“This has nothing to do with ProtonVPN” - really? The change would never have occurred if it wasn’t pointed out that ProtonVPN does not meet the criteria for recommendation. The change specifically accommodates ProtonVPN’s kill switch failure on macOS.
That’s great that you will prioritize investigating hardware solutions for kill switch, but please understand that this is not an option for everyone, and not everyone needs a 100% kill switch.
Yes, OS-level kill switches are not perfect. Yes, it is particularly difficult to make a kill switch work on macOS. But not everyone needs perfection.
As I keep stating, people have different threat levels - recommendations ought to account for this. Privacy Guides already lists “Best case” features for VPNs and amongst them you have:
Kill switch on all major platforms with highly configurable options (enable/disable on certain networks, on boot, etc.)
Great! So that is a “best case”, and hardware solutions can be recommended in the “best case”. What I am talking about, and what you keep ignoring, is that we should have reliable minimum criteria. Do you not think that at minimum the VPNs you recommend shouldn’t leak your IP during server switches?
That’s great that they are a lot better than many competitors, so are Mullvad and IVPN. Doesn’t mean you should carve out exceptions for them.
Now regarding “Apple’s recommended practices” - I already replied to you in the Remove ProtonVPN thread:
I can only say the same thing so many times, so I would encourage you to fully read the replies rather than skim through them.
I will however add, that when ProtonVPN initially launched their kill switch for macOS in 2019, they did so using Packet Filter (source), specifically because they knew that it could not work with Apple’s API:
Implementing a Kill Switch (as defined above) required us to work around certain limitations within Apple’s native VPN infrastructure, specifically that it does not allow an app to fully block network traffic outside of the VPN connection on an Apple device. To resolve this, we have created a helper application to generate a packet filter. Now, whenever you connect to a VPN server with Kill Switch enabled, the packet filter blocks all external network communications except for those routed through the VPN server you are currently connected to. Since all your network traffic is restricted to the VPN server, if connection to the VPN server is lost, all Internet traffic is stopped immediately and your data is never exposed. This workaround of Apple’s network stack allows us to achieve what was previously impossible on macOS.
The fact that people on reddit were complaining about this over a year before Apple’s guidance on Packet Filter came out demonstrates that following said guidance is not why their kill switch stopped working.
You just saw some Tech Note from Apple and decided that this is why they don’t use Packet FIlter. In reality, that’s just a handy excuse since they never invested enough engineering effort to ensure that it would work.
The other thing we’re also aware of, is tightening the criteria to the point where we only have one VPN provider really means we will have to remove the VPN section. As it is there are dangerously few decent VPN providers out there. We’d like to add more to the page.
This issue is specific to macOS. You can remove your recommendation for ProtonVPN on macOS and leave it for other platforms.