cross-posted from: https://lemmy.ml/post/37366040

VPN Comparison

After making a post about comparing VPN providers, I received a lot of requested feedback. I’ve implemented most of the ideas I received.

Providers

Notes

  • I’m human. I make mistakes. I made multiple mistakes in my last post, and there may be some here. I’ve tried my best.
  • Pricing is sometimes weird. For example, a 1 year plan for Private Internet Access is 37.19€ first year and then auto-renews annually at 46.73€. By the way, they misspelled “annually”. AirVPN has a 3 day pricing plan. For the instances when pricing is weird, I did what I felt was best on a case-by-case basis.
  • Tor is not a VPN, but there are multiple apps that allow you to use it like a VPN. They’ve released an official Tor VPN app for Android, and there is a verified Flatpak called Carburetor which you can use to use Tor like a VPN on secureblue (Linux). It’s not unreasonable to add this to the list.
  • Some projects use different licenses for different platforms. For example, NordVPN has an open source Linux client. However, to call NordVPN open source would be like calling a meat sandwich vegan because the bread is vegan.
  • The age of a VPN isn’t a good indicator of how secure it is. There could be a trustworthy VPN that’s been around for 10 years but uses insecure, outdated code, and a new VPN that’s been around for 10 days but uses up-to-date, modern code.
  • Some VPNs, like Surfshark VPN, operate in multiple countries. Legality may vary.
  • All of the VPNs claim a “no log” policy, but there’s some I trust more than others to actually uphold that.
  • Tor is special in the port forwarding category, because it depends on what you’re using port forwarding for. In some cases, Tor doesn’t need port forwarding.
  • Tor technically doesn’t have a WireGuard profile, but you could (probably?) create one.

Takeaways

  • If you don’t mind the speed cost, Tor is a really good option to protect your IP address.
  • If you’re on a budget, NymVPN, Private Internet Access, and Surfshark VPN are generally the cheapest. If you’re paying month-by-month, Mullvad VPN still can’t be beat.
  • If you want VPNs that go out of their way to collect as little information as possible, IVPN, Mullvad VPN, and NymVPN don’t require any personal information to use. And Tor, of course.

ODS file: https://files.catbox.moe/cly0o6.ods

    • turmacar@lemmy.world
      link
      fedilink
      English
      arrow-up
      1
      ·
      6 days ago

      I believe that supposed to be whether you can get to their website to download clients / register / etc through TOR. Not that the VPN can access the TOR network.

  • Eldaroth@lemmy.world
    link
    fedilink
    English
    arrow-up
    16
    ·
    6 days ago

    Just wanted to leave a comment to say thank you for sharing your findings and taking the time to write your post here. I am sure you spent a lot of time and effort researching all of this. These kinds of posts are why I love Lemmy and its communities.

    Not currently in need of a new VPN, pretty happy with Proton and my plan is active for another 1.5 years. But I still wanted to say I appreciate your post.

  • 37x4H0nUPx0s@lemmy.dbzer0.com
    link
    fedilink
    English
    arrow-up
    30
    arrow-down
    3
    ·
    edit-2
    7 days ago

    If you’re going to be giving out advice, you should at least know that Mozilla VPN is rebranded Mullvad VPN. So most of the information on your chart should be exactly the same for both.

    https://www.mozilla.org/en-US/products/vpn/features/

    Scroll down to “Convenient,” then “More than 500 servers in 30+ countries,” and click on the link “See our list of servers,” which takes you to the Mullvad website server list here:

    https://mullvad.net/en/servers

    Unless something has changed, the VPN that Malwarebytes sells is also rebranded Mullvad.

    In my opinion, if you’re going to include a VPN like PIA, you should also include who owns them (Kape Technologies - owner of multiple VPNs), and instruct people to do an internet search for “Kape Technologies malware.” I’m not saying don’t get PIA, but people should be able to at least make an informed decision:

    “Kape Technologies, originally known as Crossrider, has a history of distributing malware through its ad injection platform before rebranding and focusing on VPN services. While it has since shifted its business model, concerns about its past and corporate practices remain prevalent in discussions about its VPN offerings.”

    https://www.malwarebytes.com/blog/detections/adware-crossrider

    Adware.CrossRider

    Adware.CrossRider is Malwarebytes’ detection name for a large family of adware targeting both Windows and macOS systems. CrossRider offers a highly configurable method for its clients to monetize their software.

    Source and type of infection

    Adware.CrossRider is usually installed by bundlers. Programs offering some kind of functionality are combined with the adware component.

    Additional reading: https://en.wikipedia.org/wiki/Teddy_Sagi#Kape_Technologies

    Likewise, inform people to search for “Nord data breach,” so people can again make an informed decision. It wasn’t the fact that there was a data breach, but how it was handled that some had a problem with:

    “Evidence indicates the attack most likely happened some time between January 31st, 2018, when the server came online, and March 5th, 2018. The attack was made via a compromised data center account, not an account managed by NordVPN. The data center deleted this account on March 20th, 2018, blocking any further access to the server. NordVPN claims not to have been notified about the breach until April 13th, 2019, more than a year after it happened. It took down the server the same day, and began an immediate audit of its 5,000 servers. The company wouldn’t go public until evidence of the hack emerged some six months later. Why? The blog post stated: ‘thoroughly reviewing the providers and configurations for over 5,000 servers around the world takes time. As a result, we decided we should not notify the public until we could be sure that such an attack could not be replicated anywhere else on our infrastructure.’”

    Again, not saying there is a problem with PIA and Nord, just that people should know about these things before making a decision.

  • jungle@lemmy.world
    link
    fedilink
    English
    arrow-up
    17
    arrow-down
    1
    ·
    6 days ago

    Holy shit, the entitlement of some comments here. As if they paid for your service and you let them down and caused them damages.

    Thanks op for your contribution.

  • magguzu@midwest.social
    link
    fedilink
    English
    arrow-up
    6
    ·
    edit-2
    6 days ago

    Thanks for this, looks like it took a long time to put together!

    Some corrections with Windscribe since I use it: on Android you can get the APK directly (“sideload” - I use Obtanium) or through F-Droid. Also I think that pricing is for the full service. I pay like $3 a month with 30GB data and a choice of (I think) 3 or 4 countries IIRC. This has been more than enough for me and probably most people.

  • shalafi@lemmy.world
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    5
    ·
    edit-2
    7 days ago

    Do yourself a favor. Get a Digital Ocean droplet for $6/mo, Debian version, follow their excellent step-by-step directions to install OpenVPN Server. Done.

    You don’t have to know Linux, the instructions are tight. I only got hung on one step where they left a small thing out. Also, I was drunk. Got it going the next evening.

    This thing has been running for years and years, can’t even remember how to log in, likely lost my SSH key. 🙄 No worries about logging. It’s yours, they can’t take it away or change the rules. It’s yours.

    And BTW, not sure my rate has gone up in the ~7 years I had it. Maybe $1? That might have been because I enabled additional backups.

    • dogs0n@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      6 days ago

      Bad take

      1. You only have one country (the one you run your vps in).
      2. Costs more than any vpn provider (which come with many extra features out the box).
      3. You are not maintaining your OpenVPN installation and having to is likely a pain for most people (you said you “can’t even remember how to login”, which tells you me are not updating your servers OS or OpenVPN itself, which is leaving you open to vulnerabilities in the old software).

      There might be advantages too, but I can’t think of any unless you are gonna use the VPS for other stuff too and creating the vpn is basically free then (but I still wouldn’t do it personally).

  • MintyFresh@lemmy.world
    link
    fedilink
    English
    arrow-up
    6
    ·
    7 days ago

    Been nothing but satisfied with proton. I bought a years worth at once. The flatpack I got installed and works without issue. The only gripe I have is I can’t figure out how to make it (mint) boot up with wiregaurd/proton as the default.

  • Buffalox@lemmy.world
    link
    fedilink
    English
    arrow-up
    4
    ·
    edit-2
    7 days ago

    Nice chart, but I don’t get the payment part, I looked it up for Proton and it states:

    https://protonvpn.com/pricing

    Visa, Mastercard, American Express, PayPal, or Proton credits

    Nothing about cash???
    But they accept all major credit cards.

    • muusemuuse@sh.itjust.works
      link
      fedilink
      English
      arrow-up
      3
      ·
      7 days ago

      As we’ve seems with steam, you can’t rely on credit cards for paying for things. A credit processor simply has to saw “well he could be using that to access porn” and block processing payments for it entirely.

    • errer@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      arrow-down
      1
      ·
      7 days ago

      The Proton prices are also misleading…I got 2 years for $71 on one of their regular sales. I’m sure the same is true for many of the other provider prices listed here.

      • Alaknár@sopuli.xyz
        link
        fedilink
        English
        arrow-up
        3
        arrow-down
        1
        ·
        7 days ago

        I mean, it’s not misleading, it’s just stating the nominal price, that’s it.