I have used ivpn in the past, before apps, and have some accounts for its present iteration that are not tested yet.
The biggest problem I see with ivpn is how complex its offerings are and by extension how difficult it is for even a user who has passing familiarity with VPNs like myself to make good choices.
While recently it’s been made the default, the user can still opt to create a username and password that are subpoenable pii, if that’s a word. Able to be subpoenaed.
It is not immediately clear what the security surface is on their various product tiers. I won’t go into all of them but the top features a third party firewall program called portmaster that’s developed by a different vpn company called safing. Perhaps this is useful to you. I found it to be another fractal galaxy of loose ends to tease out.
The above stuff is largely the same boat proton is in. You can set up a simple vpn account. Will you? They would love to give you a good deal on a big bundle…
Mullvad avoids this with a single product offering, no additional attack surface (except for their now ubiquitous version of the vpn app) and no way for the user to put them in a situation where they ever even have your information.
What remains to be seen is real strongly investigated results of a legal action against ivpn. Those legal actions have happened but they’ve largely been what get called “fishing trips” by exhausted public defenders in procedural dramas. There hasn’t been anything on the scale of what’s been pointed at mullvad and with the Byzantine stuff on offer by ivpn in comparison to mullvad it would be a real hoot to dig through that disclosure if and when it comes along.
It may behove you, as it once behove me (is it really spelled the same in past and future perfect tenses, like a read/read situation?) to disregard guides or recommendations and instead look into the information directly and draw your own conclusions.
For example: Often times, a guide or recommendation is formatted as a spreadsheet and the best option is the one that accumulates the most check marks across its row. That type of decision making system would give an advantage to services that support the use of the openvpn protocol since it’s one more check than those that don’t. Except for the common modern use case of openvpn is embedded edge devices like routers that may not support safe openvpn configurations.
So presence of footgun is a plus in many systems used to recommend VPNs and that’s just a simple example.
Everyone’s different and everyone’s needs are different.
I started using ivpn almost 8 years ago, and I believe the default setting back then was to not use accounts with usernames.
Some of the key reasons I chose it at the time were port forwarding (this service was later discontinued), its open-source F-Droid application, the ability to configure the WireGuard connection on my Linux machine without the application (I never tried it), its commitment to user anonymity (zero logs, payment methods, etc.), external audits, and the fact that it wasn’t based in an EU member state (ivpn is a Gibraltar-based company).
The last reason is that I live in the EU, which shouldn’t be a problem for those who don’t.
Since then, I haven’t bothered to check how the VPN industry has evolved. Thanks for the thorough answer.
Nops, and I think that it’s a bad move to change their business model to be a VPN provider to a catch-all security related provider, also I only have the standard tie which don’t have the DNS, mail redirection or portmaster services.
Furthermore, my threat model changed with the struggle for the independence of Catalonia, it put the state as my main adversary, and making them waste their time and resources with multiple subpoenas is a plus.
Idk if it’s a good business move, some of those kitchen sink providers can offer a user a lot of value. I’m perhaps not the target demographic for that.
Completely off topic, but what kind of phone duress setup do you use? It’s not often I get to talk to someone who is primarily concerned about the state.
I have used ivpn in the past, before apps, and have some accounts for its present iteration that are not tested yet.
The biggest problem I see with ivpn is how complex its offerings are and by extension how difficult it is for even a user who has passing familiarity with VPNs like myself to make good choices.
While recently it’s been made the default, the user can still opt to create a username and password that are subpoenable pii, if that’s a word. Able to be subpoenaed.
It is not immediately clear what the security surface is on their various product tiers. I won’t go into all of them but the top features a third party firewall program called portmaster that’s developed by a different vpn company called safing. Perhaps this is useful to you. I found it to be another fractal galaxy of loose ends to tease out.
The above stuff is largely the same boat proton is in. You can set up a simple vpn account. Will you? They would love to give you a good deal on a big bundle…
Mullvad avoids this with a single product offering, no additional attack surface (except for their now ubiquitous version of the vpn app) and no way for the user to put them in a situation where they ever even have your information.
What remains to be seen is real strongly investigated results of a legal action against ivpn. Those legal actions have happened but they’ve largely been what get called “fishing trips” by exhausted public defenders in procedural dramas. There hasn’t been anything on the scale of what’s been pointed at mullvad and with the Byzantine stuff on offer by ivpn in comparison to mullvad it would be a real hoot to dig through that disclosure if and when it comes along.
It may behove you, as it once behove me (is it really spelled the same in past and future perfect tenses, like a read/read situation?) to disregard guides or recommendations and instead look into the information directly and draw your own conclusions.
For example: Often times, a guide or recommendation is formatted as a spreadsheet and the best option is the one that accumulates the most check marks across its row. That type of decision making system would give an advantage to services that support the use of the openvpn protocol since it’s one more check than those that don’t. Except for the common modern use case of openvpn is embedded edge devices like routers that may not support safe openvpn configurations.
So presence of footgun is a plus in many systems used to recommend VPNs and that’s just a simple example.
Everyone’s different and everyone’s needs are different.
I started using ivpn almost 8 years ago, and I believe the default setting back then was to not use accounts with usernames.
Some of the key reasons I chose it at the time were port forwarding (this service was later discontinued), its open-source F-Droid application, the ability to configure the WireGuard connection on my Linux machine without the application (I never tried it), its commitment to user anonymity (zero logs, payment methods, etc.), external audits, and the fact that it wasn’t based in an EU member state (ivpn is a Gibraltar-based company).
The last reason is that I live in the EU, which shouldn’t be a problem for those who don’t.
Since then, I haven’t bothered to check how the VPN industry has evolved. Thanks for the thorough answer.
Have you used any of the other stuff they offer like the dns or mail thing?
I have only used their WireGuard config file -> into /etc/WireGuard simple kind of man setup.
Nops, and I think that it’s a bad move to change their business model to be a VPN provider to a catch-all security related provider, also I only have the standard tie which don’t have the DNS, mail redirection or portmaster services.
Furthermore, my threat model changed with the struggle for the independence of Catalonia, it put the state as my main adversary, and making them waste their time and resources with multiple subpoenas is a plus.
Idk if it’s a good business move, some of those kitchen sink providers can offer a user a lot of value. I’m perhaps not the target demographic for that.
Completely off topic, but what kind of phone duress setup do you use? It’s not often I get to talk to someone who is primarily concerned about the state.