I am pretty excited about this new release. The app is open source and seems to follow strict security standards.

      • Free Palestine 🇵🇸@sh.itjust.works
        link
        fedilink
        arrow-up
        4
        arrow-down
        1
        ·
        9 months ago

        I’m pretty sure the entry server doesn’t know the destination, as WireGuard encrypts everything, and it wouldn’t make sense for the entry node to already decrypt the traffic. It also protects against ISPs or other companies/institutions monitoring network traffic.

          • Free Palestine 🇵🇸@sh.itjust.works
            link
            fedilink
            arrow-up
            4
            arrow-down
            1
            ·
            9 months ago

            I think so. But with Tor, you of course get the benefit that (ideally) all 3 nodes are run by different parties, which is not the case with multi-hop VPNs. They might be hosted by different server providers, but they are still all administered by the VPN provider.

      • jet@hackertalks.com
        link
        fedilink
        English
        arrow-up
        2
        ·
        9 months ago

        Ignoring privacy features, its a great way to make up for bad internet routing, so I can connect to local mullvad server, then route my traffic to far away mullvad server, and get a better connection (latency, packet loss) then if i went directly.

    • jet@hackertalks.com
      link
      fedilink
      English
      arrow-up
      1
      ·
      9 months ago

      Mullvad does support multi-hop when you generate a wireguard config (not in their app currently).

      • Free Palestine 🇵🇸@sh.itjust.works
        link
        fedilink
        arrow-up
        3
        arrow-down
        1
        ·
        9 months ago

        I know, but a static Wireguard config makes changing servers a pain in the butt. A native mobile app with multi-hop support is a must-have for me. Still, props to Mullvad for offering their service for just 5 EUR/month, including multi-hop (on Desktop). IVPN is 10 bucks, they have fewer servers and it can be kinda slow at times.

    • Pantherina@feddit.deOP
      link
      fedilink
      arrow-up
      4
      ·
      9 months ago

      Yes on Android it allows permanently set split tunneling. Btw, all system apps CAN bypass the VPN if they want. Captive portal, connectivity check and possibly SUPL do this. So GrapheneOS, maybe distros with the same patches, the rest will send your IP to Google.

      On Android root you can use Magisk modules to change the SUPL provider. Using an adb permission “captive portal control” can change the captive portal server.

      But nothing can change the connectivity check, device attestation and whatnot, which still all go to Google.

    • DarkThoughts@kbin.social
      link
      fedilink
      arrow-up
      2
      ·
      edit-2
      9 months ago

      Not in a comfortable way unfortunately.
      You can launch an app through the Mullvad app which then will be launched bypassing the VPN until it is closed. You cannot permanently blacklist / whitelist specific apps to always / never be routed through the VPN.

      Edit: Didn’t see the community. On Android it seems to feature a whitelist for apps to not be routed through the app, which seems to be permanent. Not sure why the desktop version does not have that.