all 16 comments

sorted by: hot top controversial new old
[โ€“] 60 points 11 months ago (3 children)

A penetration test is not an audit and does not provide any such assurance that logs are not retained. The goal of a penetration test is to penetrate via vulnerabilities and misconfigurations, not validate public logging claims about a service

  • source
  • hideshow 3 child comments
  • [โ€“] 35 points 11 months ago (2 children)

    The audit covered every public-facing component of Mullvadโ€™s online presence, including the website, the Tor-only Onion service, the rsync setup, and the internal content management system (CMS). Each of these elements was examined for common attack vectors, misconfigurations, or any signs of hidden data collection.

    I believe checking the "internal content management system (CMS)" is what they are using to say there were no logs.

    They linked a more detailed report in the article, but I didn't look at it. It may contain something different than my takeaway from the article.

  • source
  • parent
  • hideshow 2 child comments
  • [โ€“] 6 points 11 months ago

    The content management interface for the Mullvad VPN web application is a Django ap- plication that allows content administrators to manage the blog, help guides and similar articles.

    Doesn't look like the CMS is anything to do with the VPN service itself.

  • source
  • parent
  • [โ€“] 34 points 11 months ago (4 children)

    Ah, Mullchad. The best VPN for those who don't need port forwarding.

  • source
  • hideshow 4 child comments
  • [โ€“] 10 points 11 months ago (3 children)

    Still on PIA despite the sketchy history just for that feature.

  • source
  • parent
  • hideshow 3 child comments
  • [โ€“] 6 points 11 months ago (6 children)

    I wish they would make a flatpak

  • source
  • hideshow 6 child comments
  • [โ€“] 3 points 11 months ago (4 children)

    If you're using an immutable distro, you can still use mullvad. I've had no problem if I download the rpm (I'm on Bazzite), and install it as a local package. Only annoying thing is that I have to manually update it, but it's really not hard.

  • source
  • parent
  • hideshow 4 child comments
  • [โ€“] 1 point 11 months ago (3 children)

    Yeah, it's easy enough on bazzite, but it's such a pain on the steam deck to get a VPN working. I haven't been able to do the manual config lately either

    Proton VPN flatpak on steam deck works great though

  • source
  • parent
  • hideshow 3 child comments
  • [โ€“] 1 point 11 months ago

    You could try CachyOS on the Deck, I used it for a few months and it worked great. It's practically the same as SteamOS but with pacman and paru available, with all the advantages this brings.

    I sold my Deck and bought a Legion Go, and I'm also using CachyOS here. Same results.

  • source
  • parent