Some politicians in the UK think it is a good idea to introduce identity verification for using VPN services.

It could be that these politicians do not understand what they are proposing. The alternative, that they do understand, would be even worse.

1/2

Whistleblowers, activists, and journalists depend on anonymous VPN services. Requiring identity verification for VPN services would put them at risk. It would also have a chilling effect on online debate (VPNs can help people post anonymously on social media).

In authoritarian countries, VPN services are crucial forcriticizing the government. That is precisely why such governments seek to ban or restrict them. Hopefully, the UK will not join that list.

2/2

@mullvadnet personally, I'd recommend @torproject instead of a VPN simply because even Mullvad will comply with an orderly issue warrant.

  • And I don't expect your staff to risk dying of old age in jail…

https://web.archive.org/web/20220112020000/https://twitter.com/thegrugq/status/1085614812581715968

The only thing that VPNs are good for is circumventing Geoblocking and Providers violating Net Neutrality.

  • But if you are targeted by state-sponsored attackers, espechally the UK government, a VPN is clearly insifficient
    • But those OpSec, InfoSec, ComSec & ITsec issues are way beyond the scope of this post

Case in point: If you want to watch i.e. @dw_innovation / DW news then a VPN is propably the only option if you can't get the livestream working.

  • But in terms of privacy, I'd rather recommend Tor.
    • Still I have to give you guys cudos for your OnionService and pro-privacy setup, and I think that Tor over VPN is a valid strategy on the go…

#VPN #Tor #privacy #InfoSec #OpSec #ComSec #ITsec #security #VPNs #Mullvad #Tor #DW #DeutscheWelle #DWnews #OnionService

thaddeus e. grugq on Twitter

“I’m gonna tell you a secret about “logless VPNs” — they don’t exist. Noone is going to risk jail for your $5/mo https://t.co/Q2aOQJkG4g”

Twitter
@Netzblockierer
Mulvad gets pretty secure if you are paying in cash or crypto but you're right on that VPN isn't something you should use if your threat model includes state actors.
@mullvadnet @torproject @dw_innovation

@MxSpoon Yeah, and I don't fault @mullvadnet for any of it.

And for what's worth Mullvad do their job pretty well.

  • It's just that one needs to know the use-cases and limitations of things.
    • Just like a Peterbilt Semi with a Detroit Diesel is a bad car to drive for shopping trips in the City, the Smart fortwo is a bad vehicle for towing & trailers.

Everything has some drawbacks, and if it's just to circumvent Geoblocking and ISPs fucking around with one's traffic, VPNs are just fine for that…