Mullvad is a
commercial
Commercial may refer to:
* a dose of advertising conveyed through media (such as - for example - radio or television)
** Radio advertisement
** Television advertisement
* (adjective for:) commerce, a system of voluntary exchange of products and s ...
VPN service
A virtual private network (VPN) service provides a proxy server to help users bypass Internet censorship such as geoblocking and users who want to protect their communications against data profiling or MitM attacks on hostile networks.
A wide ...
based in
Sweden. The name "Mullvad" is the word for "
mole
Mole (or Molé) may refer to:
Animals
* Mole (animal) or "true mole", mammals in the family Talpidae, found in Eurasia and North America
* Golden moles, southern African mammals in the family Chrysochloridae, similar to but unrelated to Talpida ...
" in the
Swedish language
Swedish ( ) is a North Germanic language spoken predominantly in Sweden and in parts of Finland. It has at least 10 million native speakers, the fourth most spoken Germanic language and the first among any other of its type in the Nordic coun ...
. Mullvad operates using the
WireGuard and
OpenVPN
OpenVPN is a virtual private network (VPN) system that implements techniques to create secure point-to-point or site-to-site connections in routed or bridged configurations and remote access facilities. It implements both client-server architect ...
protocols. It also supports
Shadowsocks
Shadowsocks is a free and open-source encryption protocol project, widely used in China to circumvent Internet censorship. It was created in 2012 by a Chinese programmer named "clowwindy", and multiple implementations of the protocol have been ...
as a bridge protocol for censorship circumvention. Mullvad's VPN client software is publicly available under the
GPLv3
The GNU General Public License (GNU GPL or simply GPL) is a series of widely used free software licenses that guarantee end users the four freedoms to run, study, share, and modify the software. The license was the first copyleft for general u ...
, a
free and open-source software
Free and open-source software (FOSS) is a term used to refer to groups of software consisting of both free software and open-source software where anyone is freely licensed to use, copy, study, and change the software in any way, and the source ...
license.
History
Mullvad was launched in March of 2009 by Amagicom
AB, and it had begun by supporting connections via the
OpenVPN
OpenVPN is a virtual private network (VPN) system that implements techniques to create secure point-to-point or site-to-site connections in routed or bridged configurations and remote access facilities. It implements both client-server architect ...
protocol in 2009. Mullvad was an early adopter and supporter of the
WireGuard protocol, announcing the availability of the new VPN protocol in March 2017
and making a "generous donation" supporting WireGuard development between July and December 2017.
In September of 2018, the cybersecurity firm
Cure53
Cure53 is a German cybersecurity firm. The company was founded by Dr. Mario Heidrich, a client side security researcher.
After a report from Cure53 on the South Korean security app Smart Sheriff
Smart Sheriff ( ko, 스마트보안관) is a Sout ...
performed a
penetration test
A penetration test, colloquially known as a pen test or ethical hacking, is an authorized simulated cyberattack on a computer system, performed to evaluate the security of the system; this is not to be confused with a vulnerability assessment. ...
on Mullvad's macOS, Windows, and Linux applications.
[https://cure53.de/pentest-report_mullvad_v2.pdf ] Seven issues were found which were addressed by Mullvad. Cure53 tested only the applications and supporting functions. No assessment was made on the Mullvad server-side and back end.
In October of 2019, Mullvad partnered with
Mozilla
Mozilla (stylized as moz://a) is a free software community founded in 1998 by members of Netscape. The Mozilla community uses, develops, spreads and supports Mozilla products, thereby promoting exclusively free software and open standards, w ...
to utilize Mullvad's WireGuard servers for
Mozilla VPN
Mozilla VPN is an open-source software, open-source virtual private network web browser extension, desktop application, and mobile application developed by Mozilla. It launched in beta test, beta as Firefox Private Network on September 10, 2019, ...
.
In April of 2020, Mullvad partnered with
Malwarebytes
Malwarebytes Inc. is an American Internet security company that specializes in protecting home computers, smartphones, and companies from malware and other threats. It has offices in Santa Clara, California; Clearwater, Florida; Tallinn, Estonia ...
and provided WireGuard servers for their VPN service, Malwarebytes Privacy.
In May of 2022, Mullvad started officially accepting
Monero
Monero (; Abbreviation: XMR) is a decentralized cryptocurrency. It uses a public distributed ledger with privacy-enhancing technologies that obfuscate transactions to achieve anonymity and fungibility. Observers cannot decipher addresses tr ...
.
On the 18th of April, 2023, Mullvad's head office in Gothenburg was visited by officers from the
National Operations Department
The Swedish Police Authority ( sv, Polismyndigheten) is the national police force (''Polisen'') of the Kingdom of Sweden. The first modern police force in Sweden was established in the mid-19th century, and the police remained in effect under ...
of the
Swedish Police Authority
The Swedish Police Authority ( sv, Polismyndigheten) is the national police force (''Polisen'') of the Kingdom of Sweden. The first modern police force in Sweden was established in the mid-19th century, and the police remained in effect under lo ...
who had a search warrant to seize computers being used by Mullvad containing customer data. Mullvad demonstrated that in accordance with their policies, no such data existed on their systems. After consulting with the prosecutor, the officers left without seizing any equipment or obtaining customer information. Mullvad had released a public statement in relation to this information in a blog post on their website two days later, also mentioning that it was their first time that their offices had been searched by authorities. In a letter sent to Mullvad nine days after the search, the Swedish Police Authority stated that they had conducted the search at the request of
Germany
Germany, officially the Federal Republic of Germany (FRG),, is a country in Central Europe. It is the most populous member state of the European Union. Germany lies between the Baltic and North Sea to the north and the Alps to the sou ...
for an ongoing investigation. The investigation involved a blackmail attack that targeted several institutions in the state of
Mecklenburg-Western Pomerania
Mecklenburg-Vorpommern (MV; ; nds, Mäkelborg-Vörpommern), also known by its anglicized name Mecklenburg–Western Pomerania, is a state in the north-east of Germany. Of the country's sixteen states, Mecklenburg-Vorpommern ranks 14th in pop ...
which revealed
IP addresses
An Internet Protocol address (IP address) is a numerical label such as that is connected to a computer network that uses the Internet Protocol for communication.. Updated by . An IP address serves two main functions: network interface iden ...
that were traced back to Mullvad's VPN service.
On the 29th of May, 2023, Mullvad announced that they would be removing support for
port-forwarding, effective on the 1st of July, 2023. This was done due to the use of port forwarding for illegal activities, with this causing interference by law enforcement, Mullvad IP addresses getting blacklisted, and hosting providers canceling their services.
Service
A
TechRadar
''TechRadar'' is an online publication owned by Future and focused on technology. It has editorial teams in the US, UK and Australia and provides news and reviews of tech products and gadgets. It was launched in 2007 and expanded to the US in ...
review noted in 2019 that "Mullvad's core service is powerful, up-to-date, and absolutely stuffed with high-end technologies".
Complementing its use of the open-source OpenVPN and WireGuard protocols, Mullvad includes "industrial strength"
encryption
In cryptography, encryption is the process of encoding information. This process converts the original representation of the information, known as plaintext, into an alternative form known as ciphertext. Ideally, only authorized parties can dec ...
(employing
AES-256
The Advanced Encryption Standard (AES), also known by its original name Rijndael (), is a specification for the encryption of electronic data established by the U.S. National Institute of Standards and Technology (NIST) in 2001.
AES is a variant ...
GCM methodology), 4096-bit
RSA
RSA may refer to:
Organizations Academia and education
* Rabbinical Seminary of America, a yeshiva in New York City
*Regional Science Association International (formerly the Regional Science Association), a US-based learned society
*Renaissance S ...
certificates with
SHA-512
SHA-2 (Secure Hash Algorithm 2) is a set of cryptographic hash functions designed by the United States National Security Agency (NSA) and first published in 2001. They are built using the Merkle–Damgård construction, from a one-way compressi ...
for server
authentication
Authentication (from ''authentikos'', "real, genuine", from αὐθέντης ''authentes'', "author") is the act of proving an assertion, such as the identity of a computer system user. In contrast with identification, the act of indicat ...
, perfect
forward secrecy
In cryptography, forward secrecy (FS), also known as perfect forward secrecy (PFS), is a feature of specific key agreement protocols that gives assurances that session keys will not be compromised even if long-term secrets used in the session key e ...
, multiple layers of
DNS
The Domain Name System (DNS) is a hierarchical and distributed naming system for computers, services, and other resources in the Internet or other Internet Protocol (IP) networks. It associates various information with domain names assigned to ...
leak protection,
IPv6
Internet Protocol version 6 (IPv6) is the most recent version of the Internet Protocol (IP), the communications protocol that provides an identification and location system for computers on networks and routes traffic across the Internet. I ...
leak-protection, and multiple "stealth options" to help bypass government or corporate
VPN blocking
VPN blocking is a technique used to block the encrypted protocol tunneling communications methods used by virtual private network (VPN) systems. Often used by large organizations such as national governments or corporations, it can act as a tool ...
.
Mullvad provides VPN client applications for computers running the Windows, macOS and Linux operating systems. , native iOS and Android Mullvad VPN clients using the WireGuard protocol are available. iOS and Android
mobile operating system
A mobile operating system is an operating system for mobile phones, tablet computer, tablets, smartwatches, smartglasses, or other non-laptop personal computing, personal mobile computing devices. While computers such as typical laptops are "mobi ...
users can also configure and use built-in VPN clients or the OpenVPN or WireGuard apps to access Mullvad's service.
Privacy
Providing personal information used to identify users such as
email addresses
An email address identifies an email box to which messages are delivered. While early messaging systems used a variety of formats for addressing, today, email addresses follow a set of specific rules originally standardized by the Internet Engineer ...
and
phone numbers
A telephone number is a sequence of digits assigned to a landline telephone subscriber station connected to a telephone line or to a wireless electronic telephony device, such as a radio telephone or a mobile telephone, or to other devices f ...
is not required during Mullvad's registration process. Instead, a unique 16-digit account number is anonymously generated for each newly registered user, and this account number is used to log in to the Mullvad on other devices.
For anonymity purposes, Mullvad accepts the anonymous payment methods of
cash
In economics, cash is money in the physical form of currency, such as banknotes and coins.
In bookkeeping and financial accounting, cash is current assets comprising currency or currency equivalents that can be accessed immediately or near-immed ...
and
Monero
Monero (; Abbreviation: XMR) is a decentralized cryptocurrency. It uses a public distributed ledger with privacy-enhancing technologies that obfuscate transactions to achieve anonymity and fungibility. Observers cannot decipher addresses tr ...
. Payment for the service can also be made via bank
wire-transfer,
credit card
A credit card is a payment card issued to users (cardholders) to enable the cardholder to pay a merchant for goods and services based on the cardholder's accrued debt (i.e., promise to the card issuer to pay them for the amounts plus the o ...
,
Bitcoin
Bitcoin ( abbreviation: BTC; sign: ₿) is a decentralized digital currency that can be transferred on the peer-to-peer bitcoin network. Bitcoin transactions are verified by network nodes through cryptography and recorded in a public di ...
,
Bitcoin Cash
Bitcoin Cash is a cryptocurrency that is a fork of Bitcoin. Bitcoin Cash is a spin-off or altcoin that was created in 2017.
In November 2018, Bitcoin Cash split further into two cryptocurrencies: Bitcoin Cash and Bitcoin SV.
History
Sin ...
,
PayPal
PayPal Holdings, Inc. is an American multinational financial technology company operating an online payments system in the majority of countries that support online money transfers, and serves as an electronic alternative to traditional paper ...
,
Swish
Swish may refer to:
Games
* Swish, a basketball shot that goes through the basket without touching the rim or backboard
*Swish, a form of table tennis that can be played both by people who are blind or vision impaired and by people who are sig ...
, EPS Transfer,
Bancontact Bancontact Payconiq Company was formed following the merger of Bancontact Company and Payconiq Belgium. The company is the Belgian market leader in financial services. Company headquarters are in Brussels, Belgium.
History
In March 2018 the comp ...
, iDEAL, Przelewy24, and vouchers sold by multiple resellers.
Payments made via cryptocurrency have a 10% discount. In June 2022, the service announced that it will no longer offer new recurring subscriptions, as this further reduces the amount of personal information that will have to be stored.
Mullvad does not log VPN users'
IP addresses
An Internet Protocol address (IP address) is a numerical label such as that is connected to a computer network that uses the Internet Protocol for communication.. Updated by . An IP address serves two main functions: network interface iden ...
, the VPN IP address used, browsing-activity,
bandwidth
Bandwidth commonly refers to:
* Bandwidth (signal processing) or ''analog bandwidth'', ''frequency bandwidth'', or ''radio bandwidth'', a measure of the width of a frequency range
* Bandwidth (computing), the rate of data transfer, bit rate or thr ...
, connections, session duration, timestamps, and DNS-requests.
Mullvad has many privacy-focused features built into their VPN. Instances include multi-hop, which routes all traffic through an additional Mullvad server before it arrives at its destination, the ability to add a quantum-resistant key exchange to the encryption process, making all data encrypted resistant to
quantum computer
Quantum computing is a type of computation whose operations can harness the phenomena of quantum mechanics, such as superposition, interference, and entanglement. Devices that perform quantum computations are known as quantum computers. Thoug ...
related attacks, and Defense against AI-guided Traffic Analysis (DAITA), which ensures all packets are the same size and also inserts random network traffic (significantly increasing bandwidth usage), though this is only enabled on select servers.
Mullvad has been actively campaigning against the
EU's Regulation to Prevent and Combat Child Sexual Abuse (a.k.a Chat Control), which would require service providers to scan all users' online communications, even encrypted services, arguing that it would make all methods of online communication viewable and thus not private and not anonymous.
Reception
While Mullvad has been noted for "taking a strong approach to privacy and maintaining good connection speeds", the VPN client setup and interface has been noted as being more onerous and technical than most other VPN providers especially on some client platforms.
However, a follow-up review by the same source in October 2018 notes, "Mullvad has a much improved, modern Windows client (and one for Mac, too)". A
PC World
''PC World'' (stylized as PCWorld) is a global computer magazine published monthly by IDG. Since 2013, it has been an online only publication.
It offers advice on various aspects of PCs and related items, the Internet, and other personal tec ...
review, also from October 2018, concludes, "With its commitment to privacy, anonymity (as close as you can realistically get online), and performance Mullvad remains our top recommendation for a VPN service".
In November of 2018,
TechRadar
''TechRadar'' is an online publication owned by Future and focused on technology. It has editorial teams in the US, UK and Australia and provides news and reviews of tech products and gadgets. It was launched in 2007 and expanded to the US in ...
noted Mullvad VPN as one of five VPN providers to answer a set of questions for trustworthiness verification posed by the
Center for Democracy and Technology
Centre for Democracy & Technology (CDT) is a Washington, D.C.-based 501(c)(3) nonprofit organisation that advocates for digital rights and freedom of expression. CDT seeks to promote legislation that enables individuals to use the internet for p ...
.
In March 2019, a ''TechRadar'' review noted slightly substandard speeds.
However, a more recent and more thorough ''TechRadar'' review published on the 11th of June, 2019 stated that Mullvad VPN "speeds are excellent".
This is also supported by a 2024 CNET review that demonstrated 13.5% speed loss in spring 2024 tests. While the latter review notes a shortcoming for mobile users in that Mullvad had not provided mobile VPN client apps,
Mullvad apps for both Android and iOS are now available.
The non-profit
Freedom of the Press Foundation
Freedom of the Press Foundation (FPF) is a non-profit organization founded in 2012 to fund and support free speech and freedom of the press. The organization originally managed crowd-funding campaigns for independent journalistic organizations, ...
, in their "Choosing a VPN" guide, lists Mullvad amongst the five VPNs that meet their recommended settings and features for VPN use as a tool for anonymizing online activity.
Other products
Browser
On the 3rd of April, 2023, Mullvad Browser was released, developed by the
Tor Project
Tor, short for The Onion Router, is free and open-source software for enabling Anonymity, anonymous communication. It directs Internet traffic through a free, worldwide, volunteer overlay network, consisting of more than seven thousand relay ...
team and distributed by Mullvad. It has similar privacy and security settings levels to
Tor Browser
Tor, short for The Onion Router, is free and open-source software for enabling anonymous communication. It directs Internet traffic through a free, worldwide, volunteer overlay network, consisting of more than seven thousand relays, to conc ...
, with an exception being that it operates independently of the Tor network and is meant to be used with a VPN service instead, either Mullvad VPN or another trusted provider. Mullvad Browser has been programmed to minimize the risk of users being tracked and
fingerprinted. It attempts to achieve this through several measures:
* Private mode is enabled by default. This means that
cookies
A cookie is a baked or cooked snack or dessert that is typically small, flat and sweet. It usually contains flour, sugar, egg, and some type of oil, fat, or butter. It may include other ingredients such as raisins, oats, chocolate chips, n ...
are never saved between sessions, nor are visited pages, forms, or search-bar entries.
* It utilizes Firefox's "resist fingerprinting" feature.
* First-party isolation is in place, in which cookies are placed in separate cookie jars so that trackers cannot connect to each other to build a profile of its user.
* No collection of telemetry data.
Search-Engine
On 20 June 2023 Mullvad announced their search-engine Mullvad Leta. Mullvad Leta uses the
Google Search
Google Search (also known simply as Google) is a search engine provided by Google. Handling more than 3.5 billion searches per day, it has a 92% share of the global search engine market. It is also the most-visited website in the world.
The ...
API
An application programming interface (API) is a way for two or more computer programs to communicate with each other. It is a type of software interface, offering a service to other pieces of software. A document or standard that describes how ...
as a proxy and
caches each search. The service is only accessible to devices that have Mullvad VPN turned on. When a user inputs a
web query
A web query or web search query is a query that a user enters into a web search engine to satisfy their information needs. Web search queries are distinctive in that they are often plain text and boolean search directives are rarely used. They var ...
, the service checks if it has a cache of the search, which can be up to 30 days old, before making a call to the Google search API.
Public DNS
Mullvad also offers public DNS servers that offer DNS over HTTPS, DNS over TLS, and various content-blocking filters.
See also
*
Comparison of virtual private network services
A virtual private network (VPN) service provides a proxy server to help users Internet censorship circumvention, bypass Internet censorship such as Geo-blocking, geoblocking and users who want to protect their communications against data profiling ...
References
External links
*
Mullvad repositorieson
GitHub
GitHub, Inc. () is an Internet hosting service for software development and version control using Git. It provides the distributed version control of Git plus access control, bug tracking, software feature requests, task management, co ...
{{VPN
Free and open-source software
Internet privacy
Virtual private network services