So ISPs often engage in tactics that thwart VPN usage? Which ISPs? What tactics?
- rvnx 3y agoWhy would they even do so ? Large ISPs are public, so this activity would appear as extra revenue (if they sell traffic data) in their financial reports and annual reports. The most likely is that ISPs are just respecting the local laws, and doing the minimum retention as required by the law (because more data storage = more costs), and that their actual fear is that someone leaks this data and causes reputation damage, so they'd avoid storing anything if they can.
- mattlutze 3y agoISPs are also in the business of analytics [1, 2], and a significant percentage of customers hiding their traffic reduces the value of their analytic products. 1: https://www.bleepingcomputer.com/news/security/ftc-isps-collect-and-monetize-far-more-user-data-than-you-d-think/ https://www.bleepingcomputer.com/news/security/ftc-isps-coll... 2: https://surfshark.com/blog/isp-selling-data https://surfshark.com/blog/isp-selling-data
- drpossum 3y agoThis view is extremely western, not all ISPs are obligated to show "financial reports", and "shady analytics" does not imply a user's complete network traffic record into perpetuity. And even if your arguments were valid, this is not limited to the ISPs financial gain, but surveillance which occurs in every country.
- pelasaco 3y agoThen when audit team is gone, they enable user logging. I think thats a possibility in every provider. IMO based on the transparency they handle police requests to get access emails, I will keep using protonvpn.
- procone 3y agoSource? They've always been logless. I think you have this completely backwards considering Proton maliciously logged and handed out customer IPs to police [0]. [0]: https://techcrunch.com/2021/09/06/protonmail-logged-ip-address-of-french-activist-after-order-by-swiss-authorities/ https://techcrunch.com/2021/09/06/protonmail-logged-ip-addre...
- hu3 3y agoAnd how does Mullvad deals with court orders? I guess it's handled by this finding in the audit: “VPN servers accept remote logins from administrators, who technically have the ability to tap into production users' VPN traffic”
- _joel 3y agoIf your treat assessment involves this, you're probably best not using a $5 a month VPN.
- karaterobot 3y agoHere you go: https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subject-to-a-search-warrant-customer-data-not-compromised/ https://mullvad.net/en/blog/2023/4/20/mullvad-vpn-was-subjec... In short, they immediately and helpfully complied with police... by letting them know they did not store any data about customers whatsoever.
- flangola7 3y ago>maliciously They literally had no choice, it was a court order.
- stOneskull 3y ago
- yellow_lead 3y ago> These servers were deployed as though they were to be production customer-facing servers, however these servers have never been utilised as such. > Servers that ROS was given access to for testing purposes should be isolated from production data, but we found that the Wireguard host was receiving production user traffic via multihop configuration Ouch
- deleted 3y ago[deleted]
- bspammer 3y agoFWIW you can look at the network traffic in your browser devtools and verify that only the public key is being sent to them. You can even hit their API endpoint with the public key you want to add manually, I just tried it and it worked. Either way, if you don't trust them it hardly matters if your connection to their server is secure - they're the ones decrypting it!
- smartbit 3y agoAs ivpn's gateway in Brussels is more often than not 100% [0] during the evenings, I'm looking for an alternative. This wasn't the case until some 6-12 month. Anyone experience with mullvad's [1] throughput in Belgium? [0] https://www.ivpn.net/status/ https://www.ivpn.net/status/ [1] https://mullvad.net/en/servers https://mullvad.net/en/servers
- burnaway 3y agoThis is Viktor from IVPN. We have recently added more capacity to our Belgium server. I'm looking at our internal graphs and it has not been hitting 100% in the past couple of days. We are monitoring it closely and ready to add more bandwidth if necessary.
- smartbit 3y agoThank you Viktor. Keep up the good work.
- f_m 3y agoI'm a little hesitant to say the following, since I don't collect metrics, and thus it's maybe a bit unfair on Mullvad, but: sometimes the Belgian Mullvad locations can be a bit slow. I've had that feeling from time to time, and on a few occasions when switching to their Netherlands locations I get better speed. Right now for instance I get close to full theoretical speed as promised by my ISP while going through Mullvad Netherlands, and only a quarter of that speed through the Belgian locations.
- Tenoke 3y agoI have PIA paid until December but I'm getting so many captchas with them that I've been seriously considering paying for Mullvad, too. Glad to see people are still happy with them so I can go ahead.
- ibejoeb 3y agoI don't want to discourage you from using Mullvad, but there are lots of captcha and cloudflare problems there, too. I consider it a cost of doing business.
- stjohnswarts 3y agoYou'll get captchas with any VPN provider these days. Cloudflare is taking over my friend.
- digging 3y agoThere are other reasons to stop using PIA, for example they got purchased in 2019 by Kape Technologies which is quite shady.
- BoppreH 3y agoI really respect how Mullvad is willing to sacrifice business to give extra security and reliability to the (remaining) customers. I first saw it when they disabled auto-renewal with PayPal, because it'd force them to store PII along with your account. Unfortunately for me, they made one too many sacrifices, and disabled port forwarding[1]. They don't store any contact information that could be used to warn customers, so my connection mysteriously failed one day and I was left with several months of prepaid service. I'm a bit bitter for that, but honestly their technical writing and security decisions have earned enough good will from me that I want them to keep the money. As the only VPN that doesn't feel shady, I wish them all the best. [1] https://mullvad.net/en/blog/2023/5/29/removing-the-support-for-forwarded-ports/ https://mullvad.net/en/blog/2023/5/29/removing-the-support-f...
- pteraspidomorph 3y agoI'm glad to read this. We considered switching to them earlier this year (couldn't find the budget) and it was still on the table, but this is a deal breaker. If we'd switched I'd have been in the same situation, with a lot of prepaid service I couldn't use as intended.
- BoppreH 3y agoTo be fair, the announcement came with the option of asking for refunds, and I have no reason to doubt them. My few interactions with their support were pretty good.
- asynchronous 3y agoThey still support opening up ports, it’s just randomized instead of dedicated like uPnP.
- nabogh 3y agoOh really? Could you elaborate or point me in the direction of more information on this please?
- dontupvoteme 3y agoSadly I can easily imagine a future where mullvad suffers because big tech simply rangebans all their datacenters (already happens to some degree between cloudflare and individual admins - people are seemingly even banned from using chatgpt if they connect over it, or at least it's involved) and you need the shady residential proxies to actually be able to connect/scrape anything. A self hosted VPS may also work if the company is small enough to avoid the coming BlanketBans, but only time will tell.
- deleted 3y ago[deleted]
- no_time 3y agoAs an occasional mullvad customer im glad to hear. That being said, I wonder why we arent hearing about any cases involving them and cybercrime. Letter soup agency smear campaigns or actual cybercrime. They operate totally in the clear as opposed to Tor and other overlay networks, but unlike with Tor, there are no "opinion articles" or biased news articles slamming them as pedophile enablers. I just find this odd. /Paranoid schizo mode off
- pydry 3y agoThere was one recently involving Swedish police, I think. I expect VPN usage is easy enough to unmask by state level actors with timing attacks.
- user764743 3y agoIf the VPN is hosted in America or Europe it's without a doubt logging, otherwise they would not be able to operate legally. Full Spectrum Awareness logically means VPNs should be a prime targets for the surveillance state that we're in.
- Karunamon 3y agoWhat law would require an American VPN host to log the activities of their subscribers? CALEA only applies to telecoms and ISPs (legal common carriers), a VPN provider is neither.
- hammock 3y agoMullvad is THE ONLY mainstream VPN that doesn't have seriously questionable credibility. Not even Proton VPN is OK - sleuths have figured out that it's just a white-labeled version of NordVPN. I am thankful that Mullvad is doubling down on their commitment to integrity, because there isn't an alternative.
- neontomo 3y agoDo you have any sources for the NordVPN claim? Edit: I just had a look through your post history and you seem to have been claiming this for months, without providing any evidence. Shady.
- hammock 3y ago>Do you have any sources for the NordVPN claim? The trail is a rabbithole, and you might not be personally satisfied with the standard of evidence. Here is a start for you: https://news.ycombinator.com/item?id=23571653 https://news.ycombinator.com/item?id=23571653 Note in the link above [1] doesnt work anymore since Nord actually removed the product page for their white label product, but it does exist and you can see it in the Products dropdown as NordWL. And since the link to [2] in what I linked above is broken, here is the archived version: https://archive.is/iZ2l2 https://archive.is/iZ2l2
- computerfriend 3y agoI'm unaffiliated with either. But I can tell you that the allegations are true. At least, that was the state of things several years ago.
- notanemployee 3y agoSource: employee at NordSec. There was definitely overlap between the companies (and tech), but, to my knowledge, that hasn’t been the case for several years now.
- slikrick 3y agoyou are notanemployee though, so your first line seems suspect
- dimaor 3y agoI am currently using nordvpn and my subscription is going to expire pretty soon. I have been thinking to switch to mullvad for some time. apart from the price (nordvpn is cheaper) can someone please help me make a decision if to switch or stay with nord? based on the comments in the thread I assume mullvad is better in terms of privacy, security and probably more. in addition, I don't use streaming services so the netflix selling point does not apply to me. thanks in advance!
- 0xbeefcab 3y agomullvad is well worth it IMO. Genuinely reliable, privacy forward, and consumer-friendly rather than trying to maximize profits and make their own lives easier
- sourcecodeplz 3y agoI just use proton coz it is free
- Cort3z 3y agoI came across mullvad some time ago (apparently they struck a deal with Mozilla). Anyway, their service is great and it is such a rare thing to just pay for a service without all the nonsense around. Just; click here to get an account. Nothing else. Then just freaking press pay, in any of a huge array of methods, including cash in the mail!
- dev_0 3y ago[dead]