My Mullvad comparison was focused on the credential, not on the LAN model. Brute forcing the account was never the issue, I missed the point about device-to-device was the real threat, fair point. I'm starting implementing LAN connections as opt-in, not default.
Second point, you're also right, because I was mixing prevent and identify, preventions shouldn't need logs, we can't take an IP address and a timestamp and attach a user to it, and the AUP imply something else, I'll rephrase this.
Comments
You're right on both counts.
My Mullvad comparison was focused on the credential, not on the LAN model. Brute forcing the account was never the issue, I missed the point about device-to-device was the real threat, fair point. I'm starting implementing LAN connections as opt-in, not default.
Second point, you're also right, because I was mixing prevent and identify, preventions shouldn't need logs, we can't take an IP address and a timestamp and attach a user to it, and the AUP imply something else, I'll rephrase this.