4 ms·
The difference is that Mullvad doesn't enable any east/west connectivity at all. If somebody guesses a user's Mullvad 16 digit number, they can use Mullvad's se
by akerl_ 2mo ago
The difference is that Mullvad doesn't enable any east/west connectivity at all. If somebody guesses a user's Mullvad 16 digit number, they can use Mullvad's services as that user. If somebody gets a SmokeVPN users's 16 digit number, they can connect to that user's other devices.
How would you take any action with an abuse report and no logs? You'd get a report or subpoena or similar that listed an egress IP and a timestamp and say "We need information on this user for this charge" or "You're ordered to halt this illegal traffic", and you'd not have any way to tie that out to a specific user retroactively. There are plenty of providers who take the stance that they don't log and thus effectively cannot prevent or restrict illegal or abusive activity. I'm just not understanding how you could claim to both be logless and restrict those things.
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- deleted 2mo ago[deleted]
- lobito25 2mo agoYou're right on both counts. My Mullvad comparison was focused on the credential, not on the LAN model. Brute forcing the account was never the issue, I missed the point about device-to-device was the real threat, fair point. I'm starting implementing LAN connections as opt-in, not default. Second point, you're also right, because I was mixing prevent and identify, preventions shouldn't need logs, we can't take an IP address and a timestamp and attach a user to it, and the AUP imply something else, I'll rephrase this.
- lobito25 2mo agoFor completion, I decided to make device to device connections an opt-in feature that requires 2fa enabled to log into the account. AUP was also rephrased to make a clear distinction between prevention and identification.