Live data from Hacker News

(L)Awful Interception

mullvad.net

21–30 of 36 posts

Re: (L)Awful Interception

#21
post #12
post #11

How trustworthy are these VPN services? I use them because it's the best I can do, but I'm very suspicious. I would think the NSA is misappropriating my tax dollars if they hadn't compromised all of the VPN providers years ago. We also know the US has a history of selling compromised security equipment ( https://www.washingtonpost.com/graphics/2020/world/national-... ) Don't get me wrong, I wish the NSA wasn't what i…

There's a difference between what the NSA and CIA can do and what the FBI can do. Even if you are an outspoken dissident, the FBI likely won't burn the supposed fact that they have backdoored all VPN companies to try to prosecute you. The value in clandestine backdoors like these are for intelligence, not law enforcement.

With parallel construction the FBI doesn't need to burn anything.

Re: (L)Awful Interception

#22
By the way, the Max Schrems mentioned in the article has started an EU Privacy watchdog project:

https://noyb.eu/

Please suport them with an annual donation, they seem very dedicated and the work they're doing is very worthwhile (and have already gotten significant results).

Re: (L)Awful Interception

#23
post #10

Earlier quoted context omitted.

You might want to remind people what commercial VPNs are good for: it masks the IP from _COMMERCIAL_ entities. It doesn't protect from the NSAs of the world because they have no restrictions in what VPN foreign servers they compromise, and FVEY routinely bypasses constitutional protections by compromising servers of opposing countries, e.g. GCHQ and NSA exchange data they extract from the opposing countries citizens.…

> Mullvad and other VPNs only provide trivial layer of IP address masking, they don't automatically block the endless list of tracking elements from HTTP headers to web bugs, LSOs, JWTs, cookies, webRTC, or canvas fingerprinting, and user actions on the site. I’ve been a Mullvad user for a few years now and I’ve been quite happy with them but one thing I’ve noticed is that, no matter how I’ve got Mullvad or my browse…

Maybe they just assume that anyone on Mullvad isn't in the UK?

Re: (L)Awful Interception

#24
This is sort of an aside, but I find it interesting that so many people’s threat models include the NSA/CIA. I see it all over the privacy-focused forums and subreddits I read. Don’t get me wrong - I believe privacy is a fundamental right and a carte blanche dragnet approach used by these agencies is not appropriate, but paying $10/mo for ProtonMail and ProtonVPN isn’t going to address that threat. That said, there is a balance between digital security/privacy and living a normal life. If you are truly trying to hide your online activities from those agencies, you are going to need to live a very specific lifestyle.

I’m more concerned about my privacy being utterly raped for advertising purposes. That’s why I use a paid VPN, paid privacy-focused DNS, paid ProtonMail account, use Signal, etc. I could probably be better served from self hosting some of these things, but this is a good balance for me. It seems to me that this concern - hiding data from Google, Microsoft, Verizon, etc. - is secondary to hiding from the NSA/CIA in many open privacy conversations.

Note - I am sympathetic to the fact that there are hostile governments all over the world and privacy-tooling is mandatory for whistle blowers, activists, protestors, journalists, etc.

Re: (L)Awful Interception

#25
post #10

Earlier quoted context omitted.

You might want to remind people what commercial VPNs are good for: it masks the IP from _COMMERCIAL_ entities. It doesn't protect from the NSAs of the world because they have no restrictions in what VPN foreign servers they compromise, and FVEY routinely bypasses constitutional protections by compromising servers of opposing countries, e.g. GCHQ and NSA exchange data they extract from the opposing countries citizens.…

> Mullvad and other VPNs only provide trivial layer of IP address masking, they don't automatically block the endless list of tracking elements from HTTP headers to web bugs, LSOs, JWTs, cookies, webRTC, or canvas fingerprinting, and user actions on the site. I’ve been a Mullvad user for a few years now and I’ve been quite happy with them but one thing I’ve noticed is that, no matter how I’ve got Mullvad or my browse…

> BBC/Channel 4 knows I’m not actually in the UK. If anyone has any idea how they’re getting my location I’d be curious to know

Plenty ways to figure out you're connecting from behind a VPN. Aggressively filtering for well known residential address space, detecting suspicious changes in traffic patterns from shared blocks/IPs used by VPN companies, detecting split DNS behaviour, detecting much higher latency and/or lower TTL between the client and server than what's expected/average within that public address space, detecting unexpectedly low MSS/MTU on the segment behind NAT, ...

Re: (L)Awful Interception

#26

This is sort of an aside, but I find it interesting that so many people’s threat models include the NSA/CIA. I see it all over the privacy-focused forums and subreddits I read. Don’t get me wrong - I believe privacy is a fundamental right and a carte blanche dragnet approach used by these agencies is not appropriate, but paying $10/mo for ProtonMail and ProtonVPN isn’t going to address that threat. That said, there i…

I think this comment would also have worked without the "r" word.

Re: (L)Awful Interception

#27
post #3

This feels like mullad is trying to tell us something? Or, maybe, it's just slightly inept at lobbying for their cause? It should really end with a specific call to action, or at least mention if there's any legislation going through the process right now that needs support or opposition? I guess the call-to-action is to use Mullvad (which I happen to do, and can't complain about). For Germany, I will add http://frei…

>This feels like mullad is trying to tell us something?

I agree:

>If you would like to communicate in a truly safe manner, do not trust any 3rd party – encrypt yourself. Do not use any US-based service for anything secret, especially if you are a company or government handling PII information.

Re: (L)Awful Interception

#28
post #11

How trustworthy are these VPN services? I use them because it's the best I can do, but I'm very suspicious. I would think the NSA is misappropriating my tax dollars if they hadn't compromised all of the VPN providers years ago. We also know the US has a history of selling compromised security equipment ( https://www.washingtonpost.com/graphics/2020/world/national-... ) Don't get me wrong, I wish the NSA wasn't what i…

if you knew history of development of all mighty special agencies(look at ussr/russia, china etc), you would know that you could become of interest to them, even if you don't think you are a threat.

One of the benefits of mass surveillance(for the state) is that people of interest have no way of communicating with the world securely/secretly, they have to assume that everything is tapped and actively hostile to their communication setups.

That means that you could be recognized as a part of shortest path to undermine some person of interest, and there is no reason for you to assume that they will hesitate to harm you and your safety/comfort

Re: (L)Awful Interception

#29
post #16
post #11

How trustworthy are these VPN services? I use them because it's the best I can do, but I'm very suspicious. I would think the NSA is misappropriating my tax dollars if they hadn't compromised all of the VPN providers years ago. We also know the US has a history of selling compromised security equipment ( https://www.washingtonpost.com/graphics/2020/world/national-... ) Don't get me wrong, I wish the NSA wasn't what i…

Depends on what you want to use a VPN for. If your use case is pirating the latest TV show, any VPN that's been subpoenaed and produced no records like PIA will be fine. If your use case is something that could get you in trouble with actual authorities, you'd be a fool to ever use your own internet connection. A clean (never had any of your PII or files on it) computer and a long-range wifi antenna to a public hotsp…

Generally speaking - You want a library computer booted from a throw away bootable usb drive, located in a library a few hours away from your residence.

Re: (L)Awful Interception

#30
post #10

Earlier quoted context omitted.

You might want to remind people what commercial VPNs are good for: it masks the IP from _COMMERCIAL_ entities. It doesn't protect from the NSAs of the world because they have no restrictions in what VPN foreign servers they compromise, and FVEY routinely bypasses constitutional protections by compromising servers of opposing countries, e.g. GCHQ and NSA exchange data they extract from the opposing countries citizens.…

> Mullvad and other VPNs only provide trivial layer of IP address masking, they don't automatically block the endless list of tracking elements from HTTP headers to web bugs, LSOs, JWTs, cookies, webRTC, or canvas fingerprinting, and user actions on the site. I’ve been a Mullvad user for a few years now and I’ve been quite happy with them but one thing I’ve noticed is that, no matter how I’ve got Mullvad or my browse…

You might be sending a language in the request header (many browsers do this by default), something like en-gb.

I bet there are a few other areas this localization information leaks.

Post reply on HN