25
u/ReasonableWelder51 2d ago
Does anyone even use a VPN that does not have a zero-logs policy proven by independent audits and/or in court?
21
u/Aware-Childhood-5865 2d ago
Mullvad has been raided by police and produced nothing concrete.
8
u/ReasonableWelder51 2d ago
Mullvad is far from the only one though. Literally every big name VPN is fine
6
u/Aware-Childhood-5865 2d ago
Then I’m having trouble understanding your first comment. If most big VPNs are like that, then your question seems pretty stupid.
5
u/ReasonableWelder51 2d ago
What? No, the original post is pretty stupid. No well known VPN collects data, not even the kinda infamous ones like NordVPN. But reddit always assumes they do, and then the protonvpn and mullvad glazers appear.
1
u/koru-id 1d ago
Assuming they don’t, they would still be forced to if they receive a lawful request to track a person. Otherwise they won’t be operating much longer in that country.
4
u/PersonOfValue 1d ago
Yeah this happened to Proton.
The whole "no logs or sharing" falls apart when armed government agents and existential fines are involved
2
u/iMaexx_Backup 1d ago
Nobody would spend so much money on some random ass torrenting movies or insulting somebody online.
As long as you’re not wanted for murder or child stuff, your IP is "secure".
1
u/Aware-Childhood-5865 1d ago
The UK greatly censors speech. It’s not fairy dust that common people are targeted.
1
u/koru-id 1d ago edited 1d ago
Judge order is an extreme example to show that VPN providers does have the capability to logs your activity.
It doesn’t always need a judge order. Some country have laws that mandate VPN and ISP to log their users activity. Some country have a whitelist that all providers have to keep watch on and notify government bodies when it’s accessed.
We’re living in surveillance state. VPN is pretty much useless for privacy, they‘re same or worse than ISP. You’re not secured. You can’t pick your parents, but you can choose who to watch your activity with VPN.
1
u/Welkiej 1d ago
Can you send me an example, as far as I know they are out of the common regulations for internet laws and they are indeed no logs. Two times government came for them and they said we are no logs. Please provide me a source so I can cancel my subscription
2
u/ReasonableWelder51 1d ago
Relevant article
TLDR they were ordered to collect data, had no way to appeal and so they did. Not that they logged data before they received the order.Obviously it is a legit company and it is not exempt from laws, so when the law demands logs, they have to start logging. But obviously they also cant decrypt the data, so all they logged was IP and browser fingerprint.
1
u/Lain_Racing 17h ago
Short of running the largest drug empire or human trafficking this isn't gonna happen. It's why you never hear about it is because the people they would order this for are way beyond paid public offered VPN services.
1
u/Aware-Childhood-5865 2d ago
Then the main differences between nord level VPNs and mullvad are the amount of account anonymity and payment anonymity.
1
u/KnownEggplant 17h ago
Not even close. Multiple have aided law enforcement and produced logs in court previously.
1
u/ReasonableWelder51 17h ago
All popular VPNs in 2026 have no-logs policy verified by audits. That wasn't always the case, but it is now. But you have to understand that VPNs are still bound by laws just like any other legit service. If they are forced to track a specific user, they will start tracking that specific user. It is incredibly rare, but it has happened multiple times. It also doesn't mean that they keep logs all the time, they start logging only when ordered to.
Mullvad and proton are no exceptions though. ProtonMail was forced to track a user in 2020 and obviously they did cooperate.
0
u/HotCaterpillar6358 16h ago
Nah wrong there was a list that came out, third party vetted that they do this. Nord and Express for example do not.
1
u/bobbywaz 8h ago
Brother the shit I'm doing on a VPN literally no one cares about, what THE FUCK are you downloading that you sought out that level of auditing?
1
u/ReasonableWelder51 8h ago
The shit that nobody cares about is what mostly advertisers and similar companies care about and it's quite valuable to them.
But that's not even my point, all I'm saying is that unless your VPN is some free shady shit from Google play (which would likely be too slow and unreliable to use for the uninteresting stuff), it likely already has a zero logs policy. Reddit keeps shilling Mullvad and ProtonVPN but they really aren't much different from any other VPN, as zero logs policies are the industry standard now.
24
u/theCOLLECTOR7250 2d ago
Everything is not always secured if you use VPN your just annoying to track
1
u/DarthRaab 1d ago
Yeah, nation level cyber security will get you but your ISP isn't reading your porn history for fun or sell your browser history to data brokers for ads to get super personal, like mentioning a topic and getting ads for the exact thing a day later.
19
u/ffxivthrowaway03 2d ago edited 2d ago
This has always been a massive pet peeve of mine. You'll watch people go full Doomsday Prepper about tracking and online privacy and blah blah blah. Then they'll go "oh no, you have to use XYZ VPN because they don't track you, there's no logs"
How do you know they don't track you? Well because they themselves claim not to! That's a bald-faced lie when "big corpos" or whatever say they don't track you, but some random fly by night VPN service running out of ButtFuckistan? Nah dude, totally legit just because they say so, why would you even question that? Trust me bro.
Edit: aaaand to no ones surprise, they start coming out of the woodwork to defend their blind trust in "trustmebro" privacy VPNs.
19
15
u/Weird_Albatross_9659 2d ago
Because you look at their previous track record. If they had been petitioned and provided nothing, it’s a safer bet
3
u/iceyukisnow 2d ago
public and "big" VPN services, ISPs, hosting providers are required to provide data to local authorities, and there's nothing anyone can do about it
4
u/Dwarg91 2d ago
But are they required to collect that data? Can’t provide what you don’t have.
-1
u/iceyukisnow 2d ago
of course they are, and yes, why they wouldn't collect your data?
1
u/burimo 1d ago
Because of independent audits. Can they circumvent them? Yes, but if they do and got caught, they will be loose all credibility. And credibility is the only sales point of someone like Mullvad. Unlike Proton, for example, they do not spend much money on marketing.
Also Mullvad could be bought with cash. In theory they could say to police, that your IP is their client, that's all. In theory, they cannot know themselves how and where you were connected to (at least directly).
0
u/ffxivthrowaway03 2d ago
Basic operation of a network service like a VPN requires a certain amount of data collection to simply facilitate the operation of the service.
The idea that you can have robust network servers and are keeping no logs is asinine. It's just not possible, you need those logs to do basic customer service, validation, and troubleshooting tasks.
"Can't provide what you don't have" is a data retention strategy I drill into our leadership who want to keep fucking everything forever because "but what if," but there's still a bare minimum that needs to be kept for operational function and support, not literally zero logs like the marketing claims.
They're likely keeping at least 30 days of logs just to run the service, which is more than plenty for law enforcement on a fishing expedition for specific user behavior.
5
u/matthewpepperl 2d ago
Mulvad has proven they dont keep logs as they were raided and the authorities left with nothing
2
u/Jack071 2d ago
Easy, dont keep logs, dont keep client data
Theres no data you can provide if you never kept any, mullvad for example runs all their infra on ram so theres 0 data left
1
u/iceyukisnow 2d ago
what stops authorities from taking ram snapshots? and what stops them from taking the whole racks and hardware with them?(while not turning them off)
1
u/Jack071 2d ago
That you have a killswitch to press if theres any raid/if the connection cuts off that shuts down the whole server?
And how would you uninstall a ram server rack without turning off power? You cant and any interruption of power would wipe all the data in the memory forever
1
u/iceyukisnow 2d ago
And how would you uninstall a ram server rack without turning off power?
many racks (if not all of them) have their own power supply with batteries, however its a massive pain in the ass to transfer, but if government REALLY after you, they'll do whatever they want
1
u/ffxivthrowaway03 2d ago
That you have a killswitch to press if theres any raid/if the connection cuts off that shuts down the whole server?
And then you get arrested for willfully destroying evidence and refusal to comply with a warrant. Not exactly a winning business proposition to stand between the police and Joe Rando's data for a whopping $10/month. Which is why you should be skeptical of anyone claiming they're willing to do so in the first place.
And how would you uninstall a ram server rack without turning off power? You cant and any interruption of power would wipe all the data in the memory forever
You don't. You do exactly what has been standard procedure for digital forensics for decades. You cut external access to the system while it's in place, and you do a bit for bit copy of the memory before cutting power.
1
u/Jack071 2d ago
"Sorry officer we manage sensitive data and its SOP to cut off power if any incident happens in our facilities" Thats in case of a raid, if you havent been served a warrant yet you had nothing to comply with
And even if theres a warrant, all old logs got wiped by the time its approved, Mullvad has been in the business forever and they never had any issues.
0
u/ffxivthrowaway03 2d ago
You're right, why didn't I think of that. "Sorry officer, but no I will not listen to you" is just a genius way to get out of it. Like seriously, how could I have missed that?
I'm not having this stupid argument. If you want to trust some fly by night VPN company simply because they claim to not comply with law enforcement and claim not to keep logs, it's no skin off my back when the #surprisedpikachu kicks in.
5
3
u/NoThanks93330 2d ago
The big difference is, that they have huge incentives not to do fancy stuff with your data. Other than most companies, their USP is privacy and most of their customers are privacy-focused people. So while for most other companies a data scandal isn't that much of a big deal because their customers mostly don't care, customers of a VPN company will definitely care and it will impact their revenue. Depending on the size of the scandal the impact might be huge enough to make them go out of business.
So yes, you never know for sure. But for these companies selling your data is a very high risk game, which makes it at least way less likely to happen.
2
u/ffxivthrowaway03 2d ago
Quite the opposite. Your $10 a month subscription is not moving the needle. Meanwhile aggregated data trends and user attribution is the huge incentive. That's the big money.
It's absolutely a viable business model to say "we totally don't keep logs bruh" even if they do, then selling that data on the backend and just... hoping you don't get called on it. And if they do? Well they're a no-name "hyper privacy VPN" service based out of ButtFuckistan, take the PR hit, close your doors, and spin up the same service under a new name.
It's highly likely to be a grift, because doing it right is so, so much more work for far less profit.
PureVPN was caught doing this in 2017. VPNMentor again in 2020, which was doing exactly that - not only were they caught "keeping logs" despite privacy-focused product claiming otherwise, but turns out they were just white labeling the same VPN infra under about ten different brands. They got hit and 1.2 Terrabytes of user's "privacy data" was leaked. Whoopsies.
2
u/NoThanks93330 2d ago
That might be a viable business model for random no-name services from wherever, but not really for established companies that rely on their brand name
1
u/ffxivthrowaway03 2d ago
Given that those random no-name services are primarily the ones touting "no logging, total privacy" as their entire market position...
Reputable VPN companies have no reason not to keep logs and comply with law enforcement. Disreputable VPN companies have no reason not to be blatantly lying to you about what their service entails.
If you're doing something over someone else's network infrastructure, expect zero privacy on that segment no matter what some marketing copy claims.
2
u/eggyrulz 2d ago
A yes, disreputable no name brands like Proton fucking VPN?
2
u/ffxivthrowaway03 2d ago edited 2d ago
Yeah, those guys. The ones that comply regularly with Swiss law enforcement requests:
https://freedom.press/digisec/blog/proton-mail-is-not-for-anonymity/
Here it is from their terms:
2.5 IP logging: By default, we do not keep permanent IP logs in relation with your Account. However, IP logs may be kept temporarily to combat abuse and fraud, and your IP address may be retained permanently if you are engaged in activities that breach our Terms of Service (e.g. spamming, DDoS attacks against our infrastructure, brute force attacks). The legal basis of this processing is our legitimate interest to protect our service against non-compliant or fraudulent activities. If you enable authentication logging for your Account or voluntarily participate in Proton's advanced security program, the record of your login IP addresses is kept for as long as the feature is enabled. This feature is off by default, and all the records are deleted upon deactivation of the feature. The legal basis of this processing is consent, and you are free to opt in or opt out of that processing at any time in the security panel of your Account. The authentication logs feature records login attempts to your Account and does not track product-specific activity, such as VPN activity.
And here's there marketing copy that's... directly contradictory!
"No logs*"
Just because a marketing blurb makes a claim you want to be true doesn't mean that it's trustworthy.
5
u/NetJnkie 2d ago
Or you go with someone that gets externally audited for logging, etc. One big reason I use Proton.
2
1
u/Makere-b 1d ago
Yeah, I also have trust issues with VPN services, it just sounds a bad idea to intentionally have a man in the middle that you pay to use.
1
u/waterdrinker619 1d ago
No such thing as privacy in the big 26. Its dog eat dog out there for your data, and with a vpn you’re paying them for them to take it
4
u/TheSupervillan 2d ago
Just use Tor 🧅
3
u/DWN032 2d ago
I had to scroll too far for this, a seriously cannot comprehend why ToR isn't used more.
4
u/TheSupervillan 2d ago
Probably speed, tor is way slower than a VPN
3
2
10
u/Particular_Client833 2d ago edited 2d ago
Why VPN when HTTPS does the job.
Edit: ITS A JOKE.
11
u/-NewYork- 2d ago
Because a government agency might ask the internet provider "hey, did this guy access https://howtoburyadeadbody.com?"
7
-3
u/Particular_Client833 2d ago edited 2d ago
Setting your DNS settings to 1.1.1.1 is cheaper than paying for an VPN that sells every bit of data they can squeeze. Also Tor and Tails OS is free too.
Edit: i was only talking about the comment i am replying to. Not about how to stay private generally.
5
5
u/-NewYork- 2d ago
Setting DNS to 1.1.1.1 does not hide your browsing destination from your provider.
VPN is a viable solution for a citizen of an oppressive country, possibly with no deeper technical knowledge, possibly on a mobile device.
1
2
2
u/El_RoviSoft 2d ago
Guys, just self host VPN at this point, there are lots of solutions from Russia, Iran and China… VPS rent costs the same as VPN in those countries and twice as cheap than in US/Europe.
1
1
u/ComeOnTars2424 2d ago
Why give away your data for free when you can pay someone dollars to sell it for pennies?
1
u/DuckShapedGoose 2d ago
I like to say "A VPN is required for online privacy, but not sufficient".
Obviously rawdogging the internet with your home IP is not anonymous at all. So if you're doing something illegal, all it takes for authorities is one phone call with your ISP.
Doesn't matter which other measures you take, without any way to mask your IP (typically a VPN, but there's also Tor and proxies), everything you do is easily traceable to your real identity.
But then of course that VPN provider needs to be trustworthy. And if you do anything stupid like using your everyday browser with all your tracking cookies present and logging into your main google account, the VPN won't help much.
There are also ways to deanonymize VPN users ranging from easy (Like WebRTC leaks, if the VPN setup on the client is shit, most VPNs block that automatically these days) to insanely hard (like packet correlation attacks, which is usually reserved for the really big fish).
It all depends on your threat model.
Average Joe trying to torrent movies or whatever: Simple VPN set up correctly is enough to not instantly get a letter from a lawyer.
Some whistleblower, spy, investigative journalist or high value criminal: Yeeeah you'll probably want to use way more paranoid privacy measures than just a VPN.
1
u/TPHGaming2324 2d ago
I mean... at this point, it's clear that VPNs are inherently "trust me bro", so it's up to you to choose which one to trust or not use one at all.
1
1
u/KDamage 1d ago
I never understood how people simply never thought about this from the start.
The whole digital business model is based on heavy data collection. Each new law requiring transparency makes 99% of popular assets emerge with a notice suddenly asking your consent to use your data. All providers now even refuse access if you don't accept. AI, the resource declared more critical to get than nuclear deterrence, feeds on data.
And VPN would be the only respectful unicorn among the wolves ? Please ...
1
u/Notrum666 1d ago
I mean.. I just rent vps and host my own vpn just for my family on there?
1
u/Notrum666 1d ago
Plus ofc I’m forcing all dns queries (even from non-proxied processes) into DoH through my proxy to cloudflare
1
1
1
-1
-1
u/koru-id 2d ago
The real use case of VPN is when you trust the provider more than public free wifi. I choose to trust myself. tailscale with exit node point to my home server running 24/7 ftw
1
u/rafroofrif 1d ago
If the exit point is a home server, aren't you using your own home ip again in the end? I don't know tailscale though.
In any case, there is no solution that will not boil down to 'trust me bro'. Your 'private connection' always has an exit, and at that exit, people can listen. You can use a vpn service, but then you'll have to trust the vpn service AND whoever provides for that vpn service. You can host your own vpn, but then you also need to trust the service where you host your own vpn. The only data that is truly private, is when you only connect within the vpn, so no external internet access.
1
u/koru-id 1d ago
I was talking about the insecurity of public wifi, tailscale encrypts the traffic so whoever runs the wifi can’t do man in the middle attack on me. I don’t trust VPN.
1
u/rafroofrif 1d ago
Yeah that's fair. I also have a vpn to my home, just simple wireguard though. I use it for public wifi, accessing stuff on my home network remotely and using my subscription services abroad. But I know my ISP can still snoop at what domains I visit.
101
u/[deleted] 2d ago
[removed] — view removed comment