Live data from Hacker News

(L)Awful Interception

mullvad.net

11–20 of 36 posts

Re: (L)Awful Interception

#11
How trustworthy are these VPN services?

I use them because it's the best I can do, but I'm very suspicious. I would think the NSA is misappropriating my tax dollars if they hadn't compromised all of the VPN providers years ago. We also know the US has a history of selling compromised security equipment (https://www.washingtonpost.com/graphics/2020/world/national-...)

Don't get me wrong, I wish the NSA wasn't what it is, but if I'm paying for the federal government to be doing work, I expect them to do it exceedingly well.

So what's the case the United States is so incompetent as to let Mullvad go untapped?

Edit: the answer is that there apparently is no case. maqp was writing up the answer to my question in a response to another comment while I was writing mine.

Edit 2: My personal threat model largely accepts that the NSA, CIA, and FBI can have their way with me in the unlikely event that they notice my existence. I can live with that because they have no reason to take notice. Despite my annoying moral values, I'm not a threat to the state. However, I find the focus on nation-state actors in an ad for a service that clearly can't protect from them to be distressingly dishonest.

Re: (L)Awful Interception

#12
post #11

How trustworthy are these VPN services? I use them because it's the best I can do, but I'm very suspicious. I would think the NSA is misappropriating my tax dollars if they hadn't compromised all of the VPN providers years ago. We also know the US has a history of selling compromised security equipment ( https://www.washingtonpost.com/graphics/2020/world/national-... ) Don't get me wrong, I wish the NSA wasn't what i…

There's a difference between what the NSA and CIA can do and what the FBI can do. Even if you are an outspoken dissident, the FBI likely won't burn the supposed fact that they have backdoored all VPN companies to try to prosecute you. The value in clandestine backdoors like these are for intelligence, not law enforcement.

Re: (L)Awful Interception

#14
post #11

How trustworthy are these VPN services? I use them because it's the best I can do, but I'm very suspicious. I would think the NSA is misappropriating my tax dollars if they hadn't compromised all of the VPN providers years ago. We also know the US has a history of selling compromised security equipment ( https://www.washingtonpost.com/graphics/2020/world/national-... ) Don't get me wrong, I wish the NSA wasn't what i…

I generally don't trust VPNs that seem to have a huge budget to spend on advertising, because that usually means they have had a shotload of investment that a VPN service will never be able to return to the investors. These VPNs are invariably owned in some weird ownership structure in jurisdictions I don't have any confidence in.

Re: (L)Awful Interception

#16
post #11

How trustworthy are these VPN services? I use them because it's the best I can do, but I'm very suspicious. I would think the NSA is misappropriating my tax dollars if they hadn't compromised all of the VPN providers years ago. We also know the US has a history of selling compromised security equipment ( https://www.washingtonpost.com/graphics/2020/world/national-... ) Don't get me wrong, I wish the NSA wasn't what i…

Depends on what you want to use a VPN for. If your use case is pirating the latest TV show, any VPN that's been subpoenaed and produced no records like PIA will be fine. If your use case is something that could get you in trouble with actual authorities, you'd be a fool to ever use your own internet connection. A clean (never had any of your PII or files on it) computer and a long-range wifi antenna to a public hotspot is the only level of security I find acceptable. The computer should never visit any sites you visit and obviously should never log into anything. Ideally while using it you should shut down your personal wifi so the potentially compromised hot computer never detects it as the strongest wifi signal.

The correct level of paranoia is behaving in such a way that all your systems could be fully compromised and it would still never link to your real identity. If you're scared of anything short of a signal locator van you're doing it wrong.

Re: (L)Awful Interception

#17
post #9

Earlier quoted context omitted.

> or is it more like of a `cat atlantic_pipeline | grep bomb` thing For what us ordinary people know, there are "selectors", something similar in purpose to regular expressions, that can filter out data out of the streams (not just raw IP communications, but also phone call metadata and PIR datasets from airlines) for storage and human inspection. Think of stuff like the phone numbers, names or email addresses of kno…

It also can be used once shortlists are determined. EG, we suspect person 1. Now, do a deep search on 1, find associates, do deep search one those.

And it gets even “better”: the “association” goes three levels deep. Basically, your friends’ friends’ friends. So if Alice knows Bob, Bob also knows Charlie, and Charlie also knows Dave, the mere suspicion against Alice is enough to sweep Dave into the dragnet.

https://www.theguardian.com/world/interactive/2013/oct/28/ns...

Re: (L)Awful Interception

#18

I've only heard good things about mullvad and their Wireguard-based VPN solution (...so long as random reddit comments and forum posts are to be trusted). I wonder what 5/9/14 eyes actually do with the intercepted data? Isn't mere processing of the said data, a gargantuan task? Is this where Palantir comes to play or is it more like of a `cat atlantic_pipeline | grep bomb` thing?

It is really awesome. I was looking for a solution that allowed me to use the native Wireguard implementation without needing a third-party proprietary client. Mullvad was it and port forwarding was just one additional benefit. Vopono works great for my use cases, although I have a hard time sending everything through a VPN because pretty much every VPN provider is going to put you into captcha hell or some services…

Yes, it’s great to be able to just use pure WireGuard - I’m allergic to the idea of VPN providers expecting you to run their proprietary app. WireGuard has a great iOS app these days too.

Re: (L)Awful Interception

#19
post #10
post #3

This feels like mullad is trying to tell us something? Or, maybe, it's just slightly inept at lobbying for their cause? It should really end with a specific call to action, or at least mention if there's any legislation going through the process right now that needs support or opposition? I guess the call-to-action is to use Mullvad (which I happen to do, and can't complain about). For Germany, I will add http://frei…

You might want to remind people what commercial VPNs are good for: it masks the IP from _COMMERCIAL_ entities. It doesn't protect from the NSAs of the world because they have no restrictions in what VPN foreign servers they compromise, and FVEY routinely bypasses constitutional protections by compromising servers of opposing countries, e.g. GCHQ and NSA exchange data they extract from the opposing countries citizens.…

> Mullvad and other VPNs only provide trivial layer of IP address masking, they don't automatically block the endless list of tracking elements from HTTP headers to web bugs, LSOs, JWTs, cookies, webRTC, or canvas fingerprinting, and user actions on the site.

I’ve been a Mullvad user for a few years now and I’ve been quite happy with them but one thing I’ve noticed is that, no matter how I’ve got Mullvad or my browser configured, BBC/Channel 4 knows I’m not actually in the UK. If anyone has any idea how they’re getting my location I’d be curious to know.

Re: (L)Awful Interception

#20
Strange the article doesn't mention CALEA[0] for the United States. This is what actual local/state/federal law enforcement uses (with a court order) for data/voice intercept.

What's interesting about CALEA is it (essentially) requires compliance via devices with "LI" (lawful intercept) functionality and/or third party providers to provide "tap/trace" functionality in such a way that it's not even visible/detectable to the network provider, network admins, etc.

This LI functionality is typically implemented at the network device/operating system level as defined by an ETSI standard[1]. I've never implemented it personally but from what I understand it basically allows for an LI provider to siphon off tap/trace data with something like a VPN back to the LI provider, who is also the contact for response to warrants, etc.

So what happens is the LI provider gets a warrant for something like "give us everything to/from this device or phone number". The provider verifies the legality of the warrant, uses the ETSI standard to one or more devices on the provider network, receives the data, and then provides it to law enforcement (in real time). The network provider isn't even aware of the court order.

The old trope in Mafia movies of "I got a guy inside the phone company to tip us off" hasn't been accurate since CALEA came into effect in 1995.

[0] https://www.fcc.gov/public-safety-and-homeland-security/poli...

[1] https://www.etsi.org/technologies/lawful-interception

Post reply on HN