1
0
mirror of https://github.com/privacyguides/i18n.git synced 2025-08-24 23:29:18 +00:00
Files
i18n/i18n/zh/vpn.md
2025-04-17 05:35:51 +00:00

27 KiB
Raw Blame History

meta_title, title, icon, description, cover, global
meta_title title icon description cover global
Private VPN Service Recommendations and Comparison, No Sponsors or Ads - Privacy Guides VPN Services material/vpn The best VPN services for protecting your privacy and security online. Find a provider here that isn't out to spy on you. vpn.webp
randomize-element
table tbody

Protects against the following threat(s):

If you're looking for additional privacy from your ISP, on a public Wi-Fi network, or while torrenting files, a VPN may be the solution for you.

VPNs do not provide anonymity

Using a VPN will not keep your browsing habits anonymous, nor will it add additional security to non-secure (HTTP) traffic.

If you are looking for anonymity, you should use the Tor Browser. If you're looking for added security, you should always ensure you're connecting to websites using HTTPS. VPN不是良好安全实践的替代品。

Download Tor{ .md-button .md-button--primary } Tor Myths & FAQ{ .md-button }

Detailed VPN Overview :material-arrow-right-drop-circle:{.md-button}

推荐的供应商

Our recommended providers use encryption, support WireGuard & OpenVPN, and have a no logging policy. Read our full list of criteria for more information.

Provider Countries WireGuard Port Forwarding IPv6 Anonymous Payments
Proton 112+ :material-check:{ .pg-green } :material-alert-outline:{ .pg-orange } Partial Support :material-information-outline:{ .pg-blue } Limited Support Cash
IVPN 37+ :material-check:{ .pg-green } :material-alert-outline:{ .pg-orange } :material-information-outline:{ .pg-blue } Outgoing Only Monero, Cash
Mullvad 45+ :material-check:{ .pg-green } :material-alert-outline:{ .pg-orange } :material-check:{ .pg-green } Monero, Cash

Proton VPN

Proton VPN logo{ align=right }

Proton VPN是VPN领域的强有力竞争者他们自2016年以来一直保持运营。 Proton AG总部位于瑞士提供有限制的免费使用等级以及更具特色的高级选项。

:octicons-home-16: Homepage{ .md-button .md-button--primary } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title=Documentation} :octicons-code-16:{ .card-link title="Source Code" }

Downloads

:material-check:{ .pg-green } 112 Countries

Proton VPN has servers in 112 countries or 5 if you use their free plan.(1) Picking a VPN provider with a server nearest to you will reduce latency of the network traffic you send. 这是因为到达目的地的路由较短(跳数较少)。 { .annotate }

  1. Last checked: 2024-08-06

We also think it's better for the security of the VPN provider's private keys if they use dedicated servers, instead of cheaper shared solutions (with other customers) such as virtual private servers.

:material-check:{ .pg-green } Independently Audited

截至2020年1月Proton VPN已经接受了SEC咨询公司的独立审计。 SEC Consult在Proton VPN的Windows、Android和iOS应用程序中发现了一些中度和低度风险的漏洞在报告发布前Proton VPN都已经 "妥善修复"。 所发现的问题中没有任何一个能让攻击者远程访问你的设备或流量。 You can view individual reports for each platform at protonvpn.com. In April 2022 Proton VPN underwent another audit. A letter of attestation was provided for Proton VPN's apps on 9th November 2021 by Securitum.

:material-check:{ .pg-green } Open-Source Clients

Proton VPN provides the source code for their desktop and mobile clients in their GitHub organization.

:material-check:{ .pg-green } Accepts Cash

Proton VPN, in addition to accepting credit/debit cards, PayPal, and Bitcoin, also accepts cash/local currency as an anonymous form of payment.

:material-check:{ .pg-green } WireGuard Support

Proton VPN supports the WireGuard® protocol. WireGuard is a newer protocol that uses state-of-the-art cryptography. 此外, WireGuard旨在更简单、更高效。

Proton VPN recommends the use of WireGuard with their service. Proton VPN also offers a WireGuard configuration generator for use with the official WireGuard apps.

:material-alert-outline:{ .pg-orange } Limited IPv6 Support

Proton now supports IPv6 in their browser extension and Linux client, but only 80% of their servers are IPv6-compatible. On other platforms, the Proton VPN client will block all outgoing IPv6 traffic, so you don't have to worry about your IPv6 address being leaked, but you will not be able to connect to any IPv6-only sites, nor will you be able to connect to Proton VPN from an IPv6-only network.

:material-information-outline:{ .pg-info } Remote Port Forwarding

Proton VPN currently only supports ephemeral remote port forwarding via NAT-PMP, with 60 second lease times. The official Windows and Linux apps provide an easy-to-access option for it, while on other operating systems you'll need to run your own NAT-PMP client. Torrent applications often support NAT-PMP natively.

:material-information-outline:{ .pg-blue } Anti-Censorship

Proton VPN has their Stealth protocol which may help in situations where VPN protocols like OpenVPN or WireGuard are blocked with various rudimentary techniques. Stealth encapsulates the VPN tunnel in TLS session in order to look like more generic internet traffic.

Unfortunately, it does not work very well in countries where sophisticated filters that analyze all outgoing traffic in an attempt to discover encrypted tunnels are deployed. Stealth is available on Android, iOS, Windows, and macOS, but it's not yet available on Linux.

:material-check:{ .pg-green } Mobile Clients

Proton VPN has published App Store and Google Play clients, both supporting an easy-to-use interface as opposed to requiring you to manually configure your WireGuard connection. The Android client is also available on GitHub.

How to opt out of sharing telemetry

On Android, Proton hides telemetry settings under the misleadingly labeled "Help us fight censorship" menu in the settings panel. On other platforms these settings can be found under the "Usage statistics" menu.

We are noting this because while we don't necessarily recommend against sharing anonymous usage statistics with developers, it is important that these settings are easily found and clearly labeled.

:material-information-outline:{ .pg-blue } Additional Notes

Proton VPN clients support two-factor authentication on all platforms. Proton VPN has their own servers and datacenters in Switzerland, Iceland and Sweden. They offer content blocking and known-malware blocking with their DNS service. Additionally, Proton VPN also offers "Tor" servers allowing you to easily connect to onion sites, but we still strongly recommend using the official Tor Browser for this purpose.

:material-alert-outline:{ .pg-orange } Kill switch feature is broken on Intel-based Macs

System crashes may occur on Intel-based Macs when using the VPN kill switch. If you require this feature, and you are using a Mac with Intel chipset, you should consider using another VPN service.

IVPN

IVPN标志{ align=right }

IVPN是另一个高级VPN供应商他们自2009年以来一直在运营。 IVPN is based in Gibraltar and does not offer a free trial.

:octicons-home-16: Homepage{ .md-button .md-button--primary } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title=Documentation} :octicons-code-16:{ .card-link title="Source Code" }

Downloads

:material-check:{ .pg-green } 37 Countries

IVPN has servers in 37 countries.(1) Picking a VPN provider with a server nearest to you will reduce latency of the network traffic you send. 这是因为到达目的地的路由较短(跳数较少)。 { .annotate }

  1. Last checked: 2024-08-06

We also think it's better for the security of the VPN provider's private keys if they use dedicated servers, instead of cheaper shared solutions (with other customers) such as virtual private servers.

:material-check:{ .pg-green } Independently Audited

IVPN has had multiple independent audits since 2019 and has publicly announced their commitment to annual security audits.

:material-check:{ .pg-green } Open-Source Clients

As of February 2020 IVPN applications are now open source. Source code can be obtained from their GitHub organization.

:material-check:{ .pg-green } Accepts Cash and Monero

In addition to accepting credit/debit cards and PayPal, IVPN accepts Bitcoin, Monero and cash/local currency (on annual plans) as anonymous forms of payment. Prepaid cards with redeem codes are also available.

:material-check:{ .pg-green } WireGuard Support

IVPN supports the WireGuard® protocol. WireGuard is a newer protocol that uses state-of-the-art cryptography. 此外, WireGuard旨在更简单、更高效。

IVPN recommends the use of WireGuard with their service and, as such, the protocol is the default on all of IVPN's apps. IVPN also offers a WireGuard configuration generator for use with the official WireGuard apps.

:material-information-outline:{ .pg-blue } IPv6 Support

IVPN allows you to connect to services using IPv6 but doesn't allow you to connect from a device using an IPv6 address.

:material-alert-outline:{ .pg-orange } Remote Port Forwarding

IVPN previously supported port forwarding, but removed the option in June 2023. Missing this feature could negatively impact certain applications, especially peer-to-peer applications like torrent clients.

:material-check:{ .pg-green } Anti-Censorship

IVPN has obfuscation modes using V2Ray which helps in situations where VPN protocols like OpenVPN or WireGuard are blocked. Currently, this feature is only available on Desktop and iOS. It has two modes where it can use VMess over QUIC or TCP connections. QUIC is a modern protocol with better congestion control and therefore may be faster with reduced latency. The TCP mode makes your data appear as regular HTTP traffic.

:material-check:{ .pg-green } Mobile Clients

IVPN has published App Store and Google Play clients, both supporting an easy-to-use interface as opposed to requiring you to manually configure your WireGuard connection. The Android client is also available on GitHub.

:material-information-outline:{ .pg-blue } Additional Notes

IVPN clients support two-factor authentication. IVPN also provides "AntiTracker" functionality, which blocks advertising networks and trackers from the network level.

Mullvad

Mullvad logo{ align=right }

Mullvad is a fast and inexpensive VPN with a serious focus on transparency and security. They have been in operation since 2009. Mullvad is based in Sweden and offers a 14-day money-back guarantee for payment methods that allow it.

:octicons-home-16: Homepage{ .md-button .md-button--primary } :simple-torbrowser:{ .card-link title="Onion Service" } :octicons-eye-16:{ .card-link title="Privacy Policy" } :octicons-info-16:{ .card-link title=Documentation} :octicons-code-16:{ .card-link title="Source Code" }

Downloads

:material-check:{ .pg-green } 49 Countries

Mullvad has servers in 49 countries.(1) Picking a VPN provider with a server nearest to you will reduce latency of the network traffic you send. 这是因为到达目的地的路由较短(跳数较少)。 { .annotate }

  1. Last checked: 2025-03-10

We also think it's better for the security of the VPN provider's private keys if they use dedicated servers, instead of cheaper shared solutions (with other customers) such as virtual private servers.

:material-check:{ .pg-green } Independently Audited

Mullvad has had multiple independent audits and has publicly announced their endeavors to conduct annual audits of their apps and infrastructure.

:material-check:{ .pg-green } Open-Source Clients

Mullvad provides the source code for their desktop and mobile clients in their GitHub organization.

:material-check:{ .pg-green } Accepts Cash and Monero

Mullvad, in addition to accepting credit/debit cards and PayPal, accepts Bitcoin, Bitcoin Cash, Monero and cash/local currency as anonymous forms of payment. Prepaid cards with redeem codes are also available. Mullvad also accepts Swish and bank wire transfers, as well as a few European payment systems.

:material-check:{ .pg-green } WireGuard Support

Mullvad supports the WireGuard® protocol. WireGuard is a newer protocol that uses state-of-the-art cryptography. 此外, WireGuard旨在更简单、更高效。

Mullvad recommends the use of WireGuard with their service. It is the default or only protocol on Mullvad's Android, iOS, macOS, and Linux apps, but on Windows you have to manually enable WireGuard. Mullvad also offers a WireGuard configuration generator for use with the official WireGuard apps.

:material-check:{ .pg-green } IPv6 Support

Mullvad allows you to access services hosted on IPv6 and connect from a device using an IPv6 address.

:material-alert-outline:{ .pg-orange } Remote Port Forwarding

Mullvad previously supported port forwarding, but removed the option in May 2023. Missing this feature could negatively impact certain applications, especially peer-to-peer applications like torrent clients.

:material-check:{ .pg-green } Anti-Censorship

Mullvad offers several features to help bypass censorship and access the internet freely:

  • Obfuscation modes: Mullvad has two built-in obfuscation modes: "UDP-over-TCP" and "WireGuard over Shadowsocks". These modes disguise your VPN traffic as regular web traffic, making it harder for censors to detect and block. Supposedly, China has to use a new method to disrupt Shadowsocks-routed traffic.
  • Advanced obfuscation with Shadowsocks and v2ray: For more advanced users, Mullvad provides a guide on how to use the Shadowsocks with v2ray plugin with Mullvad clients. This setup provides an additional layer of obfuscation and encryption.
  • Custom server IPs: To counter IP-blocking, you can request custom server IPs from Mullvad's support team. Once you receive the custom IPs, you can input the text file in the "Server IP override" settings, which will override the chosen server IP addresses with ones that aren't known to the censor.
  • Bridges and proxies: Mullvad also allows you to use bridges or proxies to reach their API (needed for authentication), which can help bypass censorship attempts that block access to the API itself.

:material-check:{ .pg-green } Mobile Clients

Mullvad has published App Store and Google Play clients, both supporting an easy-to-use interface as opposed to requiring you to manually configure your WireGuard connection. The Android client is also available on GitHub.

:material-information-outline:{ .pg-blue } Additional Notes

Mullvad is very transparent about which nodes they own or rent. They also provide the option to enable Defense Against AI-guided Traffic Analysis (DAITA) in their apps. DAITA protects against the threat of advanced traffic analysis which can be used to connect patterns in VPN traffic with specific websites.

Criteria

Danger

值得注意的是使用VPN供应商不会使你成为匿名者但在某些情况下会给你更好的隐私。 VPN不是非法活动的工具。 不要依赖 "无日志 "政策。

请注意,我们与我们推荐的任何供应商都没有关系。 这使我们能够提供完全客观的建议。 除了 我们的标准标准我们还为任何希望被推荐的VPN供应商制定了一套明确的要求包括强大的加密、独立的安全审计、现代技术等。 我们建议你在选择VPN供应商之前熟悉这份清单并进行自己的研究以确保你选择的VPN供应商尽可能值得信赖。

技术

We require all our recommended VPN providers to provide standard configuration files which can be used in a generic, open-source client. If a VPN provides their own custom client, we require a kill switch to block network data leaks when disconnected.

符合条件的最低要求。

  • Support for strong protocols such as WireGuard.
  • Kill switch built in to clients.
  • Multi-hop support. Multi-hopping is important to keep data private in case of a single node compromise.
  • If VPN clients are provided, they should be open source, like the VPN software they generally have built into them. We believe that source code availability provides greater transparency about what the program is actually doing.
  • Censorship resistance features designed to bypass firewalls without DPI.

Best Case:

  • Kill switch with highly configurable options (enable/disable on certain networks, on boot, etc.)
  • 易于使用的VPN客户端
  • IPv6 support. 我们希望服务器将允许通过IPv6的传入连接并允许你访问IPv6地址上托管的服务。
  • 远程端口转发的能力 在使用P2P (Peer-to-Peer) 文件共享软件或托管服务器如Mumble有助于创建连接。
  • Obfuscation technology which camouflages the true nature of internet traffic, designed to circumvent advanced internet censorship methods like DPI.

隐私

We prefer our recommended providers to collect as little data as possible. 不在注册时收集个人信息,并接受匿名的支付方式,这是必须的。

符合条件的最低要求。

  • Anonymous cryptocurrency or cash payment option.
  • 注册时不需要提供个人信息。最多只有用户名、密码和电子邮件。

Best Case:

  • Accepts multiple anonymous payment options.
  • No personal information accepted (auto-generated username, no email required, etc.).

安全性

A VPN is pointless if it can't even provide adequate security. We require all our recommended providers to abide by current security standards. Ideally, they would use more future-proof encryption schemes by default. We also require an independent third-party to audit the provider's security, ideally in a very comprehensive manner and on a repeated (yearly) basis.

符合条件的最低要求。

  • Strong Encryption Schemes: OpenVPN with SHA-256 authentication; RSA-2048 or better handshake; AES-256-GCM or AES-256-CBC data encryption.
  • Forward Secrecy.
  • Published security audits from a reputable third-party firm.
  • VPN servers that use full-disk encryption or are RAM-only.

Best Case:

  • Strongest Encryption: RSA-4096.
  • Optional quantum-resistant encryption.
  • Forward Secrecy.
  • Comprehensive published security audits from a reputable third-party firm.
  • Bug-bounty programs and/or a coordinated vulnerability-disclosure process.
  • RAM-only VPN servers.

Trust

You wouldn't trust your finances to someone with a fake identity, so why trust them with your internet data? We require our recommended providers to be public about their ownership or leadership. We also would like to see frequent transparency reports, especially in regard to how government requests are handled.

符合条件的最低要求。

  • Public-facing leadership or ownership.
  • Company based in a jurisdiction where it cannot be forced to do secret logging.

Best Case:

  • Public-facing leadership.
  • Frequent transparency reports.

Marketing

With the VPN providers we recommend we like to see responsible marketing.

符合条件的最低要求。

  • Must self-host analytics (i.e., no Google Analytics).

Must not have any marketing which is irresponsible:

  • Making guarantees of protecting anonymity 100%. When someone makes a claim that something is 100% it means there is no certainty for failure. We know people can quite easily deanonymize themselves in a number of ways, e.g.:
    • Reusing personal information (e.g., email accounts, unique pseudonyms, etc.) that they accessed without anonymity software (Tor, VPN, etc.)
    • Browser fingerprinting
  • Claim that a single circuit VPN is "more anonymous" than Tor, which is a circuit of three or more hops that regularly changes.
  • Use responsible language: i.e., it is okay to say that a VPN is "disconnected" or "not connected", however claiming that someone is "exposed", "vulnerable" or "compromised" is needless use of alarming language that may be incorrect. For example, that person might simply be on another VPN provider's service or using Tor.

Best Case:

Responsible marketing that is both educational and useful to the consumer could include:

  • An accurate comparison to when Tor should be used instead.
  • Availability of the VPN provider's website over a .onion service

Additional Functionality

While not strictly requirements, there are some factors we looked into when determining which providers to recommend. These include content blocking functionality, warrant canaries, excellent customer support, the number of allowed simultaneous connections, etc.