VPN Comparison

After making a post about comparing VPN providers, I received a lot of requested feedback. I’ve implemented most of the ideas I received.

Providers

Notes

  • I’m human. I make mistakes. I made multiple mistakes in my last post, and there may be some here. I’ve tried my best.
  • Pricing is sometimes weird. For example, a 1 year plan for Private Internet Access is 37.19€ first year and then auto-renews annually at 46.73€. By the way, they misspelled “annually”. AirVPN has a 3 day pricing plan. For the instances when pricing is weird, I did what I felt was best on a case-by-case basis.
  • Tor is not a VPN, but there are multiple apps that allow you to use it like a VPN. They’ve released an official Tor VPN app for Android, and there is a verified Flatpak called Carburetor which you can use to use Tor like a VPN on secureblue (Linux). It’s not unreasonable to add this to the list.
  • Some projects use different licenses for different platforms. For example, NordVPN has an open source Linux client. However, to call NordVPN open source would be like calling a meat sandwich vegan because the bread is vegan.
  • The age of a VPN isn’t a good indicator of how secure it is. There could be a trustworthy VPN that’s been around for 10 years but uses insecure, outdated code, and a new VPN that’s been around for 10 days but uses up-to-date, modern code.
  • Some VPNs, like Surfshark VPN, operate in multiple countries. Legality may vary.
  • All of the VPNs claim a “no log” policy, but there’s some I trust more than others to actually uphold that.
  • Tor is special in the port forwarding category, because it depends on what you’re using port forwarding for. In some cases, Tor doesn’t need port forwarding.
  • Tor technically doesn’t have a WireGuard profile, but you could (probably?) create one.

Takeaways

  • If you don’t mind the speed cost, Tor is a really good option to protect your IP address.
  • If you’re on a budget, NymVPN, Private Internet Access, and Surfshark VPN are generally the cheapest. If you’re paying month-by-month, Mullvad VPN still can’t be beat.
  • If you want VPNs that go out of their way to collect as little information as possible, IVPN, Mullvad VPN, and NymVPN don’t require any personal information to use. And Tor, of course.

ODS file: https://files.catbox.moe/cly0o6.ods

  • bowreality@lemmy.ca
    link
    fedilink
    arrow-up
    0
    ·
    6 days ago

    Thanks so much! I am looking for a new one because my current one is expensive and of questionable ownership haha.

  • stupid_asshole69 [none/use name]@hexbear.net
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 days ago

    Last time I said it was hard to figure out if this was some kind of malice or just someone without much experience/knowledge.

    I been thinking about what this post and the one before it actually are though. They’re not disinformation, I don’t think they’re misinformation although I think that argument could be made if there was actual intent (and a person could also make the argument that there is intent).

    This just kind of seems like white noise or what would be called slop if it were generated by ai.

    It’s not useful in making a decision.

    A vpn is a tool and you use the right tool for the job. A chart comparing the various similarities and differences between a box and open end wrench, flare nut wrench, socket set, power drill, impact driver and torque wrench would be useless for decision making about what tool to buy because they’re for different jobs.

    If you need to take the lug nuts off a truck the right tool is an impact, if you need to replace brake lines you’re gonna use a flare nut wrench.

    It’s not useful to compare pia and mullvad. If all you need is a cheap way to reliably bypass geofencing then pia is the right tool. If you need deniability and trust then mullvad is the right tool.

    It makes no sense to compare air and nord. If you need the cheapest per device service for bypassing content blocks then the tool is nord. If you need port forwarding for torrents, soulseek and usenet all at once then the tool is air.

    The problem with posts like this is that they don’t really provide any useful understanding or decision making process and wouldn’t be useful from an educational perspective like the comparison between various wrenches made above (if it were in some kind of Tools for Dummies publication) because they’re not even contextualized as such.

    A better start for this kind of post would be “here are some reasons to use a vpn service” or “here are some actual important differences between different vpn services apps”, not weather they’re available on Jim’s cut rate Secure I Promise ™ alternative android App Store.

    • hellinkilla [they/them, they/them]@hexbear.net
      link
      fedilink
      English
      arrow-up
      0
      ·
      9 days ago

      Last time I said it was hard to figure out if this was some kind of malice or just someone without much experience/knowledge.

      Totally disagree with the first few paragraphs. Someone makes a post you feel has inadequate depth and you think they’re the goddamned CIA? I don’t see any basis for the hostile tone.

      If you need port forwarding for torrents, soulseek and usenet all at once then the tool is air.

      But like it’s nice to be able to have a reference to quickly exclude certain options without having to wade through all their various websites. If you already know that you need port forwarding, then a chart like this will help you exclude several mainstream options. If there is some other criteria you already know about it could save you a lot of time.

      A better start for this kind of post would be “here are some reasons to use a vpn service” or “here are some actual important differences between different vpn services apps”

      Those do exist elsewhere and I don’t think there is much wrong with summarizing the current state of things for an informed audience. We are on lemmy here! I wouldn’t mail this chart out to the whole neighbourhood or anything, it’s probably not a good very first intro for most people. Although even for a person just getting started, having the column of criteria on the left could be useful to point out “what are the things to consider”. Like maybe you wouldn’t even guess that the number of devices would be limited.

      Long narrative comparisons can be hard to follow. They are good for understanding the differences but then once you are having an understanding how do you pick? It’s very convenient if someone else goes to the trouble to sift through the information. On wikipedia there are some subjects that have tables comparing things and I find them very helpful. Otherwise I’d just have to spend hours making my own tables.

      BTW wikipedia has a table comparing different kinds of wrenches so obviously someone thought it would be useful!!

      The main issue is that the information could become out of date or erroneous in the first place so you need to verify for yourself whatever is key to your decisions. That’s just the nature of third party info.

      • stupid_asshole69 [none/use name]@hexbear.net
        link
        fedilink
        English
        arrow-up
        0
        ·
        9 days ago

        So like I said, I don’t think the post is malicious.

        I tried to be careful not to take a hostile tone. It’s possible you’re correctly identifying a critical tone, because my comment was intended as criticism of the post.

        There are ways of presenting factual information that are not helpful or useful and actually serve the opposite purpose. You certainly don’t need to use prose to present information in a useful way, but consider how much closer to the old car paint color versus mileage chart (or whatever example they used to teach you about uncorrelated data in school) the posters chart is than the Wikipedia wrench table you linked.

        The Wikipedia wrench table is in the context of “tools for dummies” that I said might be appropriate for that type of presentation, just as an aside.

        The whole point of using some kind of chart or table is to make understanding easier, not more difficult. The posted chart does the latter. I think its because the op doesn’t understand both what they’re trying to say or the information they’re trying to show to convey it and because they chose a really excessively dimensional way to do so. A flowchart, infographic or anything other than a three dimensional chart would be better but since it’s so unclear what they’re trying to express, except possibly how much they love nymvpn and how people should really take a look at that previously underrepresented option, I can’t really make a recommendation.

        • hellinkilla [they/them, they/them]@hexbear.net
          link
          fedilink
          English
          arrow-up
          0
          ·
          9 days ago

          OK well then I should divulge to you full disclosure that I think you, like OP, are also probably not a hostile actor who is commenting to fuck with me specifically or ?lemmy users? in general. More likely someone who’s got a bit spun up their head. But I can’t say for sure…

          As it happens, last time I was looking at different VPN vendors I had to spend a ton of time basically creating an abbreviated version of this chart that had the items most salient to my use case. To sift through the websites, forums, support sections etc, because the information isn’t clearly presented was annoying. They are all trying to emphasize their strengths to make a sale based on their marketing strategy.

          I can say that this chart, exactly as it is, would have saved me significant time had it been available. I found similar but they were old. And I looked at it to see if the conclusion I came to is still the right one for me— it is. I can clearly see the required information.

          • stupid_asshole69 [none/use name]@hexbear.net
            link
            fedilink
            English
            arrow-up
            0
            ·
            edit-2
            9 days ago

            Good! You’re on a public forum and people do that shit! Our instance is slightly better than the other Reddit offshoots but most of them haven’t kicked the social media curse and everything you read on lemmy needs to get the sidest of ways glances.

            I have trouble taking your statement that you can see the required information seriously when the required information literally isn’t there. Important stuff like weather a service accepts cash anonymously, is owned by what company and what that company’s affiliations are (talking about kape and israel here, not the proton red herring) and how forwarded ports are allocated are not included in the chart.

            Of course, that kind of information doesn’t fit neatly into a table so it’s another example of the format of the data being inadequate.

            I can believe that a broad generalized table like this is useful in the context of learning the ropes of what’s out there in terms of vpn services, but it isn’t being presented in that way. If this kind of table were around years ago when I was getting my feet under me I would have made bad choices based on it.

            My comments saying “hey, this is bad and not something to use” are not coming from my seat of power at the player haters annual dinner and awards ceremony but from clear recognition of misleading information based on experience.

  • Dr. Wesker@lemmy.sdf.org
    link
    fedilink
    English
    arrow-up
    0
    ·
    edit-2
    11 days ago

    I appreciate the attempt to quantify availability, but don’t most of these providers allow you to generate OpenVPN and Wireguard configs, which can be used practically anywhere?

    Nevertheless, your work is appreciated.

  • unexpected@forum.guncadindex.com
    link
    fedilink
    English
    arrow-up
    0
    ·
    11 days ago

    Airvpn doesn’t require any personal information. I mean… I guess it asked for a name or whatever, but it doesn’t verify any of it. I certainly didn’t give it anything legitimate, and I paid with mixed crypto so it certainly has as little personal information on me as would be possible with a vpn.

    What gives ivpn, mullvad and nym the advantage for the personal info section?

    • prole@lemmy.blahaj.zone
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      10 days ago

      I can only speak to Mullvad, but if you want to, you can visit their onion site on tor, and pay using Monero while providing zero information. They give you a 16 digit number. And that’s it. That’s the extent of your interaction with them. No name, no email address, no credit card information, nothing.

      Most of that is optional, of course, but the option is always there.

    • The 8232 Project@lemmy.mlOP
      link
      fedilink
      arrow-up
      0
      ·
      11 days ago

      What gives ivpn, mullvad and nym the advantage for the personal info section?

      Originally I was referring to the signup process (since they generate a random account for you) but I edited it to try to add some clarity.

    • Valmond@lemmy.world
      link
      fedilink
      arrow-up
      0
      ·
      10 days ago

      I’m on ProtonVPN because it’s ran by CERN people, so definitely an important information IMO.

          • eldavi@lemmy.ml
            link
            fedilink
            English
            arrow-up
            0
            ·
            9 days ago

            I do not use Windows and I do everything in my power to use non American phones.

            The difference is that proton’s founder voiced support whereas Microsoft has always had a relationship w my govt and it’s dragnet for the Gazan genocide is quiet.

        • Valmond@lemmy.world
          link
          fedilink
          arrow-up
          0
          ·
          10 days ago

          Show me where he endorses Trump.

          Oh, you can’t? But you read it on Facebook or something so it must be true?

          Common, show me your information.

          This is bullshit based on some old tweet Andy Yen did about trump doing good going against big tech. You can read about it here or search for it elsewhere.

          It always comes out when someone says something nice about ProtonVPN, who have an amazing track record IMO.

          • eldavi@lemmy.ml
            link
            fedilink
            English
            arrow-up
            0
            ·
            9 days ago

            A company’s CEO gets to determine the path their company takes and the tweet is indicative of where he plans to steer proton.

              • eldavi@lemmy.ml
                link
                fedilink
                English
                arrow-up
                0
                ·
                8 days ago

                We’re never going to know what they intend to do until they do it, but they’ve given us an indication of what they think and we should believe it

          • porcoesphino@mander.xyz
            link
            fedilink
            arrow-up
            0
            ·
            edit-2
            10 days ago

            That write up does seem to ignore the doubling down here:

            https://lemmy.ca/comment/13913116

            Calling out that JD Vance was the only one to answer is pretty troubling to me after reading about some of his new-right ties. It’s way, way too close for my liking to a mouse telling everyone that will listen that the cat was amazing for inviting him and all his friends to his house in a week. ie. Playing into what just seems like an obvious strategy.

            That said, I’m pretty ignorant about the CEO. I just remembered this lemmy comment and I didn’t notice it included in the write up that was being linked.

          • AdrianTheFrog@lemmy.world
            link
            fedilink
            English
            arrow-up
            0
            ·
            10 days ago

            Ok, just read the artlce cited on wikipedia and it sounds like calling him a Trump supporter is a bit of an exaggeration. He seems basically centrist. Which is not great but not nearly as bad.

            • Valmond@lemmy.world
              link
              fedilink
              arrow-up
              0
              ·
              edit-2
              10 days ago

              Thank you!

              And sorry if I came around a bit agressively. Kudos to you for checking the link and updating your view.

    • dogs0n@sh.itjust.works
      link
      fedilink
      arrow-up
      0
      ·
      edit-2
      9 days ago

      It’s not entirely a big deal to me.

      I think I agree with the staff reply on this thread: https://airvpn.org/forums/topic/56799-audits/

      Our software is free and open source, while we repute at the moment not acceptable to provide external companies with root access to our servers to perform audits which can not anyway guarantee future avoidance of traffic logging or transmission to third parties. On the contrary, we deem very useful anything related to penetration tests. Such tests are frequently performed by independent researchers and bounty hunters and we also have a bounty program.

  • ColeSloth@discuss.tchncs.de
    link
    fedilink
    arrow-up
    0
    ·
    11 days ago

    Been using windscribe for 2 years now. Big fan so far. Haven’t had any issues and it’s nice that I can set it up on my android phone to block access to everything on there if by off chance it were to crash or go down.

  • Ferrous@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 days ago

    Good work. Might be valuable to add a “allows port forwarding” row.

    • pineapple@lemmy.ml
      link
      fedilink
      English
      arrow-up
      0
      ·
      10 days ago

      Could be wrong but I think it’s due to the security vulnerabilities present, its generally better to just use Google play store with an anonymous account.

      • cmhe@lemmy.world
        link
        fedilink
        arrow-up
        0
        ·
        10 days ago

        Na… The likelyhood of installing some bad or fake app from google play store is much higher than on fdroid.

        • Corridor8031@lemmy.ml
          link
          fedilink
          arrow-up
          0
          ·
          10 days ago

          i think the security issues are not about fake apps, but about fdroid signing the builds themself, while their build infrastrcuture is described as insecure

          • cmhe@lemmy.world
            link
            fedilink
            arrow-up
            0
            ·
            edit-2
            10 days ago

            The issue there AFAIK is that some app builds aren’t fully reproducible, because if they were the developer signature would still apply and be used. In the reproducible case the security of the build infra wouldn’t matter, because the same app would be produced the same regardless were they are build.

            Without reproducible builds, you cannot really trust the software anyway, because the Dev could hook some hidden code only for the released binary app and sign that.

            • Corridor8031@lemmy.ml
              link
              fedilink
              arrow-up
              0
              ·
              edit-2
              10 days ago

              uhm no not really? I mean reproducible builds are used to cross verfiy that it is the same binary in this case, but like android has no mechanism to do that, this is not how it works.

              that a build should be reproducible is more about your second point and doesnt really have anything to do with fdroid, as far as i know

              Edit: these links should explain it all: https://discuss.grapheneos.org/d/21675-fdroid-security/2

              • cmhe@lemmy.world
                link
                fedilink
                arrow-up
                0
                ·
                10 days ago

                Once it passes inspection, the F-Droid build service compiles and packages the app to make it ready for distribution. The package is then signed either with F-Droid’s cryptographic key, or, if the build is reproducible, enables distribution using the original developer’s private key. In this way, users can trust that any app distributed through F-Droid is the one that was built from the specified source code and has not been tampered with.

                https://f-droid.org/en/2025/09/29/google-developer-registration-decree.html

  • MrSulu@lemmy.ml
    link
    fedilink
    English
    arrow-up
    0
    ·
    10 days ago

    Proton and Mullvad VPN appear to win the battle of the charts for privacy & security.