110
submitted 3 days ago* (last edited 3 days ago) by barnaclebill@lemmy.dbzer0.com to c/piracy@lemmy.dbzer0.com

From the article:

| VPN | HQ & Eyes Alliance | Latest Independent Audit | Real-World Test | Retention Verdict* | |


|


|


|


|


| | ExpressVPN | British Virgin Islands (no data-retention laws) | KPMG ISAE 3000 Type I, Feb 2025 (ExpressVPN) | Split-tunnelling DNS leak disclosed Feb 2024 (patched) | Gold-standard. RAM-only fleet, annual audits, BVI jurisdiction. | | NordVPN | Panama | Deloitte 5th audit, Dec 2024 (NordVPN) | 2018 server breach – no logs leaked | Regular audits and positive breach outcome. | | Surfshark | Netherlands (9-Eyes) | Deloitte, Jan 2023 (Surfshark) | TunnelCrack Wi-Fi leak (Aug 2023) → patched in <7 days. | Strong audit hygiene but concerning jurisdiction. | | Proton VPN | Switzerland | Securitum, Apr 2024 (securitum.com) | N/A | Open-source clients + Swiss privacy laws. | | Mullvad | Sweden (14-Eyes) | Assured AB config audit 2023 | Swedish police raid Apr 18 2023 left empty-handed (Mullvad VPN) | Minimal-data design proven in the wild. | | Private Internet Access | USA (5-Eyes) | Deloitte, Apr 2024 (Private Internet Access) | Multiple US subpoenas produced no logs | Paper-trail-verified despite US HQ. | | CyberGhost | Romania (EU, outside Eyes) | Deloitte, May 2024 (CyberGhost VPN) | N/A | Second audit boosts trust. | | TunnelBear | Canada (5-Eyes) | Cure53 7th audit, Dec 2023 (TunnelBear: Secure VPN Service) | N/A | Longest unbroken audit streak. | | Windscribe | Canada (5-Eyes) | Cure53 server image audit 2022 | 2025 Greek/Canadian court case upheld no-logs stance (Tom’s Guide) | Policy tested – passed. | | Hotspot Shield | USA (5-Eyes) | Performance/security review by AV-Test only; no dedicated no-logs audit (vpnMentor) | AV-TEST performance audit only; no no-logs audit to date. (CVE Details) | Speed king, privacy laggard. |

Archived links:

all 25 comments
sorted by: hot top controversial new old
[-] upstroke4448@lemmy.dbzer0.com 95 points 3 days ago* (last edited 3 days ago)

They lost me at calling ExpressVPN the gold standard. Even their audit is bs. KPMG is the same company that provides the "always-on" audit to PureVPN.

Any article that still uses the "eyes" as a factor in their evaluation is a massive red flag. Very public intelligence alliances are the least of your worries.

[-] barnaclebill@lemmy.dbzer0.com 25 points 3 days ago

I had not read about this criticism of KPMG before. For the benefit of other readers, I found this other forum post from March 2025 where commenters question the worthiness of the KPMG audit for PureVPN. For my own part, I'm not sure I understand what an audit that's acceptable to privacy communities would look like. If somebody can elaborate on this, I would appreciate it.

[-] upstroke4448@lemmy.dbzer0.com 17 points 3 days ago* (last edited 3 days ago)

Audit providers just like VPN providers come in a wide variety of quality.

Its hard to point out specifics of what makes a good audit as most people don't, and have no need to, understand the technical details of the audit and just go off its summary.

Another difficulty is just like most VPN providers, there just isn't much info provided about Auditors or the auditing process.

A few have well known reputations...

KPMG is a low quality provider. Any auditing company that provides an "always-on" service is not being serious.

Cure53 is a high quality provider.

[-] chaoticnumber@lemmy.dbzer0.com 45 points 3 days ago

The only gold standard here, is this article being the gold standard for hand-wavy "truths".

Such a load of BS. Mullvad is the only one so far that has not squealed.

[-] HappyFrog 40 points 3 days ago* (last edited 3 days ago)

The founder and CEO of redact (the site this is hosted) is Dan Saltman, a man so obsessed with online drama that he would side with Hitler if he went after Hasan.

There are also allegations that Dan has used redact to dox someone, though, I find this less substantiated.

[-] technocrit@lemmy.dbzer0.com 20 points 3 days ago* (last edited 3 days ago)

CyberGhost is great if you support zionism and trust mossad.

[-] Dsklnsadog@lemmy.dbzer0.com 18 points 3 days ago

ExpressVPN is a Chinese govt aproved company... do all audits you want. You need trust. Audits doesn't matter. They can change everything after. I trust IVPN and Mullvad

[-] 0x0@lemmy.zip 3 points 2 days ago
[-] black_flag@lemmy.dbzer0.com 7 points 3 days ago

Any of them have port forwarding? Thought not...

[-] ReCursing@feddit.uk 10 points 3 days ago

Proton does... but you need to use a shell script to enable it on Linux. It's easy enough and documented on their site, but it's annoying. Mullvad does not, that's why I moved away from them. Can't speak for others

[-] nfreak@lemmy.ml 6 points 2 days ago

This is why I moved from Mullvad to Proton. Mullvad worked great for me, but then I started my own media server, and port forwarding goes a long way for torrenting Linux ISOs. Proton also offers double the active connections as Mullvad, which helps when hooking it up to various Gluetun containers which are mostly routed through different servers for one reason or another. And despite how gimmicky the marketing for it is, the "VPN accelerator" fuckin works.

That being said, Proton sketches me out - their CEO has said some awful bullshit last year, and it just feels like enshittification is around the corner. But their VPN is proven and works great.

I'd love to go back to Mullvad for those reasons, but the feature set Proton offers right now is unmatched imo.

[-] black_flag@lemmy.dbzer0.com 4 points 3 days ago

Proton is too fucking expensive.

[-] ReCursing@feddit.uk 9 points 3 days ago

Same price as Mullvad, about a fiver a month, if you buy a year at a time. Annoying that you have to buy a year upfront but works out to the same price

[-] Rai@lemmy.dbzer0.com 7 points 3 days ago* (last edited 3 days ago)

Paid for itself for a year in like 2-3 movies!

[-] barnaclebill@lemmy.dbzer0.com 3 points 3 days ago

Do you know if Proton's port forwarding times out and needs to be reconfigured every so often in the same way the other commenter mentions about Windscribe?

[-] Flatworm7591@lemmy.dbzer0.com 5 points 3 days ago

It's pretty solid, but if you reconnect to a different server then you'll likely have a different port number. There's an add-on script for docker qbittorrent though that auto updates the port number.

[-] ReCursing@feddit.uk 3 points 3 days ago

I have it alias the external port to local port 2000 and point qbittorrent at 2000

[-] easydnesto@sh.itjust.works 5 points 3 days ago

For Linux it does timeout and basically just need to run a bash while loop to keep open. I’m not sure if windows is the same way, but from what I hear it’s more integrated.

Overall the port forwarding is not that big of a hassle on Linux. It’s an opt in feature and I just have bash aliases to enable the port forwarding when I need it.

[-] ReCursing@feddit.uk 2 points 3 days ago
[-] kbal@fedia.io 5 points 3 days ago

Windscribe, although unless you pay an extra $2/month they time out and need to be reconfigured after one week.

i use windscribe and mullvad at this point but their android apps are so useless :(

i also hate how expressvpn is the only one i found that does auto connect by wifi network

[-] DeepChill@sh.itjust.works 2 points 3 days ago

IVPN has this feature for iOS, iPadOS and macOS. I’m sure it would be in the android app too.

Network Protection

this post was submitted on 20 Aug 2025
110 points (100.0% liked)

Piracy: ꜱᴀɪʟ ᴛʜᴇ ʜɪɢʜ ꜱᴇᴀꜱ

63697 readers
674 users here now

⚓ Dedicated to the discussion of digital piracy, including ethical problems and legal advancements.

Rules • Full Version

1. Posts must be related to the discussion of digital piracy

2. Don't request invites, trade, sell, or self-promote

3. Don't request or link to specific pirated titles, including DMs

4. Don't submit low-quality posts, be entitled, or harass others



Loot, Pillage, & Plunder

📜 c/Piracy Wiki (Community Edition):

🏴‍☠️ Other communities

FUCK ADOBE!

Torrenting/P2P:

Gaming:


💰 Please help cover server costs.

Ko-Fi Liberapay
Ko-fi Liberapay

founded 2 years ago
MODERATORS