# Opinions on Windscribe VPN?

**URL:** https://discuss.privacyguides.net/t/opinions-on-windscribe-vpn/10644
**Category:** Questions
**Created:** 2022-12-03T21:13:09Z
**Posts:** 183

## Post 1 by @Creative — 2022-12-03T21:13:09Z

Hey dear community!

Any opinions about Windscribe VPN and how they handle things?  
We would be thankful for any input!

---

## Post 2 by @InconspicuousEntity — 2022-12-03T22:13:34Z

I personally don’t want to use a VPN in NA.

---

## Post 3 by @Creative — 2022-12-03T22:16:13Z

Makes sense, thank you for the answer, @InconspicuousEntity !

---

## Post 4 by @dngray — 2022-12-04T08:06:45Z

> [@InconspicuousEntity](#):
>
> I personally don’t want to use a VPN in NA.

We did away with the “eyes” nonsense some time ago, because it’s only one treaty of many. Many countries also do invasive surveillance nowadays. It’s also not 2012 anymore.

> <https://github.com/privacytools/privacytools.io/issues/1437>
>
> ## Description
> 
> These days I really don't think this specific services should …be recommended or not recommended based upon the FVEY [(Five Eyes)](https://en.wikipedia.org/wiki/Five_Eyes).
> 
> The reason for this is, that even if you were to choose a country that was not in the FVEY there is nothing stopping FVEY states from "leaning" on said country that you have chosen for your services.
> 
> Additionally we can be sure FVEY is not the only intelligence gathering agreement in the world. I would think countries that align themselves with China or Russia might very well share information too.
> 
> A user needs to establish whether their usage is going to align with their state's policy. For example if I lived in `insert EU state with good privacy legislation` might be a better choice than something overseas.
> 
> This argument comes up quite often in regard to DoH, VPN providers.
> 
> - https://github.com/privacytoolsIO/privacytools.io/issues/1428
> - https://github.com/privacytoolsIO/privacytools.io/issues/1395#issuecomment-540905268
> - https://github.com/privacytoolsIO/privacytools.io/issues/1431
> - https://github.com/privacytools/privacytools.io/issues/1915
> 
> We should encourage the use of [End to End encryption](https://en.wikipedia.org/wiki/End-to-end_encryption) wherever possible, and if anonymity is required, the usage of Tor or other strong anonymity networks.

[https://github.com/privacyguides/privacyguides.org/pull/504](https://github.com/privacyguides/privacyguides.org/pull/504)

We’re waiting for their write-up [Add Windscribe by dngray · Pull Request #1312 · privacyguides/privacyguides.org · GitHub](https://github.com/privacyguides/privacyguides.org/pull/1312#issuecomment-1220699208)

---

## Post 6 by @dngray — 2022-12-04T09:19:03Z

It was actually based on more lengthy discussions with other people that were in other threads, and in Matrix, additionally there is constructive reasoning provided behind these _scribbles_ as you put it.

---

## Post 7 by @Creative — 2022-12-04T12:57:22Z

Awesome, this discussion and vetting was exactly what we were looking for.  
I should have checked Github as well for issues.

Thank you again for the great input, Daniel!

---

## Post 8 by @CostcoFanboy — 2023-05-22T22:06:49Z

I honestly do not think the [Ukrainian event](https://arstechnica.com/gadgets/2021/07/vpn-servers-seized-by-ukrainian-authorities-werent-encrypted/) should be forgotten or forgiven.

I believe that it can be said that many other VPN providers did not have such huge fuck ups and are considerably more worthy of being recommended by such a popular privacy guide.

I also find it fairly worrisome for privacyguides to recommend a VPN led by a CEO that [behaves like an unhinged child on Twitter](https://www.youtube.com/watch?v=W-LnoTMlb1E).

---

## Post 9 by @jonah — 2023-05-24T18:06:52Z

> [@CostcoFanboy](#):
>
> I also find it fairly worrisome for privacyguides to recommend a VPN led by a CEO that [behaves like an unhinged child on Twitter](https://www.youtube.com/watch?v=W-LnoTMlb1E).

I think if we were going to start judging projects based on how unhinged their developers are, there are a number of existing recommendations I can think of that we would have to reconsider.

That being said, VPN providers do require a bit more trust than usually expected, so it’s something we can factor in. I don’t think we would recommend against Windscribe on the basis of a Tom Spark YouTube video alone.

---

## Post 10 by @dngray — 2023-05-25T05:59:58Z

> [@CostcoFanboy](#):
>
> I honestly do not think the [Ukrainian event](https://arstechnica.com/gadgets/2021/07/vpn-servers-seized-by-ukrainian-authorities-werent-encrypted/) should be forgotten or forgiven.

What I do like about them is they were honest [about the scope](https://blog.windscribe.com/ukrainian-server-seizure-a-commentary-and-state-of-the-industry-e71e8d205b26/) and took steps to make sure it could never happen again. All of their servers now operate in RAM, which is about the best you can hope for with a public VPN provider. They do seem to have a strong understanding of PKI, and use short lived certificates.

They also have other [informative articles](https://blog.windscribe.com/the-vpn-relationship-map/) rather than just “marketing SEO fluff” like a lot of VPN companies do.

We still would be waiting [for that audit](https://github.com/privacyguides/privacyguides.org/pull/1312#issuecomment-1452262340) likely they were fixing and refactoring code to be publicly available.

> [@CostcoFanboy](#):
>
> I also find it fairly worrisome for privacyguides to recommend a VPN led by a CEO that [behaves like an unhinged child on Twitter](https://www.youtube.com/watch?v=W-LnoTMlb1E).

It’s Tom Sparks, of course he’s going to be a sensationalist twit. His whole take on the [PTIO/PG transition](https://www.privacyguides.org/en/about/privacytools/) was to support Marco Wollank’s (BurungHantu) lies without any research/comment from the other side (us) and then to make some crappy “hit piece” for his channel. When challenged on Twitter there [was silence](https://twitter.com/TomSparkReviews/status/1511112980229853184). Apparently that stemmed from a post on Reddit where I suggested he had a strange obsession with Tor Guard and his “reviews” weren’t very scientific, only speed tests and no real evaluation of apps, their kill switches, (whether the implementation is safe) or other features such as IPv6 routing, port forwarding etc, if they are open source, or if they’ve had audits. I don’t know whether that has improved, as I don’t watch his videos and am not his target audience.

I have found that Windscribe has been professional in the limited correspondence I have personally had with them, regarding questions about their service.

---

## Post 11 by @yegor — 2023-05-25T15:55:27Z

Hi folks, man child here.

Firstly, I’ll say that citing Tom Spark as a source in the VPN space is like citing the opinion of a 12 year old on middle-eastern geopolitics. His recent opinion changed, not sure why but now we’re “A tier”: [https://www.youtube.com/watch?v=CNDrjlONZrg](https://www.youtube.com/watch?v=CNDrjlONZrg)

Anyhow, back on topic of the Ukraine thing. Server seizures happen all the time, for all VPN providers as it’s a function of network size and how many people use the service. Bigger services will have more seizures. This was not our first nor the last, and it’s normally not a big deal or “news worthy”.

What made that one different, is the events described in the blog post (the primary source of news from the event). It would have been real easy to say nothing, and rotate the certs as a “preventative security measure” (as some VPNs have done previously) and not a single person outside the company would ever know.

That being said, I can almost guarantee you such an event occurred with many other VPN providers and they simply said nothing, to avoid threads like this. Especially when it’s so easy to say nothing and brush it under a rug.

Don’t confuse our complete transparency for weakness. We made a mistake, we let everyone know, we learned from it, and deployed a superior solution which you can verify yourself vs other VPNs using steps mentioned in the blog post. Not a single provider that is currently subject to the same issue we had bothered to fix it, almost 2 years later.

I hope the above sheds some light on this.

---

## Post 12 by @jonah — 2023-05-25T17:45:01Z

> [@yegor](#):
>
> Firstly, I’ll say that citing Tom Spark as a source in the VPN space is like citing the opinion of a 12 year old on middle-eastern geopolitics. His recent opinion changed, not sure why but now we’re “A tier”

I suspect not for long after posting this message :slight_smile:

While I have you here, I think we are still waiting for [this](https://github.com/privacyguides/privacyguides.org/pull/1312#issuecomment-1452262340), right?

---

## Post 13 by @yegor — 2023-05-25T20:34:07Z

I addressed the questions there. The full “node audit” will be made public when the new node stack actually hits production. It’s still pre-release.

We could publicize the one we have from Cure53, but it would be rather meaningless as what was audited is not in production.

Here is a quick summary of that, all of this was already fixed.

 ![cure53](//forum-uploads.privacyguidesusercontent.com/original/2X/c/c3e1d779feca765a05b18a5ba8dd5f302d62831f.png)

---

## Post 15 by @CostcoFanboy — 2023-06-07T01:57:36Z

> I think if we were going to start judging projects based on how unhinged their developers are, there are a number of existing recommendations I can think of that we would have to reconsider.

I strongly believe you should make mention of this in general on products. Privacy is based on trust. Trust comes from integrity, history and **professionalism**.

---

## Post 17 by @Regime6045 — 2023-09-20T11:05:08Z

Any news on this? Windscribe offers port forwarding, which IVPN/ProtonVPN/Mullvad all dropped recently. Perhaps that makes it worth adding to the Guide?

---

## Post 18 by @Bhaelros — 2023-10-14T18:36:13Z

Why WS is still not added to the recommended VPN list?

---

## Post 19 by @jonah — 2023-10-14T19:00:53Z

@Regime6045 ProtonVPN supports port forwarding.

@Bhaelros I think we’re still waiting for the things we’ve been waiting for this whole time?

- The iOS client hasn’t been open sourced [https://github.com/privacyguides/privacyguides.org/pull/1312#issuecomment-1563379064](https://github.com/privacyguides/privacyguides.org/pull/1312#issuecomment-1563379064)

- Their full node audit hasn’t been released:

I’d love to add more services, but our criteria is well-defined, and unless we’re going to change them in order to list Windscribe, Windscribe isn’t going to be recommended. The simple fact is that there are already three services which _do_ meet our criteria—so our criteria obviously isn’t _too_ strict—and Windscribe isn’t demonstrably _better_ than our recommendations as far as I know, so all we can do is wait :man_shrugging:

---

## Post 20 by @jerm — 2024-04-14T15:44:12Z

> **[Why you shouldn't use a commercial VPN: Amateur hour with Windscribe](https://gergelykalman.com/why-you-shouldnt-use-a-commercial-vpn-amateur-hour-with-windscribe.html)**
>
> Intro This is a writeup about a user to root privilege escalation due to a race condition in Windscribe VPN's software. What is Windscribe? Windscribe is a smaller VPN provider, they have about 69M users according to their tweet that was published...

---

## Post 21 by @632vx8 — 2024-04-14T18:09:21Z

This researcher is lucky they aren’t being sued. His behavior was unethical and borderline illegal.

This came from pointless drama which started after Windscribe published a relief code for Brazil, because Twitter/X was threatened with a ban in that region. One person didn’t take this well and cancelled their subscription because they were mad because fighting censorship is apparently right-wing. Then lead into this guy (probably friends) who said they’d gladly drop a 0 day in their “shitware”, and so they did:  
[https://twitter.com/gergely\_kalman/status/1778208316008607812](https://twitter.com/gergely_kalman/status/1778208316008607812)

Here’s the whole reply chain if you’re interested. The researcher is acting like a 5 year old that didn’t get his bottle:  
[https://twitter.com/yegor/status/1778808157675876419](https://twitter.com/yegor/status/1778808157675876419)

The bounty he would have received was donated to a Brazilian charity for the disabled.

---

## Post 22 by @anonymous83 — 2024-04-15T11:40:00Z

i can’t see twitter comment chains since i don’t have a account. and nitter is now dead. if you could take a screenshot of the thread that would be very helpful

---

## Post 23 by @Regime6045 — 2024-04-15T16:50:14Z

> [@632vx8](#):
>
> This came from pointless drama which started after Windscribe published a relief code for Brazil, because Twitter/X was threatened with a ban in that region. One person didn’t take this well and cancelled their subscription because they were mad because fighting censorship is apparently right-wing. Then lead into this guy (probably friends) who said they’d gladly drop a 0 day in their “shitware”, and so they did:  
> [https://twitter.com/gergely\_kalman/status/1778208316008607812](https://twitter.com/gergely_kalman/status/1778208316008607812)

Seems to have started with this weirdo who is hell-bent on defending censorship and government overreach: [https://twitter.com/PhilippeDelteil](https://twitter.com/PhilippeDelteil)

---

## Post 24 by @KeepItSimple — 2024-04-16T06:17:15Z

When Windcribe app is launched there are various domain activities like [api.984bd7c214ff9239b88a0fcf1ce64690f7c53acf.com](http://api.984bd7c214ff9239b88a0fcf1ce64690f7c53acf.com) or [checkip.984bd7c214ff9239b88a0fcf1ce64690f7c53acf.com](http://checkip.984bd7c214ff9239b88a0fcf1ce64690f7c53acf.com) and even [api.block-only-if-you-have-a-small-pee-pee.io](http://api.block-only-if-you-have-a-small-pee-pee.io) is it OK naming?

---

## Post 25 by @jerm — 2024-04-16T11:44:22Z

I think these apis are used to authenticate you login? Because if they set the api to their [windscribe.com](http://windscribe.com) domain, it will be probably be blocked as many ISPs block VPNs websites in restricted countries.

---

## Post 26 by @jerm — 2024-05-03T08:46:25Z

Their [Double Hop](https://windscribe.com/features/double-hop/) implementation is really weird, it is traditional VPN + different VPN extension server location, unlike [Mullvad VPN](https://mullvad.net/en/blog/wireguard-multihop-now-easy-available-app) which is built-in their app.

---

## Post 27 by @anon29374801 — 2024-05-03T21:55:25Z

It is wild how far Windscribe has come. Eight years ago they seemed like the typical bottom of the barrel VPN who was selling super cheap **lifetime** Pro memberships (I think they still honor these, I will find out in 2026), I think my voucher was around $30 if I remember correctly. Now they may end being one of the top four or five privacy respecting VPNs out there.

---

## Post 28 by @BlackDog — 2024-05-03T22:20:34Z

They seem to be pretty competitive when it comes to price. I was using their ‘build-a-plan’ tier for a while for $3 a month as it was all I needed. I took them up on their recent birthday offering ($29 a year for Pro). They seem to have deals fairly often though.  
Stack Social have a 3 year Pro subscription for $89 at the moment.

---

## Post 29 by @Regime6045 — 2024-05-08T12:34:49Z

I’m a bit annoyed that you need to pay extra for a static IP if you want port forwarding. Unless I’m misunderstand something.

---

## Post 30 by @dngray — 2024-05-08T13:23:00Z

> [@jerm](#):
>
> I think these apis are used to authenticate you login

They’re used to grab the configs, when you login things like [api.windscribe.com](http://api.windscribe.com) are blocked, obviously though certain regimes block that and all public DoH providers. It would seem likely Windscribe are registering temporary domains not tied to [windscribe.com](http://windscribe.com)

Maybe with the last one having a bit of fun at the censor’s expense (seeing as they are the ones seeing that when they monitor internet traffic in their countries).

---

## Post 31 by @Gnarleyeh — 2024-05-13T18:09:46Z

Well said !

---

## Post 32 by @xe3 — 2024-05-13T20:07:41Z

Any other Fedora + Windscribe users here? (or Linux more broadly)

I subscribed to Windscribe recently and I’m encountering a number of frustrations.

One of the weirdest issues I’m experiencing is that when Windscribe’s desktop app is connected, I can’t open Firefox or various other applications, or if it does open, it might take 1-2 minutes to launch (compared to \<3 seconds normally), Disconnecting and then reconnecting (after launching the browser) solves the problem. But it is extremely frustrating. So far the Windscribe Linux experience feels like a _big_ step down, from Mullvad, but it is too early for me to judge with confidence. Has anyone else experienced an issue similar to this?

---

## Post 33 by @anon29374801 — 2024-05-13T20:24:50Z

Take this with a major grain of salt as I do not use Windscribe on Linux

> [@xe3](#):
>
> Firefox or various other applications, or if it does open, it might take 1-2 minutes to launch (compared to \<3 seconds normally), Disconnecting and then reconnecting (after launching the browser) solves the problem. But it is extremely frustrating

but this sounds very familiar (almost the exact same symptoms) to issues I have experienced with VPNs in the past. Have you tried lowering the MTU (no clue if Windscribe on Linux offers this option) value? Setting the MTU to 1280 for me in similair situations fixed this issue for me.

---

## Post 34 by @Sharply — 2024-05-13T20:29:08Z

I use the Windscribe client on Fedora and can’t say I’ve had the same issue, but I do use other providers with it instead of using Windscribe’s servers.

Have you tried contacting them about it?

---

## Post 35 by @xe3 — 2024-05-13T20:48:32Z

> [@Sharply](#):
>
> Have you tried contacting them about it?

I am in the process of collecting relevant info and writing up a bug report right now. Its a bit of an odd problem to try to describe  
I’m also going to give @anon29374801 's recommendation a try, see if that might help.

---

## Post 36 by @ikelatomig — 2024-05-23T08:08:11Z

[https://youtube.com/watch?v=rDQWoSb5Ibs](https://youtube.com/watch?v=rDQWoSb5Ibs) - just watched this and the security Researcher’s post and the X thread kind of downgraded the opinions and respect on Windscribe, personally. What do you all think ?

---

## Post 37 by @Niek-de-Wilde — 2024-05-23T08:37:39Z

This has been discussed before see @632vx8 message above. Also, that youtuber has personal beef with Windscribe, so I would consider any takes from him about Windscribe with a big grain of salt.

---

## Post 38 by @jerm — 2024-05-23T08:37:48Z

Video made by Tom spark, opinion automatically disqualified. But I agree with the researcher about Windscribe’s incompetence. They seem to focus more on marketing and humor than actually improving the security and privacy of the product. I would choose [Mullvad](https://mullvad.net/en/vpn) or [IVPN](https://www.ivpn.net/) if you really care about security and privacy.

---

## Post 40 by @ikelatomig — 2024-05-24T04:06:15Z

Sorry, I don’t follow Tom Spark’s too. I don’t even care about that guy, I am speaking of the Security researcher and CEO of Windscribe’s discussion in twitter thread.

---

## Post 41 by @ikelatomig — 2024-05-24T04:07:55Z

For F..'s sake, I didn’t read the thread, and just blindly commented. So, don’t rant me. I am reading it now.

---

## Post 42 by @ikelatomig — 2024-05-24T04:20:11Z

They do support custom MTU values in their App

---

## Post 44 by @ikelatomig — 2024-05-26T08:14:42Z

Why is it illegal because of being published in the public before being fixed ?

I get the unethical part.

---

## Post 47 by @Valynor — 2024-05-26T14:59:57Z

[off-topic posts removed, please create your own thread in the appropriate category if you want to discuss this]

---

## Post 48 by @anon66226834 — 2024-07-03T21:54:27Z

The lack of transparency regarding the Cure53 audit should be a red flag for Windscribe [Reddit - The heart of the internet](https://www.reddit.com/r/Windscribe/comments/1df9kl6/another_audit_post/)

---

## Post 49 by @xe3 — 2024-07-03T22:33:07Z

I’ve been using Windscribe as of a couple months ago.

I’ve had a pretty mediocre experience with some bugs and just general frustrations (some probably linux specific). Compared with Mullvad my constructive critisms are:

1. Technical documentation is lacking, they seem to devote a lot more focus edge marketing towards the teenage-torrenting crowd than to writing good detailed docs. I don’t really mind the ‘edgy’ marketing stuff, so long as it doesn’t come at the expense of good documentation, or a good service.

2. The app feels cluttered yet simultaneously not very information dense, kind of has the vibe of a las vegas billboard.

3. Double Hop depends on using a browser extension.

4. Proxy feature (seems to) rely on using a browser extension.

5. Bugs:  
A. When the VPN is enabled, updates `sudo dnf upgrade`, and applications including Firefox, Thunderbird, Freetube, and iirc Brave would take literally minutes to open. (I was able to find a workaround that solved this).  
B. The connection would drop intermittantly (kind of normal for a VPN in my experience) and nothing short of a full system restart would allow me to reconnect or even disable the firewall/“killswitch” (not restarting the app, not restarting the systemd services, not even a full logout). This would happen at least daily. I’m using a Beta version now and it seems the problem may have been solved.  
C. A separate issue with dropped connections, where the only way to reconnect was by switching from Wireguard to OpenVPN.

6. Kind of minor complains / personal preferences:  
A. No option to download config files at the state/country/region level or ‘best connection’ type option. So if I import a wireguard config into NetworkManager it must be for a single specific server.  
B. No ability to create custom lists of VPN servers like I could with Mullvad.

What I do like about Windscribe:

1. They do have a featureful linux app, despite the bugs I’ve experienced.
2. The price is hard to beat
3. Except for the criticisms above (some of which have been mitigated), most things just work (as a Linux user, I never expect that to be the case with VPN clients).
4. Haven’t used the local proxy feature but it seems useful.
5. No hard limit on concurrent or overall connections.
6. Most of my issues are probably either Linux specific or would not be relevant to casual VPN users who just want a simple VPN and don’t care about double hop, proxies, custom lists, or technical docs.
7. Did I mention price..

---

## Post 50 by @Shampoo — 2024-07-04T00:49:30Z

I haven’t seen anyone mention it yet but they recently open sourced their IOS app: [GitHub - Windscribe/iOS-App: Complete source code of the official Windscribe iOS application.](https://github.com/Windscribe/iOS-App)

One of their staff also said on [Reddit](https://www.reddit.com/r/Windscribe/comments/1df9kl6/another_audit_post/) that they had a new audit performed in May and they are “… currently incorporating the auditors’ recommendations into our software stack. We’ll then roll out the further-strengthened software stack across our server fleet.”

Those were the two things preventing Windscribe from being listed on here so that’s good. It’s one of the only VPNs I’ve found that has an actually decent Linux app so I’m happy personally.

---

## Post 51 by @anon80779245 — 2024-07-04T22:23:04Z

Who is PacketLabs ?

The only concrete bits we have so far is a partial screenshot  
[WS Audit PacketLabs - Album on Imgur](https://imgur.com/a/ws-audit-packetlabs-JH49H2T)  
Maybe they just wait to fix the bugs. But I don’t think they should communicate it. before they have finished fixing the bugs.

> [@Shampoo](#):
>
> they recently open sourced their IOS app:

This is nice, and the license is MIT 3.  
That being said, they have yet to switch development off the app on GitHub. It has been two weeks since the initial commits. That means they probably still use an internal Git system. I guess they might switch in the next few weeks, so we should wait and see.

---

## Post 52 by @Shampoo — 2024-07-05T02:39:59Z

> [@anon80779245](#):
>
> Maybe they just wait to fix the bugs. But I don’t think they should communicate it. before they have finished fixing the bugs.

Communicating it is a good thing. They didn’t give any real updates on their audit for years so any attempts at being transparent are a step in the right direction for them.

> [@anon80779245](#):
>
> This is nice, and the license is MIT 3.  
> That being said, they have yet to switch development off the app on GitHub. It has been two weeks since the initial commits. That means they probably still use an internal Git system. I guess they might switch in the next few weeks, so we should wait and see.

It looks like their other apps are also developed internally and then pushed to GitHub when there’s a new release.

---

## Post 53 by @securitybrahh — 2024-07-11T18:22:17Z

I mostly use windscribe as a disposable VPN.

iirc port forwarding & by its extension torrenting etc is nice there.

I believe its the only provider that supports all major protocols.

---

## Post 54 by @jerm — 2024-07-11T18:33:32Z

Windscribe security audit

> **[FreshScribe: Next-Generation VPN Infrastructure](https://windscribe.com/blog/freshscribe-next-generation-vpn-infrastructure-2/)**
>
> Every day, our team has woken up from a nightmare while screaming “The audit is coming soon, I swear!” This went on for quite some time, and we’re happy to say that the nightmares are over.
> 
> We’ve been working on a very large revamp of our VPN stack

---

## Post 55 by @anon66226834 — 2024-07-19T16:06:56Z

Now that the audit happened. Wonder if there’s any plan on Windscribe being added on the recommendation list.

---

## Post 56 by @anon48875053 — 2024-07-19T16:08:31Z

[https://github.com/privacyguides/privacyguides.org/pull/1312](https://github.com/privacyguides/privacyguides.org/pull/1312)

---

## Post 57 by @Shampoo — 2024-07-19T16:53:13Z

They’ll probably wait to add it until the new stack is fully rolled out. Windscribe said the end of Q3 2024 it’ll be complete so I assume it’ll be added to the site in September.

---

## Post 58 by @anon80779245 — 2024-07-24T09:01:00Z

> [@jerm](#):
>
> [FreshScribe: Next-Generation VPN Infrastructure](https://blog.windscribe.com/freshscribe-next-generation-vpn-infrastructure-2/)

Tl;dr  
Not an audit, but a penetration test, so no access to internal infrastructure. All found vulnerabilities were fixed.  
2 main vulnerabilities and one privacy issue were found

1. Outdated software with unpatched security vulnerabilities (Sonatype Nexus Repository  
• Redis Metrics Exporter)
2. **Weak control access** allowed access to their **internal repo** , which ultimately gave acess to \> the salted **SHA-512 hash** for the redacted user, along with standard users
3. **Logging of IP adresses** or users account info, depending on the connection method. Those are kept for **10-23 hours**.

While Windscribe claimed victory, this is far from reassuring. 2) is a serious vulnerability which shows the lack of defensive security thinking and 3) is concerning as they effectively logged users, although temporarily, despite claiming “no-logging”.

Of course, this “audit” was very different from Mullvad’s. Mullvad gave full access to a server source code to test it from vulnerabilities. Here, it is only a test from an outsider’s perspective, but does nothing to evaluate how one malicious employee could exploit internal code.

I don’t want to be mean with WS, but with their history, I believe a more thorough audit is warranted for inclusion on PG.

---

## Post 59 by @yegor — 2024-08-02T00:03:55Z

This TLDR is very wrong, and it sounds like the audit was not actually read, or you have an axe to grind for some reason…

Point #2: This is not a “serious vulnerability” (notice the actual severity on the issue - LOW) as this is only for rootfs, which is a blank slate server with no configs, secrets, or useful information. This also didn’t affect anything in production, as this is a pre-production audit. This was an oversight for sure, but that’s why we did the audit before going into production with this setup.

Point #3: This affected zero customers as the beta servers the select group used to provide us feedback never accessed the machine that the audit was performed on, where we did enable full logs for debugging, and forgot to put them back to how they were.

If you read the scope section, you will find the following:

> This included the `ca-023.windscribe.com` node along with the security testing and manual source-  
> code review of the Windscribe cross-process communication and microservice stack.

**So the scope is VERY extensive, and included full access to the server and all source code running on it, and the auth infrastructure it connects to.**

There were so few findings because this is not the first audit (earlier Cure53 one had more findings), so if you actually read the whole thing, the results are pretty damn good (2 low severity issues, and one info).

Since you mentioned Mullvad, they did a VERY similar audit of their pre-production infra last year: [Infrastructure audit completed by Radically Open Security | Mullvad VPN](https://mullvad.net/en/blog/infrastructure-audit-completed-by-radically-open-security)

Which resulted in:

> RoS discovered 1 High, 6 Elevated, 4 Moderate, 10 Low and 4 info-severity issues during this penetration test.

All software has bugs, as everything is done by humans who make mistakes. I caution not to add emotion into the mix, or make baseless claims that are not backed up by facts.

Cheers

---

## Post 61 by @Niek-de-Wilde — 2024-08-02T14:39:01Z

Personally I have no issue with jokes, its how a lot of brand do marketing these days. What misinformation are you talking about?

---

## Post 64 by @Rasta — 2024-08-02T14:49:08Z

While I do have some issues with Windscribe myself, the jokes aren’t a part of it. The april fools, jokes, etc are just part of a marketing gimmick. Look at Dbrand insulting their customers and their products on a regular basis. It’s modern marketing.

---

## Post 65 by @anon80779245 — 2024-08-02T14:57:39Z

> [@yegor](#):
>
> Point #2: This is not a “serious vulnerability” (notice the actual severity on the issue - LOW) as this is only for rootfs

Serious issue was a personal opinion, not a level. Anyway the audit rankings do not use

> [@yegor](#):
>
> So the scope is VERY extensive, and included full access to the server and all source code running on it, and the auth infrastructure it connects to.

From what I understand, they might had acess to your internal code, but they still were just doing pentesting, meaning they tried to penetrate it from outside. Mullvad’s audit is internal and external, like if an employee had access to a mullvad server what could he do.

## Scope 3

Maybe, but who knows ? The point of an audit is that I dont have to believe you. And your no logs policy wasnt upheld, per the audit.

---

## Post 66 by @Shampoo — 2024-08-02T15:36:45Z

> [@anon80779245](#):
>
> From what I understand, they might had acess to your internal code, but they still were just doing pentesting, meaning they tried to penetrate it from outside. Mullvad’s audit is internal and external, like if an employee had access to a mullvad server what could he do.

You clearly didn’t read the audit/blog post because there’s a section that says “External and internal penetration testing” in huge bold letters. The same section also says they were tested with full access to the machines.

---

## Post 67 by @anon80779245 — 2024-08-02T15:40:40Z

This is so annoying. I read it one week ago. Everyone say I havent but I have.

BTW, I didnt see that. I dont consider the Windscribe blogpost, just the audit. Feel free to atach screenshots

---

## Post 68 by @yegor — 2024-08-02T15:43:23Z

No disrespect, but what are you credentials to provide “personal opinions” on a security matters from a document that you have not fully read?

The scope of the audit is clearly stated in the document (and blog post), which states that full access to infrastructure and code was provided.

 ![image](//forum-uploads.privacyguidesusercontent.com/original/2X/3/3eaa14ba30d1de78373f2283985c6ce5412459d5.png)

You probably just read the title of the report which does say “Penetration Test”, which is exactly the same title of the Mulvad report, that you also have not actually read: [ros-website/ros-public-reports/ROS - Mullvad VPN 2023.pdf at d923ae2001cdf48deeb0130475a415273e5087c7 · radicallyopensecurity/ros-website · GitHub](https://github.com/radicallyopensecurity/ros-website/blob/d923ae2001cdf48deeb0130475a415273e5087c7/ros-public-reports/ROS%20-%20Mullvad%20VPN%202023.pdf)

Scope 3: Now we’re getting into the tin foil hat territory. If that was the case, it would be in the report. Much like it is Mulvad’s report where they accidently sent production traffic through a test server.

> **MLL-024 — Production multihop traffic on test system**  
> The VPN server used for testing processes multihop traffic for production VPN users.

---

## Post 81 by @Niek-de-Wilde — 2024-08-02T16:36:29Z

Im keeping this tread open for now as we haven’t decided as off yet. That said I have deleted a few comments to clean up the tread. @guest138759215 im nicely asking you to keep the nonsense at bay, or you will be muted.

---

## Post 82 by @Rasta — 2024-08-02T16:37:56Z

It looks like they’re just deleting all of their comments so this whole segment of conversation will have no visible cause

---

## Post 83 by @Niek-de-Wilde — 2024-08-02T16:38:58Z

Right, ill just delete it up to the point where the discussion was sensible.

---

## Post 84 by @mangomango — 2024-09-07T17:47:30Z

hi, where are we at with this ?  
i think that Windscribe should be recommended because the only thing lacking was an audit and tje opensourceness of the iOS app and now one audit was published and the issues have been fixed.

---

## Post 85 by @anon48875053 — 2024-09-07T17:50:56Z

> **[update: Add Windscribe (#1312) · privacyguides/privacyguides.org@3a6d052](https://github.com/privacyguides/privacyguides.org/commit/3a6d0522bdf317f8872a87f422083cdd02fd0ad8)**
>
> Protect your data against global mass surveillance programs. - update: Add Windscribe (#1312) · privacyguides/privacyguides.org@3a6d052

---

## Post 86 by @anon80779245 — 2024-09-07T21:51:07Z

This is approved ? Only a few months since audit.

I think we should wait at least for the next audit.

We already have 3 VPNs recommended. And none of them had scandals. I think they still have more to proof.

I also don’t like their aggresive marketing. Last time I criticised them and they made hjghly misleading statement (I didn’t have time to answers) and they said some of my concerns were “tinfoil hat”.

Plus, they are spreading FUD about Proton

> [@Windscribe is spreading FUD about Proton](https://discuss.privacyguides.net/t/windscribe-is-spreading-fud-about-proton/18472):
>
> Windscribe is unfairly using FUD about Proton for marketing purposes. These are done in the Proton Technologies, ProtonMail and ProtonVPN articles of [VPNMAP created by Windscribe](https://windscribe.com/vpnmap). It supports the [vpnscam[.]com smear campaign run by PIA](https://github.com/privacytools/privacytools.io/issues/928), [Spreading the false claim made by Privacy watchdog that the Proton Mail is a CIA honeypot](https://web.archive.org/web/20210719011623/https://privacy-watchdog.io/truth-about-protonmail), issues with Tesonet they [fixed](https://www.reddit.com/r/ProtonVPN/comments/8ww4h2/comment/e21tfqw/) in 2018 Despite this, it has not been corrected. (Windscribe VPNMAP is the 2024 version) PIA’s smear campaign and Privacy watchdog are noto…

---

## Post 87 by @mangomango — 2024-09-13T20:38:28Z

No it’s not approved still and don’t understand why

---

## Post 88 by @mangomango — 2024-09-13T20:41:57Z

> [@anon80779245](#):
>
> I think we should wait at least for the next audit.

Better stay close to the criteria. One audit is what is required (other recommended tools have only one audit I believe

> [@anon80779245](#):
>
> We already have 3 VPNs recommended

This is not a requirement haha wtf ?? There is no max limit on the number of recommended tools !

> [@anon80779245](#):
>
> Plus, they are spreading FUD about Proton

Not true, even yourself said in the linked thread that there is no “smear campaign”.  
Their marketing has already been discussed and it’s not problematic.

---

## Post 89 by @anon80779245 — 2024-09-14T18:49:09Z

> [@mangomango](#):
>
> This is not a requirement haha wtf ?? There is no max limit on the number of recommended tools !

I never said if was.

> [@mangomango](#):
>
> Their marketing has already been discussed and it’s not problematic.

Them basically saying I am liar and putting me a false intent doesn’t look good.

Also, theiy still have their [VPN Relationships map](https://kumu.io/Windscribe/vpn-relationships) where they promote the fact that Proton are scammers. For example they say the a Privacy Tools megathread is “shady”, unclear if they refer to Proton or PT being shady. The actual megathread is just debunking.

 ![Screenshot 2024-09-14 at 20-51-36 VPN Relationships • VPN Company Relationships _ The VPN Industry • Kumu](//forum-uploads.privacyguidesusercontent.com/original/2X/e/ecec7007a8ae6304fc366d59b129e52255165e13.png)

 ![Screenshot 2024-09-14 at 20-53-26 VPN Relationships • VPN Company Relationships _ The VPN Industry • Kumu](//forum-uploads.privacyguidesusercontent.com/original/2X/5/56230c0ff2b507fa9739db4e253f0a86437c7b0e.png)

---

## Post 90 by @mangomango — 2024-09-15T16:12:29Z

> [@anon80779245](#):
>
> I never said if was.

I am not saying that you said that this was a requirement neither. What I said is that we should recommend the tools that meet the criterias otherwise it’s just arbitrary. There is no sense in not recommending a tool that meets the criterias because we already trust 3 VPNs that meet as much the criteriaq

---

## Post 91 by @xe3 — 2024-09-15T19:06:00Z

> [@mangomango](#):
>
> What I said is that we should recommend the tools that meet the criterias otherwise it’s just arbitrary

It is my understanding that this is not how PG recommendations work.

The recommendation aren’t just exhaustive lists of _every tool that meets or exceeds the minimum._ Minimum criteria are just _minimum prerequisite_ criteria to even be considered. PGs recommendations are meant to reflect the top options for a given category. At least that is my understanding.

And (in my eyes), for categories like VPNs, where (1) there are already 3+ good and very reputable choices, and (2) its a category where trust in the provider is very important, there isn’t really any urgency or strong incentive to rush a recommendation. A bit of caution/conservatism isn’t a bad thing in this context.

---

## Post 92 by @Regime6045 — 2024-09-16T15:31:59Z

I think the current 3 providers are all lacking in some way, for example Mullvad and IVPN don’t allow port forwarding anymore while Proton doesn’t accept Monero and also has limited port forwarding (ephemeral ports, no GUI for Linux). Windscribe on the other hand allows port forwarding and Monero payments.

Also I don’t think 4 providers are too many. Look at how many recommendations there are in the email clients or password manager section.

---

## Post 93 by @mangomango — 2024-09-16T15:46:05Z

Isn’t trust established by the criteria about the audit ?

---

## Post 94 by @xe3 — 2024-09-16T20:13:07Z

> [@Regime6045](#):
>
> I don’t think 4 providers are too many.

I don’t think so either. But I do think there is much less _urgency_ to add a recommendation when there are 3 or more good options, and no harm in being methodical and selective in that context.

That is all I intended to say (and clarification that _meeting minimum requirements =/= an automatic and immediate recommendation_). I didn’t intend my comment to come off as opposing the inclusion of Windscribe (as a current Windscribe subscriber, I have some _mild_ misgivings, and a few areas Windscribe could/should improve before they are on the same level as for example Mullvad, but those are mostly minor critiques)

On the matter of urgency vs conservatism, if I understand Windscribe’s [blogpost](https://blog.windscribe.com/freshscribe-next-generation-vpn-infrastructure-2/) correctly, the infrastructure that was audited, is their _new_ infra which is still in the process of being rolled out (they expect the transition to be complete sometime this fall) and even [their own docs](https://windscribe.com/knowledge-base/articles/has-windscribe-been-audited/) haven’t all been updated to reflect the completion of the audit yet.

~~Valid and relevant point about Monero though.~~ (unconfirmed)

Port forwarding [appears to be](https://windscribe.com/knowledge-base/articles/setting-up-port-forwarding/) an additional paid feature only available to those who pay for and use a _static IP_ or a _residential IP_ in addition to their normal Windscribe subscription.

> [@mangomango](#):
>
> Isn’t trust established by the criteria about the audit ?

> **I think trust is rather personal and multifaceted, but for me, yes, undergoing audit(s) goes a long way to helping to establish a basis for trust.**
>
> I think (1) willingness to undergo an audit (2) publicly disclosing the results of that audit, (3) how a service responds to and improves from the audit, and (4) regular (routine) audits are all positive steps towards building trust and demonstrating trustworthiness.
> 
> But this is partially dependent on you reading and understanding the contents and scope of [that audit](https://drive.google.com/file/d/1EgNETLVm2oZdGJXZJmFSCDc7Ib72LIOw/view) (or reading a trusted 3rd party’s analysis of it).

---

## Post 95 by @anon80779245 — 2024-09-16T21:35:30Z

> [@Regime6045](#):
>
> Windscribe on the other hand allows port forwarding and Monero payments.

Windscribe allows Monero payments ? Do you have a source ?

---

## Post 96 by @xe3 — 2024-09-16T21:54:49Z

> [@anon80779245](#):
>
> Windscribe allows Monero payments ? Do you have a source ?

Windscribe seems to give conflicting info on this. [Their main pricing page](https://windscribe.com/upgrade) doesn’t list Monero among the available options.

But [this page](https://windscribe.com/knowledge-base/articles/which-cryptocurrencies-do-you-support/) in the knowledgebase lists an extensive list of cryptocurrencies that does include Monero.

---

## Post 97 by @anon55464882 — 2024-09-23T19:14:32Z

You can definitively make payments with XMR. Windscribe utilizes [CoinPayments](https://www.coinpayments.net/index.php) as its cryptocurrency payment processor, which allows for XMR transactions.

---

## Post 98 by @mangomango — 2024-10-15T15:34:57Z

Yes this is the only provider which offer :

- XMR payment (unlike Proton)
- [port forwarding](https://windscribe.com/features/port-forwarding/) (unlike the three current recommendations)
- dedicated IPs
- [bigger network](https://windscribe.com/features/large-network/) than Mullvad and IVPN (including more countries in Africa and LATAM which isn’t that common)
- [open-sourced all apps](https://github.com/windscribe), [have an audit](https://drive.google.com/file/d/1EgNETLVm2oZdGJXZJmFSCDc7Ib72LIOw/view)
- a good linux app (unlike Proton)
- [is](https://blog.windscribe.com/ukrainian-server-seizure-a-commentary-and-state-of-the-industry-e71e8d205b26/) [transparent](https://windscribe.com/transparency/)
- [does not require email](https://windscribe.com/signup) (unlike Proton)
- 100% RAM-only nodes (what about IVPN Mullvad and Proton?)
- has a censorship circumvention feature that seems to be one of the best, and a decoy traffic feature on Android (like Mullvad).
- not VC-funded (fully independent)
- [Honest marketing](https://windscribe.com/ethics)
- Good guides about privacy for the end-user, about VPNs and the industry.
- Not as blacklisted as IVPN, in my experience.

It don’t has double-hop for mobile though, nor quantum-resistant encryption (they are “[in the process of beefing up our KEM (Key Encapsulation Mechanism) in TLS and OpenVPN protocols.](https://blog.windscribe.com/fresh-updates-from-the-windscribe-crew/)”) however.

I think they should be added because they really try hard to get around censorship.

 ![Capture d’écran 2024-10-15 à 09.28.11](//forum-uploads.privacyguidesusercontent.com/original/2X/c/c985767ed779abff8b22cb9bdfa7011dace29a81.png)  
 ![Capture d’écran 2024-10-15 à 09.28.02](//forum-uploads.privacyguidesusercontent.com/original/2X/9/923aa07573576bd2f5b04aff6c55aceb5fa9b6fe.jpeg)

---

## Post 99 by @mangomango — 2024-10-15T15:37:38Z

> [@jonah](#):
>
> - The iOS client hasn’t been open sourced [https://github.com/privacyguides/privacyguides.org/pull/1312#issuecomment-1563379064](https://github.com/privacyguides/privacyguides.org/pull/1312#issuecomment-1563379064)
> - Their full node audit hasn’t been released:

these two problems have been resolved.

I push Windscribe that hard because I think they really bring something new and needed to the table, that I can’t find anywhere else.

---

## Post 100 by @jcprivacyguides — 2024-10-15T16:24:33Z

In response to a post I saw when scan reading this thread: please PG, recommend as many apps/services you like that meet high privacy standards. Some recommendations will not be a perfect fit for some users. For example, I’m currently in an unfortunate position where I cannot afford to pay for a VPN, so that knocks out Mullvad and IVPN and leaves me with Proton VPN, which is what I am using. However, my preference is not to rely on Proton for everything on my phone (mail, etc), so if there are other free but trustworthy VPNs out there I would love to know.

---

## Post 101 by @jonah — 2024-10-15T16:35:30Z

To be clear, there isn’t a limit on quantity of recommendations. It’s just that if we already have a bunch, adding even more is a bit lower priority. The website has over 100,000 words, which is longer than many books, and every page needs to stay up to date.

Anyway, I haven’t evaluated Windscribe myself (yet), I don’t know if any other team members are working on that at the moment. So whether it does meet high standards I couldn’t say :man_shrugging:

---

## Post 102 by @anon80779245 — 2024-10-15T17:05:22Z

> [@mangomango](#):
>
> [port forwarding](https://windscribe.com/features/port-forwarding/) (unlike the three current recommendations)

Please stop using blur it makes quoting an hassle.  
Anyway, Proton has limited port forwarding abilities.

> [@mangomango](#):
>
> 100% RAM-only nodes (what about IVPN Mullvad and Proton?)

Mullvad has RAM-only servers ([source](https://mullvad.net/en/blog/we-have-successfully-completed-our-migration-to-ram-only-vpn-infrastructure))

> [@mangomango](#):
>
> Honest marketing

Mullvad probably equals them in this regard, F

> [@mangomango](#):
>
> dedicated IPs

I hope that those dedicated IPs change their ips weekly, because if not this is a big privacy risk.

---

## Post 103 by @Hitherebeautifulpeople — 2024-05-11T19:32:26Z

Hi there. I encourage everyone to look a bit more at Windscribe.

I used to use IVPN but it was barely usable since it was blacklisted on too many services (my company website, my school, Spotify, Reddit, Ticketmaster and anibis.ch. Moreover, it did not work well with Netflix, nor does Mullvad. Moreover, it may not be very important but IVPN and Mullvad have small networks. I don’t want to use Proton because the account creation is less anonymous and I don’t like the UI and the features.

Windscribe works well with **Netflix** , it has a **large network** , R.O.B.E.R.T. looks great, has port forwarding, WireGuard, OpenVPN, STealth, Ikev2 and another protocol to **circumvent censorship.** Very important : they not only offer app split-tunneling on Android, macOS, Windows and Linux, but also split tunnelling for **domains** and IPs ! They also have **MAC Address Spoofing** on macOS and WIndows !!  
And **proxy** server for devices that don’t support vpns (TVs).  
And **custom DNS** support !!  
And their **browser extension** seems to be able to do so much :scream: I had never considered a VPN browser extension until Windscribe

Moreover, they seem to be quite good at censorship circumvention  
and a fun design and marketing.

Finally found a VPN that suits my need :)))

---

## Post 105 by @xe3 — 2024-05-11T19:51:55Z

> [@Hitherebeautifulpeople](#):
>
> And their **browser extension** seems to be able to do so much :scream: I had never considered a VPN browser extension until Windscribe

Could you expand on this? What do you like about the browser extension.

I made heavy use of the Mullvad Extension (like you that was my first time even considering using a browser extension with a VPN, but the proxy capability was really useful. I am currently testing windscribe, and I’d like to recreate the setup I had with Mullvad, but I haven’t got around to exploring Windscribe’s Browser extension yet. I’d be interested to learn abut the features you like about it.

---

## Post 106 by @moonwriting — 2024-05-11T23:42:57Z

> [@Hitherebeautifulpeople](#):
>
> it may not be very important but IVPN and Mullvad have small networks

This is usually just the result of being a smaller VPN provider. You don’t need a massive server network if you don’t have as many users as larger VPN providers. Anyway, my experience with Mullvad has always been excellent and I have never really had any problems with slow speeds.

---

## Post 107 by @Sharply — 2024-05-12T00:17:21Z

Windscribe’s client is excellent, open source and works with other VPN providers besides them, they really did an amazing job there. Definitely underrated.

As far as providers go though, it’s difficult for me to recommend Windscribe, mainly due to their incident a couple years ago with their servers in Ukraine being seized while being unencrypted. ([Source](https://web.archive.org/web/20240326122558/https://arstechnica.com/gadgets/2021/07/vpn-servers-seized-by-ukrainian-authorities-werent-encrypted/))

On one hand, I’m glad they were transparent about it, but that’s a pretty gigantic fuck up, hard for me to look past. I just don’t see any reason to use them as a provider when there’s better options like Mullvad, Proton, and IVPN, which can be used with their client anyways, so you get the best of both worlds.

---

## Post 108 by @anon32558482 — 2024-05-12T09:40:22Z

Doesn’t look like Windscribe offers a private payment method.

---

## Post 109 by @anon48875053 — 2024-05-12T09:51:14Z

They accept Monero, doesn’t get more private than that.

> **[Which cryptocurrencies do you support? | Windscribe](https://windscribe.com/knowledge-base/articles/which-cryptocurrencies-do-you-support/)**
>
> Upgrade your Windscribe account anonymously with crypto. Pay with Bitcoin, Monero, Ethereum, and more—no credit card or ID needed.

---

## Post 110 by @anon32558482 — 2024-05-12T09:57:17Z

Interesting.

Monero isn’t shown as a payment option at [Upgrade to Pro - Windscribe](https://windscribe.com/upgrade)

Bitcoin, 4 credit cards, and Paymentwall are the accepted options.

---

## Post 111 by @anon48875053 — 2024-05-12T09:58:38Z

This is how normies pay for stuff, it makes sense to put most used payment methods on that page. If they would put all of them there, it would be ugly and take a lot space.

---

## Post 112 by @Sprout3425 — 2024-05-12T10:02:38Z

PG suggests gift cards and prepaid cards are the most private, can’t you use those?

Also, out of curiosity, isn’t Proton and others in the same boat?

---

## Post 113 by @anon73886004 — 2024-05-12T10:40:53Z

In my experience (US), you can’t use prepaid cards online unless you register them first.

---

## Post 114 by @anon80779245 — 2024-05-12T15:09:51Z

> [@Hitherebeautifulpeople](#):
>
> IVPN but it was barely usable since it was blacklisted on too many services

For Spotify they will block you to login but not listen to music and you just have to login every few weeks. It will accept login only if you reset your passwords.

For Reddit, you can use Redlib (redlib.tux.pizza)

**Mullvad** does **own VPN servers in Europe** and those are less subject to captcha blocks.

> [@Hitherebeautifulpeople](#):
>
> Ikev2

Not very secured

I do agree that Windscribe is great for some use cases, especially when you use a PC where you can’t install a VPN app but can install an extension. Also they use residential server which will less likely be blocked.

For censorship circumvention, Mullvad is the best. Period. But Windscribe might be enough if your government censorship effort aren’t too developed.

---

## Post 115 by @mangomango — 2024-10-15T15:16:04Z

> [@anon80779245](#):
>
> For Spotify they will block you to login but not listen to music and you just have to login every few weeks. It will accept login only if you reset your passwords.

No. I had this clarified with the staff and it would loop to the next tune, only playing the music for a second or two. The staff confirmed it was caused by IVPN (and not AntiTracker).

Anyway, it was highly unusable for me. Too many blacklisted websites. And it also did not bypass streaming platforms blacklisting and it has a quite small network :confused: .  
I’d like to like to use IVPN but I can’t.

---

## Post 116 by @asanyan — 2024-10-16T13:10:35Z

> [@mangomango](#):
>
> Too many blacklisted websites. And it also did not bypass streaming platforms blacklisting

That’s a problem of the services that you use and not of the VPN provider. Unfortunate, sure, but not ivpn’s fault

---

## Post 117 by @anon48875053 — 2024-10-16T16:27:42Z

IVPN has 165 servers.

Mullvad has 665.

Proton VPN has almost 7000.

I wouldn’t say that this is completely not IVPN’s fault when they have a small amount of servers when compared to competition.

---

## Post 118 by @anon80779245 — 2024-10-17T10:49:52Z

> [@anon48875053](#):
>
> I wouldn’t say that this is completely not IVPN’s fault when they have a small amount of servers when compared to competition.

It is probably related to you client size, But it’s a cycle.

---

## Post 119 by @mangomango — 2024-10-20T19:13:29Z

Does Windscribe VPN meet our criterias ?

TLDR : They meet almost all of our criterias but there could be a problem with :

- Double-hop (to be specified).

- Public facing leadership. IMO it’s acceptable.

- DNT and analyticson the website. I think it’s ok too.

> **Technology**
>
> - :white_check_mark: Support for strong protocols such as WireGuard & OpenVPN.
> - They say they support strong protocols, including WireGuard and OpenVPN, on [Linux](https://windscribe.com/features/linux/?cpid=features&pcpid=features), [macOS](https://windscribe.com/features/macos/?cpid=features&pcpid=features), [Windows](https://windscribe.com/features/windows/?cpid=features&pcpid=features), [Android](https://windscribe.com/features/android/?cpid=features&pcpid=features) and [iOS](https://windscribe.com/features/ios/?cpid=features&pcpid=features).
> 
> - :white_check_mark: Killswitch built in to clients.
> - I think that their Firewall feature is what we are looking for. [source](https://windscribe.com/knowledge-base/articles/does-windscribe-have-a-killswitch/).
> 
> - :orange_circle: Multihop support.
> - They have multihop at the browser-level. [source](https://windscribe.com/knowledge-base/articles/what-is-a-double-hop-and-how-does-it-benefit-me/).
> 
> - :white_check_mark: If VPN clients are provided, they should be open source, like the VPN software they generally have built into them.
> - All their apps are open-source. [source.](https://github.com/windscribe)

> **Privacy**
>
> - :white_check_mark: Anonymous cryptocurrency **or** cash payment option.
> - They offer payment with Monero through CoinPayments. [source](https://discuss.privacyguides.net/t/opinions-on-windscribe-vpn/10644/98).
> 
> - :white_check_mark: No personal information required to register: Only username, password, and email at most.
> - They require a username and a password [source](https://windscribe.com/signup).

> **Security**
>
> - :white_check_mark: Strong Encryption Schemes: OpenVPN with SHA-256 authentication; RSA-2048 or better handshake; AES-256-GCM or AES-256-CBC data encryption.
> - They claim to use even stronger algorithms. [source](https://windscribe.com/knowledge-base/articles/what-kind-of-encryption-does-windscribe-use/).
> 
> #Encryption
> 
> OpenVPN  
> Our OpenVPN implementation uses the **AES-256-GCM cipher** with **SHA512 auth** and a **4096-bit RSA key**. **Perfect forward secrecy is also supported.**
> 
> Browser Extensions  
> We use TLS 1.3, ECDHE\_RSA with X25519 key exchange and the TLS\_AES\_256\_GCM\_SHA384 cipher.
> 
> IKEv2  
> Our in-app IKEv2 implementation utilizes AES-256-GCM for encryption, SHA-256 for integrity checks. Desktop and Android apps use ECP384 for Diffie-Hellman key negotiation (DH group 20), and iOS uses ECP521 for Diffie-Hellman key negotiation (DH group 21).
> 
> WireGuard®  
> WireGuard® is an opinionated protocol that uses ChaCha20 for symmetric encryption, authenticated with Poly1305; Curve25519 for ECDH; BLAKE2s for hashing and keyed hashing; SipHash24 for hashtable keys; and HKDF for key derivation.
> 
> - :white_check_mark: Forward Secrecy.
> - :white_check_mark:Published security audits from a reputable third-party firm.
> - [Here is](https://drive.google.com/file/d/1EgNETLVm2oZdGJXZJmFSCDc7Ib72LIOw/view) the 2024 retest from PacketLabs, after the 2022 penetration test report from Cure53 (which is also avalaible as a PDF).
> - Desktop apps audited in 2021 by Cure53. [source] ([Code Audit Report · Windscribe/Desktop-App Wiki · GitHub](https://github.com/Windscribe/Desktop-App/wiki/Code-Audit-Report)).
> - We’ve had an audit of our mobile apps as well" ([source](https://windscribe.com/knowledge-base/articles/has-windscribe-been-audited/)). Were can we find it @yegor ?

> **Trust**
>
> - :white_check_mark: Public-facing leadership or ownership.
> - Founders are named Yegor Sak ([LinkedIn](https://ca.linkedin.com/in/yegor-sak-725330b2), [Twitter](https://xcancel.com/yegor), [interview](https://blog.windscribe.com/who-is-yegor-sak/), [PrivacyGuides](https://discuss.privacyguides.net/u/yegor)), Alex Elisenko and Mark Ulicki.
> - “Since its inception in 2016, Windscribe has been and continues to be privately owned and operated. We have zero outside investors, and 100% of the equity is owned by the three founders Yegor Sak, Alex Paguis ([Linkedin](https://ca.linkedin.com/in/alex-paguis-53a21815?trk=org-employees)) and Mark Ulicki) and Windscribe employees.” [source](https://windscribe.com/knowledge-base/articles/who-owns-windscribe/).
> - “You can reach our CEO, co-founders, and staff directly through any of the channels listed above. We listen to every issue that our users have and engage in discussions on features, improvements, favorite snacks, you name it.” [source](https://windscribe.com/ethics)
> - There is the name of several employees on Windscribbles and we can find their social media.
> - Connie Lukawski (Backend Team Lead/Sr. Software Developer). [source](https://backlight.ca/) (There even is her CV).
> - Catt Garrod (software developer, frontend engineer). ([LinkedIn](https://ca.linkedin.com/in/catt-garrod)).
> - Ben Thornton (Content Lead). [LinkedIn](https://uk.linkedin.com/in/benjamin-thornton-7009a272).
> - Rebecca Rosenberg ([Marketing Team Member](https://ca.linkedin.com/in/rrosenbergpm)).
> - Daniel Sobey-Harker (Head of Community). [Twitter](https://xcancel.com/sobeyharker). [LinkedIn](https://www.linkedin.com/today/author/danielsobeyharker).
> - Johnny Mainframe,
> - Unni Menon,
> - Simon Phoenix
> 
> - We can see even more of their employees of LinkedIn.
> - Jaime Yu ([Senior Software Engineer](https://ca.linkedin.com/in/jaimeyu?trk=org-employees)).
> - Jess Malone ([Senior Software Engineer](https://ca.linkedin.com/in/jesse-malone-29970a14?trk=org-employees)).
> - Animesh Pal ([Senior Software Engineer](https://ca.linkedin.com/in/animeshpal?trk=org-employees)).
> 
> - They have blog posts where we can see their pets, their Spotify playlist, [the daily routine of Catt Garrod (frontend engineer)](https://blog.windscribe.com/day-in-the-life-of-a-windscribe-employee/), … :laughing::sweat_smile:
> 
> #The Cure53 audit also names precisely some 5 employees
> 
> “Cure53 would like to thank Yegor Sak, Alex Elisenko, Connie Lukawski, Konnor Klashinsky, Mark Ulicki, and all other participatory personnel from the Windscribe team for their excellent project coordination, support, and assistance, both before and during this assignment.”

> **Marketing**
>
> - :white_check_mark: Must self-host analytics. The provider’s site must also comply with DNT.
> - I don’t know how to check for DNT.
> - They claim “The Windscribe website does not contain any 3rd party analytics, tracking pixels, A/B test platforms, or social widgets.” [source.](https://windscribe.com/ethics)
> - Blacklight from the The MarkUp finds zero ad-tech companies of [windscribe.com](http://windscribe.com). However, the website tries to connect to [https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015](https://static.cloudflareinsights.com/beacon.min.js/vcd15cbe7772f49c399c6a5babf22c1241717689176015) and [https://stats.windscribe.com/piwik.js](https://stats.windscribe.com/piwik.js) .  
> ![Capture d’écran 2024-10-20 à 19.09.59](//forum-uploads.privacyguidesusercontent.com/original/2X/b/b02b0ecdb6d308b571a344385fd04f488e3676dc.png)
> 
> Must not have any marketing which is irresponsible:
> 
> - :white_check_mark: Making guarantees of protecting anonymity 100%.
> - “No Bull Poop. A VPN is not a magic privacy button powered by “military grade encryption”. A VPN alone will actually do very little for your privacy, and is just [one of several tools](https://blog.windscribe.com/how-to-actually-be-anonymous-online-801811b7088d/) that you should have in your toolbelt.“ [source.](https://windscribe.com/ethics)
> - “almost nothing can give you absolute anonymity online“. source : [Do VPN services offer true/absolute online anonymity?](https://windscribe.com/knowledge-base/articles/do-vpn-services-offer-true-absolute-online-anonymity/)
> 
> - :white_check_mark: Claim that a single circuit VPN is “more anonymous” than Tor, which is a circuit of three or more hops that regularly changes.
> - not aware of that. They also say “Here, at Windscribe, we’re not a fan of being misleading; many VPNs hype up their product and its capabilities beyond reality. “ [source](https://blog.windscribe.com/welcome-to-captains-club/).
> 
> - :white_check_mark: Use responsible language
> - “the amount of ways to hack a person far outweigh the protection a VPN offers you.“. source : [Will Windscribe protect me from Hackers?](https://windscribe.com/knowledge-base/articles/will-windscribe-protect-me-from-hackers/)

I have slightly edited the criterias for the sake of brevity.

---

## Post 120 by @anon80779245 — 2024-10-20T19:21:46Z

> [@mangomango](#):
>
> \*[You can reach our CEO, co-founders, and staff directly through any of the channels listed above. We listen to every issue that our users have and engage in discussions on features, improvements, favorite snacks, you name it.](https://windscribe.com/ethics)

Where is the list of all employees, or at least those with leadership positions? Mullvad has such a _[list](https://mullvad.net/en/about)_, Proton VPN doesn’t have a specific list, but [Proton AG does,](https://proton.me/about/team) which may or may not include Prton VPN employees.IVPN also has such a [list](https://www.ivpn.net/en/team/)

---

## Post 121 by @mangomango — 2024-10-20T19:32:40Z

> [@anon80779245](#):
>
> Where is the list

Did I say there was a list ?  
Thank you for the ressources you bring though.

---

## Post 122 by @faxe — 2024-10-20T19:34:23Z

From above Proton AG list:

> Laurent Fasnacht  
> Senior Engineering Manager  
> Laurent leads the Proton VPN research and development team.

edit: might also contain more people working on ProtonVPN but didn’t check further

---

## Post 123 by @anon80779245 — 2024-10-20T20:21:29Z

> [@mangomango](#):
>
> Did I say there was a list ?

You said the requirements for public-facing leadership or ownership is met. (You previously didn’t include the info about people in the blog). It seems pretty clear that for this requirement to be met, they would need to put in plaintext (other than a hard-to-find blog post) who their CEO and main execs are. @yegor could you put a page on your website (for example in about) with the main execs ? This is standard pracitice for other VPNs listed by us.

---

## Post 124 by @mangomango — 2024-10-20T20:25:53Z

I did not say the requirement was met wtf haha ??? calm down and don’t over-interprate what I say  
I only put this : “You can reach our CEO, co-founders, and staff directly through any of the channels listed above. We listen to every issue that our users have and engage in discussions on features, improvements, favorite snacks, you name it.”

But now yes I indeed changed the orange mark to green, after adding more infos.

---

## Post 125 by @anon80779245 — 2024-10-20T20:37:08Z

> [@mangomango](#):
>
> alm down and don’t over-interprate what I say

I am calm :grin:

> [@mangomango](#):
>
> I only put this : “You can reach our CEO, co-founders, and staff directly through any of the channels listed above. We listen to every issue that our users have and engage in discussions on features, improvements, favorite snacks, you name it.”
> 
> But now yes I indeed changed the orange mark to green, after adding more infos.

Yup, so initially you only had included this quote and put it in green meaning it is met (that’s how I interpret it)

---

## Post 126 by @mangomango — 2024-10-20T20:39:36Z

> I am calm :grin:

Nice to hear, same here.  
Let’s give up with this. I was doing a lot of edits and I initially did not put a green mark. Then I added more informations and put the green emoji.

Going forward, we have to decide if that is enough or not and we wait for yegor’s response.

---

## Post 127 by @anon80779245 — 2024-10-20T20:48:13Z

Yup let’s wait for his answer.

---

## Post 128 by @mangomango — 2024-10-21T00:44:06Z

Please note that I have added quite a lot of informations to my review of the compliance of Windscribe with the requirements.

---

## Post 129 by @mangomango — 2024-10-21T03:28:52Z

Why @ph00lt0 considered my tool suggestion as a double of this topic and deleted it ?  
Could the mods let us vote please ? It would make sense to talk about more than “opinions” here asked by OP, to speak about it being listed on PG.

---

## Post 130 by @ph00lt0 — 2024-10-21T08:18:08Z

because the OP of that was litterly just an opinion, there was no suggesting of adding it to the website either in the post. I suggest we wait on the answers on the **minimum** requirements and we can change this thread into a tool suggestion.

---

## Post 131 by @mangomango — 2024-10-24T04:21:24Z

> [@mangomango](#):
>
> I don’t know how to check for DNT.

Doesn’t someone know how to check for this ?

---

## Post 132 by @mangomango — 2024-10-24T04:25:30Z

> [@mangomango](#):
>
> It seems that they only support it for OpenVPN ? Is it normal ?

It seems normal since IVPN [says](https://www.ivpn.net/knowledgebase/privacy/does-ivpn-offer-perfect-forward-secrecy-pfs/) “Does IVPN offer Perfect Forward Secrecy (PFS)?  
Yes, our OpenVPN servers are configured to automatically generate new encryption keys every hour. If an adversary was able to crack the encryption key, they would only be able to decrypt the traffic captures since the last key rotation.”

So it seems that this feature is applicable only to OpenVPN so I will put a green mark to this criteria for Windscribe since they also support PFS for OpenVPN.

---

## Post 133 by @mangomango — 2024-10-24T18:12:02Z

The support told me :  
"Yes, all of Windscribe’s VPN protocols support Perfect Forward Secrecy (PFS). PFS ensures that even if one session key is compromised, it cannot be used to decrypt past or future sessions, providing an extra layer of security.

Windscribe doesn’t use any third-party trackers or analytics, which means it should respect the Do Not Track (DNT) settings in your browser. However, to verify if a website respects DNT, you can use browser extensions like “Privacy Badger” or “Disconnect.” These can provide insights into whether websites are tracking you.

Windscribe prides itself on minimizing third-party interactions to protect user privacy. The connection to Cloudflare Insights is part of our infrastructural security and performance management provided by Cloudflare. It’s primarily used to ensure the website’s stability and security, not for tracking or analytics in the traditional sense. We aim to keep our users informed and maintain trust by avoiding unnecessary tracking."

Hence, I put a green mark for the requirement about DNT and analytics.

Consequently, I think they meet all the criterias. We just have to decide if it is acceptable to support double-hop only at the browser level. But otherwise, they meet all the criterias.

Now do you authorize to suggest it as a tool recommendation ? @ph00lt0

---

## Post 134 by @8pen-s8urce — 2024-10-27T17:49:35Z

> **Off-topic corrections**
>
> At least two of those values are outdated. As of writing, the following are the correct values:
> 
> iVPN: I couldn’t find the total number of iVPN servers, only a [server status page](https://www.ivpn.net/en/status/) with a list of their servers and I don’t have the time to count them.
> 
> Mullvad: [647](https://mullvad.net/en/servers).
> 
> Proton VPN: [8633](https://protonvpn.com/vpn-servers) (only shows the amount of total Proton VPN servers with cookies and JavaScript enabled, at least to me when using Brave on Android).
> 
> You likely took that data from the [Techlore VPN toolkit](https://www.techlore.tech/vpn), it is outdated and I just made a [pull request](https://github.com/techlore/website/pull/137) and opened an [issue](https://github.com/techlore/website/issues/138) to update it on its GitHub project.

---

## Post 135 by @anon29374801 — 2024-10-30T17:09:48Z

I know there is now seeminly two Windscribe threads going but this felt more like a question to ask here…

Is [this](https://nyc1.lr.ggtyler.dev/r/Windscribe/comments/174wrjl/comment/k4cvrt2/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button) still an issue for using P2P with Windscribe port forwarding?

> If the government shows up and says, “who is using port xyz on this IP address?” it seems like windscribe must have a record to hand over (that will lead directly to the user), at least during those 7 days that the forwarding is active.

> If the port forward is active at the time of the request, yes we have this information (there is no way not to). If we lie, we go to jail.

---

## Post 136 by @mangomango — 2024-10-30T19:19:32Z

> [@anon29374801](#):
>
> Is [this](https://nyc1.lr.ggtyler.dev/r/Windscribe/comments/174wrjl/comment/k4cvrt2/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button) still an issue for using P2P with Windscribe port forwarding?

Following the answer, it seems it’s not an issue but the normal functioning of port forwarding.:person_shrugging:

---

## Post 137 by @anon29374801 — 2024-10-30T19:33:21Z

> [@mangomango](#):
>
> Following the answer, it seems it’s not an issue but the normal functioning of port forwarding.

Could just be my lack of understanding but it seems like, if you are personally identifiable for 7 days anytime port forwarding is active that would be an issue. Especially for users who are constantly forwarding a port to host a service.

Maybe this is true for all VPNs that allow port forwarding and I just did not realize it.

---

## Post 138 by @mangomango — 2024-11-03T15:43:54Z

[https://wellfound.com/company/windscribe/people](https://wellfound.com/company/windscribe/people)

They have a list of employees in LinkedIn and in Wellfound, the website they use for job offers.

---

## Post 139 by @anon80779245 — 2024-11-03T21:58:20Z

My point is that they should have everything on their website, otherwise who knows wheter it’s reliable.

---

## Post 140 by @mangomango — 2024-11-04T14:45:59Z

understandble.  
But in this case Wellfound seems very very reliable.  
In fact I wanted to share their [employee handbook.](https://handbook.windscribe.com/#desktop-applications) which is on Wellfound and I would recommend everyone interested or indeterminate about the company to read it, especially the About Us section.

> **They explain the meme thing there too.**
>
> ### The Windscribe Corporate Philosophy
> 
> 1. Create and release the best possible products that are reliable and easy to use
> 2. Do not lie, cheat, or make false promises
> 3. Provide our products and services for free to those that need it most and have the least
> 4. Offer fair prices to everyone else  
> **5. _AFTER_ keeping users safe and protecting their privacy, make them laugh**
> 
> There are only three things anyone should take seriously in life: their business, their relationships and their health. Apart from that, laugh as much as you can, and make others laugh as much as they can. We take our business very seriously, on all levels - technical especially - but we have the ability to have a lot of fun in the process. Our customer communications are very informal, because we treat our customers like our friends. We want them to have the best possible experience and to get the best possible value from our products - all while laughing their butts off. Life isn’t always fun, it isn’t always happy, but we will be damned if we don’t crack a joke or five in the face of it all.

---

## Post 141 by @yegor — 2024-11-04T19:30:05Z

Too many replies, didn’t read them all. Anyone need anything from me?

Re: Cloudflare pixel - this was auto-enabled by Cloudflare for some reason, it was disabled and no longer appears.

Re: New staff page - this is in the works part of our website overhaul. This page should be live before end of the year.

---

## Post 142 by @anon48875053 — 2024-11-04T19:42:08Z

The new thread for inclusion is here: [Windscribe](https://discuss.privacyguides.net/t/windscribe/21923)

---

## Post 143 by @mangomango — 2024-11-04T20:06:05Z

> [@yegor](#):
>
> Re: Cloudflare pixel - this was auto-enabled by Cloudflare for some reason, it was disabled and no longer appears.
> 
> Re: New staff page - this is in the works part of our website overhaul. This page should be live before end of the year.

Great ! Can’t wait for the new website and for FreshScribe to be fully launched. ^^

1. I guess we would need you to tell us if Windscribe respects DNT.
2. Why do [you plan to support multihop on desktop apps](https://github.com/Windscribe/Desktop-App/issues/189) but [not on mobile ones](https://github.com/Windscribe/Android-App/issues/36) ?
3. Can you confirm if PFS is applicable to all protocols or only OpenVPN ? If yes, do all our protocols support PFS ?
4. Do you plan to do new audits of your clients ? Support told me " [the 2022 audits](https://github.com/Windscribe/Android-App/files/11266292/Windscribe.Limited.-.2022.-.VPN.Source.Code.Review.Final.Report.pdf) are pretty much irrelevant at this time". The audit of the mobiles apps was very difficult to find.

---

## Post 144 by @yegor — 2024-11-04T20:24:19Z

1. I assume this relates to our website? If so, its 1st party tracking and its blocked by our browser extensions and when you sue ROBERT, but default. Details on what is “tracked” is in our privacy policy.

2. I’m not sure why the dev said that in the Android repo, support will be the same and identical in all apps. Reply updated.

3. Yes, they all do.

4. Audits are in the relevant project repos. We have another round scheduled in early 2025 after all the FreshScribe features are added to the clients.

---

## Post 145 by @anon80779245 — 2024-11-05T19:17:50Z

> [@yegor](#):
>
> Anyone need anything from me?

Yes. As I said previously, it would be nice if you **put the list of key executives, and if possible your employees** directly **on your website**. It is was reported that the list is available on internet, but having the list on your website would be an additional token of confidence.

---

## Post 146 by @anon29374801 — 2024-11-05T19:44:29Z

@yegor would you be able to provide some clarity on [this](https://nyc1.lr.ggtyler.dev/r/Windscribe/comments/174wrjl/comment/k4cvrt2/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button)?

> [@Opinions on Windscribe VPN?](https://discuss.privacyguides.net/t/opinions-on-windscribe-vpn/10644/135):
>
> I know there is now seeminly two Windscribe threads going but this felt more like a question to ask here… Is [this](https://nyc1.lr.ggtyler.dev/r/Windscribe/comments/174wrjl/comment/k4cvrt2/?utm_source=share&utm_medium=web3x&utm_name=web3xcss&utm_term=1&utm_content=share_button) still an issue for using P2P with Windscribe port forwarding? If the government shows up and says, “who is using port xyz on this IP address?” it seems like windscribe must have a record to hand over (that will lead directly to the user), at least during those 7 days that the forwarding is active. If the port forward is active at the time of the request, yes we have this inform…

---

## Post 147 by @mangomango — 2024-11-05T21:10:35Z

He already replied to this.

> [@Opinions on Windscribe VPN?](https://discuss.privacyguides.net/t/opinions-on-windscribe-vpn/10644/141):
>
> Too many replies, didn’t read them all. Anyone need anything from me? Re: Cloudflare pixel - this was auto-enabled by Cloudflare for some reason, it was disabled and no longer appears. Re: New staff page - this is in the works part of our website overhaul. This page should be live before end of the year.

---

## Post 148 by @yegor — 2024-11-05T21:15:41Z

Yes, this is still true, and it’s impossible to do it any other way because…computers.

If you have a unique anything (IP, port) that is only used by a single person, then there is a record somewhere. This record can exist on a single server, as a route or iptables entry in memory, or in a central database. It makes no difference as far as subpoenas are concerned.

Anyone who will tell you otherwise doesn’t know what they’re talking about, or lying.

---

## Post 149 by @anon80779245 — 2024-11-06T08:35:55Z

Ok sorry I didn’t see it.

---

## Post 162 by @mangomango — 2024-11-18T16:38:26Z

may be relevant for you @anon29374801 [Port Forwarding, Static IPs and Lies](https://windscribe.com/blog/port-forwarding-static-ips-and-lies-bcf427fdb283/)

---

## Post 163 by @anon29374801 — 2024-11-18T17:26:15Z

Thanks! This is super useful. I think what confused me and what confused the original Reddit poster was conflating statics IPs with dedicated IPs. It looks like Windscribe assigns a static IP to a small group (less then 10 according to the article).

My understanding is that this makes the “paper trail” of the user traffic from that static IP a bit less concerning since they may have logs of which users were assigned to that IP but would not be able to sort which person did what on that assigned IP out of the group. @yegor feel free to correct me if I misunderstood.

---

## Post 164 by @mangomango — 2025-03-16T11:22:26Z

> [@yegor](#):
>
> We have another round scheduled in early 2025 after all the FreshScribe features are added to the clients.

Hi, I am a bit impatient but how are you doing on the roll-out of your new stack called Freshscribe, and the audits ? I ask here because I don’t have Discord sorry.

---

## Post 165 by @mangomango — 2025-04-06T10:00:12Z

> [@mangomango](#):
>
> a decoy traffic feature on Android (like Mullvad)

The feature is now avalaible on macOS too. [since v2.14.10](https://windscribe.com/changelog/mac/)

---

## Post 169 by @iluvprivacy — 2025-09-19T01:19:31Z

As for Windscribe, what’s preventing them from being recommended by Privacy Guides?

Why should I consider Windscribe over Proton VPN when it comes to streaming? I mainly use services like YouTube TV, Hulu, Netflix, and the BBC iPlayer.

---

## Post 170 by @Bhaelros — 2025-09-19T06:12:28Z

WS seems to get less blocked by streaming services, except for Disney. They are blocking everything

---

## Post 171 by @BlackDog — 2025-09-26T20:43:05Z

Just a heads up if anyone was waiting for one of their cheap deals to try them out. There’s a “$39 yearly subscription sale” which has just gone live for Windscribe Pro. It’s a recurring offer, $39 every 12 months, unless you cancel it.

I’m not getting a referral fee for this, just passing it on in case anyone wants to take advantage of it! :grin:

More info [HERE](https://windscribe.com/upgrade?promo=IWANTP2P)

---

## Post 172 by @Confusing2348 — 2025-09-26T21:03:57Z

Thanks for the heads up. I was only looking for deals on them yesterday.

---

## Post 173 by @BlackDog — 2025-09-26T21:24:52Z

> [@Confusing2348](#):
>
> I found that their previous deals including the last one in April was $29 a month. I wonder if $39 is the new deal price or this is just a once off.

I think it might be their new price for deals. People were saying on the subreddit that they were going to have fewer sales in future and they seem to be tightening up on people taking the p1ss with their ‘unlimited device’ torrenting etc. Maybe the VPN market is becoming more competitive lately?

---

## Post 174 by @Regime6045 — 2025-10-01T13:30:18Z

> [@BlackDog](#):
>
> It’s a recurring offer, $39 every 12 months, unless you cancel it.

How long is this going to be offered? I still have 3 months on Mullvad but this is tempting!

---

## Post 175 by @OhNoes — 2026-01-29T13:08:00Z

Thought I would take them up on their 3 months offer together with [addy.io](http://addy.io), but then noticed they host their “jobs” section on [x.com](http://x.com). :poop:

---

## Post 176 by @cuyholc6857 — 2026-01-30T08:31:17Z

To recruit staff, you should of course post on mainstream websites. If you create an onion site using the Tor browser, will anyone see it? :joy:

---

## Post 177 by @Tech_User_Station — 2026-02-03T06:41:11Z

So Proton works with Disney and WS doesn’t? Or both don’t work with Disney? WS has static residential IP’s at an additional cost, would that work?

---

## Post 178 by @Bhaelros — 2026-02-03T07:23:26Z

Additional cost is 96 USD for residential IP. Proton Unlimited costs less. I have a long time discount from WS, paying only 19 USD per year. I have no intention to pay 96 USD for additional IP.

---

## Post 179 by @ramusica — 2026-02-06T07:46:58Z

Windscribe had one of their servers seized without a warrant by Dutch authorities. [https://x.com/windscribecom/status/2019529769008685438](https://x.com/windscribecom/status/2019529769008685438)  
 ![THIS IS NOT A DRILL: The Dutch authorities, without a warrant, just seized one of our VPN servers saying they](https://forum-uploads.privacyguidesusercontent.com/optimized/3X/d/b/dbea3fd6363ba3a0c4da13fe3980a7debf621b60_2_375x500.jpeg)

---

## Post 180 by @iluvprivacy — 2026-02-06T08:10:02Z

Since when did the Netherlands become a lawless country?!

---

## Post 181 by @fckCensorship — 2026-05-07T14:04:05Z

Windscribe: “no BS advertising”

Also Windscribe: [Best VPN for Public Wi-Fi Security | Windscribe](https://windscribe.com/vpn-service/public-wifi) (blatantly making the “public wifi is dangerous, if you use it you will get hacked” bullshit claim)

Yea nah I think I’ll pass

---

## Post 182 by @anonymous549 — 2026-05-07T15:15:44Z

Unless I am missing something

> Public Wi-Fi is a playground for cybercriminals. Whether you’re at a coffee shop, airport, or that sketchy hotel with “complimentary” internet, your data is at risk.

is not the same as

> [@fckCensorship](#):
>
> (blatantly making the “public wifi is dangerous, if you use it you will get hacked” bullshit claim)

I think its generally agreed upon that public wifi is a risk to your data. I don’t see much of an issue there.

I also think the “Tips to Stay Safe on Public Wi-Fi” provided are pretty common sense useful tips.

---

## Post 183 by @Shampoo — 2026-05-07T17:09:15Z

> [@fckCensorship](#):
>
> (blatantly making the “public wifi is dangerous, if you use it you will get hacked” bullshit claim)

That’s not a bullshit claim. You have no idea who’s in control of that network and what they’re doing with it. Research DNS poisoning and downgrade attacks. Here’s some articles to get you started.

> **[SSL Stripping Explained and How to Avoid It](https://www.cyberghostvpn.com/privacyhub/ssl-stripping-explained/)**
>
> Attackers use SSL stripping to downgrade HTTPS to HTTP to steal sensitive information. Click to know more about these attacks and how to protect yourself.

> **[Police allege 'evil twin' in-flight Wi-Fi used to steal info](https://www.theregister.com/security/2024/07/01/police-allege-evil-twin-in-flight-wi-fi-used-to-steal-info/423843)**
>
> Fasten your seat belts, secure your tray table, and try not to give away your passwords
