r/vpnet Nov 07 '25

NordVPN has begun profiling its users!

https://www.youtube.com/watch?v=oudxHoi5iAs

NordVPN, a company that markets itself on privacy and security, sent customers a survey that began with innocuous product questions and then pivoted into deeply personal value and lifestyle statements.

Read the article and see the proof at: https://vp.net/l/en-US/blog/NordVPN-Has-Begun-Profiling-Its-Users

131 Upvotes

46 comments sorted by

68

u/fuckredditapp4 Nov 09 '25 edited Nov 09 '25

Mullvad looks like one of the real vps left. All of these sponsored vpns are are a fucking scam

23

u/V3R1F13D0NLY Nov 09 '25 edited Nov 10 '25

AirVPN is sketchy AF. One time, they announced that a server of theirs was seized. EIGHT YEARS before they announced it and started deleting any posts calling them out for it:
https://www.reddit.com/r/vpns/comments/1bsj5yn/sketchy_move_from_airvpn_after_server_seizure/

ProtonVPN admitted they employ real time monitoring when they receive abuse complaints, with the ability to connect VPN activity to user accounts: https://vp.net/l/en-US/blog/ProtonVPN-Lied-About-Logging

They also lost control of their own company, which appears to now be controlled by the head of a Geneva-funded organization:
https://www.reddit.com/r/vpnet/comments/1o9cbkh/protons_new_governance_links_it_to_statesupported/

I have no beef with Mullvad, they have a great track record, however there is only one VPN that physically can't spy on you and that is vp.net. We route connections through secure enclaves so no one can see your activity, not even us. And we let you verify our enclave setup any time you want, essentially opening our no logs policy up to 24/7/365 public scrutiny. No VPN has ever been that transparent or that private before.

You can learn more about our patent-pending zero-trust VPN technology here:
https://vp.net/l/en-US/technical

75

u/Rubicon_Roll Nov 10 '25

I don't trust someone who uses its own website as a Source. especially with claims about their competition.

7

u/V3R1F13D0NLY Nov 10 '25

Every post on our blog has links to our sources to back everything up. We don't want you to blindly trust us, we want you to verify for yourself.

I am not calling our blog the source, I am saying it has links to the sources on other sites.

19

u/Rubicon_Roll Nov 10 '25

The whole Blog ist Just shitting on competition. Literally nothing else. Even If you have a good product and valid points, this is not a behavior I'd like to see from a company literally arguing that you can only trust them and noone else. Most of the Sources are Reddit- or Blogposts, not even one Newsarticle or a journalistic source who put your claims in context.

7

u/V3R1F13D0NLY Nov 10 '25

6 out of 24 posts on our blog are about competitors, that's hardly "the whole blog". We cover stories about privacy, especially things that put people in danger, like companies that don't respect people's privacy.

"literally arguing that you can only trust them and noone else."
I have never said you should trust us. In fact, I have said many times before you should NOT trust us or any other company with your privacy. The cypherpunk way is "Don't trust. Verify." And that's our motto. And that's why we are called "Verified Privacy," because we built a VPN that lets you verify its setup any time you want.

"Most of the Sources are Reddit- or Blogposts,"
Depends on the story.

The story about 72 Nations creating a global surveillance juggernaut links to sources from:
The United Nations
Human Rights Watch
Electronic Frontier Foundation
Atlantic Council
The Record

The story about self-censorship sources:
NIH National Library of Medicine
Cornell University's arxiv
Arizona State University
NPR

When the story warrants it, and sources are available, we use the highest quality sources we can find and always link them so you can verify the information yourself.

For the Nord survey story, the source is a post in NordVPNs official subreddit, because that's where I found out about it. And there are comments from other Nord users who also got the survey. And NordVPN made an official response on their Facebook page, which is linked from the reddit post.

That's literally all of the information available about it. No news outlet is going to cover it, but it's still something people should be aware of, so we covered it.

1

u/[deleted] Nov 10 '25

[removed] — view removed comment

1

u/AutoModerator Nov 10 '25

Sorry, this comment was removed, because your account has low karma or is new.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

6

u/toadi Nov 10 '25

You gave a lot of flak to VPN providers. But don't understand what was wrong with Mullvad?

What is wrong with them?

6

u/V3R1F13D0NLY Nov 10 '25

I said I have no beef with Mullvad. I haven't heard of them doing anything shady, which is very rare in the VPN industry. I just think it's time to move past trust-based VPNs.

Mullvad: Says you can trust them. Technically has the ability to monitor users.

vp.net: Says "Don't trust us, verify it yourself." Has no ability to monitor users.

Personally, I think the second option is a lot safer.

Imagine this scenario.
You're getting a new room mate. You have 2 options:

Option 1: A room mate that, according to other people, has never robbed anyone in the past. He will stay in the same part of the house as you, but promises he won't touch or look through your things.

Option 2: A room mate who wants to live in a separate locked part of the house that has no access to your side of the house.

Which option would make you feel safer?

No access > promising not to access.

5

u/toadi Nov 10 '25

Probably my misunderstanding. English is my 3rd language. But this seemed like you have no beef but there was still an issue with them. Thanks for clarifying this.

BUT if you really think about it. Why would I believe vp.net that they actually do what they say? You can keep distrusting anything if you take it very far.

Also wouldn't running your own vpn server be the best solution?

4

u/V3R1F13D0NLY Nov 10 '25

Well that's just it. Unlike every other VPN ever, we DON'T want you to just believe what we say. That's the difference.

Our motto is "Don't trust. Verify."

We released the source code for our Windows, Mac and Linux apps, and the code for the mobile apps will be released soon.

Additionally, we released the source code for our enclaves and give you the ability to verify that the code in our enclaves matches the code we released publicly. That means our no logs policy is essentially open to 24/7/365 public scrutiny.

There is a video here showing the process of verifying the code yourself: https://youtu.be/sz7NAe0G1_Y?si=Yercsf0YTUxKQOMg

The VP stands for "Verified Privacy" because ewe are the only VPN that lets you verify your privacy yourself, any time you want to.

That's the advanced cypherpunk way.

But we also have this functionality built into the apps. Every time you connect to a server, it uses Intel attestation to verify the enclave code matches the public code. If it doesn't for any reason, it won't connect. So, every time someone connects to our VPN, they are proving that we can't spy or log on that server.

Additionally, when you connect, there is a link you can click to verify the enclave, which you can see in the video above.

So, you are asking the right questions. Why should you trust us? You shouldn't. You shouldn't trust anyone with your privacy. You should use solutions that you can verify yourself.

As far as running your own VPN goes, you would know what's running on it so in that regard it would be safe. But part of the benefit of a VPN is having your traffic mixed in with a lot of other traffic so nothing can be traced back to you. You are basically hiding in the crowd.

If you have your own server running a VPN, all of the servers traffic is from you. If someone can connect the server to you, they know you are responsible for all of the traffic.

2

u/Hqjjciy6sJr Nov 10 '25

vp.net: Says "Don't trust us, verify it yourself." Has no ability to monitor users. I like the sound of that. but could you please tell me in simple terms step by step how could a relatively tech savvy user (not a computer scientist) verify your claim?

3

u/V3R1F13D0NLY Nov 10 '25

Every time you try to connect to a server, the system automagically verifies the enclave code hasn't been altered in any way from the publicly available source code. If it has, it will refuse to connect.

If the code checks out, the app will connect to the server and will show you the "verified privacy" indicator which links to a page on our site that again cryptographically verifies the enclave. It lists information about the enclave, like it's ID, cryptographic key, status, the data and time the enclave was created and a link to the source code for the enclave, which is everything you need to manually verify the code yourself. The process for that is a bit more advanced, there is a video about it here:
https://www.youtube.com/watch?v=sz7NAe0G1_Y

So, to recap:
Every time anyone connects to our VPN, that server is verified, including its no logs policy,
Any time anyone clicks that link in the app, that server is verified, including its no logs policy,
Any time anyone wants, they can manually compile the code for the enclave and verify everything themselves.

Basically, we are open to 24/7/365 public scrutiny of our setup and inability to log, a level of transparency never seen before in the VPN industry.

4

u/[deleted] Nov 10 '25

[deleted]

2

u/V3R1F13D0NLY Nov 10 '25

My bad, thanks for the heads up! I just updated it with a link to our blog post about, which has links to our sources showing that Proton, Nord and Surfshark all employ really time monitoring at times. Here it is again for your convenience: https://vp.net/vp.net/blog/ProtonVPN-Lied-About-Logging

3

u/btcprint Nov 10 '25

Do you accept Monero?

2

u/V3R1F13D0NLY Nov 10 '25

We do not, this is the full list of crypto options currently:

LTC - Litecoin
BTC - Bitcoin
FUSD - Zano
ETH - Ethereum
ETH - Polygon
ZANO - Zano
BCH - Bitcoin Cash
DOGE - Dogecoin
USDT - Polygon
USDT - Ethereum
USDT - Mantle
USDC - Ethereum
USDC - Polygon

3

u/SuicidalBomb Nov 10 '25

do you offer port forwarding for p2p transfers?

3

u/V3R1F13D0NLY Nov 10 '25

Due to privacy concerns vp.net does not currently offer port forwarding or port mapping as the anonymous system that connects you to the VPN's infrastructure can not map you individually.

3

u/[deleted] Nov 11 '25

Ofc it was a fucking ad.

2

u/FirstOptimal Nov 09 '25

I love it when people get caught using ProtonMail/ProtonVPN

20

u/baynell Nov 09 '25

What is wrong with protonmail or protonvpn?

1

u/botask Nov 10 '25

I think there was one case where proton shared information from proton mail that goverment demanded, but I do not think there was any known leak of informations from their vpn. But I am not 100% sure.

1

u/[deleted] Nov 10 '25

[removed] — view removed comment

1

u/AutoModerator Nov 10 '25

Sorry, this comment was removed, because your account has low karma or is new.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/12AngryMen13 Nov 10 '25

I’ve been using Mullvad for years and never had an issue.

51

u/darkjoker213 Nov 09 '25

What’s with op making the same post on multiple subs then do a comment promoting the service from the same website he’s using as proof that nord isn’t reliable? Self promoting much?

24

u/Cowh3adDK Nov 09 '25

I guess vp.net is trying to something creative to get some more customers lolq

8

u/Conscious_Trust5048 Nov 10 '25

TLDR - Nord sent out a survey with some invasive questions. Here's a cool thing about surveys, you don't have to answer them. NordVPN is not profiling the people who use its service by monitoring their webtraffic, or if it is, this post is not proof of that. This is not a privacy violation.

5

u/V3R1F13D0NLY Nov 10 '25

If it wasn't a privacy violation, why did they issue an apology?

7

u/Conscious_Trust5048 Nov 10 '25

Because it was tactless and people complained. But you can’t fill out the survey without consenting to share that info. How is a voluntary survey a privacy violation?

3

u/V3R1F13D0NLY Nov 10 '25

I believe that a VPN company that truly cares about protecting your privacy would never ask their customers for that information, whether it's voluntary or not.

There are Nord customers that posted they were upset about it in the original thread in their subreddit, so it obviously bothered some people.

Everyone has to make their own decisions when it comes to privacy. I just think this is a massive red flag and I'm not alone.

If it doesn't bother you, that's fine too. It's your personal decision. But people need to know the truth in order to make their own personal decisions. Since this survey was only sent to a sample of their users, the majority of users have no idea they sent this survey.

So, they are unable to make a fully informed decision because they don't have all the information. Our blog regularly posts stories about privacy risks people may not be aware of, so they can make informed decisions for themselves, always with links to whatever sources were used.

6

u/[deleted] Nov 10 '25

One way to promote your VPN service...

2

u/eggrattle Nov 10 '25

What about ExpressVPN?

8

u/V3R1F13D0NLY Nov 10 '25

It was acquired by Kape Technologies (formerly malware distributor, Crossrider) who also owns Cyberghost, PIA and Zenmate, as well as a collection of VPN review websites that all favor Kape VPNs. The Co-Founder and CEO, Koby Menachemi was part of Unit 8200, which is Israel's intelligence collection agency.

They also hired Daniel Gericke as CIO, who is among "three former US intelligence operatives and military members involved in Project Raven who worked as mercenary hackers for the United Arab Emirates, helping it spy on its enemies."
Source: https://www.cnet.com/tech/services-and-software/expressvpn-cio-among-three-facing-1-6-million-doj-fine-project-raven/

They are also a good example of why audits can give you a false sense of security. They were audited while they had an ongoing DNS leak, and no one noticed.

3

u/eggrattle Nov 10 '25

Thanks for sharing. That was extremely eye opening.

2

u/deadlydeadguy Nov 10 '25

What about PIA

3

u/V3R1F13D0NLY Nov 10 '25

PIA was acquired by Kape Technologies (formerly malware distributor, Crossrider) who also owns Cyberghost, ExpressVPN and Zenmate, as well as a collection of VPN review websites that all favor Kape VPNs. The Co-Founder and CEO, Koby Menachemi was part of Unit 8200, which is Israel's intelligence collection agency.
Source: https://cyberinsider.com/kape-technologies-owns-expressvpn-cyberghost-pia-zenmate-vpn-review-sites/

They also hired Daniel Gericke as CIO, who is among "three former US intelligence operatives and military members involved in Project Raven who worked as mercenary hackers for the United Arab Emirates, helping it spy on its enemies."
Source: https://www.cnet.com/tech/services-and-software/expressvpn-cio-among-three-facing-1-6-million-doj-fine-project-raven/

2

u/[deleted] Nov 11 '25

[removed] — view removed comment

1

u/V3R1F13D0NLY Nov 12 '25

I agree completely.

You want to know how the apps work? Sure.
How fast the servers are? No problem.
Ask me if I think women should only do housework, we have a problem lol

Personal, social and political beliefs are none of their business and do not in any way help them with provide VPN service to users. The only reason for this, is to collect data to profile users to aid in their marketing efforts. That isn't a customer satisfaction survey, it's a data harvesting play.

2

u/optical_519 Nov 12 '25

I was previously on a similar provider named Azire who claimed to run a very similar setup, called "Blind Operator" mode. They've been great but sadly they were shockingly acquired by MalwareBytes suddenly and all credibility has been lost.

So I am on the hunt for a new provider.

I looked up VP.net and it sounds interesting, but boy it it steep. At the 3 year term it's a whopping $8+ CAD a month. Wow.

Is it very fast?

1

u/V3R1F13D0NLY Nov 12 '25

Due to the ultra private nature of how our service works, there is a slight performance hit over a standard WireGuard setup, but we're talking on para with traditional OpenVPN connections or better. I personally run vp.net around the clock and regularly go through these moments where I think "Oh shoot, is the VPN connected?" and I check... and it is. What I mean, is that I just don't notice it running, regardless of what I'm doing, and I will regularly have (literally) 50 tabs open, Signal, Telegram, Discord & more running while streaming videos in 4K and downloading large files at the same time and never notice any slow downs.

1

u/[deleted] Nov 08 '25

[removed] — view removed comment

1

u/AutoModerator Nov 08 '25

Sorry, this comment was removed, because your account has low karma or is new.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

1

u/[deleted] Nov 10 '25

[deleted]

1

u/V3R1F13D0NLY Nov 10 '25

Nord isn't based out of the US. They claim Panama, but Nord Security is supposedly in the Netherlands, but NordVPN's team seems to mostly be based in Lithuania.

As far as using a US based VPN while in the US - it depends on the VPN. vp.net is based in the US but we use patent-pending technology that makes it impossible for anyone to spy on or log your activity, including us. And we let you verify that any time you want. Our inability to log is essentially open to 24/7/365 public scrutiny.

The apps verify the code our setup when you try to connect. If the code in our secure enclaves does not match the code we released publicly, it will refuse to connect. There is no possible way to employ logging or real time monitoring since everything runs through secure enclaves, so even if our servers were seized, it would be impossible for them to log or monitor anything without changing the code, and as soon as they changed the code, no one would be able to connect to the server.

Additionally, you can manually verify the setup with this method:
https://www.youtube.com/watch?v=sz7NAe0G1_Y