First off, I am not a user of their service so I have no understanding as to what happened with them. But the more we read the more controversial it has become. So I thought of asking you guys here about Kicksecure and therefore any dependencies relying on Mullvad.
Kicksecure includes their browser known as Mullvad Browser (among others) which itself is made by The Tor Project team. Do you see the reputation getting butchered here? I mean I really am not able to digest all these. I mean somebody early on even mentioned way back whether the Tor developers can trust Mullvad like that as they are supporting a for profit entity!
Found it here - [https://]forum[.]torproject[.]org/t/can-we-really-trust-mullvad-vpn-browser-like-tor-browser-no-disclosure-using-gmail-as-support-for-vpn-browser-extension-is-unnecessary-a-for-profit-model/12029
Please share your inputs. Should we support them and continue to include them or not?
This is the wrong forum. Kicksecure has a dedicated forum:
Kicksecure does not include any web browser by default, as there are various issues, controversies, etc., preventing any one web browser from being officially endorsed by or shipped with the project. See:
Instead, a number of popular browsers adhering to the (somewhat loose) criteria for inclusion in browser-choice are offered:
Individual end users are expected to decide for themselves which web browser they want to use based on whatever factors they consider worthwhile to consider. Browsers are presented in alphabetical order to avoid presentation order appearing biased.
I didn’t pay much attention earlier, so sorry for that mixed up.
I really am just stunned to see such development coming from them. On a more technical note, downloading the Mullvad Browser will automatically enable the option for users to fetch their VPN offering too, correct? And although by default the browser does not include the VPN, the DNS gateway (among other things), will ping to Mullvad back without user consent. This DNS servers run on a closed source system. No public information shared about them except for the block list seen on GitHub.
As I understand it, the ability to connect to Mullvad VPN is built into the browser itself, so in that case yes. (Edit: Apparently I was wrong here, see Patrick’s reply below.) All the browser-choice code does is enable Mullvad’s repository and install the browser, whether that allows installing other things or not depends on what Mullvad does. browser-choice has warnings in it that enabling a third-party apt repository has dangers.
I haven’t checked this claim, but yes, browsers often ping back to their creators, this is not a good thing but it’s not an avoidable thing for most existing well-maintained browsers.