Things you connect to or log in to are clearly going to be able to ID you at least with in the context of the login that you use regardless of what the VPN does.
I'm logged into HN through Mullvad as it happens. I usually leave it on regardless of what I'm doing because what I'm doing isn't my ISP's business even though I'm pretty happy with them.
Most likely these people just look to hide their torrenting, saying political shit on Twitter from employer and not share their choice of porn with local ISP. Also just adding one more layer between them and occasional scammer who can sometimes infer more broad geodata from their IP leaked from yet another database. Oh and now to avoid "Show your ID" page on the same porn sites.
It works well enough for this goal. Not everyone needs NSA-proof solution.
PS: Obviously more tech savvy people understand importance of hiding traffic on public WiFi, but I doubt average Joe the VPN user will buy VPN for this.
What percent on people on Hacker News who say they care about privacy live without Google, Apple, Microsoft and Facebook accounts?
How many people outside of HN do you think care about privacy for real? Like about adtech surveillance and not about their naked photos leaking?
I doubt either % is very high sadly. We tend to say we care, but very few people actually do anything or use self hosted solutions or not tied to Apple or Google ecosystems.
You really cant blame VPN providers for selling on "privacy" hype and not delivering because most people dont care either way.
Might be I wrong, but I feel in west for most normal people use VPNs for torrents, watching porn and hidding activity from school or employeer. Small subsets are also sport fans who bypass geo blocking and people scheming for cheaper regional prices on netflix / steam / consoles.
I blame mullvad for messing up, but I do not suspect them of working with some state sponsored surveillance programme at the moment.
Do you have any facts? I know they really on _additional_ stuff, but do you have sources showing that they never use cookies or source IPs?
On that topic, though, is the Mullvad Browser, who's entire intention is to defeat browser fingerprinting.