# NymVPN (Nym)

**URL:** https://discuss.privacyguides.net/t/nymvpn-nym/25085
**Category:** Tool Suggestions
**Tags:** waiting
**Created:** 2025-02-18T20:19:57Z
**Posts:** 46

## Post 1 by @anon39279085 — 2025-02-18T20:19:57Z

### Check this box to affirm you have no conflict of interest.

on

### Website

> **[Nym | the world's most private VPN for desktop & mobile](https://nym.com/)**
>
> Stay private online with Nym’s decentralized VPN. Block trackers, hide your IP, and browse safely—now 75% off, try free VPN trial

### Short description

Nym/NymVPN is a decentralized VPN network that aims to offer full privacy and/or anonymity with decentralization, open source, no-logs policy, some unique traffic obfuscation features and anonymous payment and signup/login

### Why I think this tool should be added

It has been independently audited:

> **[Independently audited](https://nym.com/trust-center/independently-audited)**
>
> Nym and NymVPN undergo regular audits and technical reviews conducted by leading security firms and cryptographers.

One of them being Cure53 which is a famous auditor.  
It’s fully open souce (so not just clients but also there’s the nym repo itself and some others)

> **[Nym](https://github.com/orgs/nymtech/repositories)**
>
> Protecting user privacy at the network and application levels, using mixnets and threshold credential systems. - Nym

> **[GitHub - nymtech/nym: Nym provides strong network-level privacy against...](https://github.com/nymtech/nym)**
>
> Nym provides strong network-level privacy against sophisticated end-to-end attackers, and anonymous transactions using blinded, re-randomizable, decentralized credentials.

Privacy policy of apps state they will not log your data unless it is on a legal basis (If it’s decentralized and anonymous though how they’re gonna do it though, unless they can use the third parties but :thinking:, and anyways I guess that can be confirmed with it’s open source nature)

> Your internet activity while using NymVPN services is not monitored, recorded, logged, stored, or passed to any third party, unless doing so is required by applicable law, e.g. in case of a lawful intercept request, required for providing the NymVPN services, required for billing and debt collection purposes or you have granted consent to this (by enabling telemetry).

> **[NymVPN apps Privacy Statement](https://nym.com/vpn-privacy-statement)**
>
> Learn about the power of our decentralized VPN. dVPNs are the future of privacy on the internet, making our online activity private and secure

They have Litepapers and whitepapers outlining alot of those things that can be combined with the open source code and other things:

> **[NymVPN litepaper](https://nym.com/nymvpn-litepaper)**
>
> Learn about the power of our decentralized VPN. dVPNs are the future of privacy on the internet, making our online activity private and secure

> **[nym-whitepaper.pdf](https://nym.com/nym-whitepaper.pdf)**
>
> 1306.48 KB

(Optional but helpful criteria)  
they have their roadmap open over at trello: [Trello](https://trello.com/b/qVhBo3e2/nymvpn-public-roadmap)

### Section on Privacy Guides

Virtual Private Network (VPN)

---

## Post 2 by @fria — 2025-02-18T20:23:03Z

Marking this rejected for now until they officially release:

> **[Official launch of NymVPN in March 2025](https://nym.com/blog/nymvpn-official-launch-2025)**
>
> Statement from Harry Halpin, CEO

---

## Post 3 by @anon39279085 — 2025-02-18T20:23:30Z

yep sure.

---

## Post 4 by @jonah — 2025-02-18T21:32:36Z

Actually it would be #waiting :wink:

> [@anon39279085](#):
>
> ### Section on Privacy Guides
> 
> Virtual Private Network (VPN)

I do wonder if we should have an entirely separate category and criteria for decentralized VPNs. We’ll have to consider this.

---

## Post 5 by @anon29374801 — 2025-02-18T21:35:39Z

just linking to their showcase as @nym-product did go over how nym works within the criteria

> [@Nym and NymVPN - Next-gen privacy with mixnet and VPN service](https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service/25072/4):
>
> Thanks, @anon29374801. Here are some initial responses based on the criteria you provided. The following applies to NymVPN. We’re happy to provide evidence, but are limited in the number of hyperlinks we can include to articles. gear Technology Protocols: The dVPN mode is based off AmneziaWG, a censorship-resistant fork of WireGuard. NymVPN does not support OpenVPN. Killswitch: The Android app relies on the native Android killswitch. By end of Q1 2025, the iOS app will rely on Apple’s “VPN O…

---

## Post 6 by @nym-product — 2025-02-19T10:07:07Z

Thanks all. Happy to answer more questions here. A valuable resource to many of the questions raised is our “Trust Center”: [Trust Center | Nym](https://nym.com/trust-center)

---

## Post 7 by @fria — 2025-02-19T10:21:34Z

Actually it’s already available I misinterpreted the blog post.

---

## Post 8 by @Niek-de-Wilde — 2025-02-19T10:32:52Z

Welcome to the forum @nym-product

---

## Post 9 by @nym-product — 2025-02-19T11:50:12Z

> [@fria](#):
>
> Actually it’s already available I misinterpreted the blog post.

Yes it is! It’s effectively a free WireGuard (actually AmneziaWG) dVPN and mixnet, available on 5 major platforms (Android, iOS, Linux, macOS, Windows), and run by reputable scientists, cryptographers and privacy people. Worth giving it a try (and sharing your feedback with us :slightly_smiling_face:) before we switch to the paid version in March!

Caveats apply depending on your use cases and threat model (no killswitch yet, no post-quantum, etc., see [Nym and NymVPN - Next-gen privacy with mixnet and VPN service - #4 by nym-product](https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service/25072/4)).

> [@Niek-de-Wilde](#):
>
> Welcome to the forum @nym-product

Thanks :slight_smile:

---

## Post 10 by @anon39279085 — 2025-03-13T10:50:31Z

Speaking of Nym, today is the London/Paid Launch, Have we thought about it everyone?

> [@Nym and NymVPN - Next-gen privacy with mixnet and VPN service](https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service/25072/52):
>
> Paid versions start on March 13.

Well we did have the last 21 days or so to try it :person_shrugging:  
But anyways with the paid launch just wanted to know.

---

## Post 11 by @laracan988 — 2025-03-31T14:16:46Z

Hi. Long time reader of the forum. I think I’d be great if Nym were added too (breaking this response into 3 parts due to posting requirements).

`---` `---` `---` `---` `---` `---` `---` `---` Part 1 `---` `---` `---` `---` `---` `---` `---` `---` `---`

As a statistician and ML engineer, I see that most people in the privacy community don’t understand (through no fault of their own) how easy it is for governments to track who they are communicating with e.g. know that Bob is texting Jim on Signal or that Bob is on privacyguides. This is due to 2 factors: 1) governments are known to cooperate with each other on mass surveillance through ISP monitoring and are increasingly doing so more (e.g. [United Nations Convention against Cybercrime](https://news.un.org/en/story/2024/12/1158521)); and 2) ML algorithms (which require no human guidance after training) can **very easily** fingerprint the websites people view if they can passively view the servers (though ISP level monitoring i.e. point 1). A good example of how easy it is for ML algorithms to “fingerprint” what websites people navigate to is evident in the following 2018 paper - [dl.acm.org/doi/pdf/10.1145/3243734.3243768](http://dl.acm.org/doi/pdf/10.1145/3243734.3243768). This paper shows almost perfect detection rates:

“_On undefended traffic, the DF attack attains a 0.99 precision and a 0.94 recall_” - quote from paper [1] [2]

_[1] BTW, precision and recall are fancy terms for measuring how well a model finds the right things (websites in this example). Precision is about the accuracy of the things it finds (how many found are actually correct), while recall is about how many of the total correct things it actually found. For simplicity sake, you can just think of them both as measuring raw accuracy - which in this example is 99% and 94% (lol)! This basically shows how useless traditional VPNs are at evading government surveillance (although their great tools against corporate surveillance)._  
_[2] DF (Deep Fingerprinting) is the named approach in the paper which uses an algorithm (CNN) which is a whole lot less powerful than the algorithms used today (Transformers)_

---

## Post 12 by @laracan988 — 2025-03-31T14:17:24Z

`---` `---` `---` `---` `---` `---` `---` `---` Part 2 `---` `---` `---` `---` `---` `---` `---` `---` `---`

Although the effectiveness of Nym will never truly be tested (because we don’t know which algorithms and resources governments use), it employs a lot of techniques which made me think as an ML engineer - “that’s a really good idea to confuse an ML algorithm”. These main techniques include: 1) cover traffic; and 2) mixnet (with continuous mixing). Currently there is no technology which employs these two capabilities and are therefore more susceptible to ML-based attacks. In addition to the links @anon39279085 provided I found the following guide to be a really easy way to understand how Nym works - [Introduction - Nym docs](https://nym.com/docs/network). Also the following provides a brief overview on the main privacy mechanisms it uses - [Nym (mixnet) - Wikipedia](https://en.wikipedia.org/wiki/Nym_(mixnet)#Privacy-preserving_mechanisms).

---

## Post 13 by @laracan988 — 2025-03-31T14:18:48Z

`---` `---` `---` `---` `---` `---` `---` `---` Part 3 `---` `---` `---` `---` `---` `---` `---` `---` `---`

Recently Switzerland has issued a statement to amend its surveillance laws. If you look closely at the amendment which is written in French ([https://www.newsd.admin.ch/newsd/message/attachments/91537.pdf](https://www.newsd.admin.ch/newsd/message/attachments/91537.pdf)), it states that the law is about knowing “who is talking to who” communications and not end-to-end encryption communications:

_“Providers with limited obligations and providers with full obligations shall remove any encryptions they have performed or that have been performed for them. For this purpose, they shall capture and decrypt the telecommunications correspondence of the monitored person at appropriate points so that the surveillance data is delivered without the mentioned encryptions. End-to-end encryptions between end customers are not affected.”_ - part of the linked Swiss Amendment translated from French

To me, this new surveillance law looks like a direct attack on Nym [3], which only recently launched its product in Switzerland (as discussed in this topic). To make it very clear, Nym protects against “who is talking to who” communications and this is what this law is about. In my opinion, this may be an early indication that governments are finding it harder to surveil this type of network (again just my opinion based purely on the events I’m seeing).

I understand that this forum likes to see technologies which have stood the test of time. However, I think that Nym should be actively recommended and added soon due to the lack of technologies which match its described mechanisms. From my reading it seems much better equipped than Mullvad’s DAITA at preventing website fingerprinting attacks - and I love Mullvad and have been a customer for 5 years (not planning on leaving).

I think this should be accepted soon. If the first VPN came around and this forum hadn’t seen a VPN before, would we be saying “it needs to stand the test of time” or “lets go use this product because it provides clear technological benefits”.

Apologies for this ending rant.

_[3] This may also apply to the messenger Session which recently moved to Switzerland and which focuses on hiding “who is talking to who” communications_ - [Encrypted Messenger Session Moves to Switzerland Amid Privacy Concerns | CyberInsider](https://cyberinsider.com/encrypted-messenger-session-moves-to-switzerland-amid-privacy-concerns/)

---

## Post 14 by @ignoramous — 2025-03-31T15:43:21Z

> [@laracan988](#):
>
> These main techniques include: 1) cover traffic; and 2) mixnet (with continuous mixing).

Is the “cover traffic” part in Nym is just Amnezia?

> [@laracan988](#):
>
> as an ML engineer - “that’s a really good idea to confuse an ML algorithm”.

Which other techniques? Curious since you bring up DAITA (aka [maybenot](https://github.com/ewitwer/maybenot-defenses)) which I find quite … _neat_, too.

---

## Post 15 by @privacyisconsent — 2025-03-31T16:44:37Z

Nym is a full-fledged mixnet that comes as a result of years of study of network anonymity systems and their various trade-offs: [https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/piotrowska](https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/piotrowska)

In comparison to Tor (see section 3.1 [Tor: The Second-Generation Onion Router](https://svn-archive.torproject.org/svn/projects/design-paper/tor-design.html)) it attempts to thwart GPAs (global passive adversaries) from linking communication partners/endpoints over the network. Assumedly, the mixnet is what you route your traffic through when using the anonymous mode in NymVPN.

I believe AmneziaWG is for censorship circumvention for their fast mode in NymVPN which is a two-hop Wireguard VPN a bit like Obscura, more suited for latency sensitive tasks.

---

## Post 16 by @laracan988 — 2025-03-31T17:11:44Z

Hi Igor.

The “cover traffic” Nym employs constantly sends data packets to be routed through its decentralized servers, whether you are using the service or not e.g. your phone could be idle and it will always send packets at a constant rate. I sometimes use Sniffnet ([https://sniffnet.net](https://sniffnet.net)) when using Nym and (if i can remember correctly) it uploads/downloads packets at a rate of 200 packets per second. Because everyone using the Nym network is uploading/downloading at a rate of 200 data packets per second, it makes it difficult or even impossible to use a ML algorithm to classify peoples traffic **purely** on their upload/download rate. For example if Bob was using a regular VPN service and was watching a video on privacyguides and had a download rate of 500 packets per second and some server on the same VPN service he was using had a download rate of 500 packets per second, it may be possible to infer that Bob is on privacyguides if you had access to the ISP of his output VPN server [1]. However, if Bob was using Nym this inference is not possible because everyone uploads/downloads at a constant rate. This “cover traffic” is actually only one of the mechanisms Nym uses to stop governments using ML algorithms to make inferences on what websites people are on or what people you are texting.

DAITA is very cool also. However, from my reading of the two papers Nym employs a lot more useful techniques for the purposes of evading an AI guided traffic analysis. From a simple mans perspective, the two techniques Mullvad’s DAITA employs are: 1) constant packet sizes; and 2) dummy/random packet injection. The constant packet size makes all data packets the same size which i would only assume would be ideal for ML “website fingerprinting” algorithms because data packets range from up to 1460 bytes and can be anything in between - [MTU vs. MSS: What Every Network Administrator Should Know - The Network DNA](https://www.thenetworkdna.com/2023/12/mtu-vs-mss-what-every-network.html). The dummy packet injection randomly inserts packets when you make a request which are sent based on a random generation process. This is useful for confusing an AI/ML algorithms on the total number of packets sent.

Simply put Nym does all DAITA does but more [5].

- It has constant packet sizes - as with Mullvad
- Instead of sending random packets along with your internet request it sends constant cover traffic (always 200 packets are uploaded/downloaded). Sending constant cover traffic is a better idea to defend against a ML algorithms because it removes the identifiable piece of information of “when you are using the network” and removes estimates of “how many packets are being sent per second” (which may be able to be modeled by an ML algorithm)
- Finally, it uses a mixnet which means all you packets don’t flow through the same server. They are constantly being mixed with other users packets and random packets are being added to the mix nodes [2]. This is one of the main parts of Nym which makes it so hard to perform an AI/ML guided traffic analysis (in theory at least - again no one really knows what techniques governments use lol).

Not that this type of comparison matters when comparing systems. However, it must be pointed out that Nym consists of the very top researchers from their field. Both Claudia Diaz and Harry Haplin have h-index scores of 39 and 31 respectively [3]. These are indicative of researchers who have made top contributions to cybersecurity. In other words, they really know what they are doing [4].

_[1] In reality, you dont upload/download at a constant rate - giving even more information to an ML algorithm for you to be classified e.g. at second 1 you may download 255 packets, at second 2 you may download 297 packets, etc._  
_[2] Better off to read about the Nym mixnet on their website. In short it shuffles you network packets with other peoples packets, making it much more difficult know who owns which packet._  
_[3] You can view this on Google Scholar_  
_[4] I’m starting to sound like I’m being paid as an affiliate marketer for Nym lol - I’m not. Also here’s my Nord link …_  
_[5] I’m still a paid subscriber of Mullvad due to their other great features though_

---

## Post 17 by @TrashPanda — 2025-03-31T22:40:52Z

Hello,

Thank you for working on Mixnet - this is marvelous and innovative.

I am concerned about Nyms’ decision to ship NymVPN as an AppImage. This is, in my opinion an unpopular decision, as fuse2 is unmaintained and is SUID root dependent.

---

## Post 18 by @Alvah.Lind64 — 2025-04-01T10:48:22Z

Sounds very promising. I’ll keep an eye on the roadmap items for [access to LAN](https://trello.com/c/Qs5X06Gb/92-%F0%9F%96%A5%EF%B8%8F-access-other-devices-on-local-network-for-docker-p2p-apps) and [split tunnelling](https://trello.com/c/R6wVmUDQ/1-%F0%9F%94%80-split-tunneling-between-no-tunnel-wireguard-dvpn-and-mixnet-modes), I plan to try Nym when those features land.

---

## Post 19 by @jerm — 2025-04-01T16:33:58Z

Hey lara, welcome to the forum.

> [@laracan988](#):
>
> it will always send packets at a constant rate

> [@laracan988](#):
>
> (if i can remember correctly) it uploads/downloads packets at a rate of 200 packets per second.

> [@laracan988](#):
>
> It has constant packet sizes - as with Mullvad

If Nym sends a fixed amount of constant 200 packets per second which also have a fixed amount of packet size, can’t a AI/ML algorithms just be able to “strip out” these packets and be left with _real_ packets that are transmitted?

Doesn’t it also make it possible that Nym traffic stands out more as one that sends a fixed amount of packets & size per second, which means ISP or global adversary can point every Nym user?

These are the 2 questions I have for now from just reading the thread. On why PrivacyGuides didn’t include it yet, is because it needs to meet their [_new_ criteria](https://discuss.privacyguides.net/t/nymvpn-nym/25085/4) which will take time to set a decent one, get tested by a member, share their experience etc and many other factors that plays into adding to ensure it fits all possible threat models and a safe recommendation because people lives may depend on such addition or their [long time investment](https://discuss.privacyguides.net/t/avoiding-the-next-skiff/16722).

@nym-product@ania

Thanks.

---

## Post 20 by @nym-product — 2025-04-01T17:06:40Z

> [@TrashPanda](#):
>
> I am concerned about Nyms’ decision to ship NymVPN as an AppImage. This is, in my opinion an unpopular decision, as fuse2 is unmaintained and is SUID root dependent.

Thanks for the feedback, what would be your recommendation? Only offering Flatpak?

> [@Alvah.Lind64](#):
>
> I’ll keep an eye on the roadmap items for [access to LAN](https://trello.com/c/Qs5X06Gb/92-%F0%9F%96%A5%EF%B8%8F-access-other-devices-on-local-network-for-docker-p2p-apps) and [split tunnelling](https://trello.com/c/R6wVmUDQ/1-%F0%9F%94%80-split-tunneling-between-no-tunnel-wireguard-dvpn-and-mixnet-modes), I plan to try Nym when those features land.

Access to LAN should be here next week. Split tunneling is a bit more involved. As a v1 we want to offer basic split tunneling (either inside or outside of NymVPN). The long term vision is a more advanced split tunneling (mixnet or VPN or outside) - likely not doable on all platforms.

> [@jerm](#):
>
> because it needs to meet their [_new_ criteria](https://discuss.privacyguides.net/t/nymvpn-nym/25085/4) which will take time to set a decent one

I believe we provided evidence on most of the criteria ([Nym and NymVPN - Next-gen privacy with mixnet and VPN service - #4 by nym-product](https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service/25072/4)). The killswitch got added in the meantime FYI. We do understand that the community is debating the privacy properties/risks of dVPNs and wants to see the effects of time.

I’ll let @ania @cdiaz reply on the 2 other questions.

---

## Post 21 by @laracan988 — 2025-04-01T17:57:09Z

Hi Jerm.

> [@jerm](#):
>
> If Nym sends a fixed amount of constant 200 packets per second which also have a fixed amount of packet size, can’t a AI/ML algorithms just be able to “strip out” these packets and be left with _real_ packets that are transmitted?

Apologies, I’m not quite sure by what you mean by “can’t a AI/ML algorithms just be able to strip out these packets and be left with _real_ packets that are transmitted” in this context. I’ll try to answer your question with an explanation …

As you (and I) said, Nym sends/receives a fixed number of packets per second (200 or so). These packets may be dummy or real packets, but it’s not possible to know because their content is encrypted. Nym also makes all packets the same size [1] so that a ML algorithm cant use this information to classify which communications people are using [2]. Sending dummy packets (or sending a constant flow or them in Nym’s case) along with padding packets (or making them the maximum size) is a common technique done used by both TOR and Mullvad, as well as Nym.

If by “strip out” in this context you mean actually go inside the packet and see if its dummy or real - that’s not currently possible because of encryption (AI/ML cant break encryption). However, if you mean an ML algorithm is able to observe the network and distinguish between the real ones and the dummy ones - Nym makes it very difficult for this to happen because of its mixnet and the techniques they use within the mix nodes e.g. packet-based routing, packet shuffling etc.

> [@jerm](#):
>
> Doesn’t it also make it possible that Nym traffic stands out more as one that sends a fixed amount of packets & size per second, which means ISP or global adversary can point every Nym user?

They could, but it’d be much easier to view the entry nodes on their publicly available server list [server list](https://explorer.nymtech.net/network-components/nodes) lol (at least that’s what I’d do if my name were _FBI-laracan988_ instead). Publicly available entry nodes/server lists with associated IP addresses are also available for TOR and Mullvad on their websites. The way I see it is, if I’m using Nym I assume my government knows I’m using it because I’m connecting to a IP address which is publicly associated with its network.

> [@jerm](#):
>
> On why PrivacyGuides didn’t include it yet, is because it needs to meet their _new_ criteria which will take time to set a decent one, get tested by a member, share their experience etc and many other factors that plays into adding to ensure it fits all possible threat models and a safe recommendation because people lives may depend on such addition or their long time investment.

Yes, I get the “it must stand the test of time” argument along with the Skiff problem. However, Skiff wasn’t some new revolutionary technology which changed the game [3]. On the other hand, Nym provides clear advantages over technologies people have been using for decades i.e. TOR and VPNs. This is through the use of a commercial mixnet and other privacy enhancing technologies e.g. constant cover traffic (which seems like it is super necessary for evading AI/ML systems and not a feature in TOR/other VPNs).

Nym’s founders also seem quite into this whole privacy thing. One of their founders describes himself as a “crypto anarchist” [4] [Harry Halpin on “The Hated One”](https://www.youtube-nocookie.com/embed/dVtw-4Eox2E). It doesn’t seem like he’s gonna sell out for some cash like Skiff, but that’s just my opinion. They also have Chelsea Manning and Snowden as partners who have both promoted the product and done talks/promotions on their YouTube channel [5]. If Manning and Snowden were involved in the next “big Skiff sellout”, I’d find that totally wild lol (I’d also loose faith in humanity).

_[1] By filling them with some dummy content as I understand it_  
_[2] I would only assume this packet-size content would be a great predictor for a ML model_  
_[3] That being said I dont know too much about Skiff, so maybe it did in some way_  
_[4] Crypto-anarchy, crypto-anarchism, cyberanarchy or cyberanarchism is a political ideology focusing on the protection of privacy, political freedom, and economic freedom, the adherents of which use cryptographic software for confidentiality and security while sending and receiving information over computer networks._  
_[5] Can’t link the Snowden interview (ran out of links) - you can view a 1 hour interview of Snowden on their YouTube channel (talking about Nym to some extent)_

---

## Post 22 by @TrashPanda — 2025-04-01T19:39:32Z

> [@nym-product](#):
>
> Thanks for the feedback, what would be your recommendation? Only offering Flatpak?

Yes, as fuse2 is highly vulnerable.

* * *

May I ask when the 50% crypto offer ends? Asking as I want to test and review Nym, but I need a month or so as I’m currently busy.

Thank you!

---

## Post 23 by @nym-product — 2025-04-02T08:36:46Z

> [@TrashPanda](#):
>
> May I ask when the 50% crypto offer ends? Asking as I want to test and review Nym, but I need a month or so as I’m currently busy.

Likely for a few more weeks (+/- end of April).

---

## Post 24 by @Wings — 2025-04-04T20:00:05Z

@nym-product Hoping Nym is everything it claims to be, and appreciate your official presence here to earn user trust and answer specific questions. In that vein of things:

1. In terms of real world performance, what are the maximum download and upload speeds currently attainable both for Fast Mode and Anonymous Mode?

2. What security protocols and accountability layers are in place to ensure that decentralized user nodes can’t be compromised by bad actors?

3. Does Nym work with firewall applications like Portmaster and Simplewall for Windows? Portmaster offers system wide DNS filtering and per-app entry and exit node control via the SPN, but doesn’t play well with most third party VPN’s. NymConnect doesn’t support many apps and looks neglected on the Github page. Is there a way to use Nym on Windows and Android having it protect internet traffic for ALL apps, not just the web browser?

4. In terms of parity, Mullvad VPN with Obscura and DAITA v2 and Portmaster’s SPN (soon to be integrated with IVPN) both offer multi-hop/decentralized/anonymized services. In what ways is Nym better or worse or justifiably different than these other players in the market?

5. With the uncertain future of privacy in Switzerland, what plans or options does Nym have if the proposed changes to the OSCPT pass? Worst case scenario, are all Nym users immediately compromised or highly vulnerable once the law goes into effect if Nym hasn’t changed jurisdictions or protocols by then?

6. In a market that’s increasingly consolidated, any written reassurances of no future Skiff-like exit plans/acquisition buyouts? If not, why not?

---

## Post 25 by @privacyisconsent — 2025-04-04T20:56:14Z

> [@Wings](#):
>
> 1. NymConnect doesn’t support many apps and looks neglected on the Github page. **Is there a way to use Nym on** Windows and **Android having it protect internet traffic for ALL apps** , not just the web browser?

Yes, NymVPN!

> [@Wings](#):
>
> In terms of parity, Mullvad VPN with Obscura and DAITA v2 and Portmaster’s SPN (soon to be integrated with IVPN) both offer multi-hop/decentralized/anonymized services.

Nym is a mixnet not an MPR or VPN. Fast Mode in NymVPN is a MPR but it is not really the main reason Nym exists. Mixnets are strong privacy tools that provide unlinkability and sender or recipient anonymity, and Nym fills the gap left when you want to use an anonymity network but don’t mind higher latency.

> Real anonymity for sensitive communications and transactions, with technology that offers protection from advanced threats and surveillance. Best for: email, messaging, banking, and crypto.

> **[Nym | the world's most private VPN for desktop & mobile](https://nym.com/#low-density-215)**
>
> Stay truly anonymous online. Nym’s decentralized mixnet prevents surveillance, shields metadata, and delivers private, high-speed browsing.

Mullvad VPN is not a multi-party relay. Obscura is but I am not sure you can use it with DAITA v2 because you will be using Obscura’s client or configuration rather than Mullvad’s.

> [@Wings](#):
>
> Portmaster’s SPN (soon to be integrated with IVPN)

Where have you seen this integration being specified?

---

## Post 26 by @nym-product — 2025-04-07T13:30:48Z

Hi @Wings

> [@Wings](#):
>
> In terms of real world performance, what are the maximum download and upload speeds currently attainable both for Fast Mode and Anonymous Mode?

The performance will depend on multiple factors. Remember that 1.NymVPN is designed with privacy in mind, and 2. is multi-hop by default (2 or 5 servers). Thus it can’t offer the same performance as 1-hop centralized VPNs. With a good connection and good choice of nodes, you can expect 200 to 300 Mbps on the dVPN mode, with reasonable latency. With the mixnet, speeds are lower than 1 Mbps. This mode is intended for maximum privacy and best-suited for use cases such as messaging.

> [@Wings](#):
>
> What security protocols and accountability layers are in place to ensure that decentralized user nodes can’t be compromised by bad actors?

Nodes can (and will be) compromised by bad actors. Limiting bad actors is done by actively managing our community of operators, and making full use of the staking mechanisms described in the “Reward sharing for mixnets” article (“costs” to setup a node + reputation system based on staking). Limiting the impact of bad actors is done by being multi-hop (so one node doesn’t see both your IP address and the destination of your traffic – which is not the case of single-hop VPNs). Users can also limit that by frequently rotating the nodes they use.

In the future we plan to include mechanisms to detect active attacks and penalize/exclude nodes found to engage in active malicious behavior, as well as to limit opportunities for passive (undetectable) malicious behavior through the use of secure hardware.

> [@Wings](#):
>
> Does Nym work with firewall applications like Portmaster and Simplewall for Windows? Portmaster offers system wide DNS filtering and per-app entry and exit node control via the SPN, but doesn’t play well with most third party VPN’s.

I’d need to get back to you on this one.

> [@Wings](#):
>
> NymConnect doesn’t support many apps and looks neglected on the Github page. Is there a way to use Nym on Windows and Android having it protect internet traffic for ALL apps, not just the web browser?

As shared by @privacyisconsent, NymConnect (which worked with a short app allowlist - Telegram and a few crypto wallets) is deprecated. It is now replaced by NymVPN (which provides a multi-purpose VPN-like experience covering your full device traffic).

> [@Wings](#):
>
> both offer multi-hop/decentralized/anonymized services. In what ways is Nym better or worse or justifiably different than these other players in the market?

These are all great services which we vastly respect. While they offer a multi-hop solution, they are more multi-party / “bi-centralized” than decentralized (as in, both entry and exits are centralized, and you need to trust them not to collude). We don’t believe they are “anonymized” either, unless you pay with cash (paying with a crypto doesn’t provide anonymity). Nym aims to unlink users payment data from their network usage, thanks to the “zk-nyms” (zero-knowledge access credentials, which are already live). This property is valid across all payment methods! I.e. one may know that you are a NymVPN user, but cannot trace that to your online activities.

> [@Wings](#):
>
> With the uncertain future of privacy in Switzerland, what plans or options does Nym have if the proposed changes to the OSCPT pass?

You can check Nym’s position on our Blog: [Online privacy and digital integrity under threat / Nym](https://nym.com/blog/privacy-under-threat-switzerland) Our Ops / Legal people are actively following the matter together with Proton, Threema and others.

> [@Wings](#):
>
> In a market that’s increasingly consolidated, any written reassurances of no future Skiff-like exit plans/acquisition buyouts? If not, why not?

There are no such plans. The goal is to get the network self-sustainable, with various apps (starting with NymVPN) and SDK integrations paying for its usage.

---

## Post 27 by @anonymous261 — 2025-06-29T23:35:53Z

So I imagine that Nym’s current status on being added to PG is similar to IronFox, that we’re waiting for both projects to demonstrate a good security posture over time?

> [@nym-product](#):
>
> what would be your recommendation

I would prefer an RPM package or even a Homebrew CLI package over keeping AppImage. Both of my suggested packages would help provide accessibility for immutable Linux distributions like Fedora Silverblue or OpenSUSE Aeon, where the install script (in the “other” [Linux download instructions](https://nym.com/download/linux)) fails due to immutable directories.

---

## Post 28 by @nym-product — 2025-07-08T14:28:04Z

> [@anonymous261](#):
>
> we’re waiting for both projects to demonstrate a good security posture over time?

Fair enough! If there are specific things you’d like to see us prove or features we’re missing, let us know. We totally understand that trust takes time to build.

> [@anonymous261](#):
>
> I would prefer an RPM package or even a Homebrew CLI package over keeping AppImage.

Clear. I’ll make sure to pass the feedback to our Linux Dev.

PS: Could we possibly merge this with the other thread at [https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service](https://discuss.privacyguides.net/t/nym-and-nymvpn-next-gen-privacy-with-mixnet-and-vpn-service) ?

---

## Post 29 by @anon39279085 — 2025-07-08T20:42:32Z

For your PS I would ask the moderators privately but since you asked publicly I’ll do them and I’ll let them handle it accordingly  
[@moderators](/groups/moderators) [@discussion\_moderators](/groups/discussion_moderators)

---

## Post 30 by @Alvah.Lind64 — 2025-07-09T13:11:09Z

> [@nym-product](#):
>
> If there are specific things you’d like to see us prove or features we’re missing, let us know.

I’d be interested to see mesh VPN capability like Tailscale, which also utilises Mullvad VPN as an exit node.

---

## Post 31 by @Copernicus — 2025-08-26T21:37:30Z

[@staff](/groups/staff) I apologise for asking after only 8 months have passed since original proposal, but could it be the time to reevaluate the Nym? Or am I thinking on wrong timescale? Thanks in advance

---

## Post 32 by @KevPham — 2025-08-26T22:22:36Z

You’re more than welcome to add to the discussion if you feel that would help their case (and the other way around).

Our timeline for approving these proposals are understandably long. It’s hard to reach the same level of trust as Mullvad and Proton; therefore, we will be taking our time to ensure that people are safe when using our recommendations.

---

## Post 33 by @Copernicus — 2025-08-27T08:37:37Z

I see, thank you, I’ll be waiting patiently then :slight_smile:

---

## Post 34 by @nym-product — 2025-09-18T10:30:15Z

Thanks for the continued support @Copernicus, and the clarification @KevPham. We understand that trust takes time to build, especially in the privacy space.

We’ve been focusing on core stability and performance improvements this summer. Recent user-facing developments:

- iOS in-app subscriptions now live (free trials launching soon)

- Dash payment integration available on [nym.com](http://nym.com) (via our self-hosted BTCPay Server)

- Localization expansion - iOS app now supports 10+ languages, with [nym.com](http://nym.com) following suit (Ukrainian version already live thanks to community support, more languages coming soon)

Coming next:

- Android in-app subscriptions and free trials (via Google Play for now)

- New anti-censorship capabilities

- Enhanced node info and selection interface (long overdue update)

We’re happy to provide any additional documentation or evidence that would be helpful for the evaluation process!

---

## Post 35 by @Encounter5729 — 2025-09-20T10:41:08Z

Hi, would be great if you didn’t use trackers in your emails. I don’t know if mailchimp allows to remove trackers, but if not maybe consider switching.

 ![c43ef1ec-b673-4694-9d84-0db227d1ae71](https://forum-uploads.privacyguidesusercontent.com/original/2X/2/2ce9d64c7b34f7cf132ba1b1ca3d3aad16109874.png)

TBC: Trackers might come from Mailchimp so not sure they intentionally put those themselves.

---

## Post 36 by @anon39279085 — 2025-09-20T10:41:59Z

@nym-product would you kindly be able to clarify this?

---

## Post 37 by @nym-product — 2025-09-21T15:21:35Z

Hi @Encounter5729 thanks for bringing this up. these trackers are likely Mailchimp defaults that we haven’t disabled (or can’t disable?). We’ll check if we can make Mailchimp more private, and explore privacy-friendly alternatives for future migration. A platform switch won’t be immediate due to resource constraints.

In the meantime, we can make sure all our newsletter content is made available on our blog and social media accounts.

---

## Post 38 by @Encounter5729 — 2025-09-25T19:46:34Z

> [@nym-product](#):
>
> In the meantime, we can make sure all our newsletter content is made available on our blog and social media accounts.

That would be nice yes.

---

## Post 39 by @object2598 — 2026-05-19T09:16:41Z

This VPN hasn’t been getting the attention it deserves. A lot of updates since the last comment, they’re working very well on their roadmap.

---

## Post 40 by @Bumbashirovich — 2026-05-19T12:46:12Z

It doesn’t run on most Linux distributions. What’s so good about it?

---

## Post 41 by @DanielM — 2026-05-19T13:36:07Z

At first glance, it seems like an interesting project, but:

1. Connecting to the 5 nodes is much slower than a turtle. Having more doesn’t offer any real benefits.
2. Agents of malicious actors can infiltrate the network by posing as “volunteers.” For example: the U.S. NSA.
3. On the official website, there is a claim: Privacy guaranteed

Annual audits and technical reviews ensure that the network is transparent, secure, and log-free

As it stands, it sounds impressive, but it’s superficial; let’s dig deeper:

- It does not literally mention synonyms such as “maximum,” “total,” or “absolute” privacy.

- It mentions the word “guaranteed,” but overlooks point 2 that I mentioned.

- Audits and technical reviews do not “guarantee” privacy, as the title claims. To reinforce my argument within the VPN industry itself, I’ll quote a few words from IVPN:

After considering a repeat of this audit scope, we have decided that claims around ’no logs’ audits can be misleading, or at best ambiguous to customers. We often remark that audits are just a snapshot in time. Any VPN service receiving a stamp of ’no logs’ from independent evaluators can update their systems and start collecting sensitive customer information the following day.

Source: [IVPN infrastructure is ready for 5th annual security audit](https://www.ivpn.net/blog/ivpn-infrastructure-fifth-audit-announcement/)

- ….

Carefully analyze the wording used on their website.

---

## Post 42 by @object2598 — 2026-05-19T20:19:27Z

1. It is very slow, but not all of your traffic needs to pass through it. You can split tunnel and put only the most sensitive traffic, such as chats, mails, crypto transactions, etc. The number of nodes is also not arbitrary for marketing. There is an entry node, an exit node, and three mix nodes.

---

## Post 43 by @Bumbashirovich — 2026-05-20T00:42:33Z

> [@DanielM](#):
>
> Agents of malicious actors can infiltrate the network by posing as “volunteers.” For example: the U.S. NSA.

It has already been reported elsewhere that the NSA seeks to monitor all VPN nodes. However, NymVPN operates on two nodes: these nodes can be configured in jurisdictions that are either neutral or hostile to one another.

---

## Post 44 by @DanielM — 2026-05-20T03:07:01Z

Here’s my response:

No need to explain the nodes, but thanks anyway.

As I mentioned in point 1, more nodes don’t provide any real benefits.

-\> For someone who needs to send a highly valuable 8GB file—compressed and encrypted—to a person who is being persecuted, the 5 nodes won’t resolve the issue urgently; according to the Android client, the speed is 5 Mbps. Using two nodes—at what cost, really? Will it come down to “luck”?

Malicious actors have large-scale adaptation capabilities, such as the NSA; they don’t care about the features implemented by the VPN service.

Worse still, if they pay to keep nodes active, it attracts mafia groups, high-level hackers, etc.—it’s free money. How does the company address this to counteract infiltrated agents, or are there no methods? Will it be similar to or the same as Google 2.0, allowing external APK installation on Android? The second question arises from the first.

Why are you comparing Nym to Tor? I see Nym as having interesting features that are better than Tor’s; however, we have to look at the reality itself (the context).

As I said in point 3, if the company doesn’t prove to me what they claim (“guaranteed”), there’s no point in conducting a deep, exhaustive investigation into the people behind Nym.

I say this from personal experience.

---

## Post 46 by @DanielM — 2026-05-26T00:17:09Z

I contacted Nym Support on the Telegram platform so that the company could give me a direct answer based on the facts and in a way that is visible to everyone, not hidden.

Now, I want to clarify that I am a native Spanish speaker and use translators like Google Translate or DeepL. The problem with these technologies is that they can add words I never said, so I wrote to support directly in Spanish. Therefore, I will present two versions of this message:

> **English translation:**
>
> @butterbrbutterbr  
> Hi, in Spanish:
> 
> Greetings.
> 
> I have some fundamental questions about Nym’s VPN service, but before I ask them, I should mention that I tested it briefly in trial mode.
> 
> Based on the official information:
> 
> Two words appear: “guaranteed” privacy - how does Nym guarantee this privacy simultaneously against whom (adversaries, for example), how, and what is its actual method?
> 
> How does Nym defend itself against adversaries like the US NSA by adapting to or overcoming their VPN service methods?
> 
> How does Nym protect legitimate users of its services against apparent infiltrations from “legitimate” nodes? What are its methods, and how does it act in relation to this? For example: the mafia, veteran hackers, etc.
> 
> Which option would you recommend (2 nodes or 5 nodes) in a life-or-death situation involving stalking, when someone needs to send an encrypted, compressed, 8GB file to the person being stalked? Would it be a matter of “luck”?
> 
> If the answer to all the above questions is yes, do you have real-world, legitimate, public-facing evidence against real-life scenarios? I need to be convinced with concrete evidence, because someone claiming “guaranteed” is certain that what they’re saying is true.

> **Original Spanish version:**
>
> @butterbr  
> Hi, in Spanish:
> 
> Saludos.
> 
> Tengo preguntas fundamentales sobre el servicio VPN de Nym, pero antes de presentarlos, aviso que lo probé durante un poco de tiempo en modo de prueba.
> 
> Basado en la información oficial:
> 
> Aparecen dos palabras que dicen: privacidad “garantizada” - ¿cómo garantiza a la vez simultáneamente contra quién (adversarios por ejemplo), cómo y su método real?.  
> ¿Cómo se defiende Nym contra adversarios como la NSA de los Estados Unidos al adaptarse o superar sus métodos del servicio VPN?.  
> ¿Cómo protege Nym a las personas legítimas que utilizan sus servicios contra infiltraciones aparentes de nodos “legítimos”?, ¿cuáles son sus métodos y cómo actúan en relación a ésto?. Por ejemplo: La mafia, hackers veteranos, etc.  
> ¿Qué opción aconsejaría (2 nodos o de 5 nodos) vosotros en una situación de vida o muerte basado en persecuciones cuando alguien necesita enviar un archivo cifrado, comprimido y de 8GB a la persona perseguida?, ¿será cuestión de “suerte”?.
> 
> Si todas las preguntas anteriores son positivas, ¿tienen pruebas reales contra escenarios reales legítimos para el público?.  
> Necesito que me convenzan con pruebas reales, porque el que afirma “garantizado” está seguro de lo que dice es verdadero.

If the company doesn’t respond within 5 days, their silence is a sign of something. If they do respond, I will reply according to their arguments, and you will witness what lies behind their words.

Observation: I saw that the CEO replied to another person’s message in the General category regarding unlimited bandwidth for the VPN service, which means it is active.
