@kazani
Mullvad continues to pass audits
https://mullvad.net/en/blog/new-security-audit-of-account-and-payment-services
A new security audit report conducted by the German firm X41 D-Sec on Mullvad VPN concludes that no critical flaws or risks to user's privacy were found.
The white-box audit focused on the backend services of accounts and payments, including the public API, authentication, device registration, payment processing, and WireGuard key distribution.
While 3 medium-severity issues were found, Mullvad responded quickly by fixing the vulnerabilities during the audit and considering recommendations to strengthen aspects such as mutual TLS configuration, cryptographic signatures in VPN relays, and concurrency management in multithreaded environments.
The audit positively highlights Mullvad's minimalist approach to data management, with strict compartmentalization separating user identities from VPN keys, and regular key rotation.
Rightly so, Mullvad is one of the best VPN you can have today.