Oddbean new post about | logout
â–² â–¼
 DuckDuckGo announces new 3-in-1 Privacy Pro subscription with VPN, Personal Information Removal, and Identity Theft Restoration.

I don't recommend your daily-driver VPN(s) knowing your personal info. However, not having a vanilla front-facing identity online can often be more suspicious than not having one, so I can definitely see a compartmentalized usecase for it this service.

#cybersecgirl #duckduckgo #privacy #vpn #infosec

https://spreadprivacy.com/meetprivacypro/ 
â–² â–¼
 I was reading their privacy policy yesterday...

```
We don't keep logs of your VPN activity.
We have no way to tie what you do while connected to the DuckDuckGo VPN to you as an individual. For example, we don't have any record of website visits, DNS requests, IP addresses connected, or session lengths.

We only keep anonymous performance metrics that we cannot connect to your VPN activity.
Our VPN servers store generic usage and diagnostic data (for example, CPU load and errors), but nothing connected to any individual. We use this non-identifying information for VPN performance, for example to ensure VPN servers aren't overloaded, under attack, or having network issues.

We only use dedicated VPN servers.
This means our VPN servers are not shared with anyone else. We rent our VPN servers from hosting providers carefully selected to meet our privacy requirements. Our VPN servers are also physically separated from other DuckDuckGo servers, like those used for search infrastructure.
```

But then goes on to say...

```
VPN Terms
- You may use our VPN on a maximum of five devices simultaneously.
- You agree that we may impose usage or service limits or block certain kinds of usage (for example, abuse) at our sole discretion to protect us, our users, and DuckDuckGo.
```

How would they know you're abusing the service if they aren't tracking you? 🤔 
â–² â–¼
 I don’t trust DuckDuckGo 
â–² â–¼
 Checks out 🙄

🎯 I would not trust this service for anything but the suggested usecase above. The DDG Microsoft debacle ruined my trust in them as a true privacy-respecting service, even they claim this is just legalese to cover their asses. 
â–² â–¼
 Any VPN services you would recommend above the rest? 
â–² â–¼
 I recommend having at least one backup VPN. Proton, Mullvad, and IPVPN each have strengths and weaknesses for specific usecases, but are all good choices. 
â–² â–¼
 Would you run two or more at the same time? 
â–² â–¼
 Sometimes, for very specific usecases but as a rule, I don't recommend double VPN, it can lead to network issues and reduced security vs a multi-hop vpn like IVPN. 
â–² â–¼
 *IVPN 
â–² â–¼
 What are the individual strengths of each, and what you of work is each best for? 
â–² â–¼
 Mullvad servers tend to get blocked by more sites than Proton so I don't recommend it for installing as an always-on VPN on a firewall for example while Proton is a good choice. It's easier to set up Proton on QubesOS ATM. Mullvad doesn't require any sign-up info like email etc. IVPN has multi-hop VPN routes so it's more private, but will be slower. These are just a few examples. 
â–² â–¼
 Great summary thanks! Mullvad has multi-hop now also. 
â–² â–¼
 Thx. Yes, but not yet on mobile. 
â–² â–¼
 Yep, good point. 
â–² â–¼
 DDG was always lacking to me as a search engine  
â–² â–¼
 💯 Check out Kagi