4 ms·
Mullvad had national police come with a warrant and nothing was able to be obtained as they were able to prove their servers had nothing identifiable on them (a
by Springtime 3y ago
Mullvad had national police come with a warrant and nothing was able to be obtained as they were able to prove their servers had nothing identifiable on them (and as such it would be illegal to seize anything per Swedish law).
They also had a recent audit of their VPN servers and no leakage or logging was found. Among other factors they're the only such VPN I'm aware of to hold up under scrutiny.
Do I even use a third-party VPN? No; but they're the only one I've seen that are as close to trustworthy.
- Geisterde 3y agoProton also has a record for proving they don't keep logs due to a warrant.
- coldtea 3y ago>Mullvad had national police come with a warrant and nothing was able to be obtained as they were able to prove their servers had nothing identifiable on them (and as such it would be illegal to seize anything per Swedish law). They also had a recent audit of their VPN servers and no leakage or logging was found. Of course that requires trusting the police report and the auditor (and that the audit process didn't happen while they were on a different operation mode than their usual, and that the police case wasn't on some class of persons who they don't log, while for others, e.g. when they get "special orders" they do)...
- Springtime 3y agoThe author of the OP's article was making the case that there's 'no way' to verify whether a third-party VPN logs and thus as their broad conclusion none should be used. If the baseline position is that any company can and will lie, regardless of available knowledge about law enforcement intervention or audits then one could say nothing can really be trusted (even hardware we utilize everyday), since there's always some potential undisclosed 'gotcha'. Otherwise it's where one draws the line of verifiability. There have been other VPNs that haven't held up under scrutiny and been found logging (and had poor security), while Mullvad goes into detail about their infrastructure, mitigation methods (including some quite paranoid anti-tamper hardware techniques, which anecdotally the founders were into prior to forming the company), has had various audits, resisted a warrant and apparently doesn't spend on advertising. Could all these things be some elaborate ruse? Possibly. There will always be some judgment call.
- coldtea 3y ago>If the baseline position is that any company can and will lie, regardless of available knowledge about law enforcement intervention or audits then one could say nothing can really be trusted I think it's a good starting assumption if you need full trust. For regular Joes however, it's more about being able to trust the raw technical mechanics (that the data won't go to the wi-fi in the open or to your ISP and in-betweens, but to some remote VPN). If you can assume those targetting you don't (or can't) buy your non-anonymized data from that VPN service, you're OK, even if the VPN service logs and lies that it doesn't log. Because, sure, they can lie about that (and even the audit service can), but in-betweens can't just bypass SSL (unless you're compromised otherwise, in which case VPN or not is the least of your problems).