Apple Vision Pro finally gets a YouTube app today

Apple’s Vision Pro is a curious product — it initially wowed me two years ago, but it was hard to ignore that the visionOS platform felt incomplete without dedicated apps for YouTube and Netflix. Well, it seems that Google has finally decided to take the Vision Pro seriously, as it’s launching a YouTube app on the platform today. Previously, you could only view YouTube videos via Safari, or through third-party apps like Tubular Pro.

According to an Apple representative, the YouTube Vision Pro app features every video on on the service, including shorts, 360, 3D and VR 180 content. I haven’t tried it myself yet, but it certainly couldn’t be worse than trying to navigate through YouTube’s desktop app via finger gestures. Now that Google is spinning up its Android XR ecosystem, the company probably couldn’t avoid the Vision Pro for long. And don’t forget, we may also see a cheaper Vision Air next year.

Your move, Netflix.

This article originally appeared on Engadget at https://www.engadget.com/ar-vr/apple-vision-pro-finally-gets-a-youtube-app-today-170000886.html?src=rss

NVIDIA’s GeForce Now app lands on Amazon Fire TV sticks

NVIDIA's cloud gaming service, GeForce Now, has expanded to another platform. Starting today, folks with select Amazon Fire TV sticks can install a native GeForce Now app. While it was already possible to access GeForce Now through the Fire TV platform, you won't necessarily need to sideload an Android app to do so anymore.

At the outset, the new app is compatible with the second-gen Fire TV Stick 4K Plus and second-gen Fire TV Stick 4K Max (running Fire OS 8.1.6.0 and later). It also works with the original Fire TV Stick 4K Max if you're running Fire OS 7.7.1.1 or later. 

On the Fire TV platform, GeForce Now streaming quality tops out at a resolution of 1080p and a frame rate of 60 fps, with SDR visuals, H.264 video encoding and stereo audio. So you won't necessarily get the best GeForce Now experience here as the service has support for up to 5K resolution and up to 360 fps, along with HDR10 and 7.1 audio at the highest tier. But it's not a bad option if you already have the right hardware. You'll need a controller too, of course.

NVIDIA announced the GeForce Now app for Fire TV during CES last month. It joins other cloud gaming services on the Fire TV platform, including Xbox Cloud Gaming (PC Game Pass titles are available on GeForce Now as well) and Amazon's own Luna.

This article originally appeared on Engadget at https://www.engadget.com/gaming/nvidias-geforce-now-app-lands-on-amazon-fire-tv-sticks-140000516.html?src=rss

WhatsApp is now fully blocked in Russia

After warnings from lawmakers last year, WhatsApp has been blocked in Russia for as many as 100 million users, the Financial Times reported. Russian authorities removed the app from an online directory, effectively wiping it from Russia's internet. The government has previously said that it wants users to switch to an app called Max, an unencrypted WeChat clone. 

"Today the Russian government has attempted to fully block WhatsApp in an effort to drive users to a state-owned surveillance app," Meta told the FT in a statement. "Trying to isolate over 100 million people from private and secure communication is a backwards step and can only lead to less safety for people in Russia."

The Russian government deleted WhatsApp rival Telegram yesterday, while also erasing Meta apps Facebook and Instagram. YouTube access was also reportedly degraded, though it's not clear if the app has been completely removed. 

In July 2025, a Russian lawmaker who regulates the IT industry said it's very likely that WhatsApp would be placed on a list of restricted software. Parent Meta has been designated as an extremist organization in Russia, and last year Vladimir Putin issued a directive for the nation to further restrict communication apps originating from "unfriendly countries" that have sanctioned Russia. 

The state has said that an in-house app would protect citizens from fraud and terrorism, given the large number of scammers on WhatsApp in the nation. However, restrictions on Telegram haven't gone over well domestically, even among Putin's allies, as residents along Ukraine's borders have relied on it for drone and missile alerts. "I am concerned that slowing Telegram could affect the flow of information, if the situation deteriorates," said the governor of one of those regions.  

This article originally appeared on Engadget at https://www.engadget.com/social-media/whatsapp-is-now-fully-blocked-in-russia-110953485.html?src=rss

TikTok US launches a local feed that leverages a user’s exact location

TikTok US just launched a local feed for users to "get the inside scoop on must-try restaurants, shops, museums and events." This is done by leveraging the exact location of people that are using the app and comes after a change in the platform's terms of service that says the app can do just that. The platform's terms of service used to note that it could collect approximate locations, but the sale to US investors looks to have changed that to precise locations.

This is an opt-in feature, despite the app potentially collecting this data whether the feed is activated or not. The feed is set to "off" by default, but can be changed via a trip to settings.

The local feed doesn't show your neighbors or people you might vibe with to help solve that pesky loneliness epidemic. Instead, it prioritizes local businesses and will highlight nearby events, shopping suggestions and restaurants to try.

The feed.
TikTok

This looks to be part of a broader push to attract small businesses to the app, both as content producers and as advertisers. As TechCrunch notes, this could also help insulate the company from future regulation and increased scrutiny, as it could point to the many small businesses that rely on its services. 

TikTok states that over 7.5 million businesses use the platform in the US to reach customers. However, this data is sourced from an Oxford Economics report from before a group of investors finalized a deal for the US version of the app.

Supporting local businesses is a noble goal, but users will have to consider whether or not the value of a dedicated feed is worth the privacy risk. Oracle is a prominent investor in the new American TikTok, and company founder Larry Ellison once said "citizens will be on their best behavior" when they are being constantly surveilled.

This local feed isn't exactly a new idea. TikTok has been trying something similar in Europe since the tail-end of last year. It has shown up in the UK, France, Italy and Germany.

This article originally appeared on Engadget at https://www.engadget.com/big-tech/tiktok-us-launches-a-local-feed-that-leverages-a-users-exact-location-170651916.html?src=rss

Mullvad VPN review: Near-total privacy with a few sacrifices

Mullvad, a virtual private network (VPN) named after the Swedish word for "mole," is often recognized as one of the best VPNs for privacy. I put it on my best VPN list for exactly that reason. I've got huge respect for the extra lengths Mullvad goes to in order to ensure its user's privacy.

To give you a preview, Mullvad is one of the few VPNs — other than my normal privacy recommendation, Proton VPN — that lets users pay entirely in cash. But even Proton VPN asks for an email address to make an account and uses a few marketing cookies on its own website. Mullvad represents every account as a randomly generated 16-digit code and uses no marketing cookies whatsoever.

That's just one example of how Mullvad goes beyond the call of duty to keep users private. But while privacy is the most important aspect of a VPN alongside security, it's not the only thing that matters. For this review, I set out to investigate whether Mullvad pairs its rights-protecting bonafides with versatile, convenient and enjoyable VPN apps. Using our rigorous VPN testing procedure, I'll rate Mullvad in 11 areas. You can find a summary of my results in the table below, skip to the sections that matter most to you or just read my final advice in the conclusion.

Editor's note (2/11/26): We've overhauled our VPN coverage to provide more detailed, actionable buying advice. Going forward, we'll continue to update both our best VPN list and individual reviews (like this one) as circumstances change. Most recently, we added official scores to all of our VPN reviews. Check out how we test VPNs to learn more about the new standards we're using.

Category

Notes

Installation and UI

All apps share roughly the same user interface

Apps are responsive and easy to navigate, with no design choices that would threaten beginners

Lack of "fastest server" button is an issue

Browser extension is only available on Firefox and still in beta

Speed

Reasonably good average latency

Reduces download speeds by 26 percent and upload speeds by 17 percent

Speed declines are consistent and chartable

All speed metrics are quite good on nearby servers

Security

Only uses WireGuard protocol

No IP address leaks, even when switching servers

Packet test showed successful encryption

Pricing

Always costs 5 Euro per month, though prices outside Europe depend on exchange rates

No auto-renewal — membership lasts until money runs out

Can pay using cash or by purchasing scratch-off vouchers on Amazon

14 day money-back guarantee, except on cash payments

Bundles

Only app besides the VPN is the free Mullvad Browser, which removes the tracking habits of typical web browsers

Allows several smaller VPNs to use its servers in their networks

Privacy policy

No vague lines or loopholes in privacy policy

Only saves account numbers and expiration dates for each user

Uses an extremely limited range of cookies with no marketing trackers

Has undergone a total of 17 audits of different aspects of its service

Swedish police demanded customer information in 2023; Mullvad couldn't comply because the data wasn't logged

Virtual location change

Unblocked Netflix 13 out of 15 times

When it failed, virtual location was still changed

Server network

90 locations in 50 countries, majority in North America and Europe

No virtual servers whatsoever

Features

DAITA conceals traffic patterns that might let an AI identify what sites you visit

Uses quantum-resistant encryption on WireGuard

Can choose your own multihop entry and exit points

Several options for getting around nation-level firewalls

Can block ads, trackers, malware and other unwanted content using predetermined DNS block lists

Supports IPv6 traffic

Kill switch and stronger lockdown mode

Split tunneling by app

Customer support

Help center includes useful filters to find the topic

Well-written articles with good internal linking

No live chat support, but staff answers emails quickly

Can view app logs at any time

Background check

Founded in 2009 in Sweden; still owned and operated by initial founders

User account numbers were exposed in a 2023 incident, but Mullvad quickly closed the leak

Let's start by examining how Mullvad feels as a piece of software. In this section, I'll be testing its desktop apps for Windows and Mac, its mobile apps for Android and iOS and its browser extension for Firefox. To start with the installation process, Mullvad downloads and installs in a snap on mobile. On desktop, installation requires a few more steps than is typical, but the app guides you quickly through everything.

Across the board, my only serious complaint is that there's no option for automatically choosing the fastest server. You can usually assume that the nearest one to you will be the fastest, but there's always the chance of an unusual server overload. It's a bizarre oversight for an app that otherwise goes out of its way to be usable.

Mullvad's Windows app has a slim UI that uses space efficiently without being too cramped. It doesn't give you a lot of information, such as live speed tests or data in transit, but I've mostly found that to be needless filler on VPN apps.

Mullvad on Windows.
Mullvad on Windows.
Sam Chapman for Engadget

Speaking of needless filler, the map may be a little bigger than it needs to be, but maps on VPN clients aren't just about teaching you geography — they do a lot to make the apps more welcoming to casual users who might not otherwise fire up security software. In fact, Mullvad's UI is admirably beginner-friendly, befitting its focus on privacy for everybody rather than just the tech-savvy.

All the settings are accessed by clicking the gear in the top-right. Here, you can turn on DAITA (Mullvad's defense against AI traffic scanning), activate multihop and control Mullvad's other features. There are also some quality-of-life features for the UI itself, such as whether it remains pinned to the taskbar or operates as a standalone window. Some options, especially under the VPN settings tab, are a bit technical, but don't need to be touched for a good experience.

Mullvad's macOS app is quite similar to its Windows app, both in terms of the interface and the features offered. The big difference used to be that macOS lacked split tunneling, but that's been added in a recent update. The only serious distinction now is that the Mac client can't be unpinned from the taskbar, which is just a little bothersome.

Mullvad on Mac.
Mullvad on Mac.
Sam Chapman for Engadget

Other than that, you'll find every setting you need under the gear, just like on Windows. Similarly, connections to VPN servers happen quickly, and selecting locations from the menu is very straightforward. While connected on either app, you can click the circular arrow by your location to swap to another server in the same location — highly convenient if you're trying to unblock Netflix.

Mullvad's Android app has the same nearly-perfect design approach as all its other apps. The main page has nothing on it but the connect/disconnect button, the choice of server locations, a map and the buttons for your account information and preferences. Those preferences are a manageable set of options that are almost all managed with simple on-off switches. It's all highly responsive and annoyance-free.

Mullvad on Android.
Mullvad on Android.
Sam Chapman for Engadget

Mullvad's iOS app looks very similar to its apps on every other platform. The front page is kept simple, with large controls in the foreground and a map taking up most of the space. Everything else is located in the menu accessed through the gear icon at top right. Neither mobile app has the options for toggling the UI itself that the desktop apps have, but it's mostly free of quality-of-life problems to start with.

Mullvad on iPhone.
Mullvad on iPhone.
Sam Chapman for Engadget

Mullvad's browser extension is only compatible with Firefox. You can't actually connect to the VPN through this extension. Its main functions are to tell you whether you're connected to a Mullvad server and to connect to a SOCKS5 proxy in a Mullvad location. If you do this while connected to Mullvad through the desktop app, you'll get a second layer of protection, similar to the multi-hop feature.

The Firefox extension is a rare misfire for Mullvad — perhaps fair, since it's still in beta. Its only real feature is something that the desktop app already does perfectly well, and it looks like a software malfunction to boot. However, given Mullvad's track record, I'm confident they'll figure out what to do with it in time.

A VPN almost always slows browsing speeds and increases latencies. It's unavoidable, given the extra steps a VPN protocol adds to the process of getting online. The trick is to find VPNs that keep the slowdown to a minimum, using a combination of regular maintenance, good planning and smart load balancing.

For this test, I used speedtest.net to check how six of Mullvad's server locations influenced three key speed metrics. Ping measures latency, the time in milliseconds (ms) that one data packet needs to travel between a client device and an ISP. Download speed measures the amount of data in Megabits that a web browser can download in one second. Upload speed tracks how much data can be uploaded in a second. We're looking for low latencies and high download and upload speeds.

Server location

Ping (ms)

Increase factor

Download speed (Mbps)

Percentage drop

Upload speed (Mbps)

Percentage drop

Portland, USA (unprotected)

15

58.96

5.85

Seattle, USA (fastest location)

23

1.5x

55.07

6.6

5.51

5.8

Montreal, Canada

165

11.0x

44.28

24.9

4.62

21.0

Fortaleza, Brazil

307

20.5x

40.96

30.5

4.65

20.5

Prague, Czechia

368

24.5x

43.17

26.8

5.47

6.5

Lagos, Nigeria

528

35.2x

37.41

36.6

4.61

21.2

Bangkok, Thailand

473

31.5x

39.76

32.6

4.13

29.4

Average

311

20.7x

43.44

26.3

4.83

17.4

I'll start with the bad news: the tests didn't exactly make Mullvad look like a speed demon. Its speeds have gone up and down in the years I've been using it, and right now they appear to be on the downswing. If you use locations all around Mullvad's server network, you can expect your download speeds to decrease by about 26 percent and your upload speeds to decline by 17 percent.

However, it's important to put those numbers in perspective. First, Mullvad's numbers aren't markedly worse than the ones I got when testing CyberGhost. Its speeds are average, but by definition, most things are average. Its average worldwide latency is actually better than Surfshark, the current champion of download and upload speeds.

Speed-testing a Mullvad server in Los Angeles.
Speed-testing a Mullvad server in Los Angeles.
Sam Chapman for Engadget

It's also nice that Mullvad's speed drops follow a predictable curve. Lots of VPNs have unexpectedly sharp declines in certain locations, frequently in Africa. By contrast, Mullvad's speed decreases pretty much as a direct function of how far from the server you are. This not only makes speed drops easier to plan around, but also means you can expect very good speeds on nearby servers.

This property of being fastest on servers near the user is another sign of Mullvad's focus on its core privacy mission. If anonymity is your main reason for using a VPN, it doesn't matter what your IP address is, so long as it's not your real one. Using a nearby Mullvad server should guarantee you an internet connection that's both fast and private.

To be secure, a VPN has to check two critical boxes. It must provide you with a secondary IP address without leaking your real one, and it must encrypt your communications with its servers so your activity can't be traced. In the sections below, I'll see whether Mullvad meets those requirements.

VPNs use protocols to mediate between end devices, ISPs and their own servers. The first step is to ensure that the service you're considering uses protocols that have expert confidence. Mullvad has kindly made this step easy for me by using only WireGuard on all its apps, with no OpenVPN, IKEv2 or in-house unique protocols.

There's no question that WireGuard is a solid protocol. It uses the ChaCha20 stream cipher for symmetric encryption and Poly1305 for authentication, both uncrackable with current technology. Mullvad has even added its own fix for WireGuard's one flaw, its need to save static IP addresses — the Mullvad implementation is set up to delete the IP address if it goes 10 minutes without being used.

Even so, it's unfortunate to lose the ability to change protocols, which is one of the most common steps for troubleshooting a VPN connection. I understand Mullvad's reasoning for cutting out OpenVPN (it claims the cryptography isn't strong enough) but don't agree. It's one of this provider's few unforced errors.

There's a straightforward test to determine if your VPN is leaking. Load up any website that shows your IP address — I personally use ipleak.net — and see what IP and location it reveals without your VPN active. Then activate the VPN and refresh the page. If you see your real IP address anywhere, your VPN is leaking.

Testing Mullvad for IP leaks.
Testing Mullvad for IP leaks.
Sam Chapman for Engadget

I ran that test on five Mullvad servers. Each time, the website showed me the IP address of the VPN server, concealing my real one. To keep things simple, I ran the initial tests with IPv6 blocked via the Mullvad client. When I turned it on and tried again, the IPv6 traffic didn't leak any more than the IPv4 did. I also saw no signs of WebRTC leaks. Unless you set up a custom DNS server, Mullvad also uses its own DNS, which remains entirely within the VPN tunnel.

I had one more leak test to try. Frequently, VPNs are leak-proof when maintaining a connection to one server but drop encryption when switching between servers. That problem is why I ultimately couldn't recommend Norton VPN. Luckily for me, Mullvad has a button that lets you shuffle to another server in the same location, so I used that to see if it stayed leak-proof.

Mullvad doesn't leak your IP even while changing servers.
Mullvad doesn't leak your IP even while changing servers.
Sam Chapman for Engadget

As you can see in the screenshot, Mullvad jumped seamlessly from one server to another without showing my real location in-between. On a practical level, that's enough for me to declare Mullvad leak-proof.

For one final experiment, I used the WireShark packet sniffer to see whether the data Mullvad sent from my computer to my ISP was encrypted. After capturing a few packets, I was gratified to see that they were totally unreadable to interlopers. Most established VPNs pass this test, but it's still important for due diligence.

Mullvad's pricing structure is one of the most unusual things about it. This is normally the section where I untangle 47 different Pro+ and Business- accounts that are all sold at three different durations. Mullvad couldn't be further from that. It costs 5 Euro a month — that’s it. Each 5-Euro subscription can be used on five devices at once.

It manages payments through a system inspired by parking meters. When you sign up for Mullvad, you'll buy as much time as you want. That time will count down until it expires, unless you top it up with more 5-Euro payments. If you run out of money, Mullvad won't charge you a new subscription fee because you didn't tell it not to. It'll just stop working until you pay again. Every payment also comes with a 14-day money-back guarantee, except for payments made in cash.

The Mullvad account dashboard.
The Mullvad account dashboard.
Sam Chapman for Engadget

The only real complexity in the process is that Mullvad always figures out its prices in Euro, so outside the EU, the cost per month is affected by exchange rates. If you happen to live in a country where the government's economic policy shuttles between capricious and arbitrary, you might want to grab a few months in advance.

The other most interesting thing about Mullvad's pricing is the options you can use to pay. For maximum privacy, you can pay with cash using the payment token you'll find on your account page. Note that this is not the same as your account number. To find it, log into your dashboard on Mullvad.net, click Add time to your account in the left-hand bar, then click the button labeled Cash and scroll down. Make your cash payment by writing the token on an envelope and mailing it to Sweden (full instructions here).

Unredacted, in case any hackers out there want to buy me some more time.
Unredacted, in case any hackers out there want to buy me some more time.
Sam Chapman for Engadget

You can also get untraceable Mullvad vouchers by paying cash at participating retail locations. Most of them are in Europe, but you can order them from Amazon. While your payment to Amazon won't be private, the voucher can't be linked directly to your VPN account, since the actual number is hidden behind a scratch-off panel. It's actually pretty ingenious.

Of course, you can also pay using any of the normal methods, including credit cards, cryptocurrency and bank wires (though not PayPal). But the more private methods are always there for people who need them.

Mullvad is that rare VPN that's still content to be a VPN and not an all-inclusive security suite. No shade to NordVPN or Surfshark, whose extra features are generally quite good, but it's nice to see at least one of the top providers staying focused.

Although Mullvad doesn't have any partners that sell their products alongside its VPN, it does have several partnerships with other VPNs who use its network as the basis for their own products. MalwareBytes Privacy VPN, Mozilla VPN, Tailscale and Obscura can all be considered Mullvad side apps if you squint.

Mullvad's only product other than the VPN is Mullvad Browser, which is free to download and works on Windows, macOS and Linux. Mullvad Browser works in the background, blocking common methods of browser fingerprinting that can be used to deduce your identity even when you have a VPN running.

For example, it automatically reports your time zone as UTC, disguises personal preferences like font and window size, scrambles information sent by APIs and conceals your browser version and computer operating system. It's also in private mode by default, which doesn't hide what your ISP sees but is useful for concealing your activity from other people that might use your computer.

Since privacy is Mullvad's main selling point, this section is even more important than usual. Loopholes in the privacy policy of the privacy VPN would be deeply ironic. Fortunately, Mullvad's privacy policy backs up its high-flying rhetoric. It's a short, pointed and readable document with no problems I could discern. Mullvad has no parent company or subsidiary it might use as a loophole, and no clauses in its policy are left open to interpretation. It's a masterpiece of the privacy-policy genre.

The document is actually three policies: a privacy policy, a no-logging policy and a cookie policy. The privacy policy lists all the times Mullvad might collect data about a user. That's exactly two situations — using financial information to process payments (which will be entirely anonymous if you use cash or a voucher) and using your email address to track support tickets you open. That's it.

The no-logging policy is a bit longer, but mostly because it's explaining exactly how Mullvad manages to run a VPN service with so little information on individual users. For each account, it stores a number and an expiration date, plus public keys and tunnel addresses if you're using WireGuard (deleted at most 10 minutes after your session ends). Everything else is completely anonymized. Mullvad even claims that its 500,000 or so user accounts could have been created by the same user 500,000 times, which I suppose is one way to spend 2.5 million Euro.

The cookie policy is the shortest because Mullvad uses exactly five cookies. One saves your login status in your browser, one saves your language preferences, one protects its site from being used in a specific kind of forgery hack and the other two are for handling Stripe payments.

Mullvad corroborates its privacy policy with regular audits of various aspects of its service. Currently, there are 17 audits listed on its website, including four infrastructure audits by Cure53. All of its apps have been separately audited and found to be solid. It has been a couple of years since the last full infrastructure audit in 2024, but given how many other targeted reviews Mullvad has gone through since then, it's hard to be too upset about the pause.

In 2023, Mullvad achieved the holy grail of VPN privacy: being ordered by subpoena to turn over customer information and not being able to comply because that information didn't exist. Nothing compares to a VPN's privacy being tested in the wild like this.

Sometimes, a VPN appears to be working, but still reveals your real location to websites. Netflix is a useful proxy for this. To unblock a streaming site like Netflix, a VPN needs to change your virtual location while not appearing to do so — if Netflix sees any hint of VPN traffic, you'll get blocked with the hated proxy error. I used five different locations to check whether Mullvad is up to the streaming task.

Server location

Unblocked Netflix?

Changed content?

Vancouver, Canada

3/3

3/3

Gothenberg, Sweden

2/3

2/3

Istanbul, Turkey

3/3

3/3

Johannesburg, South Africa

3/3

3/3

Singapore, Singapore

2/3

2/3

Mullvad did well for streaming, but it didn't manage a perfect score like its fellow anti-establishment VPN Windscribe did. Two of the 15 servers I tested failed to unblock Netflix, one in Singapore and one in Mullvad's hometown of Gothenburg. I also had trouble logging into Netflix while connected to a Vancouver server, though that server did unblock the site consistently once I got inside.

Mullvad's servers all tricked Netflix into believing my new location.
Mullvad's servers all tricked Netflix into believing my new location.
Sam Chapman for Engadget

In Mullvad's defense, no location failed more than once. It's completely possible to get good streaming performance out of this VPN; you just have to be willing to click the server refresh button a few times. Privacy is still the main use case for Mullvad, but it's fine for streaming too.

Mullvad has 90 server locations in 50 countries and territories. Unusually for a VPN, users can choose between all 590 of its total servers, including several in each location. There's even a list on its website that shows you the status of every server.

Mullvad does not use virtual server locations, so every server is physically located in the place where it claims to be. Here's how they're distributed.

Region

Countries with servers

Total server locations

North America

3

25

South America

5

6

Europe

29

41

Africa

2

2

Middle East

2

2

Asia

7

8

Oceania

2

6

Total

50

90

Over half the countries with servers are in Europe and over two-thirds of the cities with servers are in either Europe or North America. That lopsided network is a limitation of Mullvad's refusal to use virtual server locations, since its real servers have to be concentrated in nations developed enough to host data centers. With an all-real network, it's easier to tell which servers will give you the fastest performance, but you can't simulate as much of the world as you can with larger services like ExpressVPN.

The good news is that there's at least two real server locations on every continent. Mullvad has a surprisingly robust presence in South America and two bare-metal servers in Africa, which is more than some other VPNs have. In the end, though, the best application of Mullvad is to protect the online privacy of users in North America, Europe and eastern Asia.

Most of Mullvad's features are augmentations to the VPN itself, rather than side options that do other things. Some of them are bread-and-butter, like the kill switch and split tunneling, but a few you won't find anywhere else. Note beforehand that Mullvad does not support port forwarding, so if you depend on that for your torrenting, try another VPN.

Mullvad's most novel feature is a recent one. DAITA, which stands for Defense against AI-guided Traffic Analysis, can be toggled on and off in the Mullvad app. According to Mullvad, certain patterns in how browsers communicate with websites can be analyzed by AI to reveal the truth behind encrypted internet history. DAITA hides those packets by filling communications with background noise so the AI won't know what's real.

Mullvad's anti-AI settings.
Mullvad's anti-AI settings.
Sam Chapman for Engadget

DAITA is a laudably forward-looking feature, but as Mullvad itself admits, it will make your browsing speeds slower and drain your battery. I recommend only using it for activities you really want to hide.

Mullvad's desktop apps establish quantum-proof WireGuard tunnels by default. Quantum computing isn't yet a threat to WireGuard, but it may become dangerous in the future, so Mullvad is getting ahead of the problem (along with a few other services like NordVPN). When quantum resistance is active, Mullvad encapsulates its keys using the current standard mechanism, ML-KEM.

If you find yourself in a country where government censorship makes it hard to access the internet, Mullvad has options that might help. These anti-censorship features can be used to get around firewalls that block visible VPN traffic. You have several options, including changing your WireGuard port, randomizing your port number, disguising your VPN traffic as an ordinary HTTPS connection or using an obfuscated Shadowsocks proxy.

Mullvad's anti-censorship involves more features than most VPNs have in this area. This makes it a bit less user-friendly, but a lot more likely to work. If you're new to getting around censorship, Mullvad's help center has a helpful page about using its anti-censor settings.

Many VPNs offer a double-hop connection that routes your traffic through two servers instead of one, adding a redundant layer of encryption in case one server malfunctions. Mullvad pulls ahead of the competition (except Surfshark, which also does this) by allowing you to choose your entry and exit servers. When you activate the multihop option and open the server list, you'll be prompted to pick two locations instead of one.

Mullvad's server list with multihop enabled.
Mullvad's server list with multihop enabled.
Sam Chapman for Engadget

This means you can select an entry server that's close to you and an exit server in any country whose location you want to spoof, letting you fine-tune your own performance. It's way nicer than being railroaded into certain paths.

Mullvad includes six blocklists that can keep you or your family members from looking at unwanted content: ads, trackers, malware, gambling, adult content and social media. These lists can't be customized like Windscribe's R.O.B.E.R.T. blocks can, so you're limited to just turning them on and off.

The internet is gradually transitioning from the old IPv4 standard over to IPv6, which will allow many more addresses to be shared out. Mullvad is one of a few VPNs looking ahead to the IPv6 era. You can leave it to block all IPv6 traffic, but if you do need IPv6 for any reason, you can enable it while still being connected to a Mullvad server.

Mullvad comes with two features that protect against unexpectedly losing your VPN defenses. The first is a kill switch, a common VPN option that cuts off internet access if the VPN tunnel ever fails. This simple measure helps guard against accidental leaks.

Lockdown mode is the stronger option. While it's active, you will be unable to get on the internet unless you connect to a Mullvad server first. This will remain true if you turn the connection off yourself and even if you quit the app.

Split tunneling is available on Mullvad's apps for every system except iOS. It lets you send some apps outside the VPN tunnel so they get online with your normal IP address. It's helpful if you have some apps that don't work with the VPN active — this is common with online banking, as an example. Another common application is to protect a torrenting client in the background while using your browser unprotected for better speeds.

Mullvad makes two forms of support available in the app. You can report a problem by going to Settings -> Support -> Report a problem, typing your question (requested to be in either English or Swedish, though they'd probably be able to read a question run through Google Translate) and optionally providing your email. You can also view the app's logs at any time, which can be useful to help a technician diagnose your problem.

If you'd rather search for a solution at your own pace, you can go to that same page and click FAQs and Guides instead. This opens the help center in a browser.

Mullvad's help center, including the dropdown filter menus.
Mullvad's help center, including the dropdown filter menus.
Sam Chapman for Engadget

I love Mullvad's approach to laying out its FAQs. Instead of crowding topics into five or six categories and making you guess whether your problem falls under setup, usage or troubleshooting, Mullvad gives you a set of dropdown filters to narrow down the articles which might relate to your problem.

By the time you've named which device, OS and protocol you're dealing with, you won’t have many articles left to sift through. There is an annoying tendency for certain sets of filters to reduce the number of surfaced links to zero, but for those cases, there's a search bar that also works well.

The articles themselves are good enough that I referred to them several times while writing this review. Some of them are a bit overlong, but they're diligent about including both internal and external links to get you where you're going fast.

This is normally where I cover how it feels to get live chat support from the VPN I'm reviewing. However, Mullvad doesn't have live chat support. That's unfortunate, although it's still better than Windscribe's approach of forcing you to banter with a sarcastic robot. Instead, I sent a question via email to Mullvad's support team, and got a response within 24 hours.

Mullvad was founded in 2009 in Sweden. It's still owned and operated by its original founders. According to a detailed timeline on its website, its 16-year history has been as uneventful as any user could ask for, with not much changing except updates to stay on the technological leading edge. The only controversy mentioned in Mullvad's own materials is the 2023 police raid of its headquarters, which (as I covered in the privacy section) only makes them look better.

So as not to take Mullvad at its word, I scoured the last 16 years of news items and user reports to search for any other blemishes on its record. Based on that research, I found no reason to doubt Mullvad's honesty about its location, owners or team.

I found just one leak that wasn't noted on Mullvad's own site. In 2023, a security research group called ZATAZ alleged that it found anonymized information on Mullvad users saved on an Internet Archive page, including account numbers (linked article is in French). According to ZATAZ, Mullvad contacted the Archive and got the page deleted.

To my mind, the only mistake Mullvad made in response to the ZATAZ allegations was not making a public statement about the incident. I can see why they didn't think it was a big deal, since even logging into someone else's Mullvad account wouldn't show you their browsing history, but it's always better to communicate about these things.

Mullvad is a VPN that knows what it wants to be and achieves that goal with flying colors. It's not trying to be an everything app — it does privacy and does it well. That's not to say it has nothing going on outside the VPN itself, as its DNS blockers, AI defenses and split tunneling all work smoothly. But if you want a VPN that's not ashamed to be a VPN, Mullvad is the right choice.

Of course, it has its own compromises. It's solidly in the middle of the speed pack and occasionally trips up when unblocking streaming sites. The lack of any protocols other than WireGuard grates on me a bit, since it reduces the user's options for troubleshooting. With all that said, those are minor hiccups on a VPN that does such a thorough job keeping you anonymous online.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/vpn/mullvad-vpn-review-near-total-privacy-with-a-few-sacrifices-130000056.html?src=rss

Facebook is offering Meta AI-powered animations for profile photos

Meta has been going all in on AI, whether people want it or not, and now it's bringing more features in that vein to Facebook. The network's latest move is to let people use Meta AI to animate their profile photos. Because what better way to express your individuality than to use a pre-canned AI-generated animation on your own face?

Meta AI is also coming for your Facebook Stories and Memories. The network's Restyle lets you use gen-AI to change up the aesthetic of your posts. You can once again use pre-canned stylings or give the AI assistant your own prompt.

In the company's own words, the new tools that will create "share-worthy moments that spark meaningful interactions and conversations with friends." I guess meaning is in the eye of the beholder. If you're desperate to behold even more AI slop, Meta recently said its Vibes feed of exactly that content will be getting a standalone app.

This article originally appeared on Engadget at https://www.engadget.com/social-media/facebook-is-offering-meta-ai-powered-animations-for-profile-photos-201022506.html?src=rss

Google’s new tool helps you remove non-consensual explicit images from Search

The internet is ripe with horrible violations of people's privacy, including non-consensual explicit images. A new tool from Google won't do much in the way of prevention, but can help you remove this media from Search. 

Now, you can choose an image and quickly request its deletion. Just click on the three dots that appear on the image. From there, choose "remove result" and then "It shows a sexual image of me." Other choices include the picture shows a person under 18 and that it has your personal information. If you choose the initial option then you will also be asked whether it contains a real image or deepfake. There's also an option to submit multiple photos at once. 

Google claims that, upon submitting your request, you will "immediately" see links to emotional and legal support organizations. Plus, you can opt-in to safeguards that filter out similar results in Search — though it seems these unreported images will still be available for other users to see. This feature should be available in most countries over the coming days. 

You can go on Google's "Results about you" hub to track your request. To use the tool, you will have to add in your personal contact information and government ID numbers. Google already had the hub to track if any of that information appears on Search, but now it will also look for your social security number, drivers license and passport information. The company should notify you if any of that information comes up in Search results and allow you to take removal steps. 

Results about you's updates should roll out to US users in the coming days. Notably, it arrives as Google shutters its dark web reports. They would alert you if your name, number, or email address appeared on the internet — typically because of a data breach. However, Google found it didn't help users take next steps to fix the problem, something these new features will hopefully do. 

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/googles-new-tool-helps-you-remove-non-consensual-explicit-images-from-search-155352248.html?src=rss

UK takes ‘light touch’ approach to regulating Apple and Google’s app stores

Last year the UK declared that Apple and Google were a duopoly with "strategic market status" in the mobile platforms market, making them subject to special regulations. However, the UK's Competition and Markets Authority (CMA) will not regulate Google and Apple's app stores like the EU has done. Rather, government plans to enforce its own digital markets rules in a "pragmatic" way by accepting "commitments" from Apple and Google in areas like app rankings, the CMA announced

Google and Apple agreed to work with the CMA to address concerns on the following matters: app review, app ranking, use of data and interoperability process. Effectively, regulators require the tech giants to treat developers fairly, particularly when they compete against Google and Apple's own apps. However, the UK's rules are more like suggestions and "not legally binding in any case," former CMA director Tom Smith told the Financial Times.

This is in stark contrast to Europe's Digital Markets Act, which forced Apple to make changes to open up iOS features and data to rivals, allow app installations from outside its Store and reduce fees collected on purchases. 

That could change if the companies fail to comply with its measures, though. The CMA plans to check metrics like the number of apps approved or rejected, app review times and developer complaints received. New requirements could then be brought forward if deemed necessary. "For example, if we find Apple is routinely declining interoperability requests without good reason... we could bring forward specific interoperability requirements. Non-compliance would also mean we would be unlikely to consider commitments as a similar approach in [the] future."

Google said in a blog today that it "welcomed the opportunity to resolve the CMA's concerns collaboratively." Apple, meanwhile, seemed similarly pleased with the deal. "The commitments announced today allow Apple to continue advancing important privacy and security innovations for users and great opportunities for developers,” an Apple spokesperson told Bloomberg.

The UK is possibly taking a light touch on app store rules to avoid antagonizing the Trump administration. Earlier today, French President Emmanuel Macron predicted that the US could go after the EU on areas like data privacy, digital taxation and the plan of multiple EU countries to ban children from social media. "The US will, in the coming months — that’s certain — attack us over digital regulation," Macron said at a special summit yesterday. 

This article originally appeared on Engadget at https://www.engadget.com/big-tech/uk-takes-light-touch-approach-to-regulating-apple-and-googles-app-stores-131119575.html?src=rss

Apple will reportedly allow third-party AI assistants in CarPlay

Apple plans to allow third-party voice-controlled AI apps in CarPlay, Bloomberg reports. Siri is the default voice assistant for things like controlling music and looking up directions, but future AI apps in CarPlay could handle the complicated, open-ended requests Siri can't answer.

The expanded support would let developers like OpenAI or Google offer versions of their ChatGPT and Gemini apps for CarPlay. Similar functionality is possible just by connecting a smartphone to a car over Bluetooth and using an AI app's voice mode, but CarPlay support would presumably make the process a little more seamless. 

Not so seamless that it replaces Siri, however. Bloomberg writes that these third-party apps won't be able to replace the Siri button in the CarPlay interface or use their own wake words ("Hey Google," etc.). Instead, anyone who wants to spend a long drive talking to Gemini will have to open the app first. That could cut down on the utility of using one of these apps, but Apple presumably wants to get Siri to a place where CarPlay users prefer it as their in-car assistant anyway.

Apple and Google recently announced that Gemini would power future versions of Siri and Apple Foundation Models, the AI models underpinning Apple Intelligence. The delayed, updated version of Siri Apple introduced alongside Apple Intelligence in 2024 is supposed to be able to take actions on user's behalf, work across apps and understand the context of what's on screen, all things Gemini can currently do. Reports suggest Apple wants to eventually use Google's Gemini models to transform Siri into a proper conversational chatbot, too. That future version of the voice assistant could be right at home in CarPlay.

This article originally appeared on Engadget at https://www.engadget.com/transportation/apple-will-reportedly-allow-third-party-ai-assistants-in-carplay-213432646.html?src=rss

NordVPN review 2025: Innovative features, a few missteps

When we say that NordVPN is a good VPN that's not quite great, it's important to put that in perspective. Building a good VPN is hard, as evidenced by all the shovelware VPNs flooding the market. NordVPN may not be perfect, but it's easily top-five caliber and excels in certain use cases.

First, the bad: NordVPN's apps could all stand to undergo a little more quality control, with elements distracting from other elements and inconsistent designs from platform to platform. At least one of its FAQ pages directly contradicts itself. And while all the server locations could unblock Netflix, the one in Nigeria still showed U.S. content, indicating that our real location might have leaked.

However, there's a lot of good to balance that out. Speeds are fantastic and we saw no other hint of any kind of leak. Its server network is expansive and not overly reliant on virtual locations. The vast majority of servers are ideal for unblocking foreign websites. The real draw, though, is the extra features, including the innovative and flexible Meshnet, plus a malware blocker that acts more like a full antivirus and forward-looking quantum resistant encryption.

Editor's note (9/24/25): We've overhauled our VPN coverage to provide more detailed, actionable buying advice. Going forward, we'll continue to update both our best VPN list and individual reviews (like this one) as circumstances change. Most recently, we added official scores to all of our VPN reviews. Check out how we test VPNs to learn more about the new standards we're using.

Check out a summary of our NordVPN review in the table below.

Category

Notes

Installation and UI

Connections happen quickly and features are easy to use on all platforms

UI sometimes gets in the way; map screens can be clunky and apps come with unnecessary notifications

Surprisingly, the best UI may be in the browser extension

Speed

Extremely fast download speeds with only a 6.4-percent average drop

Good latencies on nearby servers, but farther ones have some lag

Fast upload speeds, but losses spiked in a few locations

Security

Uses acceptable protocols with uncracked encryption

NordWhisper obfuscated protocol recently implemented on Windows, Android and Linux

No DNS, WebRTC or IPv6 leaks on five test servers

Pricing

Best plan is the 2-year Basic for $81.36, or $3.39 per month

Basic gives you the complete VPN

If you get a multi-year plan, be sure to manually renew in order to keep the promotional rates

Bundles

Plus tier adds advanced malware protection and NordPass password manager

Complete plan adds NordLocker cloud storage

Prime tier adds ID theft protection and insurance features

Privacy policy

NordVPN does not log user activity on the VPN, a policy backed up by several third-party audits

However, it does log potentially identifiable device information unless you opt out in settings

Some concerning liberties taken in the overall Nord policy, but no documented malfeasance

Virtual location change

Four out of five test servers unblocked Netflix three times running, including virtual India location

Location in Nigeria got into Netflix, but didn't change available titles

Server network

153 server locations in 117 countries and territories

Server network is about 40 percent virtual, including all locations in Africa

Features

Extra servers grant additional privacy (double VPN, Onion over VPN, obfuscation) or specific optimizations (P2P, dedicated IP)

Threat Protection blocks dangerous domains and the Pro upgrade has some antivirus capability

Dark Web Monitor reports to you when any sensitive information has appeared on clandestine leak sites

Presets let you activate several settings with one click

Post-quantum encryption is nice, but not necessary yet

Kill switch is a useful safety feature on all apps

Split tunneling by app on Windows and Android, and by URL on browser extensions

Customer support

Written FAQs, live chat and email support

Live chat connected to an expert human within a minute

FAQs are poorly organized and contain some conflicts, but well-written on average

Background check

NordVPN is headquartered in Panama, while its parent company Nord Security is based in the Netherlands

2018 theft of public keys was a mistake, but NordVPN did almost everything right in response

Claims of law enforcement collaboration are overblown — NordVPN will comply with requests, but that doesn't mean they'll have information to provide

NordVPN's biggest strengths are its speeds and the range of options it puts at your fingertips. User experience is important, but it's not quite as front-and-center as it is with ExpressVPN and Proton VPN. Here's how the apps run on all the major platforms.

The Windows app is the first instance of NordVPN's UI being not bad enough to complain about, but not good enough to be considered excellent. The initial connection process is a little slow, and it's far easier to connect than it is to disconnect (click the power button while connected to shut the VPN off). The map takes up space that would have been better allocated to the server list.

NordVPN Windows app
Sam Chapman for Engadget

The minor problems continue in the settings list, which makes the mistake of not keeping all its tabs visible in the window — if you open one, you have to click back to the main menu to reach another page. The pages themselves are easy to use; it's just a bit clunkier than it could have been.

Setup is swift and easy on Mac, but the full NordVPN interface is a little awkward. The vast majority of the main window is taken up by a large map, which is mostly useless. There's no way to zoom out to see the whole world, and you can't choose between servers in each country unless you zoom way in. The server list on the left-hand side is almost always more useful.

NordVPN macOS app
Sam Chapman for Engadget

The preferences panel is better. All the tabs come with clear explanations of their function, and are laid out so the menu is always visible, unlike the Windows app. The gear icon at the bottom includes its own set of tabs that encompass most of the common functions, including changing your VPN protocol, activating the kill switch and setting the VPN to automatically connect on untrusted networks.

NordVPN on mobile can be described in much the same way as its desktop apps: generally great, occasionally getting in its own way. On Android, the map screen is much more helpful. It's expandable to the entire world and allows you to choose between servers within a country. On the other hand, the important settings are buried in the Profile tab, and the app notifies you about your "security score" to pressure you into activating certain settings.

NordVPN Android UI
Sam Chapman for Engadget

To find the general settings page on Android, tap the bottom-right Profile tab and scroll down. Except for Threat Protection, which has its own tab on the main window, every feature is located here. It's probably necessary to keep the main app from getting cluttered, but still mildly frustrating.

The NordVPN iOS app resembles a compressed version of the macOS client, for better or worse. As with Android, most of its features are in the bottom-right Profile tab. It works well most of the time, but often feels slightly cumbersome. There's a bit too much on the screen, and a bit too much of the stuff has nothing to do with the VPN's core function.

NordVPN iOS app
Sam Chapman for Engadget

As an example, you can't log into your account within the app — you have to load your Nord account page in a web browser. Forced app switching is a design choice that truly needs to die. That said, VPN connections happen quickly. If you tend to simply leave your VPN active, you probably won't notice any of this stuff.

Most VPN browser extensions consist of the same features on a smaller scale, and NordVPN's — on Chrome, Firefox and Edge — are no exception. They are important for one reason, though: they're the only way to split tunnels by URL and the only split tunneling at all on macOS and iOS. Despite being more compact, they're also easy to use, making for an excellent quick-start VPN solution.

NordVPN Browser Extension
Sam Chapman for Engadget

All VPNs slow down your average browsing speeds by adding extra steps into the connection process. When we test speed, we're looking for the VPN to drag as little as possible on your unprotected speeds. Download speed will be the most important stat for most users, since that determines how fast web pages load and how quickly videos can buffer.

Latency is important for live connections like video chats, games and live streaming. Latency increases with distance — in the test below, data packets were sent to the remote server, then back to our home network. Upload speeds likewise influence your live two-way communications and are also vital for torrenting. Let's see how NordVPN performs on all three metrics.

Server location Latency (ms) Increase factor Download speed (Mbps) Percentage drop Upload speed (Mbps) Percentage drop
Unprotected (Portland, OR, USA) 22 -- 59.20 -- 5.86 --
Seattle, WA, USA (Fastest) 44 2x 57.21 3.4 5.62 4.1
New York, NY, USA 177 8x 56.90 3.9 5.60 4.4
Stockholm, Sweden 371 16.9x 55.94 5.5 5.63 3.9
Istanbul, Turkey 411 18.7x 53.02 10.4 5.78 5.9
Hong Kong 350 15.9x 56.18 5.1 5.72 2.4
Johannesburg, South Africa 602 27.4x 53.26 10.0 5.67 3.3
Average 326 14.8x 55.42 6.4 5.54 4.0

To summarize: NordVPN's download speeds are the fastest we've seen and its upload speeds and latency tie with the best. Downloads only dropped by an average of 6.4 percent across the globe and readings were mostly consistent — the servers in question performed much the same in each test. We even threw in Turkey and South Africa, two locations that commonly cause problems, but NordVPN still kept the drop to 10 percent.

NordVPN speed test
Sam Chapman for Engadget

Latency is more a product of physical distance than VPN infrastructure, but you can still see differences between services. When tested on a similar range of locations, ExpressVPN and Proton VPN both kept average latencies under 300 ms. NordVPN's average came out to 326 milliseconds, though we should note that its latency increased less than Proton's on the closest server.

Upload speeds declined an average of four percent, but there were a few anomalously high readings in Istanbul that skewed those numbers up. Without that location, NordVPN's upload rates would also have been the industry's current best.

No matter how well-built a VPN looks from the outside, there are several ways its security can fail. The most common problems are outdated protocols with weak encryption, failing to block IPv6 traffic or inadvertent leaks from sending DNS requests outside the encrypted tunnel. We'll start by looking for those common leak sources, then check whether NordVPN's encryption might be failing in less traceable ways.

A VPN protocol is a set of rules used to get data quickly and safely from your device to a VPN server and back, even while that data is encrypted. Different protocols are connected with different encryption algorithms and can impact the speed, security and stability of your connection.

When testing VPN security, the first step is to see if it's using any protocols like PPTP that are outdated and crackable, or homebrewed protocols with unclear security. NordVPN users have four options for protocols: OpenVPN, IKEv2 (not available on Mac or iOS), NordLynx and NordWhisper (available on Windows, Android and Linux only). 

NordVPN protocol selection
Sam Chapman for Engadget

OpenVPN and IKEv2 are both standard protocols you'll find on most VPN providers. Both use various strengths of the Advanced Encryption Standard (AES), with OpenVPN defaulting to AES-256 and IKEv2 to AES-128. OpenVPN can be set to UDP (faster but less stable) or TCP (more reliable but slower). So far, so secure.

NordLynx is unique to NordVPN, but it's not that far off the beaten track — it's just WireGuard with extra security. WireGuard normally works by saving a stable IP address for each connection, which raises the very slight risk of exposing a user. NordLynx adds a second layer of abstraction that means those stable addresses are never revealed. Since NordVPN strongly recommends it for most situations, we used it for all our tests in this review.

Finally, there's NordWhisper, a new protocol introduced in early 2025 that disguises your VPN traffic as normal web traffic to evade blanket web blocks. It's likely to be slower than the other protocols, so don't use it unless everything else has been blocked. We also don't recommend counting on it too much in general — large-scale censorship technology, like the Great Firewall of China, tends to rely on blocklists of known VPN servers, whose identity NordWhisper can't disguise.

Our first order of business was to check five test servers to see if they leaked our real IP address — staying away from the ones in the speed test in order to get as comprehensive a picture of NordVPN's security as possible. With help from ipleak.net, we found all five to be free of the three major types of leaks.

  • DNS leaks occur when a VPN sends DNS requests (in short, how your browser knows which websites to show you) outside its encrypted tunnel. By default, NordVPN uses its own private DNS servers, which our tests showed to effectively prevent leaks.

  • WebRTC leaks are caused by real-time communication protocols sending information outside the VPN, which may reveal your real IP address. NordVPN is consistently successful at keeping WebRTC inside the tunnel, but you can have your browser block it if you're still worried.

  • IPv6 leaks happen when a VPN only blocks IPv4 traffic and lets v6 through. NordVPN automatically blocks IPv6 traffic while it's active, so an IPv6 leak is all but impossible.

NordVPN leak test
Sam Chapman for Engadget

Although that's all great news, it is still possible for leaks to occur without a clear explanation, so we ran one final test on NordVPN.

Wireshark is a program that captures detailed images of information sent over a device's internet connection. Even though our tests showed NordVPN to be free of leaks, we wanted to inspect it at the most granular level. Using WireShark, we recorded the traffic sent to an unencrypted HTTP site, before and after connecting to each NordVPN test server.

Every server showed the same pattern: readable plaintext before, encrypted ciphertext after. If there is a security flaw remaining in NordVPN, it's unlikely to be relevant to the overwhelming majority of users.

NordVPN's pricing structure looks convoluted at first, but it's much simpler than it appears. A Basic subscription gets you full VPN functionality, and all the other tiers just add more features. If all you need is a VPN, you only need to concern yourself with the left side of the table below.

The best deal for a Basic NordVPN subscription, which lets you connect to NordVPN with up to 10 devices at once, costs $81.36 for two years when you pay upfront ($3.39 per month). One year of the same plan costs $59.88 in advance ($4.99 per month) or $12.99 for one month at a time. The table below shows the complete cost; for more information on plans above Basic, see "side apps and bundles" in the next section.

Plan 1-month cost 1-year cost 2-year cost
Basic $12.99 $59.88 ($4.99/month) $81.36 ($3.39/month)
Plus $13.99 $71.88 ($5.99/month) $105.36 ($4.39/month)
Complete $14.99 $83.88 ($6.99/month) $129.36 ($5.39/month)
Prime $17.99 $107.88 ($8.99/month) $177.36 ($7.39/month)

The longer plans save money, but be careful: if you let them expire, you'll automatically renew at the more expensive one-year plan. Enough customers claim to have been auto-renewed at the higher rate that they've launched a class-action lawsuit against NordVPN, accusing the company of deceptive pricing practices and making renewals too difficult to cancel. A NordVPN PR rep said they could not comment on ongoing legal action, "other than to state that we are and always have been very clear about the recurring nature of our services." No court date has been set so far.

That said, there's a fairly straightforward workaround in the meantime: To prevent the auto renewal, log out of your NordVPN account, then sign up for a discounted plan again using the same email. As long as you do this before your subscription expires, your new account should link to your old one, keeping you subscribed at the introductory rate.

Every NordVPN plan comes with a 30-day money-back guarantee. If you cancel and request a refund before 30 days are up, you'll get the full cost back. The only way to try it for free without paying is to get the app on Android, where there's a seven-day trial through the Google Play Store.

NordVPN is part of a larger family of Nord Security products, which you can save money on if you need more than one. We won't review all of them here, but for reference, here's everything you'll get from the higher subscription tiers. 

  • Basic: VPN on 10 devices, specialty servers, DNS ad-blocking, Meshnet

  • Plus: All Basic features, plus malware scanning, extra scam blocking, tracker blocking, NordPass password manager, data breach scanner

  • Complete: All Plus features, along with 1TB of NordLocker encrypted cloud storage

  • Prime: All Complete features, plus NordProtect features like dark web monitoring, credit monitoring, ID theft insurance and extortion insurance

Another tier called Ultra includes a subscription to Incogni, a data removal service run by Nord's partner Surfshark. The Ultra bundle is only available in certain countries, since NordVPN is still testing it; users outside the test countries can still add Incogni service at checkout. There also used to be a NordVPN family plan, but it seems to have been eliminated after Nord expanded the devices per subscription to 10.

You can get a dedicated IP address on NordVPN to ensure you have the same IP every time you connect. This lets you configure remote firewalls to let you through while you're connected to the VPN. A dedicated IP costs $8.99 per month, $70.68 for a year ($5.89 per month) or $100.56 for two years ($4.19 per month).

The NordVPN pricing page lists access to a Saily eSIM plan as a perk, though mysteriously, none of the existing plans seem to include it yet. A lot of VPNs are expanding into the eSIM space, so this may change soon.

A VPN privacy policy isn't just empty words — it's a contract between the provider and its users. If a service openly defied its own policy, it could be sued for false advertising. VPNs tend to sneak loopholes into their privacy policies instead of flouting them outright; these loopholes can shed light on how the provider actually views your privacy.

We combed through NordVPN's privacy policy to see whether it tries to take any such liberties. The policy has two parts: the general Nord Security policy and an addendum specific to NordVPN.

This policy applies to all Nord Security apps. It's impossible to create an account without a valid email address, but you can use a separate email masking service to make that anonymous. The policy also explicitly says that your email address will be added to a marketing mailing list, though you can opt out. Irritating, but not a privacy risk in itself.

We're more concerned about the later statement that it may process data without the user's consent "under the legal basis of our or third parties' legitimate interest." This clause covers some cases we'd agree are legitimate, such as identifying people who launch cyberattacks from NordVPN servers. But Nord also considers it "legitimate interest" to process your personal data "to improve or maintain our services and provide new products and features."

Reached for comment, a NordVPN representative said that using personal data in this way "generally involves aggregated, depersonalized or technical information." That's somewhat reassuring, but the "generally" leaves a bit too much wiggle room. Ideally, we'd prefer that personal data exist wholly in the "consent only" section.

The section on sharing your data with third parties only lists "some of" the service providers who may receive your information. Among these are Google Analytics, which is known to store personal data on U.S. servers — all of which are potential security risks in the age of DOGE. Other unnamed "third parties" are involved in targeting ads at users of Nord websites.

The NordVPN representative said that "since some partners, such as payment processors, can vary by region or specific service and may change over time depending on our operational needs, we do not publish a fixed list." They added that all third parties are "contractually required to handle personal data in accordance with applicable laws and industry standards."

We aren't using this to condemn Nord; many of these practices are fairly standard in the VPN industry. But it's important to know about all the potential leakage points before trusting your deepest secrets to any company.

The NordVPN privacy policy doesn't add much atop the general Nord notice. It does track session activity connected to your username to make sure you're staying within the 10-device limit, but it automatically deletes these logs 15 minutes after you disconnect. The logs also don't include your IP address or the addresses of VPN servers you used.

NordVPN turn off analytics
Sam Chapman for Engadget

The only real problem we found is that NordVPN apps collect information about your activity on the app by default. This doesn't include information about your browsing habits, but it does include unique traits that could conceivably be used for "device fingerprinting" — in which a third party can deduce a user's identity through clues about their device. You can turn this off in the General settings.

A NordVPN spokesperson told us that the data collected is "not personally identifiable," and that the company takes "deliberate steps to strip out anything that could be linked back to a specific person." This presumably means the data is aggregated so it only shows general trends, not any one device's activity. That's a lot less risky, but we still recommend switching the setting off.

NordVPN has passed five independent audits of its privacy policy so far, most recently from Deloitte in late 2024. Annoyingly, you can only read the entire report by logging into a Nord account, but it at least doesn't have to be a paid account.

The audit found that NordVPN was following its own no-logs policy. Specifically, the Deloitte Lithuania investigators concluded that "the configuration of IT systems and management of the supporting IT operations is properly prepared, in all material respects in accordance with the NordVPN's description set out in the Appendix I." (Appendix I of the report is identical to NordVPN's privacy policy.)

You'll be most interested in this section if you mainly use a VPN to change their location for streaming. To see if NordVPN could unlock new streaming libraries, we picked a new batch of five test servers, then logged onto Netflix. Since Netflix tries to block all VPN servers to prevent copyright issues, our first question was whether we'd get through at all.

Our second question: would connecting to a NordVPN server actually change what Netflix library we saw? It should, given that NordVPN seems leak-proof, but thoroughness demands we check anyway. Here's what we found.

Server location Netflix unblocked? Content changed?
Canada Yes Yes
Argentina Yes Yes
Germany Yes Yes
India Yes Yes
Nigeria Yes No

Four out of five locations worked perfectly. On a Canadian server, we were able to stream Star Trek: The Next Generation, which left American Netflix years ago. The Argentine server gave us access to something called Pasion de Gavilanes, which we'd never heard of but sounds great.

NordVPN Canadian Netflix
Sam Chapman for Engadget

The only problem was Nigeria. We tested it several times, connected to multiple different Nigerian locations, but saw our American Netflix library every time. We then ran a leak test on Nigeria, which wasn't one of our security test locations, and found it to be working normally. It's hard to say what happened, especially since the Nigeria server doesn't appear to be virtual, but we can confirm that it wasn't working.

NordVPN has servers in 153 cities in 117 countries. Out of all total options, 62 are virtual locations (about 40 percent), where the server is really located somewhere else. This makes it possible to get servers into more places, but depending on your actual location relative to the server, it may perform differently than you expect.

NordVPN Western US servers
Sam Chapman for Engadget

Virtual locations have allowed NordVPN's server network to grow quite extensive, with lots more locations in South America, Africa and Asia than the industry standard. Check out the distribution in the table.

Region Countries and territories with servers Total server locations Total virtual server locations
North America 15 36 12
South America 10 10 6
Europe 48 57 11
Africa 10 10 10
Middle East 7 7 4
Asia 24 26 18
Oceania 3 7 1
Total 117 153 62 (40.5 percent)

The relatively low proportion of virtual locations (nearly identical to that of ExpressVPN) is a good sign, as it means NordVPN has been growing its server network thoughtfully. Some VPNs — looking at you, HMA — inflate their server lists as a marketing point without seriously considering what it takes to maintain such a large network. That thankfully doesn't seem to be the case here.

Here's everything you get with a NordVPN app other than the VPN itself. There's a lot going on here, so we'll limit ourselves to a sketch of each feature.

As soon as you load NordVPN, you'll see a list of special servers near the top of the right-hand column. We'll go over each of them in order.

  • Dedicated IP: As discussed in the bundles section, a dedicated IP address costs extra. With this, you'll always connect with the same IP, which is private to you alone. It may be worth the price if you find yourself getting asked for CAPTCHAs a lot more while connected to NordVPN — though for what it's worth, that didn't happen to us.

  • Double VPN: This sends your connection through a second VPN server before it reaches your ISP. The second server is your apparent location. There are 10 endpoints to choose from. As you might imagine, your internet will run slower with two VPN servers in the mix, so only use this if you seriously need security.

  • Obfuscated servers: These are only available on OpenVPN. Obfuscation can help you get around firewalls that seek out and block VPN traffic. If you can't get online with NordVPN when you're on a certain network, obfuscated servers might work.

  • Onion Over VPN: After encrypting your data as normal, these servers send it through several nodes of the Tor network, granting you the total anonymity of onion routing while keeping you safe from malicious relays. It's available in two locations, Netherlands and Switzerland, and — like double VPN — is best used only when you need the utmost privacy.

  • P2P: NordVPN only allows torrenting on its peer-to-peer servers, but fortunately, it's got P2P servers in 114 countries — only three fewer than it has in total. NordVPN keeps your download and upload speeds very fast on average, so you shouldn't have trouble torrenting from any location.

Meshnet is NordVPN's most unique and exciting feature by a long shot. By logging into the same NordVPN account on multiple devices, you can connect those devices directly through a NordLynx tunnel without needing a NordVPN server in between.

NordVPN Meshnet
Sam Chapman for Engadget

Essentially, you're using your own devices as VPN servers — obviously not great for privacy, but amazing for accessing web services in other countries. While two devices are connected, you can transfer files between them through the NordLynx tunnel. You can even invite friends and use their devices.

NordVPN has two levels of antivirus: Threat Protection and Threat Protection Pro. The former is a simple DNS filter that stops your browsing from loading unsafe web pages while NordVPN is active. It's the highest level available on Android, iOS and Linux, or on any Basic subscription.

NordVPN Threat Protection
Sam Chapman for Engadget

Threat Protection Pro, which Plus subscribers or higher can set up on Windows and Mac, can work even when you aren't connected to a NordVPN server. It acts more like a standalone antivirus by scanning downloaded files for malware, and can even block trackers. Basic Threat Protection (without Pro) can block some trackers by filtering out domains known to use them, but doesn't block the trackers directly.

While active, Dark Web Monitor continually searches known data breach dump sites on the dark web and notifies you if it ever finds your account email address. If you get that notification, change any passwords associated with the address. With a Prime subscription, you can also have it search for your phone number, social security number or other financial information.

Presets let you set up one-click VPN connections with a desired group of settings, a lot like Proton VPN's Profiles. NordVPN comes pre-loaded with presets that optimize for "Downloads," "Speed" and "Browsing," which sounds to us like the same thing three times.

More usefully, you can create presets for particular countries, then add website shortcuts that will appear once you've connected. You could, for example, set one that connects to a specific location, then add a shortcut to a streaming site available in that location.

Post-Quantum encryption

Experts widely believe that quantum computers will eventually make our current encryption algorithms obsolete, but there's almost no consensus on when that will actually happen — except that it hasn't happened yet. Knowing that, NordVPN's "post-quantum encryption" feature comes across as a bit premature, but it's reassuring that someone is thinking about it.

Having said that, we don't recommend using post-quantum encryption yet. It works by layering one of the known quantum-proof encryption standards on top of a standard NordLynx session, which makes your VPN connection slower and more erratic. Until we can verify a real quantum cyberattack, post-quantum encryption is a needless precaution.

A kill switch cuts off your internet the instant you lose your connection to a NordVPN server. This protects you in case a server unexpectedly fails, and as a side benefit, prevents you from connecting to any fake VPN servers. You should keep the kill switch on at all times.

Split tunneling is available on NordVPN's Windows and Android apps (and Android TV by extension), along with its browser extensions. On Windows and Android, it splits by app: you can determine which apps get online through the VPN and which go unprotected. The browser extensions let you split by URL, so the VPN only protects certain sites.

NordVPN's apps link directly to its online help center. As always, we went in with a specific question in mind: whether the basic level of Threat Protection could block trackers, and if so, what kind. We found the categories on the written support page difficult to parse, especially the troubleshooting section — would the average user appreciate the difference between "app issues," "connection issues" and "errors"?

We correctly guessed that our question would be under "Using NordVPN -> Features," but the introductory article on Threat Protection and Threat Protection Pro was buried at the bottom of the list. Unfortunately, that made things more confusing, as this article says that Threat Protection (not Pro) both does and doesn't block trackers. In NordVPN's favor, however, using the search bar brought us instantly back to that article without any confusion.

Using NordVPN's live chat was a smooth and reassuring experience. From the time we decided to ask directly, it took us less than a minute to connect with a real person, who quickly cleared up the confusion and promised to update the confusing support page (we'll check back to see if they actually do).

NordVPN live chat support
Sam Chapman for Engadget

One other option is an email support form, which can be found both on the website and in the help sections of NordVPN apps. This is best for complex problems that require screenshots to explain, and promises a response within 24 hours.

NordVPN was founded in 2012. Launching with its desktop apps, it moved to iOS and Android in 2016, then added apps for browser extensions and smart TVs. Its developer, Nord Security, has no parent company, and its history is relatively uncontroversial. We've documented two notable incidents below, plus more about Nord Security's operations.

Nord Security was founded in Lithuania, and maintains offices there. Although Nord Security is registered in Amsterdam, NordVPN operates under a separate license in Panama, which makes any data requests subject to Panama's courts.

The first serious incident in NordVPN's history began in March 2018, when unidentified hackers managed to steal three private keys from one of Nord's data centers in Finland. Researchers didn't notice the leak until October 2019, well after the stolen keys had expired, but NordVPN's encryption was still technically vulnerable for several months.

We say "technically," because it was really only the outer layer of encryption — and even if they'd broken through it all, the hackers would only have seen browsing activity, not usernames, passwords or anything else sensitive. If anything, NordVPN's response actually makes us trust it more. It ended its relationship with the contractor who ran the Finnish data center and revamped its policies to eliminate the kind of negligence that led to the breach.

Arguably, its only real error was not immediately disclosing the breach. NordVPN learned about the leak and started addressing it in May 2018, but the news didn't break until more than a year later. That timing probably made it look more suspicious than any actual mishandling did.

Another minor controversy erupted in 2022, when PCMag and other outlets reported that NordVPN had edited its website to say that it would comply with data requests from law enforcement. NordVPN responded with a new post that said nothing had changed: their policy was always to comply with lawful requests, which — provided the requests were lawfully submitted through a Panamanian court — is literally their only option.

We're inclined to agree. VPNs are legal companies. They wouldn't last long if they openly declared their intent to break the law. The key is that when law enforcement comes calling, there shouldn't be anything to show them, as with the Turkish seizure of ExpressVPN. That's why verifiable no-logging policies are so important.

NordVPN is a great service on its own merits. It only suffers from having to be compared with the likes of ExpressVPN and Proton VPN. For example, its P2P servers are good for torrenting, but not as useful without Proton's port forwarding. It's fast, but speed tests fluctuated just a little more than Express.

NordVPN's extra features are the best reason to pick it over its rivals. With Meshnet, you can theoretically set up a VPN connection anywhere in the world, and no other VPN has anything close to Meshnet's file transfer powers. Threat Protection Pro is also great if you can get it, adding file scanning to bolster the typical approach of just blocking suspicious DNS addresses. Specialty servers round out the offering, with double VPN maintaining good speeds with extra safety and Onion over VPN being among the safest ways to use Tor.

This article originally appeared on Engadget at https://www.engadget.com/cybersecurity/vpn/nordvpn-review-2025-innovative-features-a-few-missteps-163000578.html?src=rss