# Mullvad's 2024 security audit is now available

**URL:** https://discuss.privacyguides.net/t/mullvads-2024-security-audit-is-now-available/23108
**Category:** General
**Created:** 2024-12-11T16:41:30Z
**Posts:** 22

## Post 1 by @anon80779245 — 2024-12-11T16:41:30Z

> **[The report for the 2024 security audit of the app is now available | Mullvad VPN](https://mullvad.net/en/blog/2024/12/11/the-report-for-the-2024-security-audit-of-the-app-is-now-available)**
>
> The third party security audit of the Mullvad VPN app has concluded that the app has a high security level. Some non-critical issues were found, and have been fixed to the extent possible.

Very interrestting. They fixed the vulnerability of overflows, and a Windows specific one.

Other vulnerabilities are privacy-related, including minor leaks of the tunnel. This has already been remedied on Linux and they asked Google to fix it on Android.

> Last words  
> Mullvad is very happy with the quality of the audit performed by X41 D-Sec. X41 managed to find issues in our code that previous audits missed, which shows that there is great benefit in having audits performed by different companies. This is not meant as criticism against the previous audit companies. The app is too big to realistically look into every aspect and detail in a few weeks. We have always had the explicit tactic to use a different third party auditor for every audit, to get different sets of eyes from people with different skills and mindsets every time.

---

## Post 8 by @anon29374801 — 2024-12-12T00:14:34Z

Slightly off topic but how does PG evaluate if an auditor, such as X41, is trustworthy or not?

I have no doubts that this is a legit audit but, anytime audits come up I do wonder what the process is for telling if the audit meets the “security audits from a **reputable** third-party firm.” requirement? :slight_smile:

---

## Post 9 by @anon42475305 — 2024-12-12T00:30:31Z

Maybe it’s just me, but I feel as though the word reputable almost speaks for itself? If an auditing company has been around for a while and demonstrates an ability to find serious vulnerabilities in the software they review, then they would be considered trustworthy. It would be difficult for an incompetent actor to present themselves as a competent one in this context. Hopefully, that helps.

---

## Post 10 by @anon29374801 — 2024-12-12T00:36:05Z

Thanks for the response.

> [@anon42475305](#):
>
> Maybe it’s just me, but I feel as though the word reputable almost speaks for itself?

Maybe I am misunderstanding what you mean but from what I can tell most users would not be able to name two auditing companies let alone evaluate based on reputation. In my mind, none of these companies have reputations that speak for themselves.

> [@anon42475305](#):
>
> It would be difficult for an incompetent actor to present themselves as a competent one in this context.

I am not sure that’s true, auditing is a notorious marketing tool in the VPN space. Take [PureVPN](https://www.purevpn.com/blog/kpmg-validates-purevpn-no-log-claims/) and their “always on” audit from [KPMG](https://kpmg.com/us/en/capabilities-services/audit-services.html) as an example.

How many users are able to look at KPMG and X41 and have any clue which is a “reputable” service?

---

## Post 11 by @anon42475305 — 2024-12-12T00:41:55Z

I feel there has been a misunderstanding on my part. In terms of auditing whether a VPN provider keeps logs, I don’t have a good answer for what makes an auditing company trustworthy. I was referring to audits like the subject of this topic, which audit the security of a company’s products/services. In that case, I still feel that demonstrating an ability to deliver results indicates they are at least somewhat competent. This specific audit caught potential vulnerabilities which had been present for years despite previous audits, which for me adds to this company’s credibility.

---

## Post 12 by @anon29374801 — 2024-12-12T00:43:56Z

> [@anon42475305](#):
>
> I feel there has been a misunderstanding on my part. In terms of auditing whether a VPN provider keeps logs, I don’t have a good answer for what makes an auditing company trustworthy.

Yeah. I meant how does PG tell if the company providing the audit is reputable? It seems like something that would be important to the VPN criteria.

My assumption is most users just read the conclusion at the end of the audit and have no clue if the audit itself is technically sound, which means there needs to be some level of trust in the company providing the audit.

---

## Post 14 by @anon29374801 — 2024-12-12T13:27:56Z

> [@Anon47486929](#):
>
> There is no way for a person to check of the audit was technically sound unless you are the one doing the audit.

Interesting, did not realize that.

> [@Anon47486929](#):
>
> Its mostly a web of trust thing, at least for me

Sounds reasonable to me. I think from a criteria perspective it would be nice to hear from [@staff](/groups/staff) about how they do it but, this sounds reasonable.

I do wonder if its appropriate to re-evaluate these groups every so often and if there is a process to do that. A company like Kaspersky Labs comes to mind, where they have all the accomplishments you could want from a company in their field but could also be considered untrustworthy.

It has always been interesting to me that there is seemingly so little known about auditing companies for most users while audits are a minimum criteria for VPNs, so it always interested me on how PG looks at those companies.

---

## Post 16 by @anon29374801 — 2024-12-12T15:52:46Z

> [@Anon47486929](#):
>
> What is PG’s view is more important than what I do.

Was not going to respond, as I agree with you and I have probably veered the original post a bit off topic but, I do want to say your view is just as important and I think anytime someone offers how they evaluate an issue, gives perspective to the rest of the community. :slight_smile:

Would also be interested in seeing if someone like @ruihildt could provide perspective on how Mullvad chooses an auditor.

---

## Post 17 by @ruihildt — 2024-12-12T16:26:33Z

I actually don’t know what are the criterias, I only know we try to have different auditor each time, as stated in the blog post.

---

## Post 18 by @Kris — 2024-12-17T18:10:28Z

I would love to be a Mullvad customer. But unfortunately that’s out of the question for me because they don’t support port forwarding. That’s what I call a poor feature set.

---

## Post 19 by @anon29374801 — 2024-12-17T18:20:53Z

Mullvad gave [clear reasons why](https://mullvad.net/en/blog/removing-the-support-for-forwarded-ports) at the time. [IVPN also soon followed](https://www.ivpn.net/blog/gradual-removal-of-port-forwarding), so its not like Mullvad was alone in this thinking.

Their customer support, for me personally, was super accomodating and even gave me a refund and extra time on my subscripton even though I had said I was leaving as port forwarding was a need.

[Proton](https://protonvpn.com/), another PG reccomendation, offers it if you need it.

You can also use Quantum to really reduce the annoyance of their ephemeral port forwarding implementation.

[https://github.com/UHAXM1/Quantum](https://github.com/UHAXM1/Quantum)

I think if you are willing to look outside of PG reccomendations, [AirVPN](https://airvpn.org/) offers the best implementation of port forwarding while also being a reasonable choice in terms of privacy. Just to be transparent, I used AirVPN for 18 months after moving on from Mullvad, before switching to Proton this year.

---

## Post 20 by @bigdzi — 2024-12-17T18:28:33Z

I’d use MullVad all the time, but it keeps disconnecting once/twice per every 15 minutes.

---

## Post 21 by @Kris — 2024-12-17T18:29:41Z

> [@anon29374801](#):
>
> You can also use Quantum to really reduce the annoyance of their ephemeral port forwarding implementation.
> 
> [GitHub - UHAXM1/Quantum](https://github.com/UHAXM1/Quantum)

Is there something similar for `rtorrent`?  
It must be running on OpenWrt router, because my hole network is behind VPN tunnel.

---

## Post 22 by @anon29374801 — 2024-12-17T18:31:16Z

Could be misunderstanding but no, I dont think so.

Quantum just reads the logs on Windows to find the port ProtonVPN uses, and then updates the qbit client with that port.

EDIT: I did misunderstand. @Kris I have not seen one for rtorrent. But you could possibly ask the developer or fork the project to do so.
