NymVPN (Nym)

At first glance, it seems like an interesting project, but:

  1. Connecting to the 5 nodes is much slower than a turtle. Having more doesn’t offer any real benefits.
  2. Agents of malicious actors can infiltrate the network by posing as “volunteers.” For example: the U.S. NSA.
  3. On the official website, there is a claim: Privacy guaranteed

Annual audits and technical reviews ensure that the network is transparent, secure, and log-free

As it stands, it sounds impressive, but it’s superficial; let’s dig deeper:

  • It does not literally mention synonyms such as “maximum,” “total,” or “absolute” privacy.

  • It mentions the word “guaranteed,” but overlooks point 2 that I mentioned.

  • Audits and technical reviews do not “guarantee” privacy, as the title claims. To reinforce my argument within the VPN industry itself, I’ll quote a few words from IVPN:

After considering a repeat of this audit scope, we have decided that claims around ’no logs’ audits can be misleading, or at best ambiguous to customers. We often remark that audits are just a snapshot in time. Any VPN service receiving a stamp of ’no logs’ from independent evaluators can update their systems and start collecting sensitive customer information the following day.

Source: IVPN infrastructure is ready for 5th annual security audit

  • ….

Carefully analyze the wording used on their website.

  1. It is very slow, but not all of your traffic needs to pass through it. You can split tunnel and put only the most sensitive traffic, such as chats, mails, crypto transactions, etc. The number of nodes is also not arbitrary for marketing. There is an entry node, an exit node, and three mix nodes.

    A mix node delays packets and sends them out in a different order. With one mix layer, an observer has one noisy transformation to solve:

    packets in → random delay/reorder → packets out

    With three independent mix layers, the observer has to track the packet through three separate timing scramblers:

    in → delay/reorder → delay/reorder → delay/reorder → out

    Each layer compounds uncertainty.

    The additional nodes also mitigate your second point, i’ll address below.

    1. For the malicious agent infiltrators (Sybil attacks), we could say the same about TOR, but TOR is even ““worse”” because nodes don’t usually get a financial incentive, whereas Nym nodes are paid for their work. This issue is addressed on some of Nym white papers, with some proposed solutions. I think they do add some cost

    As long as at least one of the middle mix layers is honest and actually mixes traffic, simple end-to-end linking becomes much harder, thus having three mix nodes does indeed help in this regard.

    Bottom line:
    Check who works on Nym. They are actual researchers and put their name on the line for the product. Of course i’m not saying this means they deserve trust just because of this, but the technology they are building seems to be going in the right direction.

It has already been reported elsewhere that the NSA seeks to monitor all VPN nodes. However, NymVPN operates on two nodes: these nodes can be configured in jurisdictions that are either neutral or hostile to one another.

Here’s my response:

No need to explain the nodes, but thanks anyway.

As I mentioned in point 1, more nodes don’t provide any real benefits.

-> For someone who needs to send a highly valuable 8GB file—compressed and encrypted—to a person who is being persecuted, the 5 nodes won’t resolve the issue urgently; according to the Android client, the speed is 5 Mbps. Using two nodes—at what cost, really? Will it come down to “luck”?

Malicious actors have large-scale adaptation capabilities, such as the NSA; they don’t care about the features implemented by the VPN service.

Worse still, if they pay to keep nodes active, it attracts mafia groups, high-level hackers, etc.—it’s free money. How does the company address this to counteract infiltrated agents, or are there no methods? Will it be similar to or the same as Google 2.0, allowing external APK installation on Android? The second question arises from the first.

Why are you comparing Nym to Tor? I see Nym as having interesting features that are better than Tor’s; however, we have to look at the reality itself (the context).

As I said in point 3, if the company doesn’t prove to me what they claim (“guaranteed”), there’s no point in conducting a deep, exhaustive investigation into the people behind Nym.

I say this from personal experience.

I contacted Nym Support on the Telegram platform so that the company could give me a direct answer based on the facts and in a way that is visible to everyone, not hidden.

Now, I want to clarify that I am a native Spanish speaker and use translators like Google Translate or DeepL. The problem with these technologies is that they can add words I never said, so I wrote to support directly in Spanish. Therefore, I will present two versions of this message:

English translation:

@butterbrbutterbr
Hi, in Spanish:

Greetings.

I have some fundamental questions about Nym’s VPN service, but before I ask them, I should mention that I tested it briefly in trial mode.

Based on the official information:

Two words appear: “guaranteed” privacy - how does Nym guarantee this privacy simultaneously against whom (adversaries, for example), how, and what is its actual method?

How does Nym defend itself against adversaries like the US NSA by adapting to or overcoming their VPN service methods?

How does Nym protect legitimate users of its services against apparent infiltrations from “legitimate” nodes? What are its methods, and how does it act in relation to this? For example: the mafia, veteran hackers, etc.

Which option would you recommend (2 nodes or 5 nodes) in a life-or-death situation involving stalking, when someone needs to send an encrypted, compressed, 8GB file to the person being stalked? Would it be a matter of “luck”?

If the answer to all the above questions is yes, do you have real-world, legitimate, public-facing evidence against real-life scenarios? I need to be convinced with concrete evidence, because someone claiming “guaranteed” is certain that what they’re saying is true.

Original Spanish version:

@butterbr
Hi, in Spanish:

Saludos.

Tengo preguntas fundamentales sobre el servicio VPN de Nym, pero antes de presentarlos, aviso que lo probé durante un poco de tiempo en modo de prueba.

Basado en la información oficial:

Aparecen dos palabras que dicen: privacidad “garantizada” - ¿cómo garantiza a la vez simultáneamente contra quién (adversarios por ejemplo), cómo y su método real?.
¿Cómo se defiende Nym contra adversarios como la NSA de los Estados Unidos al adaptarse o superar sus métodos del servicio VPN?.
¿Cómo protege Nym a las personas legítimas que utilizan sus servicios contra infiltraciones aparentes de nodos “legítimos”?, ¿cuáles son sus métodos y cómo actúan en relación a ésto?. Por ejemplo: La mafia, hackers veteranos, etc.
¿Qué opción aconsejaría (2 nodos o de 5 nodos) vosotros en una situación de vida o muerte basado en persecuciones cuando alguien necesita enviar un archivo cifrado, comprimido y de 8GB a la persona perseguida?, ¿será cuestión de “suerte”?.

Si todas las preguntas anteriores son positivas, ¿tienen pruebas reales contra escenarios reales legítimos para el público?.
Necesito que me convenzan con pruebas reales, porque el que afirma “garantizado” está seguro de lo que dice es verdadero.

If the company doesn’t respond within 5 days, their silence is a sign of something. If they do respond, I will reply according to their arguments, and you will witness what lies behind their words.

Observation: I saw that the CEO replied to another person’s message in the General category regarding unlimited bandwidth for the VPN service, which means it is active.